Latest posts

Write-ups, disclosure notes, CTF learnings, and practical security research logs.

Hunting IDOR at Scale

A repeatable approach for finding authorization gaps in modern API surfaces.

Lessons from CVE Disclosure

What changed between initial report, vendor coordination, patch release, and advisory.