Field notes
How things break, and how to fix them.
Technical write-ups for engineers and security teams: attack patterns, validation checklists and remediation that holds.
6 articles shown
Cloud IAM: review privilege paths, not permission lists
Understand how role passing, workload control and service-account impersonation combine into effective access—and how to reduce it.
ReadBusiness logic & race conditions: protect the invariant
A request can be valid on its own and unsafe in combination. Test the business rule across concurrency, retries and state transitions.
ReadTop 5 IDOR Vulnerabilities We Found in 2024
Broken object-level authorization keeps topping our findings — here's how we hunt it, and how to kill it for good.
ReadWhy Your API Is Probably Misconfigured
The five API misconfigurations we end up exploiting in almost every single engagement.
ReadHow We Took Over an Account in Under 10 Minutes
A walkthrough of chaining a password-reset flaw into a full pre-auth account takeover.
ReadStart an engagement
Tell us what you're shipping.
We'll tell you what it's exposing.
Book a 30-minute scoping call with a senior engineer. You'll leave with a clear recommendation on scope, approach, and timeline.