Simon Willison’s Weblog

Tip: Configure SAX parsers for secure processing. Explains the billion laughs attack, among others.