Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

CVE-2025-54322 (ZERODAY) - Unauthenticated Root RCE affecting ~70,000+ Hosts- 1850

pwn.aiPosted 4 Months Ago

How init and init_if_needed work under the hood and the associated token account griefing attack- 1849

jesjupyterPosted 4 Months Ago

From Zero to Shell: Hunting Critical Vulnerabilities in AVideo - 1848

Valentin LobsteinPosted 4 Months Ago

Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096)- 1847

Mehmet IncePosted 4 Months Ago

The Arcanum Prompt Injection Taxonomy v1.5- 1846

Jason HaddixPosted 4 Months Ago

postMessage targetOrigin bypass opens room for OAuth authorization code stealing scenarios- 1845

Jakub DomerackiPosted 4 Months Ago

Cache Deception + CSPT: Turning Non Impactful Findings into Account Takeover- 1844

zerePosted 4 Months Ago

Mozilla VPN Clients: RCE via file write and path traversal- 1843

Trein - HackerOnePosted 4 Months Ago

Using Mintlify to Hack Fortune 500 Companies- 1842

eva, hackermon & MDLPosted 4 Months Ago

ORM Leaking More Than You Joined For- 1841

Alex Brown - elttamPosted 4 Months Ago