Intel

Field notes from the work itself.

Short write-ups pulled from engagements once they're fully closed out and anonymized. No client names, no identifying details — just the pattern, so other teams can check themselves against it.

Advisory 2026.07.28

Session tokens surviving password resets

A recurring pattern across three unrelated audits this quarter: password reset flows that invalidate the password but leave every existing session token active. An attacker who already has a token keeps access indefinitely.

Research 2026.07.12

Third-party SDKs quietly widening data collection

Analytics and crash-reporting SDKs updating their own collection scope in minor version bumps, without changing your app's privacy posture on paper. Pin versions, diff manifests.

Archive

All field notes.

Cache headers leaking authenticated pages to CDNs
Misconfiguration · surfaced during 4 separate CDN migrations
2026.06.30
OSINT trail left by internal Slack export tools
Exposure mapping · metadata retained past deletion request
2026.06.14
Encrypted-at-rest doesn't mean encrypted-in-backup
Privacy architecture · backup pipelines skipping the encryption layer
2026.05.22
Phishing kits now cloning MFA prompts in real time
Threat landscape · adversary-in-the-middle proxy kits
2026.05.03
Debug endpoints reintroduced after "temporary" hotfixes
Adversarial audit · staging routes shipped to prod under time pressure
2026.04.19
Metadata scrubbing gaps in shared PDF exports
Exposure mapping · author, device and edit history left intact
2026.04.02

Full technical write-ups, reproduction steps and affected version ranges are shared directly with impacted parties and under NDA on request. Public notes here are intentionally stripped of anything actionable.

Request a report →