Here is a list of all my security (or somewhat security adjacent) publications/writings/research etc. I have plans to move my threads from Twitter to longer form articles, but as they were first published there I will still treat them as a separate publication.
assetnote, 2019 - Getting access to Zendesk’s Google Cloud and Artifactory from GitHub dotfile repos
hackerone, 2019 - Leaked artifactory_key, artifactory_api_key, and gcloud refresh_token via GitHub.
tokyo, 2018 - Hack me if you can: inside the world of bug bounty hunting
nist, 2017 - CVE-2017-16755 / CVE-2017-16756 (HelpSpot disclosure)
hackerone, 2016 - Incoming email hijacking on sc-cdn.net (Snapchat)
medium, 2016 - First thoughts and a quick setup guide on Bash for Windows