Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

WeLiveSecurity research Nov 13

How password managers can be hacked – and how to stay safe

Look no further to learn how cybercriminals could try to crack your vault and how you can keep your logins safe

WeLiveSecurity → Details

PortSwigger Research research Nov 11

Introducing HTTP Anomaly Rank

HTTP Anomaly Rank If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses ...

PortSwigger Research → Details

WeLiveSecurity research Nov 11

Why shadow AI could be your biggest security blind spot

From unintentional data leakage to buggy code, here’s why you should care about unsanctioned AI use in your company

WeLiveSecurity → Details

WeLiveSecurity research Nov 7

In memoriam: David Harley

Former colleagues and friends remember the cybersecurity researcher, author, and mentor whose work bridged the human and technical sides of security

WeLiveSecurity → Details

WeLiveSecurity research Nov 7

The who, where, and how of APT attacks in Q2 2025–Q3 2025

ESET Chief Security Evangelist Tony Anscombe highlights some of the key findings from the latest issue of the ESET APT Activity Report

WeLiveSecurity → Details

WeLiveSecurity research Nov 6

ESET APT Activity Report Q2 2025–Q3 2025

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2025 and Q3 2025

WeLiveSecurity → Details

WeLiveSecurity research SAP Nov 5

Sharing is scaring: The WhatsApp scam you didn’t see coming

How a fast-growing scam is tricking WhatsApp users into revealing their most sensitive financial and other data

WeLiveSecurity → Details

PortSwigger Research research Sep 17

WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine

Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis.

PortSwigger Research → Details

PortSwigger Research research Sep 3

Cookie Chaos: How to bypass __Host and __Secure cookie prefixes

Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies.

PortSwigger Research → Details

PortSwigger Research research Aug 26

Inline Style Exfiltration: leaking data with chained CSS conditionals

I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes!

T1041

PortSwigger Research → Details

PortSwigger Research research Aug 19

Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling

Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining.

PortSwigger Research → Details

PortSwigger Research research Aug 6

HTTP/1.1 must die: the desync endgame

Abstract Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover.

PortSwigger Research → Details

PortSwigger Research research Jul 15

Repeater Strike: manual testing, amplified

Manual testing doesn't have to be repetitive.

PortSwigger Research → Details

PortSwigger Research research Apr 30

Drag and Pwnd: Leverage ASCII characters to exploit VS Code

Control characters like SOH, STX, EOT and ETX were never meant to run your code - but in the world of modern terminal emulators, they sometimes do.

PortSwigger Research → Details

PortSwigger Research research Apr 23

Document My Pentest: you hack, the AI writes it up!

Tired of repeating yourself? Automate your web security audit trail.

PortSwigger Research → Details

PortSwigger Research research GitLab Mar 18

SAML roulette: the hacker always wins

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Ent...

PortSwigger Research → Details

PortSwigger Research research Feb 20

Shadow Repeater:AI-enhanced manual testing

Have you ever wondered how many vulnerabilities you've missed by a hair's breadth, due to a single flawed choice?

PortSwigger Research → Details

PortSwigger Research research Feb 4

Top 10 web hacking techniques of 2024

Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web s...

PortSwigger Research → Details

PortSwigger Research research Jan 28

Bypassing character blocklists with unicode overflows

Unicode codepoint truncation - also called a Unicode overflow attack - happens when a server tries to store a Unicode character in a single byte.

T1598

PortSwigger Research → Details

PortSwigger Research research Jan 22

Stealing HttpOnly cookies with the cookie sandwich technique

In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers.

PortSwigger Research → Details

«Previous page 1 ... 15 16 17 18 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA