$ ls ~/blog/2024/
Archive 2024
3 posts
From Staging to Full Admin Control In Prod: A Breakdown of Critical Authentication Flaws
In this blog, I explore a real-world case of an Admin Panel Takeover caused by broken authentication and insecure configurations. By exploiting a misconfigured JWT token from a sta…
AI Hijack: How I Took Control of an AI Assistant
A simple API key leak led to the complete takeover of an AI assistant in production. Allowing to change AI's Instructions.
Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST
Found a critical vulnerability involving leaked AWS credentials within an Android App API during a bug bounty hunt. by utilizing Dynamic Application Security Testing (DAST) and the…


