PortSwigger Web Security Blog: Bypassing CSP using polyglot JPEGs