@SecurityMBi
iAccount based inPoland
About this account
- Account based in
- Poland
- Connected via
- Switzerland App Store
Account-level information from X, not a live location or the device used for a specific post.
Improving the world’s security at Google. Opinions are mine.
Zurich, Switzerland
Joined September 2014
- Tweets1.2K
- Following284
- Followers11.3K
- Likes924
Pinned Tweet
We just published two blog posts about PageBreak, Google's AI web security scanner (that I've helped develop for the better part of the year). We share our approach and a couple of findings, enjoy!
- blog.google/security/agentic…
- bughunters.google.com/blog/p…
“And no, AI isn't perfect. But Christ, anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time.
Because it's not like natural intelligence is always all that great either.”
lore.kernel.org/linux-media/…
This is a really awesome summary of how to approach bypassing HTML sanitizers, I highly recommend to check this out!
DOMPurifyバイパスの歴史をまとめたページ。HTMLサニタイザーバイパスのノウハウがぎっしり詰まってる。
特に今年に入ってから発見された<selectedcontent>のバイパスは驚いた
github.com/cure53/DOMPurify/…
@[email protected] retweeted
Have been working on agentic vulnerability discovery for a while now, happy to share about CodeMender! 🚀🚀
While AI is helping us tackle big challenges, it also poses new potential security risks. That’s why we’re focused on building tools that keep the broader ecosystem safe — like CodeMender, a code security agent that automatically finds and fixes critical software vulnerabilities.
Today, we’re inviting a select group of experts to test a new CodeMender API, and we’ll be launching it more broadly soon.
#GoogleIO
Anyone I know interested in joining the Google Security Team in Zurich? Let me know, I can give a referral :D
Here's the job posting: google.com/about/careers/app…
That was a nice bug, thanks for the shoutout!
Replying to @intigriti
2️⃣ XSS in GMail's AMP4Email via DOM Clobbering
Michał Bentkowski (@SecurityMB) exploited DOM clobbering to achieve XSS in Gmail's AMP4Email feature. Found that AMP4Email allowed id attributes, which could be leveraged to overwrite JavaScript variables and bypass Google's strict security filters.
research.securitum.com/xss-i…
@[email protected] retweeted
Why the "Agents Rule of Two" is flawed
shhnjk.substack.com/p/why-ag…
@[email protected] retweeted
Cross-Site ETag Length Leak
blog.arkark.dev/2025/12/26/e…
I just posted the author writeup for impossible-leak in SECCON CTF 14 Quals. As far as I know, this is a new XS-Leak technique! The ETag header can become a side channel :)
Has there been some email leak from @Canva? Just got a spam message for an email used only for Canva.
Ah, it's probably from the old leak: haveibeenpwned.com/Breach/Ca…
We launched a redesigned Project Zero website today at projectzero.google !
To mark the occasion, we released some older posts that never quite made it out of drafts.
Enjoy!
Interested in the security of AI Agents 💁🛡️?
Then you've likely heard of "prompt injection", but do you know what "task injection" is? If you're curious, check out our latest post for a description and some real-world examples we discovered.
bughunters.google.com/blog/4… bughunters.google.com/blog/4…
@[email protected] retweeted
my new blogpost is out!!
this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration
and i've already used it to get a google docs bounty ^^
have fun <3
lyra.horse/blog/2025/12/svg-…
JavaScript’s lexer ambiguity in action. Might fool you and some weak parsers.
Demo: jsfiddle.net/yo0a24dj/
@[email protected] retweeted
We published a blogpost about SafeContentFrame - a library for rendering untrusted content inside an iframe. The library is a big party of what I've been up to in the few last years! Check out the blog and take a slice of my birthday cake 🎂!
bughunters.google.com/blog/6…
Rendering untrusted web content is fraught with security risks 🕸️ 🛡️.
Read how SafeContentFrame, a new TypeScript library, offers a robust solution for isolating web content and protecting against threats like XSS and side-channel attacks.
goo.gle/3K5DRQJ
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥
The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇
gmsgadget.com/
1/4
@[email protected] retweeted
It started!
pV!
Google CTF is on! Here's a challenge that I created:
capturetheflag.withgoogle.co….
Good luck 😀