<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>SecurityBugFocus — Sim4n6</title><description>Field notes on vulnerability research, disclosure, and the bug classes I keep finding.</description><link>https://securitybugfocus.com/</link><language>en-us</language><item><title>DNS rebinding in 2026 — why egress allowlists aren&apos;t enough</title><link>https://securitybugfocus.com/writing/dns-rebinding-in-2026/</link><guid isPermaLink="true">https://securitybugfocus.com/writing/dns-rebinding-in-2026/</guid><description>A short field guide to why a TTL-window race against your own DNS resolver beats most &apos;block private IPs&apos; controls, drawn from cases against MobSF, MindsDB, and a recent GitLab importer.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><category>SSRF</category></item><item><title>Late-Unicode normalisation as a DoS primitive</title><link>https://securitybugfocus.com/writing/late-unicode-normalisation-dos/</link><guid isPermaLink="true">https://securitybugfocus.com/writing/late-unicode-normalisation-dos/</guid><description>Filenames, email addresses, identifiers — anywhere user input gets normalised after a length check, the multiplier between bytes-in and bytes-out becomes a denial-of-service primitive. Three case studies.</description><pubDate>Sun, 08 Feb 2026 00:00:00 GMT</pubDate><category>UNICODE</category></item></channel></rss>