<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RVFET.COM</title><description>Rafet Abbasli (RVFET) - Offensive Security Researcher &amp; Software Engineer.</description><link>https://rvfet.com/</link><item><title>Killing firefox with CJK Page Titles on Wayland</title><link>https://rvfet.com/blog/firefox-wayland-dos.md/</link><guid isPermaLink="true">https://rvfet.com/blog/firefox-wayland-dos.md/</guid><description>How a 4-byte oversight in Firefox allowed webpages to abuse CJK page titles to crash any Firefox based browser on Wayland compositors upon page view</description><pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Zero-Click Phishing &amp; Email DoS via Google&apos;s Identity Toolkit</title><link>https://rvfet.com/blog/google-identity-toolkit-abuse.md/</link><guid isPermaLink="true">https://rvfet.com/blog/google-identity-toolkit-abuse.md/</guid><description>How I discovered a logic flaw in Google&apos;s Identity Toolkit that allowed unauthenticated attackers to send unlimited official security notifications with content injection for high-fidelity phishing and DoS.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Manipulating LinkedIn&apos;s Search Algorithm and Poisoning SERP Results</title><link>https://rvfet.com/blog/linkedin-search-poisoning.md/</link><guid isPermaLink="true">https://rvfet.com/blog/linkedin-search-poisoning.md/</guid><description>How I discovered a validation and logic flaw in LinkedIn&apos;s Search Algorithm that allowed me to manipulate search results and poison the search experience for users.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item><item><title>CVSS 9.6 Account Takeover in Azerbaijan&apos;s Most Visited Platforms</title><link>https://rvfet.com/blog/open-redirect-to-ato.md/</link><guid isPermaLink="true">https://rvfet.com/blog/open-redirect-to-ato.md/</guid><description>How I discovered a critical Open Redirect to Account Takeover (ATO) vulnerability in Azerbaijan&apos;s largest online marketplaces, tap.az and turbo.az</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate></item><item><title>AZƏRBAYCANIN ƏN ÇOX ZİYARƏT EDİLƏN PLATFORMALARINDA CVSS 9.6 HESAB ƏLƏ KEÇİRMƏ</title><link>https://rvfet.com/blog/open-redirect-to-ato_az.md/</link><guid isPermaLink="true">https://rvfet.com/blog/open-redirect-to-ato_az.md/</guid><description>Azərbaycanın ən böyük saytları olan tap.az və turbo.az-da kritik Open Redirect to Account Takeover (ATO) boşluğunu necə aşkar etdim?</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate></item><item><title>CVSS 6.5 Persistent State Corruption in Linear.app</title><link>https://rvfet.com/blog/linear-permanent-state-corruption.md/</link><guid isPermaLink="true">https://rvfet.com/blog/linear-permanent-state-corruption.md/</guid><description>How I discovered a logic flaw in Linear.app&apos;s optimistic UI architecture that allowed authenticated users to permanently &apos;brick&apos; other accounts via ID collision, resulting in a persistent Denial of Service (DoS) with no recovery path.</description><pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate></item><item><title>P2/S2 Unauthenticated Redirect Loop Leading to DoS In Google Image Proxy</title><link>https://rvfet.com/blog/google-image-proxy-abuse.md/</link><guid isPermaLink="true">https://rvfet.com/blog/google-image-proxy-abuse.md/</guid><description>How I discovered a logic flaw in Google&apos;s internal proxy service that led to unauthenticated, attribution-free DDoS amplification and infrastructure resource exhaustion.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>