my new blogpost is out!!
this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration
and i've already used it to get a google docs bounty ^^
have fun <3
lyra.horse/blog/2025/12...
SVG Filters - Clickjacking 2.0
If you have a fediverse account, you can quote this note from your own instance. Search https://bsky.brid.gy/convert/ap/at://did:plc:bzdtu4vjo2quk2ef3ykhqtv6/app.bsky.feed.post/3m765a2oywc2f on your instance and quote it. (Note that quoting is not supported in Mastodon.)