41554 blogs · [ { "id": "01a096b8-1633-7044-a7ec-5ff01df519c7", "title": "Security Conference Speaking", "url": "https://chs.us/speaking/", "published_at": "2026-09-12T00:00:00+00:00" }, { "id": "01a096b8-1633-7044-a7ec-5ff01e4166b3", "title": "Security Research & Advisories", "url": "https://chs.us/research/", "published_at": "2026-09-12T00:00:00+00:00" }, { "id": "01a0b0b6-85d2-725f-983e-1f77266f783f", "title": "Vulnerability Disclosure Policy", "url": "https://chs.us/disclosure/", "published_at": "2026-09-12T00:00:00+00:00" }, { "id": "01a096b8-1633-7044-a7ec-5ff01e8fdada", "title": "About Carl Sampson — Security Researcher", "url": "https://chs.us/about/", "published_at": "2026-09-09T00:00:00+00:00" }, { "id": "01a096b8-1633-7044-a7ec-5ff01ed2da27", "title": "My Other Sites", "url": "https://chs.us/sites/", "published_at": "2026-09-09T00:00:00+00:00" }, { "id": "01a096b8-1633-7044-a7ec-5ff01f6b8a09", "title": "Security Tools & Projects", "url": "https://chs.us/projects/", "published_at": "2026-09-09T00:00:00+00:00" }, { "id": "01a096b8-1633-7044-a7ec-5ff01ff30619", "title": "Uses", "url": "https://chs.us/uses/", "published_at": "2026-09-08T00:00:00+00:00" }, { "id": "01a096b8-1633-7044-a7ec-5ff02043aeac", "title": "XSS (Cross-Site Scripting) Prevention Guide", "url": "https://chs.us/xss/", "published_at": "2026-09-08T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004b4528af", "title": "Hand-rolling an LDAP listener to catch Log4Shell callbacks", "url": "https://chs.us/2026/09/ldap-ber-listener-from-scratch/", "published_at": "2026-09-04T12:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004c0963ec", "title": "Fail the build when your CSP regresses", "url": "https://chs.us/2026/08/csp-ci-gating/", "published_at": "2026-08-28T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004c7ee746", "title": "Multi-tenant isolation as defense-in-depth: when WHERE owner_user_id isn't enough", "url": "https://chs.us/2026/07/multi-tenant-isolation-defense-in-depth/", "published_at": "2026-07-24T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004ceb3449", "title": "Six layers to sandbox untrusted Python — and the escape I missed", "url": "https://chs.us/2026/07/sandboxing-untrusted-python/", "published_at": "2026-07-15T12:00:00+00:00" }, { "id": "01a096b8-1633-7044-a7ec-5ff02372df7e", "title": "Interactive Security Tools", "url": "https://chs.us/tools/", "published_at": "2026-07-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004dbbb0dc", "title": "Building an authoritative DNS server in ~200 lines", "url": "https://chs.us/2026/07/authoritative-dns-from-scratch/", "published_at": "2026-07-08T12:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004dfc7f11", "title": "The OWASP LLM Top 10: A Practitioner's Field Guide", "url": "https://chs.us/2026/07/owasp-llm-top-10/", "published_at": "2026-07-05T10:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004e7a4f74", "title": "Hand-rolling the JNDI Reference: what the JVM actually deserializes", "url": "https://chs.us/2026/07/jndi-reference-deserialization/", "published_at": "2026-07-01T12:00:00+00:00" }, { "id": "01a096b8-1634-71b1-b464-5173bf6dcb2c", "title": "Newsletter", "url": "https://chs.us/newsletter/", "published_at": "2026-07-01T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004f142490", "title": "OWASP A05: Injection Prevention Guide 2025", "url": "https://chs.us/2026/06/owasp-a05-injection-prevention/", "published_at": "2026-06-30T18:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004fa6e4a5", "title": "OWASP A04: Cryptographic Failures Guide 2025", "url": "https://chs.us/2026/06/owasp-a04-cryptographic-failures-prevention/", "published_at": "2026-06-30T16:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00505610cb", "title": "OWASP A03: Software Supply Chain Failures Guide 2025", "url": "https://chs.us/2026/06/owasp-a03-software-supply-chain-failures-prevention/", "published_at": "2026-06-30T14:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0050be026e", "title": "Book Review: The Developer's Playbook for Large Language Model Security: Building Secure AI Applications", "url": "https://chs.us/2026/06/developers-playbook-llm-security-review/", "published_at": "2026-06-22T16:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0050f88c64", "title": "Don't Trust JWT Headers: Algorithm Confusion Attacks Explained", "url": "https://chs.us/2026/05/jwt-algorithm-confusion-attacks/", "published_at": "2026-05-27T22:00:06+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0051f64746", "title": "OWASP A01: Broken Access Control Prevention Guide", "url": "https://chs.us/2026/06/owasp-a01-broken-access-control-prevention/", "published_at": "2026-05-06T10:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0052432bcb", "title": "OWASP Top 10 2025 Developer Guide", "url": "https://chs.us/2026/05/owasp-top-10-2025-complete-developer-security-guide/", "published_at": "2026-05-05T20:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea005274fcaa", "title": "OWASP A02: Security Misconfiguration Guide 2025", "url": "https://chs.us/2026/05/owasp-a02-security-misconfiguration-prevention/", "published_at": "2026-05-05T16:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0042f0eefd", "title": "Authentication Bypass Security Guide", "url": "https://chs.us/guides/authentication-bypass/", "published_at": "2026-05-02T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0044ae87ff", "title": "Comprehensive Python Security