Add-ons, Extensions and CSP Violations: Playing Nice with Content Security PoliciesTroy Hunt·Nov 14, 12:03 UTC · Nov 14, 2018Vulnerability30
Soft-Launching and Open Sourcing the Have I Been Pwned RebrandTroy Hunt·Mar 11, 19:56 UTC · Mar 11, 2025Vulnerability130
Locking Down Your Website Scripts with CSP, Hashes, Nonces and Report URITroy Hunt·Nov 15, 04:08 UTC · Nov 15, 2017Vulnerability130
With great Azure VM comes great responsibility (which is why you really want an Azure Web Site)Troy Hunt·Jan 22, 00:00 UTC · Jan 22, 2014Vulnerability55
Are You One of the 533M People Who Got Facebooked?Krebs on Security·Apr 15, 00:00 UTC · Apr 15, 2021Vulnerability30
Promiscuous Cookies and Their Impending Death via the SameSite PolicyTroy Hunt·Jan 3, 08:06 UTC · Jan 3, 2020Vulnerability30
How Chrome's buggy content security policy implementation cost me moneyTroy Hunt·Dec 7, 20:32 UTC · Dec 7, 2016VulnerabilityCVE-2016-522535
Millions of job seekers' info exposed via easily accessible database backupsHelp Net Security·Nov 11, 00:00 UTC · Nov 11, 2016Vulnerability42