Resources
Research, experimentation, and continuous improvement are fundamental to how we operate at elttam. Our consultants spend a significant amount of time exploring new technologies, building tooling, analysing vulnerabilities, and turning interesting problems encountered in the field into deeper technical investigations.
This section brings together that work - from detailed research posts and vulnerability disclosures to tools, publications, and updates from the team. By sharing what we learn, we aim to contribute back to the security community while pushing our own knowledge and capabilities forward.

Exploiting Auth0 Defaults in XSS Attacks
This article explores how insecure default configurations in Auth0, particularly the enabled by default Implicit Grant Flow, can be exploited in combination with an XSS vulnerability to access unintended APIs and escalate privileges. It demonstrates real-world attack paths, including token leakage and account linking abuse, and provides practical recommendations for hardening Auth0 environments.
In the News
What all the fuss is about













