What’s your go-to bug class? Is it XSS? One could say cross-site scripting is a favourite among our researchers. Check it out:

How To Hack Web Applications in 2022: Part 2

Account hijacking using “dirty dancing” in sign-in OAuth-flows

How To Hack Web Applications in 2022: Part 1

CVE-2020-29653: Stealing Froxlor login credentials using dangling markup

Scratching the surface of host headers in Safari

Dissecting the Chrome Extension Facebook malware

How we invented the Tesla DOM DOOM XSS

A deep dive into AWS S3 access controls – taking full control over your assets

How I found a persistent XSS affecting thousands of career sites

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack