RESEARCH & INSIGHTS

Published work, not marketing.

Every engagement is backed by the same methodology we write about publicly. A selection of recent writeups from our Medium publications.

All Writeups

BUG BOUNTY

Part II — Understanding the Internet Before You Attack It

Every vulnerability begins with a request. To understand vulnerabilities, you must first understand the journey that request takes — DNS, TCP, TLS, CDNs, proxies and where trust quietly fails.

Yassin HamadaJUL 21, 2026
METHODOLOGY

Part I — BugBounty: The Hunter's Roadmap

Why most people never find their first bug. A practical journey that begins long before your first HTTP request — built on understanding systems, not memorising payloads.

Yassin HamadaJUL 20, 2026
OSINT

How Much Can a Stranger Learn About You From Public Information Alone?

A walkthrough of how open-source intelligence builds a surprisingly detailed profile of someone — using only information they have already made public. The risk is never one post. It is aggregation.

Yassin HamadaJUL 19, 2026
THREAT INTEL

Anatomy of a Modern Phishing-as-a-Service Operation

A threat-intelligence breakdown of how commoditised phishing kits industrialised credential theft — and why MFA alone is no longer enough against adversary-in-the-middle tradecraft.

Yassin HamadaJUL 18, 2026
TOOLING

Hunting GraphQL Vulnerabilities with Precision

Building an AST-powered security tool for the modern hunter — surfacing GraphQL operations, variables and hardcoded secrets buried deep inside minified JavaScript bundles.

Bassel SayedFEB 6, 2026
WEB EXPLOITATION

Breaking Access Control: Object References & Data Leakage

IDOR and sensitive data exposure — the closing part of the Broken Access Control series. The recurring lesson: never trust the user, and never rely on the secrecy of an identifier.

Yassin HamadaJUN 16, 2026

Ready to Put the Methodology to Work?

Book a free scope call and apply the same research-driven approach to your actual security posture.