Log inSign up
Log inSign up
@[email protected]
1,212 posts
@SecurityMB

@[email protected]

@SecurityMB
Improving the world’s security at Google. Opinions are mine.
Zurich, Switzerland
bentkowski.info
Joined September 2014
284 Following
11.2K Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.
  • Pinned
    @SecurityMB
    @[email protected]
    @SecurityMB
    Sep 24
    We just published two blog posts about PageBreak, Google's AI web security scanner (that I've helped develop for the better part of the year). We share our approach and a couple of findings, enjoy! - blog.google/security/agent… - bughunters.google.com/blog/pagebreak…
    Agentic Hacks, Real Proofs: Inside Google's PageBreak Project
    From blog.google
    12
  • @SecurityMB
    @[email protected]
    @SecurityMB
    Jun 15
    This is a really awesome summary of how to approach bypassing HTML sanitizers, I highly recommend to check this out!
    @kinugawamasato
    Masato Kinugawa
    @kinugawamasato
    Jun 12
    DOMPurifyバイパスの歴史をまとめたページ。HTMLサニタイザーバイパスのノウハウがぎっしり詰まってる。 特に今年に入ってから発見された<selectedcontent>のバイパスは驚いた github.com/cure53/DOMPuri…
  • @SecurityMB
    @[email protected]
    @SecurityMB
    May 18
    Anyone I know interested in joining the Google Security Team in Zurich? Let me know, I can give a referral :D Here's the job posting: google.com/about/careers/…
    11
  • @SecurityMB
    @[email protected]
    @SecurityMB
    Mar 6
    That must be the worst captcha I’ve ever seen.
  • @SecurityMB
    @[email protected]
    @SecurityMB
    Jan 24
    That was a nice bug, thanks for the shoutout!
    @intigriti
    Intigriti
    @intigriti
    Jan 23
    Replying to @intigriti
    2️⃣ XSS in GMail's AMP4Email via DOM Clobbering Michał Bentkowski (@SecurityMB) exploited DOM clobbering to achieve XSS in Gmail's AMP4Email feature. Found that AMP4Email allowed id attributes, which could be leveraged to overwrite JavaScript variables and bypass Google's strict
    1