Notes & writeups
Writing
Tutorials, research, rants, and random thoughts
BrowserOS: Zero Click RCE
LLM controlling the browser, what can go wrong? (spoiler: everything)
SSRF in Nym Exit Nodes
A Server-Side Request Forgery vulnerability in Nym Technologies nym-node v1.30.0 and earlier allows a remote attacker to obtain sensitive information from internal services on exit gateways via SOCKS5 CONNECT requests
Finding Exposed LLM API Keys on GitHub
A weekend project, a few GitHub tokens, and 2,356 API keys later: a look at what vibe coding leaves behind.