← Back to feed
research PortSwigger Research

Hiding payloads in Java source code strings

PortSwigger Research Oracle

In this post we'll show you how Java handles unicode escapes in source code strings in a way you might find surprising - and how you can abuse them to concea...

Read the full story PortSwigger Research →

Related Coverage

research What's in a tag name? JavaScript, apparently PortSwigger Research · Aug 25 research State divergence enables unauthorized access Trail of Bits · Aug 25 research The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Unit 42 · Aug 25