Research Library
Everything the Bandits have found, in one place.
Sixteen years of vulnerability research - advisories, papers, write-ups, talks and tools in a single searchable library.
Filter by what you need, or browse the whole body of work.
Filter by what you need, or browse the whole body of work.
Advisories & CVEs
Responsibly disclosed vulnerabilities from our team.
CVE-2026-8971: Mozilla Firefox Same-Origin Policy Bypass via JAR URI Null Byte Handling
Exploitation occurs when a target loads a specifically crafted jar:, resource:///, or moz-extension:// URI, whether through direct navigation, a redirect served by attacker controlled web content, or…
Browser
Spoofing

See all Advisories & CVEs


Blog & Write-ups
The story behind the findings, in readable form.
Talks & Trainings
Our researchers on the world’s security stages.
Open-source Tools
The tools we built and gave away, free.



















.avif)

.avif)




