<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://thomas.stacey.se/posts/Account-Takeover-in-Azure&apos;s-API-Management-Developer-Portal/</loc>
<lastmod>2025-10-20T15:02:58+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/Using-HTTP-request-smuggling-to-hijack-users&apos;-sessions/</loc>
<lastmod>2025-10-20T15:02:58+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/Can-traditional-pen-testing-keep-up-with-modern-AppSec/</loc>
<lastmod>2025-10-20T15:02:58+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/Making-web-cache-deception-critical-in-30-minutes/</loc>
<lastmod>2025-10-20T15:02:58+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/Cross-site-scripting-attacks-in-action-and-how-to-protect-against-them/</loc>
<lastmod>2025-10-20T15:02:58+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/Empowering-junior-testers-strategies-for-uncovering-critical-vulns-in-web-applications/</loc>
<lastmod>2025-10-20T15:02:58+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/exploiting-permissive-cors-configurations/</loc>
<lastmod>2025-10-20T15:02:58+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/the-single-packet-shovel/</loc>
<lastmod>2025-10-20T14:49:49+02:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/how-to-join-the-desync-endgame/</loc>
<lastmod>2026-03-05T10:20:05+01:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/posts/Burp-to-discord/</loc>
<lastmod>2026-03-05T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/categories/</loc>
<lastmod>2026-03-05T10:21:07+01:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/tags/</loc>
<lastmod>2026-03-05T10:21:07+01:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/archives/</loc>
<lastmod>2026-03-05T10:21:07+01:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/about/</loc>
<lastmod>2026-03-05T10:21:07+01:00</lastmod>
</url>
<url>
<loc>https://thomas.stacey.se/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/tags/outpost24/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/tags/bug-bounty/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/tags/webinar/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/tags/exploit-development/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/tags/assured/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/tags/tooling/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/categories/write-up/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/categories/thoughts/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/categories/presentation/</loc>
</url>
<url>
<loc>https://thomas.stacey.se/categories/research/</loc>
</url>
</urlset>
