#securityresearch

3 posts · Last used 7d

Back to Timeline
Pratik M. Kamble @pratikkamble@infosec.exchange · Jul 19, 2026
Our recent work "Dead Weight: Analyzing Code Bloat and Its Security Implications in WebAssembly Binaries" was presented at DIMVA 2026 in Chania, Greece. We analyzed over 8,000 real-world WebAssembly binaries and found that 70-85% of compiled functions are never executed. Beyond just taking up space, this dead code leaves a large attack surface for indirect exploitation primitives. Proceedings to appear in Springer LNCS. Author preprint: https://www.pratikkamble.com/DIMVA2026_WasmBloat.pdf Work done with my advisor Dr. Aravind Prakash. Thank you for the guidance and support. #WebAssembly #SecurityResearch #BinaryAnalysis #DIMVA2026
0
0
0
Kallisti @kallisti@infosec.exchange · Jul 01, 2026
Replying to @kallisti@infosec.exchange
New blog post! The title should be self-explanatory, it's an appreciation post for Nightmare Eclipse. You might notice that the tone is a bit more emotional/angry than my usual style of writing. This one's personal. https://ti-kallisti.com/general/ms/nightmare-eclipse.html #NightmareEclipse #Microsoft #Hackers #InfoSec #SecurityResearch #ChainsawMan #Reze
15
2
15
Daniel Isaac E @daniel_e@infosec.exchange · Jul 13, 2026
🚨 The biggest mistake in modern web security? Believing your WAF is enough. For years, we were taught: Deploy a Web Application Firewall and you're protected. That mindset no longer matches how many real-world attacks work. Today's attackers increasingly focus on: 🔓 Broken Authorization (BOLA/BFLA) 🔑 Identity & OAuth/JWT abuse 🔌 API vulnerabilities 🧠 Business Logic flaws ⚡ Race Conditions 🤖 Legitimate functionality abused in unintended ways These attacks often don't rely on payloads that a WAF is designed to block. Instead, they exploit trust. As cybersecurity professionals, we need to think beyond signatures and filtering rules. Understanding how attackers chain application logic, identities, and APIs together is becoming just as important as finding SQL injection or XSS. I wrote an article exploring this shift in modern application security. 📖 Read it here: 👉 https://danielisaace.hashnode.dev/stop-trusting-your-waf-modern-attackers-have-already-moved-on I'm curious to hear from the community: What do you think is the most overlooked attack vector in modern web applications today? Your perspective might help someone else rethink their security strategy. #CyberSecurity #ApplicationSecurity #AppSec #WebSecurity #API #OWASP #EthicalHacking #PenetrationTesting #DevSecOps #SecurityResearch #CyberDefense #InfoSec
0
0
1

You've seen all posts