thumbnail Stealing passwords from infosec Mastodon - without bypassing CSP | PortSwigger Research