Stories

CVE-2025-27580

You're so... Predictable Earlier this year, while red teaming some public-facing web apps, I came across an unknown vulnerability in a platform called BRICS. It relied on tokens generated using...

Password Reset Poisoning

Poisoning Password Reset Links

CVE-2024-53553

Authentication Bypass in FOIAXpress® Public Access Link (PAL)

Getting Started in Bug Bounty

The Bug Bounty Journey

Finding Hidden Features

Fuzzing to Find Hidden Features

OSINT and Weak Passwords

Leave No Stone Unturned

Writeups

Certificates