g3n3r4l14
-
AWS WAF Bypass: invalid JSON object and unicode escape sequences (blog.sicuranext.com)
-
Streamlining Websocket Pentesting with wsrepl (blog.doyensec.com)
-
Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style (sec-consult.com)
-
How hackers may steal your Ethers and why does eth\sign function (officercia.mirror.xyz)
-
Securing macOS: A Closer Look At Built-In macOS Application Security (picussecurity.com)
-
RedTeam Pentesting - Blog - Bringing Monsoon to the Next Level (blog.redteam-pentesting.de)
-
How Secrets Leak in CI/CD Pipelines (trufflesecurity.com)
-
SVG Security Risks - not just a scalable graphic (securesystems.de)
-
Server-Side Spreadsheet Injection - Formula Injection to… (bishopfox.com)
-
Serverless Functions Post-Mortem (matduggan.com)
-
New techniques and tools for web race conditions (portswigger.net)
-
Downfall Attacks (downfall.page)
g1thub12
-
ignis-sec/puff (github.com)
-
omar2535/GraphQLer (github.com)
-
doyensec/wsrepl (github.com)
-
scipag/websocket\fuzzer (github.com)
-
henry-richard7/Browser-password-stealer (github.com)
-
nullenc0de/ChromeAudit (github.com)
-
LemonSec/johnnyapplethief (github.com)
-
yunuscadirci/XboxOneDirectoryTraversal (github.com)
-
padok-team/cognito-scanner (github.com)
-
adityatelange/bhhb (github.com)
-
Escape-Technologies/goctopus (github.com)
-
hahwul/noir (github.com)