
From Reflected XSS to Critical Bug Led to Sensitive Data Leakage
Chaining a reflected XSS with CORS misconfiguration to bypass origin restrictions and exfiltrate sensitive user data.
Security research, CTF walkthroughs, and bug hunting adventures

Chaining a reflected XSS with CORS misconfiguration to bypass origin restrictions and exfiltrate sensitive user data.

Exploring dark web data leakage, threat intelligence gathering, and analysis of underground cybercriminal operations.

A deep dive into CVE-2025-55182, a critical RCE vulnerability found in React server-side rendering implementations.

Complete reverse engineering walkthrough of the Zinad Cyber Champions CTF challenge, from binary analysis to flag extraction.

A bug bounty story detailing how a privilege escalation vulnerability allowed full application admin access.

Official writeup for the Facts machine from HackTheBox Season 10, covering web exploitation and Linux privilege escalation.

Analysis of CVE-2025-24071, a Windows File Explorer vulnerability that exposes NTLM hashes via crafted .library-ms files.

A comprehensive guide to Android application security testing, from setting up the environment to exploiting common vulnerabilities.