2021
- Automating DOM XSS Discovery
- Mitigation schmitigation: Control HttpOnly cookies through XSS
- Fuzz the Unfuzzable
- Cheatsheet: XSS that works in 2021
- Escape Static Website Dependency Hell with Hugo
- Breaking Python 3 eval protections