Notes and write-ups, mostly on web application security.
Injection gets the write-ups. Broken access control gets the incidents. Here is why it survives every framework, and how I look for it.