Risk of reflected cross site scripting and Content-Security-Policy bypass in the WebSub intent verification Published: Jun 3 2026
computer web websub security xss
CVE-2026-50571
I was reading the WebSub specification (formerly PubSubHubbub ) when I found that there was a risk of reflected browser-side code injection (reflected cross site scripting , reflected XSS) in the WebSub intent verification exchange.
Read more…
Computer security guidelines and references Published: May 28 2026
computer security references
A list of computer security guidelines and references.
Read more…
computer web security nginx http
Two related authority-ambiguity vulnerabilities in NGINX and Debian's proxy_params configuration snippet.
Read more…
Cryptography formats Published: May 19 2026
computer security cryptography ssh jose jwt cose
If you are trying to understand the difference between the different cryptography-related formats (PKS#12, PKCS#8, PEM, X.509 certificate, DER, JWK, BEGIN ENCRYPTED PRIVATE KEY??? 🤯), you will hopefully find some useful information here (and a lot more your did not wanted to know about).
Read more…
Books I have read in 2025 Published: Jan 12 2026
book society
Books I have read in 2025. Should be mostly spoiler free.
Read more…
Asymmetric keys and Siths Published: Dec 8 2025
computer cryptography star-wars
Some (not so serious) cryptographic wisdom from a long time ago…
Read more…
Reinforcement Learning formulas cheat sheet Published: Sep 22 2025
computer machine-learning reinforcement-learning neural-networks
Cheat sheet for (some) reinforcement learning mathematical formulas and algorithms.
Read more…
Concealing XSS payloads Published: Aug 22 2025
computer security xss waf
PortSwigger “Concealing payloads in URL credentials” talks about concealing XSS payloads in URL credentials. The nice thing is that this makes the payload invisible to WAFs and other server-side XSS filters. You can actually conceal the payloads in other places
Read more…
Codingame Spring Challenge 2025 Published: Aug 22 2025
computer rust optimization profiling flamegraph
My experience from the Codingame Spring Challenge 2025 .
Read more…
computer security language-model LLM
Testing ASCII smuggling using Unicode Tags on LLMs/chatbots. Nothing new here. Just a short summary.
Read more…
Page 1 of 12 | Previous page | Next page | JSON Feed | Atom Feed | RSS Feed