A living collection of the blogs, writeups, tools, and platforms I keep coming back to. Bookmark it, raid it, get lost in it.
Credits
This list started from Mushroom’s brilliant resources page. Huge thanks to them for curating it, go read the original and the rest of their blog at mushroom.cat.
Research Blogs & Labs
- PortSwigger Research
- Watchtowr Labs
- Synacktiv Publications
- Checkpoint Research
- SonarSource Blog
- Elttam Blog
- Snyk Articles
- Positive Security
- Pentester Academy Blog
- Black Hills InfoSec
- Intigriti — Bug Bytes
- The Hacker Blog
- SecurityOnline.info
- Acunetix Blog
Individual Researcher Blogs
- Orange Tsai
- Ajin Abraham
- GhostCCamm
- Huli
- Jorian Woltjer
- SpaceRaccoon
- Mizu.re
- Shubs (Assetnote)
- Diefunction
- Omer Gil
- Ben Hayak
- RyoTaK
- Arkark
- Adam Caudill
- Daniel Stenberg (curl)
- Fushuling
- 0dayfans
- Brutecat
- Devansh Batham
- Rafa
- DimasC
- Worst.fit
Web & Client-Side Security
- Beyond XSS — CSP Bypass
- Beyond XSS — CSS Injection
- Client-Side Bugs Resources
- Huli — iframe & window.open
- Huli — Learn Frontend from a Security POV
JavaScript Recon & Analysis
- JavaScript Enumeration for Bug Bounty
- JavaScript Analysis for Pentesters
- Monitoring JS Files
- Bug Bounty Hunter — JS Files Guide
- Easy Bounties via JS File Analysis
- JavaScript to API Bugs
- Leaks & Disclosure — PII / API Keys
- Gowtham’s Bug Hunter Handbook
- Pwnfunction — Leaked API Keys (video)
- Zseano — .js File Analysis (video)
Binary Exploitation & Reversing
- pwn.college
- Binary Exploitation 101 (Crypto-Cat)
- ired.team
- Getting Started in 2024 (dayzerosec)
- 0xinfection — Reversing
- x86 Reverse Engineering
- Pwn Challenges (playlist)
- HTB pwn series (Crypto-Cat)
- Snwo (KR)
Cryptography
CTF Writeups & Challenge Repos
- Trail of Bits — CTF Field Guide
- TheMaccabees — CTF Writeups
- Siunam321 — CTF
- 0xkalawy — My CTF Challenges
- Ouuan — TPCTF 2025
- Secure Code Review Challenges
Practice Platforms
Methodology, Notes & Gitbooks
- Pentestbook (six2dez)
- Sallam Gitbook
- Ahmed Tarek — 0x_xnum
- 0xhunterr Gitbook
- Oreobiscuit Gitbook
- Gowsundar Gitbook
- Mohamed Wagdy — Researchers’ Blogs
- Web Exploitation Suite (Notion)
- 40sp3l — Methodology Notes
Notable Writeups
- Elttam — Plorming your Prisma ORM
- RyoTaK — DOM-based Race Condition
- Adam Caudill — Jackson RCE (CVE-2017-7525)
- RCE.moe — CVE-2025-41243
- Jorian Woltjer — Kittychat Secure (openECSC 2025)
- Exploiting Number Parsers in JavaScript
Handy Tools & References
Found something that belongs here? Ping me. And again, much of this was curated by Mushroom; go show them some love.