Matteo Golinelli

Cybersecurity Researcher

My main research interests include web security, with special focus on web caches and CDNs.

01

My research interests include web security, with special focus on web caches and CDNs.

Web security, caches and proxiesCTFAI Agents security
02

News

September, 2026: Our paper AgentLSD: Evaluating AI Security Agents Under Adversarial Task Contamination has been accepted at AISec 2026.

September, 2026: Our paper When POST Becomes GET: Investigating HTTP Method Interchangeability and Its Security Implications has been accepted at ACSAC 2026.

August, 2026: Our paper Web Cache Overflow: Exploiting Imprecise Keys for Cache Degradation and Beyond is now available on arXiv. The source code is available on GitHub.

November, 2025: We arrived 3rd place in the WP CTF 2025, a Capture The Flag competition in Bolzano, Italy, organized by Würth IT.

04

Recent publications

all papers →
2025

Koney: A Cyber Deception Orchestration Framework for Kubernetes

Mario Kahlhofer, Matteo Golinelli, Stefan Rass

4th Workshop on Active Defense and Deception (ADnD 2025) co-located with IEEE EuroS&P

2024

Hidden Web Caches Discovery

Matteo Golinelli, Bruno Crispo

The 27th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2024)

2023

OAuth 2.0 Redirect URI Validation Falls Short Literally

Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Ali Mirheidari, Bruno Crispo, Engin Kirda

Annual Computer Security Applications Conference (ACSAC)

05

Recent posts

all posts →