Research

JWT Attacks in Practice: Algorithm Confusion, alg:none, and Weak Secrets

The four JWT verification mistakes we find most in assessments: the alg:none downgrade, RS256-to-HS256 algorithm confusion, weak HMAC secrets, and jwk/jku/kid header injection. Why each works and what fixes it.

August 25, 2026
Research

IDN Homograph Attacks Revisited: Browser Handling in 2026

A five-year status update on our IDN homograph writeup. Browsers largely handle the address bar now, but the attack moved to email, chat, and non-browser clients. Why passkeys, not warning banners, are the real fix.

August 12, 2026
Bug Bounty

Should You Start Bug Bounty in 2021?

An honest look at the current state of bug bounty hunting - what platforms pay, what the real competition looks like, and whether it makes sense to start now.

February 15, 2021
Research

IDN Homograph Attacks and Prevention

How attackers exploit Unicode lookalike characters to create convincing phishing domains, and the DNS-level and browser-level defenses that can stop them.

January 8, 2021
Disclosure

How RST and Isiraadithya Could Have Compromised Yahoo.com

Our coordinated disclosure of a stored XSS vulnerability chain in Yahoo Mail that could have enabled full account takeover through the attachment handler.

April 22, 2020
Research

0-Day Chains: Combining Low-Severity Bugs for Critical Impact

Why low-severity bugs should never be ignored - our methodology for identifying and chaining multiple vulnerabilities into critical exploit paths.

March 12, 2020