Resource library
Useful security material, organized around the next decision.
Research, practical guidance, and buyer resources for teams preparing an assessment, reviewing a report, or building a security decision from evidence.
Find the right starting point
Scope, evidence, decision.
Choose a route based on what needs to be understood, not a generic content category.
Buyer resources
Prepare before the work begins.
A concise starting point for setting boundaries, recognizing useful evidence, and understanding how the engagement is run.
Public research
Case files with the useful reasoning intact.
How a mobile observation comment became stored XSS on a public NASA GLOBE web page, with verified impact, root cause, and remediation.
Jun 15, 2026publicIntigriti 0526: Unintended Stored XSS BypassAn unintended stored XSS path in Intigriti Challenge 0526 involving unsafe innerHTML, observed SCA Shield bypass behavior, and sink-side remediation.
May 26, 2026publicBlind Stored XSS Through a Text File UploadHow an accepted text file rendered as HTML became blind stored XSS inside an internal review workflow.
Apr 28, 2026Technical guidance
Focused guides for builders and owners.
Manual testing, authorization, identity, API behavior, and validation practices for teams responsible for web and application risk.
Operational resilienceSmall-Business SecurityPractical controls for website ownership, impersonation, ransomware exposure, and the systems small organizations rely on every day.
Keep the library close
New research and practical guidance, sent with restraint.
Use the newsletter for occasional updates, or follow the RSS feed in the reader you already use.
