SSRF/XSPA in MailChimp · February 18, 2014 · OAuth MailChimp SSRF/XSPA

PayPal CSRF aids in account takeover! · September 21, 2013 · Bug Bounty CSRF PayPal

Triggering an unexploitable DOM-based XSS in Rediff Blogs automagically · June 29, 2013 · XSS Rediff DOM

Pwning Facebook accounts, taking a little help from Quora · June 14, 2013 · Open Redirect Facebook Quora OAuth

Flash-based XSS Mayhem: Most Security Solution Vendors Vulnerable · June 7, 2013 · XSS Anti-Virus Flash