All articles
- Never Trust the Output: Data Pollution in AI Agents and MCP
- Make Self-XSS Great Again
- Why Protocol Matters: Evil PWA Attack on Casdoor
- DOM Purify - dirty namespace bypass
- Old new email attacks
- Exploring IPv6 Zone Identifier
- MySQL2: Dangers of User-Defined Database Connections
- DOM Purify - untrusted Node bypass
- CVE-2023-5480: Chrome new XSS Vector
- Who Am I