Vertical dossiers from the lab — multi-stage RCE, broken trust boundaries, and infrastructure ghosts. Open a case file to read the full chain.
Critical heap buffer overflow in NGINX rewrite/set dating back to 2008 — unauthenticated RCE risk on millions of deployments.
Technical breakdown of CVE-2026-21858 — content-type confusion to arbitrary file read, session forgery, workflow injection, and unauthenticated…
Reversing client-side AES on a hotel booking platform and abusing payment_method / membership flags to activate Diamond benefits without…
How a profile-update mass-assignment bug, array injection, and verbose MySQL errors chained into error-based SQL injection and full…
How a financial web app mixed cookie authentication with sessionStorage identity, user enumeration APIs, and OSINT-derived employee emails…
Breaking a multinational CMS that used AWS Cognito for authentication but trusted a localStorage user_role flag for editor/publisher…
How hardcoded AES-CBC keys and IVs in shared CDN JavaScript turned encrypted REST traffic into a fully automatable API surface — including…