Guide", "url": "https://chs.us/guides/python/", "published_at": "2026-05-02T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004580b515", "title": "Comprehensive OSINT Guide", "url": "https://chs.us/guides/osint/", "published_at": "2026-05-02T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004631bc3a", "title": "Comprehensive Bug Bounty Hunting Guide", "url": "https://chs.us/guides/bug-bounty/", "published_at": "2026-05-02T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0049b9e322", "title": "Comprehensive Session Management Security Guide", "url": "https://chs.us/guides/session-management/", "published_at": "2026-05-02T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004b19e3d0", "title": "Comprehensive Business Logic Flaws Guide", "url": "https://chs.us/guides/business-logic-flaws/", "published_at": "2026-05-02T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00533da529", "title": "Python SSRF Prevention Guide [2026]", "url": "https://chs.us/2026/05/python-ssrf-prevention-guide/", "published_at": "2026-05-01T14:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea005365e2ba", "title": "CSRF vs SSRF: Developer Guide [2026]", "url": "https://chs.us/2026/05/csrf-vs-ssrf-complete-guide/", "published_at": "2026-05-01T12:00:00+00:00" }, { "id": "01a08760-1c34-70d1-9e42-4b0c521bc376", "title": "XSS Prevention Guide 2026", "url": "https://chs.us/guides/xss/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea003d7e8d21", "title": "SSRF Prevention Guide 2026", "url": "https://chs.us/guides/ssrf/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea003eea0814", "title": "Comprehensive SQL Injection Guide", "url": "https://chs.us/guides/sqli/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea003fe04a7f", "title": "Comprehensive CSRF Guide", "url": "https://chs.us/guides/csrf/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004070386e", "title": "Comprehensive IDOR Guide", "url": "https://chs.us/guides/idor/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0040aaed70", "title": "Comprehensive RCE Guide", "url": "https://chs.us/guides/rce/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0041846869", "title": "Comprehensive XXE Guide", "url": "https://chs.us/guides/xxe/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004212d713", "title": "Comprehensive Insecure Deserialization Guide", "url": "https://chs.us/guides/deserialization/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004228c0ce", "title": "Comprehensive GraphQL Security Guide", "url": "https://chs.us/guides/graphql/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004342953d", "title": "API Security Guide 2026", "url": "https://chs.us/guides/api-security/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00441aacde", "title": "Comprehensive Authorization & Access Control Guide", "url": "https://chs.us/guides/authz/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00447c0c29", "title": "Comprehensive Mobile Application Security Guide", "url": "https://chs.us/guides/mobile/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0044de1ad5", "title": "Comprehensive Fuzzing Guide", "url": "https://chs.us/guides/fuzzing/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004535f868", "title": "Comprehensive Recon Guide", "url": "https://chs.us/guides/recon/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0045f23ca3", "title": "Comprehensive Secrets Management & Leakage Guide", "url": "https://chs.us/guides/secrets/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00464d6962", "title": "Software Supply Chain Security Guide", "url": "https://chs.us/guides/supply-chain/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0046c87c00", "title": "Comprehensive Burp Suite Guide", "url": "https://chs.us/guides/burp-suite/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea0047bd5a8d", "title": "Comprehensive AI / LLM Security Guide", "url": "https://chs.us/guides/ai/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00487a384f", "title": "Comprehensive Authentication Guide", "url": "https://chs.us/guides/authentication/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00491b4163", "title": "Comprehensive JWT Security Guide", "url": "https://chs.us/guides/jwt/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00491ed51d", "title": "Comprehensive SSTI Guide", "url": "https://chs.us/guides/ssti/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea004aafe6fa", "title": "Security Conference Talks & Research Guide", "url": "https://chs.us/guides/talks/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00544055e4", "title": "AppSec.fyi Hits 2,200+ Resources: What's New", "url": "https://chs.us/2026/04/appsec-fyi-2200-resources/", "published_at": "2026-04-07T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea00545d625c", "title": "MCP Tool Poisoning: Hidden Attack Surface", "url": "https://chs.us/2026/04/mcp-tool-poisoning/", "published_at": "2026-04-03T00:00:00+00:00" }, { "id": "01a08760-1c35-738f-be18-ea003c7fa647", "title": "Web Security Hub 2026", "url": "https://chs.us/guides/web-vulnerabilities/", "published_at": null }, { "id": "01a08760-1c35-738f-be18-ea003e55bd80", "title": "API Security Hub 2026", "url": "https://chs.us/guides/api-security-hub/", "published_at": null }, { "id": "01a08760-1c35-738f-be18-ea003f7f9273", "title": "Security Testing Hub 2026", "url": "https://chs.us/guides/testing-methodology/", "published_at": null } ] posts Claim your blog
Back to chs.us
Blog · corpus.blog/blogs/chs.us/posts

chs.us

chs.us

2026

8 Sept 2026

Undated