<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Nisal Priyanka — Blog</title><description>Long-form research on malware, red teaming, and offensive security.</description><link>https://nisalpriyanka.dev/</link><language>en-us</language><item><title>JWT Pitfalls That Still Ship in 2026</title><link>https://nisalpriyanka.dev/blog/jwt-pitfalls-2026/</link><guid isPermaLink="true">https://nisalpriyanka.dev/blog/jwt-pitfalls-2026/</guid><description>None-algorithm attacks were &apos;fixed&apos; a decade ago. Here are five JWT misconfigurations I still find in production every quarter, with payloads and fixes.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item></channel></rss>