Research notes
Findings we reported, and the reading that came with them. Same facts, kept on this house domain.
- CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring
- CVE-2025-59489: Arbitrary Code Execution in Unity Runtime
- Beyond the Limit: Expanding single-packet race condition with a first sequence sync for breaking the 65,535 byte limit
- Bypassing DOMPurify with good old XML
- Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
- Achieving RCE in famous Japanese chat tool with an obsolete Electron feature
- Finding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql
- Finding bugs to trigger Unauthenticated Command Injection in a NETGEAR router (PSV-2022–0044)
- LLM App Security: Risk & Prevent for GenAI Development
- Security Risks of LLM Frameworks with Case Studies
- Non-Intrusive Web Recon: Techniques from Chrome DevTools Recorder
- Poisoning Claude Code: One Issue to Break the Supply Chain
- CVE-2020–15702 Race Condition vulnerability in handling of PID by apport
- Remote Command Execution in Google Cloud with Single Directory Deletion
- Securing LLM Function-Calling: Risks & Mitigations for AI Agents
- Why XSS Persists in This Frameworks Era?