BlogSecurity Research
CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint
Nico WaismanBlogCompany News
XBOW on HackerOne: What’s Next
Nico WaismanBlogCompany News
Black Hat & DEF CON: Running XBOW Live, Presentation Slides, and The Talk You Didn’t Miss
Nico WaismanBlogSecurity Research
The Campaign Is Not Available in Your Country: XBOW Discovered an SQLi While Attempting to Bypass Geolocation Restrictions.
Nico WaismanBlogTechnical Deep Dive
How XBOW Turned a JavaScript Hint Into a Working File Inclusion
Nico WaismanBlogCompany News
The Road to Top 1: How XBOW Did It
Nico WaismanBlogSecurity Research
The Nightmare Before Christmas: An Arbitrary File Download on Zoo-Project
Nico WaismanBlogSecurity Research
SSRF & URI Validation Bypass in 2FAuth
Nico WaismanBlogSecurity Research