<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Youssef Elsayyad — Security Research</title><link>https://elsayyay.github.io/bounty-blog/</link><description>Recent content on Youssef Elsayyad — Security Research</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 17 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://elsayyay.github.io/bounty-blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Forcefully Joining Private Servers via Shared Invite ID Namespace</title><link>https://elsayyay.github.io/bounty-blog/posts/shared-name-invitespace-improper-access-control/</link><pubDate>Fri, 17 Apr 2026 00:00:00 +0000</pubDate><guid>https://elsayyay.github.io/bounty-blog/posts/shared-name-invitespace-improper-access-control/</guid><description>How I discovered that a staging environment shared its invite ID namespace with production, allowing an attacker to generate invite codes on staging and use them to forcefully join random private servers on production — including invite-only ones.</description></item><item><title>Hello World — Why I Started This Blog</title><link>https://elsayyay.github.io/bounty-blog/posts/hello-world/</link><pubDate>Fri, 17 Apr 2026 00:00:00 +0000</pubDate><guid>https://elsayyay.github.io/bounty-blog/posts/hello-world/</guid><description>Introducing my security research blog — what to expect and why I&amp;rsquo;m writing.</description></item><item><title>About</title><link>https://elsayyay.github.io/bounty-blog/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://elsayyay.github.io/bounty-blog/about/</guid><description>About me and this blog.</description></item></channel></rss>