Engineering notes from the trenches.
Reverse-engineering APIs, automation that survives production, security research, and honest takes on the tools I ship with.
Reverse-engineering APIs, automation that survives production, security research, and honest takes on the tools I ship with.
2 posts ← reset filters

A newly disclosed identrail flaw shows how a correctly scoped connection state can still be paired with an attacker-supplied GitHub App installation ID. The result is a cross-tenant path to another customer's private repository inventory.

The Sylius IDOR GHSA-mr9r-h354-966r lets attackers read payment requests, recover order tokens, and redirect buyers to malicious URLs — all without authentication. Here's the breakdown, the fix, and why API ownership checks can't be an afterthought.