(01) - Writing and disclosure[ 17 posts ]
Blog
Coordinated security disclosures and engineering notes. No hot takes, no reposted news.
- 001CybersecurityReportsDenial of Service in Next.js Server Actions via Malformed Origin HeaderA vulnerability in Next.js Server Actions allows attackers to trigger unhandled exceptions using malformed Origin headers, leading to Denial of Service.13 April 20263 min
- 002EngineeringStop Building Mappings, Start Writing RulesHow I stopped maintaining hundreds of lines of mapping objects and started writing functions that derive the output instead.10 April 20265 min
- 003EngineeringOpenTunnel: Self-Hosted Tunnels With Custom DomainsI built OpenTunnel after getting tired of paying for custom subdomains on tunnel services. It's a self-hosted alternative that gives you full control, free WAF, and works with any domain you own.31 March 20265 min
- 004EngineeringMLMap: Open Source Browser-Based Projection MappingI built a free, browser-based projection mapping application that runs entirely client-side. No server required, just vanilla JS, HTML, and CSS.07 March 20265 min
- 005CybersecurityReportsInsufficient Rate Limiting and Chatbot Abuse in Chatwoot Web WidgetMultiple issues in the Chatwoot web chatbot widget allow message spamming, external iframe reuse, and lack of origin enforcement, leading to potential abuse and service degradation.26 February 20263 min
- 006CybersecurityReportsRCE Vulnerability Found in BeValk - React2ShellA critical Remote Code Execution vulnerability was discovered in BeValk due to its use of React 19, allowing attackers to escape Docker containers and escalate privileges.12 December 20254 min
- 007CybersecurityReportsCritical RCE Found in Teleparty Chrome ExtensionA Remote Code Execution vulnerability in the Teleparty browser extension allows attackers to take control of users' tabs and execute arbitrary code.29 November 20253 min
- 008CybersecurityReportsPhishing Campaign Targeting lto.gov.ph - PhilippinesAutomated security scans detected a phishing operation impersonating the Land Transportation Office of the Philippines, harvesting personal and payment information.19 November 20253 min
- 009CybersecurityReportsPhishing Campaign Impersonating pcivil.rj.gov.brSecurity researchers identified a phishing campaign mimicking the Civil Registry Portal of Rio de Janeiro, Brazil, designed to steal user credentials and personal data.28 October 20253 min
- 010CybersecurityReportsEmail Exposure Vulnerability in e-Nidhi Bihar PortalAn automated scan detected that the e-Nidhi Bihar Portal potentially exposed users' email addresses to unauthorized access due to a security misconfiguration.16 October 20252 min
- 011CybersecurityReportsSubdomain Vulnerability in Vinnytsia Municipal Portal - UkraineA misconfiguration in the Vinnytsia Municipal Portal subdomains could allow attackers to host malicious content under official-looking subdomains.02 October 20252 min
- 012CybersecurityReportsSubdomain Vulnerability in Spanish DGT DomainA misconfiguration in subdomain management for dgt.es was discovered, potentially allowing attackers to host malicious content under official-looking subdomains.29 September 20252 min
- 013CybersecurityReportsEmail Authentication Vulnerability in US Social Security SystemA critical flaw in the US Social Security email systems allows attackers to send fraudulent emails appearing to come from official government accounts, including the minister's address.23 September 20253 min
- 014CybersecurityReportsEmail Authentication Vulnerability in Ministry of Women of ParaguayA flaw in the Ministry of Women's email servers allows attackers to send fraudulent emails appearing to come from official government accounts.21 August 20252 min
- 015CybersecurityReportsEmail Authentication Vulnerability in Legislative Assembly of Costa RicaA vulnerability in the Legislative Assembly of Costa Rica's email servers allows attackers to send fraudulent cryptocurrency-related campaigns from official addresses.23 June 20252 min
- 016CybersecurityReportsEmail Authentication Vulnerability in Public Prosecution Office of OmanA critical vulnerability in the Public Prosecution Office of Oman's email servers allows attackers to send fraudulent cryptocurrency-related campaigns from official addresses.21 June 20252 min
- 017CybersecurityReportsEmail Authentication Vulnerability in National Police of EcuadorA flaw in the Ecuadorian National Police email servers allows attackers to send fraudulent emails appearing to come from official government accounts.14 April 20252 min


