Dr. Zifeng Kang graduated from Johns Hopkins University, advised by Dr. Yinzhi Cao. He is interested in security issues on the Web and in LLM-driven systems.
I am excited to announce that our paper titled “Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World Websites” won the Distinguished Paper Award on IEEE S&P 2025! Great thanks to Dr. Yinzhi Cao and other colleagues! #ieeesp2025
JavaScript Prototype Vulnerabilities - Investigation by Yinzhi Cao (@yzcao) of @JohnsHopkins Whiting School @HopkinsEngineer reveals that more than 2,700 websites, including 10 of top 1,000 had flaws that could expose them to exploitable vulnerabilities. https://t.co/cB9uylhENs
Computer scientist identifies JavaScript vulnerability in thousands of websites - ProbeTheProto framework developed by computer scientist Yinzhi Cao helps identify and alert websites vulnerable to a flaw that allows malicious actors to... https://t.co/foIAXj4z9T
My pleasure to present our work, "Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-World Websites" on #NDSS2022 !
Our system discovered 2,917 zero-day vulnerabilities! Codes are available at https://t.co/wAyJuRu5zJ.
I looked into some of these same accounts on Facebook to see if I could find any evidence of a similar trend there, but there’s no trace of it there (or on YouTube, for the accounts I’ve checked thus far). It’s just a Twitter thing. 1/