In-depth technical writeups on real vulnerabilities I've discovered — covering IDOR, XSS, logic flaws, and more across government, enterprise, and academic targets.
High-severity discovery · 2025
An Insecure Direct Object Reference in a United States court system portal exposed confidential case records, filing documents, and party details to any unauthenticated user. A full breakdown of the recon, exploit chain, responsible disclosure, and remediation.