Pentesting Passkeys: A Practical Methodology for WebAuthn Deployments
Recon, server-side Relying Party tests, and the Windows-focused OS and authenticator attacks: end-to-end, tool by tool.
field-notes
Field Notes from Black Hat US 2026 and DEF CON 34
Field notes from Black Hat USA 2026 and DEF CON 34: the talks that mattered to me most, honest questions about where AI-accelerated research is heading, and the deep dives I'm committing to next.
npts
Chaos Threat Actors: Why Corporations, Parents and Legal Systems Fail against Teenage Hackers
A discussion on Joe Tidy's "Ctrl + Alt + Chaos" and my takeaways. From the release of Julius Kivimäki to the rise of "Chaos-Evil" groups, I analyze company reactions to hacks, parents navigating the digital minefields and why the legal system might need a "cartel-style" overhaul.
blackhat
Road to Black Hat London 2025: The Trends and Talks on My Radar
We celebrate the launch of the new blog layout as I prepare to attend Black Hat Europe 2025, I present my highly curated technical agenda, focusing on critical research in enterprise exploitation, macOS malware, and hardware hacking.
Privacy settingsniklas-heringer.com
This website uses strictly necessary cookies and optional cookies for newsletter tracking.
Learn more in our Privacy Policy.
Manage cookies
Strictly necessaryRequired
Required for the website to function. Includes session cookies, security features, and Stripe fraud-prevention cookies (active only during payment flows). Cannot be disabled.
Newsletter & marketing
Enables tracking of newsletter opens and clicks to deliver more relevant content.