
How I Found a Chain of Critical Vulnerabilities in a Public Platform’s GraphQL API
A chain of GraphQL vulnerabilities discovered while testing a public application, walked through end to end.
Read on Medium →
Who Needs Admin Rights When You’ve Got Bugs?
A business-logic vulnerability that let low-privilege actions produce admin-level outcomes.
Read on Medium →
Exploit the Game Blindly: With Blind XSS
How a blind XSS payload was used to exfiltrate sensitive information from an internal admin panel.
Read on Medium →
How One Header Broke Next.js Auth — CVE-2025-29927
How injecting the x-middleware-subrequest header lets attackers bypass middleware-based authorization checks entirely.
Read on Medium →Hacking the Cloud 🌩 : Unveiling Secrets in AWS CTF Challenges
A hands-on walkthrough of cloud pentesting scenarios from TryHackMe’s Hackfinity Battle Encore CTF.
Read on Medium →
Hacking with SSRF: A Deep Dive into Server-Side Request Forgery
What SSRF is, how it’s exploited, and how to bypass common restrictions to reach internal services.
Read on Medium →