Every conference talk we've analyzed. Sorted newest first.. Talks analyzed in full.
Learn how a 10-month experiment quantified AST accuracy in application security testing — and why the best automated scanner scored just 36.9% F1.
Learn why server-side HTML sanitization is structurally broken and how client-side tools like DOMPurify eliminate parser differential XSS bypasses.
Learn how GraphQL ID and String scalars enable path traversal-based secondary context attacks in BFF architectures. Two real-world critical exploits and defensive strategies.