<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>TRIADA Research</title>
    <link>https://research.triada.in</link>
    <atom:link href="https://research.triada.in/feed.xml" rel="self" type="application/rss+xml" />
    <description>Blog, whitepapers, and research from Team Triada: offensive and defensive security write-ups, CTF postmortems, and vulnerability research.</description>
    <language>en-IN</language>
    <lastBuildDate>Thu, 02 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Client-Side Secret Exposure in Modern SPA/JAMstack Applications</title>
      <link>https://research.triada.in/client-side-secrets-in-modern-webapps</link>
      <guid isPermaLink="true">https://research.triada.in/client-side-secrets-in-modern-webapps</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>How we found hardcoded signing keys and BaaS credentials in production JS bundles across two separate engagements, and how we triaged them.</description>
      <author>Adarsh SR</author>
      <category>methodology</category>
      <category>secrets</category>
      <category>spa</category>
      <category>supabase</category>
      <category>jwt</category>
    </item>
    <item>
      <title>Old Commits, Live Credentials: The Git History Blind Spot</title>
      <link>https://research.triada.in/git-history-credential-hygiene</link>
      <guid isPermaLink="true">https://research.triada.in/git-history-credential-hygiene</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <description>Why secret scanning limited to HEAD misses a whole class of long-lived exposure, and the sweep methodology we now run on every engagement.</description>
      <author>Adarsh SR</author>
      <category>research</category>
      <category>secrets</category>
      <category>git</category>
      <category>supply-chain</category>
    </item>
    <item>
      <title>SSRF via WordPress XML-RPC Pingback: A Recurring Finding</title>
      <link>https://research.triada.in/ssrf-via-wordpress-pingback</link>
      <guid isPermaLink="true">https://research.triada.in/ssrf-via-wordpress-pingback</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>How we found and confirmed SSRF and brute-force amplification through a decade-old WordPress endpoint during a recent web assessment.</description>
      <author>Adarsh SR</author>
      <category>ssrf</category>
      <category>wordpress</category>
      <category>web</category>
    </item>
  </channel>
</rss>