By RUGERO Tesla ( @404Saint ). It started with an article I couldn't stop thinking about A few months back I read about how attackers were poisoning search results to push malicious software downloads. The attack isn't sophisticated. You register a convincing-looking domain, keyword-stuff it correctly, buy or manipulate your way into the top results, and wait. Someone searches "Siemens TIA Portal V17 download", clicks the third result, and downloads a trojanised installer. What got me wasn't that it worked. It was how it worked. People trust search results. Not because they've verified them. Just because they're there. And the thing is, most people only check one search engine. That thought wouldn't leave me alone. If an attacker has to poison Google AND Bing AND Brave AND DuckDuckGo simultaneously for the same query at comparable rank positions... that's a much harder problem. Cross-referencing results across engines should make poisoned results stick out. So one slow weekend I started building something.…