| 2026-04-24 | Tool demo | Blackhat |
BugHound MCP
| Krishna Naidu, Eric Tee, Lwin Min Oo, Kai Wei Hoon, Valen Sai | #bug-bounty#web-security#ai-security+2 |
| 2026-03-01 | Talk | Nullcon |
The Hidden Cost of Sanitization: How Secure Parsing Can Introduce New XSS Attack Surfaces
| Ashish Kataria | #xss#web-security#web-pentesting+1 |
| 2026-02-28 | Talk | Nullcon |
The Future of Augmented AppSec: Integrating LLM Reasoning into Burp Workflows with VISTA
| Rajkumar Rathod, Rishav Raj | #web-pentesting#ai-security#web-security+1 |
| 2026-02-28 | Talk | Nullcon |
The SOAP Effect: Breaking Security Assumptions in Real-World Systems
| Kamalpreet Singh | #web-security#web-pentesting#api-security+1 |
| 2025-06-27 | Talk | Lehack |
From HTML Injection to Full AWS Account Takeover: Discovering Critical Risks in PDF Generation
| Raunak Parmar | #ssrf#aws#web-security+2 |
| 2024-12-12 | Tool demo | Blackhat |
Damn Vulnerable Browser Extension (DVBE) - Knowing the risks of your Browser Supplements
| Abhinav Khanna, Krishna Chaganti | #browser-security#web-security#web-pentesting |
| 2023-08-11 | Talk | Defcon |
Generative Adversarial Network (GAN) based autonomous penetration testing for Web Applications
| Ankur Chowdhary | #web-security#xss#application-pentesting+3 |
| 2022-03-25 | Talk | Insomnihack |
Hook, Line and Sinker - Pillaging API Webhooks
| Abhay Bhargav | #web-security#api-security#ssrf+1 |
| 2021-11-13 | Talk | C0c0n |
Server-side javascript Injection
| Kavisha Sheth | #web-security#secure-coding#web-pentesting |
| 2020-09-18 | Talk | C0c0n |
Web Application hacking with WebZGround
| Parveen Yadav, Narendra Kumar | #web-security#web-pentesting#security-assessment+3 |
| 2018-05-30 | Talk | Auscert |
How to Bypass Authentication & Authorization
| Sarwar Jahan | #authentication#authorization#web-security+1 |
| 2014-09-12 | Talk | 44con |
Pentesting NoSQL DB’s Using NoSQL Exploitation Framework
| Francis Alexander | #exploitation#web-pentesting#penetration-testing-tools |
| 2014-05-29 | Talk | Hitbsecconf |
Exploiting NoSQL Like Never Before
| Francis Alexander | #exploitation#web-pentesting#code-injection |
| 2014-02-15 | Tool demo | Nullcon |
XMLChor
| Harshal Jamdade | #exploitation#web-pentesting#security-tools |
| 2012-09-28 | Talk | Nullcon |
Alert(/xss/) - How to catch an XSS before someone exploits / reports it?
| Ahamed Nafeez | #web-security#xss#secure-coding+2 |
| 2012-08-15 | Award | |
Attacking OData: HTTP Verb Tunneling, Navigation Properties for Additional Data Access, System Query Options ($select)
| Gursev Singh Kalra | #api-security#web-pentesting#security-tools |
| 2012-07-25 | Tool demo | Blackhat |
Oyedata for OData Assessments
| Gursev Singh Kalra | #api-security#web-pentesting#security-tools |
| 2011-09-06 | Talk | Securitybyte |
Enabling Un-trusted Mashups
| Bishan Singh | #web-security#xss#csrf+4 |
| 2010-11-11 | Talk | Blackhat |
Attacking with HTML5
| Lavakumar Kuppan | #web-security#xss#web-pentesting+1 |
| 2007-03-15 | Talk | Blackhat |
Exploit-Me Series β Free Firefox Application Penetration Testing Suite Launch
| Nish Bhalla, Rohit Sethi | #web-security#xss#sql-injection+4 |
| 2005-06-10 | Talk | Syscan |
.Net Web Security-Attack And Defense
| Shreeraj Shah | #.net#web-security#web-pentesting |