The four JWT verification mistakes we find most in assessments: the alg:none downgrade, RS256-to-HS256 algorithm confusion, weak HMAC secrets, and jwk/jku/kid header injection. Why each works and what fixes it.
A five-year status update on our IDN homograph writeup. Browsers largely handle the address bar now, but the attack moved to email, chat, and non-browser clients. Why passkeys, not warning banners, are the real fix.
An honest look at the current state of bug bounty hunting - what platforms pay, what the real competition looks like, and whether it makes sense to start now.
How attackers exploit Unicode lookalike characters to create convincing phishing domains, and the DNS-level and browser-level defenses that can stop them.
Our coordinated disclosure of a stored XSS vulnerability chain in Yahoo Mail that could have enabled full account takeover through the attachment handler.
Why low-severity bugs should never be ignored - our methodology for identifying and chaining multiple vulnerabilities into critical exploit paths.