The case for a common representation, argued in public. Docs make the argument; lab posts test it against real targets, with the vulnerable build, the run, and the result published so the claim can be checked.
Research themes
A common representation
Why exploit knowledge, not exploit execution, is the layer worth standardizing.
Exploit language fragmentation
The same attack written in a dozen dialects, and what that costs research and reuse.
Reproducibility
What it takes for an exploit result to be repeatable: data, not memory, as the artifact.
AI-assisted vulnerability research
What changes when agents can draft exploit logic, and why a landing place matters.
Agent interoperability
One object that an agent can produce and a runtime can consume, without a proprietary loop.
Evidence and provenance
Where a result comes from, and how a run report can be an honest, checkable record.
Validation workflows
Turning a documented technique into a pass or fail test that survives a patch.
The future of exploit research
Human and machine authors converging on one shared artifact instead of diverging.
Research and lab writeups
Each post documents real research: a CVE, the vulnerable and patched
builds, the request chain, and the verified run report that proves the
claim.
A walkthrough of CVE-2026-75604, an unauthenticated remote code execution in Windows-hosted Next.js 13.4 through 15.5.23 and 16.0 through 16.3.2. A backslash cache traversal leaks the private Server Action encryption key, and a forged multipart request runs cmd.exe.
A walkthrough of CVE-2026-18963, an unauthenticated account takeover in Keycloak 26.0.0 through 26.7.1. The reset-credentials flow trusts a boolean note and skips the email gate, so anyone who knows a username sets a new password.