Writing
Writing on security, infrastructure, and whatever I'm taking apart.
On February 13, 2026, I reported a pre-authentication SQL injection in Moodle’s auth_db plugin to the Moodle bug bounty program on Bugcrowd. It was the kind of…
Today, cPanel quietly shipped an emergency security update across every supported branch. The advisory was short. There was a vague reference to “session loading…
I was recently included in IBD’s 2026 Coordinated Vulnerability Disclosure Hall of Fame for a responsible disclosure report involving an exposed Firebase Realtime…
The postMessage API lets different contexts in a browser talk to each other: iframes to parent windows, content scripts to page scripts, extension components to…
On February 12, 2026, I responsibly disclosed an open redirect vulnerability in LimeSurvey, the popular open-source survey platform. The issue was patched and…
Most people assume that using a VPN makes them anonymous online. Your real IP is hidden, your traffic is encrypted, and websites see the VPN server’s location…
Last week I was doing some bug bounty hunting and stumbled upon what many websites seem to be having nowadays: an LLM-powered chatbot. I thought it would be really…
Yesterday Joomla published version 3.6.4, an update to patch security issues: Because I was curious to see how these vulnerabilies worked I decided to check out the…