SSRF/XSPA in MailChimp · February 18, 2014 · OAuth MailChimp SSRF/XSPA

PayPal CSRF aids in account takeover! · September 21, 2013 · Bug Bounty CSRF PayPal

Triggering an unexploitable DOM-based XSS in Rediff Blogs automagically · June 28, 2013 · XSS Rediff DOM

Pwning Facebook accounts, taking a little help from Quora · June 13, 2013 · Open Redirect Facebook Quora OAuth

Flash-based XSS Mayhem: Most Security Solution Vendors Vulnerable · June 6, 2013 · XSS Anti-Virus Flash

Dropbox for Business Mailing List Unsubscribe Users (Permission Issue) · May 21, 2013 · Bug Bounty Dropbox Elevation of Privilege