Research Worth Reading Week 20/2025

Published: 18 May 2025

Passkeys, parser differentials, and another week full of fun content!

🔑 The cryptography behind passkeys

Trail of Bits walks us through how passkeys work and what their limitations are: The cryptography behind passkeys.

🧠 Parser Differentials

A keynote from Joern Schneeweisz on parser differentials, featuring plenty of fun bugs and clever exploits. If you still think all parsers behave the same, check these slides: Parser Differentials.

🏖️ How I ruined my vacation by reverse-engineering WSC

The journey of reversing Windows Security Center to disable Windows Defender: How I ruined my vacation by reverse-engineering WSC.

🪲 Can You Really Trust That Permission Pop-Up on macOS? (CVE-2025-31250)

A bit of fun with the macOS permission pop-up: Can You Really Trust That Permission Pop-Up on macOS? (CVE-2025-31250).

Photo of PentesterLab
Written by PentesterLab
The platform to learn web hacking and security code review