Research
Teardowns and analysis of the QR chain — the payloads, the redirects, and the shortcuts mobile operating systems take between a scan and your browser.
-
Quishing OS Security
Trustworthy QR Codes: A Field Guide
Best practices for safe and secure QR codes. How to print codes that protect your users and your brand — make the destination obvious, own your routing, make tampering obvious, and scan reliably everywhere. Includes a pre-print checklist.
-
Quishing Payments
India Skipped the Credit Card. Now It’s Paying for It.
India leapt straight to UPI and QR payments — and skipped the decades of fraud defenses that came bundled with cards. The same “convenience ships first, security catches up” pattern that hit analog mobile in the 1980s, now playing out in payments.
-
Quishing OS Security
The Desktop-to-Mobile Air Gap: Breaking Down ESET’s H1 2026 Quishing Telemetry
ESET logged ~100,000 quishing email detections a month in H1 2026. QR phishing is an intentional exploit of the gap between hardened desktop email security and unmonitored mobile endpoints — and the telemetry shows it going nation-state.
-
URL Obfuscation OS Security
The Visual Lie: Combosquatting, Homographs, and the Mobile Preview Gap
Domain spoofing is 25 years old. Combosquatting and IDN homograph attacks lean on the same lookalike-domain trick — and the truncated mobile camera preview is where the browser’s punycode defenses fall away.
-
Quishing OS Security
The French EV-Charger Scams Highlight How Dumb Phone Cameras Still Are
France flagged 800+ QR-phishing cases on public EV chargers. The sticker is low-tech — the real gap is how blindly iOS and Android hand a raw QR payload to the browser with no pre-execution inspection.