Blog
Security Research
CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint
Nico WaismanSecurity Research
The Campaign Is Not Available in Your Country: XBOW Discovered an SQLi While Attempting to Bypass Geolocation Restrictions.
Nico WaismanSecurity Research
Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle
Alvaro MuñozSecurity Research
Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution
Alvaro MuñozSecurity Research
Finding XSS in Salesforce Aura Components: How XBOW Got Creative
Diego JuradoSecurity Research
CVE-2025-49493: XML External Entity (XXE) Injection in Akamai CloudTest
Diego JuradoSecurity Research
Breaking the Shield: How XBOW Discovered Multiple XSS Vulnerabilities in Palo Alto’s GlobalProtect VPN
Alvaro MuñozSecurity Research
The Nightmare Before Christmas: An Arbitrary File Download on Zoo-Project
Nico WaismanSecurity Research