- On LLMs and Vulnerability Research
- More egress filtering bypasses in harden-runner
- Needle in the haystack: LLMs for vulnerability research
- Four Vulnerabilities in Parse Server
- Bypassing egress filtering in BullFrog GitHub Action using shared IP
- Hacking Better-Hub
- sudo restriction bypass via Docker Group in BullFrog GitHub Action
- Bypassing egress filtering in BullFrog GitHub Action
- [CVE-2026-25598] Bypassing Outbound Connections Detection in harden-runner
- HonoJS JWT/JWKS Algorithm Confusion
- Is Complexity just an illusion?
- ElysiaJS Cookie Signature Validation Bypass
- Do Your Bit Anyway
- AI powered SAST : The New Frontier?
- Reflections on my 5 years at HackerOne
- Hitchhiker's Guide to Attack Surface Management
- AI pentest scoping playbook
- On AI Slop vs OSS Security
- Art of Learning
- On Higher Order thinking
- On Learning
- Fragility of The Internet: How Sacrificial Nameservers allowed potential DNS hijacking of 1.6+ million domains
- Horrors of DNS: A Tale of 1800 potential domain takeovers due to mistyped NS
- Trojan War against State-of-the-Art LLMs