Latest Posts

Deep-dive into the deployment of an on-premise low-privileged LLM server

Post
Charles Senges
Mar 20, 2026

Fantastic unwind information and where to find them

Post
klezVirus
Mar 16, 2026

Slacker Slash: Bypassing Bun Security Middleware via Normalization Desync

Post
Mohamed Salem Eddah
Mar 13, 2026

Python pitfalls: Turning developer mistakes into vulnerabilities

Post
YesWeHack
Feb 27, 2026

Total.js RCE gadgets all around

Post
Diyan Apostolov
Feb 23, 2026

XSLeaks Wiki

Post
Feb 10, 2026
webxsleaks

XML external entity: The ultimate Bug Bounty guide to exploiting XXE vulnerabilities

Post
YesWeHack
Feb 6, 2026

Top 10 web hacking techniques of 2025

Post
James Kettle
Feb 5, 2026

Beyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHound

Post
Noah Chaslin
Feb 2, 2026

Parse and Parse: MIME Validation Bypass to XSS via Parser Differential

Post
Tang Cheuk Hei
Jan 30, 2026