Pentesting Passkeys: A Practical Methodology for WebAuthn Deployments
Recon, server-side Relying Party tests, and the Windows-focused OS and authenticator attacks: end-to-end, tool by tool.
Field Notes from Black Hat US 2026 and DEF CON 34
Field notes from Black Hat USA 2026 and DEF CON 34: the talks that mattered to me most, honest questions about where AI-accelerated research is heading, and the deep dives I'm committing to next.
A Hacker's Guide to Post-Quantum Cryptography: ML-KEM & FIPS 203
Everything you need to understand the algorithm that's replacing RSA (in terms of Key Exchange), from polynomial rings to key encapsulation, with zero hand-waving.
Curing University Math Trauma: A Hacker's Guide to Cryptography
Remember sitting in university linear algebra, staring at the ceiling, begging the universe to tell you when you would EVER use this in the real world? Welcome. In this series, we take the seemingly useless math you slept through and show you how they secretly power the entire internet.
Road to Black Hat London 2025: The Trends and Talks on My Radar
We celebrate the launch of the new blog layout as I prepare to attend Black Hat Europe 2025, I present my highly curated technical agenda, focusing on critical research in enterprise exploitation, macOS malware, and hardware hacking.
Statistical Dreams: The Intimate History of AI
From ancient automatons to the Transformer age, this is the story of how we taught machines to think. We'll dive into breakthroughs like the Perceptron, Backpropagation, and Attention, taking a critical look at AI's origins, its dangers, and where it's headed next.