







Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio...
Using Claude Code: The Unreasonable Effectiveness of HTML
Thought-provoking piece by Thariq Shihipar (on the Claude Code team at Anthropic) advocating for HTML over Markdown as an output format to request from Claude. The article is crammed with …

Using Claude Code: The Unreasonable Effectiveness of HTML
Thought-provoking piece by Thariq Shihipar (on the Claude Code team at Anthropic) advocating for HTML over Markdown as an output format to request from Claude. The article is crammed with …

shikoshib/winerr
A fast and accurate Windows fake error messages generator made with HTML5 Canvas
Embedding The Web
We need to talk more The web is much more than browsers. What works great in browser development is missing in related spaces like embedding. Can we get together to collectively describe security and compatibility properties of user agents that are not browsers? Can we develop things that don’t ...
Put aria-hidden=true on decorative SVGs - Manuel Matuzovic
I'm a frontend developer in Graz, specialized in HTML, accessibility, and CSS layout and architecture.

My HTML boilerplate in 2026 - Manuel Matuzović
Every element I use for the basic structure of a HTML document, with explanations why.

My HTML boilerplate in 2026 - Manuel Matuzović
Every element I use for the basic structure of a HTML document, with explanations why.

Trust Me, I’m Local: Chrome Extensions, MCP, and the Sandbox Escape
Trust Me, I’m Local reveals how Chrome extensions and MCP abuses enabled sandbox escapes, exposing users to major security vulnerabilities.

Client side include feature for HTML · Issue #2791 · whatwg/html
Spun off from HTML modules discussion There are certain amount of interest that including HTML snippet into an HTML document, without using JavaScript. That would be similar to <iframe>, but ...
Obfuscate – Get this Extension for 🦊 Firefox (en-US)
Download Obfuscate for Firefox. Make web page text unreadable

CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies

The Consent Layer: Using ligatures to make web text expensive to scrape without asking
ShieldFont is an open-source creative technology project that offers a practical opt-out from unauthorized AI training and disrupts what is collected when that choice is ignored. It swaps 45.8% of content words (around 24.4% of all words) in a page's source code for other (partially) random words, while the font restores the original text on screen. Readers see the work as intended; mass scrapers collect an altered version. In testing, shielding caused over 90% of pages that would otherwise pass the quality filter to be rejected, keeping them out of the training pipeline. Of those that still passed, 19.4% of all words conveyed false meaning, adding noise to unauthorized AI training datasets. This paper's goal is to walk newcomers through the whole process, in plain language and in order: the project's rationale, how it was built, the results, how to deploy it, and where to contribute.
BFTML/docs/notes.md at main · npetrangelo/BFTML
Blazingly Fast Text Markup Language. Standards designed for web apps. Browser implementation in Rust. - npetrangelo/BFTML
Behind the Scenes Hardening Firefox with Claude Mythos Preview – Mozilla Hacks - the Web developer blog
New details about what we found, and how agentic harnesses are now able to reproduce real bugs and dismiss false positives.

Improving the trustworthiness of Javascript on the Web
Today, there's no way to audit a site’s client-side code as it changes, making it hard to trust sites that use cryptography. We preview a specification we coauthored that adds auditability to the web.
