Riot Security Team (RiotSec) is an independent security research group focused on web application vulnerabilities and responsible disclosure. Our team identifies, documents, and reports security flaws in widely used platforms and services through coordinated disclosure programs.
What We Do
Our primary focus is web application security research. We specialize in finding vulnerabilities that automated tools miss - logic flaws, authentication bypasses, cross-site scripting in complex rendering pipelines, and vulnerability chains that combine multiple low-severity issues into critical attack paths.
We are active participants in bug bounty and vulnerability disclosure programs on HackerOne and Bugcrowd. Through these platforms, we have reported vulnerabilities to Yahoo, Microsoft, and other major technology companies. All of our research follows responsible disclosure practices - we coordinate with affected vendors and do not publish technical details until fixes are deployed.
Our Approach
We believe that security research should be thorough, ethical, and collaborative. Our methodology prioritizes understanding how applications work at a deep level rather than running automated scans. We invest significant time in reconnaissance, architecture mapping, and manual testing before we write a single line of exploit code.
When we find something, we write detailed reports that include clear reproduction steps, impact analysis, and remediation recommendations. We work with vendor security teams throughout the fix process and verify patches before considering a finding resolved.
This Blog
We use this blog to share research findings after disclosure windows have closed, discuss vulnerability classes and attack techniques, and provide practical guidance for other security researchers. Our goal is to contribute to the broader security community's understanding of the threats facing modern web applications.
Contact
For responsible disclosure inquiries, collaboration proposals, or general questions, reach us at [email protected].
For vulnerability reports affecting our own infrastructure, please email the same address with "Security" in the subject line.