Matteo Golinelli

Cybersecurity Researcher

My main research interests include web security, with special focus on web caches and CDNs.

01

My research interests include web security, with special focus on web caches and CDNs.

Web security, caches and proxiesCTFAI Agents security
02

News

August, 2026: Our paper Web Cache Overflow: Exploiting Imprecise Keys for Cache Degradation and Beyond is now available on arXiv. The source code is available on GitHub.

November, 2025: We arrived 3rd place in the WP CTF 2025, a Capture The Flag competition in Bolzano, Italy, organized by Würth IT.

January, 2025: We have been accepted for a poster session at KubeCon, between April 1-4 in London. We will present Koney, our new Kubernetes operator for automated cyber-deception in cloud-native environments.

03

Recent publications

all papers →
2025

Koney: A Cyber Deception Orchestration Framework for Kubernetes

Mario Kahlhofer, Matteo Golinelli, Stefan Rass

4th Workshop on Active Defense and Deception (ADnD 2025) co-located with IEEE EuroS&P

2024

Hidden Web Caches Discovery

Matteo Golinelli, Bruno Crispo

The 27th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2024)

2023

OAuth 2.0 Redirect URI Validation Falls Short Literally

Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Ali Mirheidari, Bruno Crispo, Engin Kirda

Annual Computer Security Applications Conference (ACSAC)

2023

The Nonce-nce of Web Security: An Investigation of CSP Nonces Reuse

Matteo Golinelli, Francesco Bonomi, Bruno Crispo

Workshop on Attacks and Software Protection at ESORICS 2023

2023

Mind the CORS

Matteo Golinelli, Elham Arshad, Dmytro Kashchuk, Bruno Crispo

The Fifth IEEE International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications

04

Recent posts

all posts →