Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

OAuth Non-Happy Path to ATO- 1730

Omid RezaeiPosted 7 Months Ago

Forcing Quirks Mode with PHP Warnings + CSS Exfiltration without Network Requests- 1729

Takeshi KanekoPosted 7 Months Ago

You Already Have Our Personal Data, Take Our Phone Calls Too (FreePBX CVE-2025-57819) - 1728

Piotr Bazydlo - WatchTowrPosted 7 Months Ago

Slice: SAST + LLM Interprocedural Context Extractor - 1727

Caleb Gross Posted 7 Months Ago

When a SSRF is enough: Full Docker Escape on Windows Docker Desktop (CVE-2025-9074) - 1725

Felix BouletPosted 8 Months Ago

Phishing Emails Are Now Aimed at Users and AI Defenses- 1724

anuragPosted 8 Months Ago

Vtenext 25.02: A three-way path to RCE- 1723

Mattia (0xbro) BrolloPosted 8 Months Ago

How to Phish Users on Android Applications - Case Study on Meta Threads - 1722

remoteawesomethoughtsPosted 8 Months Ago

Cache Me If You - Sitecore Experience Platform Vulns- 1721

PIOTR BAZYDLO - WatchTowr Posted 8 Months Ago

All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge- 1720

Wil GibbsPosted 8 Months Ago