Skip to content
Hmmnm
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Search this website

Web & API Security

  1. Home>
  2. Blog>
  3. Security>
  4. Web & API Security>
  5. Page 4
Read more about the article T-Mobile API Scraping 2023: 37M Accounts, One Credential

T-Mobile API Scraping 2023: 37M Accounts, One Credential

  • Post author:Hmmnm
  • Post published:January 19, 2023
  • Post category:Identity & Phishing/Security/Web & API Security

A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.

Continue ReadingT-Mobile API Scraping 2023: 37M Accounts, One Credential
Read more about the article FortiOS SSL-VPN Heap Overflow: Pre-Auth Emergency

FortiOS SSL-VPN Heap Overflow: Pre-Auth Emergency

  • Post author:Hmmnm
  • Post published:December 9, 2022
  • Post category:Cloud & Infrastructure/Security/Web & API Security

CVE-2022-42475 was a CVSS 9.8 pre-auth heap overflow in FortiOS SSL-VPN, patched silently then confirmed exploited. Edge memory safety lessons.

Continue ReadingFortiOS SSL-VPN Heap Overflow: Pre-Auth Emergency
Read more about the article ProxyNotShell: Exchange Zero-Days Auctioned Before the Patch

ProxyNotShell: Exchange Zero-Days Auctioned Before the Patch

  • Post author:Hmmnm
  • Post published:November 11, 2022
  • Post category:Cloud & Infrastructure/Security/Web & API Security

Two Exchange zero-days chained SSRF-to-RCE were sold on a forum before Microsoft's November 2022 patch — and mass-exploited in the gap. Assume-the-edge lessons.

Continue ReadingProxyNotShell: Exchange Zero-Days Auctioned Before the Patch
Read more about the article Fortinet CVE-2022-40684: Admin Access Without a Password

Fortinet CVE-2022-40684: Admin Access Without a Password

  • Post author:Hmmnm
  • Post published:October 10, 2022
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A CVSS 9.8 authentication bypass let attackers add their own SSH keys to FortiOS admin accounts via crafted HTTPS requests. Exploited at disclosure.

Continue ReadingFortinet CVE-2022-40684: Admin Access Without a Password
Read more about the article WhatsApp’s 2022 Ring-Phase RCE: Code Execution Before You Answer

WhatsApp’s 2022 Ring-Phase RCE: Code Execution Before You Answer

  • Post author:Hmmnm
  • Post published:September 26, 2022
  • Post category:Security/Web & API Security

CVE-2022-36934 gave WhatsApp a CVSS 9.8 integer-overflow RCE that could execute during the video-call ring — before the victim answered. Zero interaction.

Continue ReadingWhatsApp’s 2022 Ring-Phase RCE: Code Execution Before You Answer
Read more about the article Optus 2022: 9.8M Records, One Unauthenticated API, Zero Exploits

Optus 2022: 9.8M Records, One Unauthenticated API, Zero Exploits

  • Post author:Hmmnm
  • Post published:September 22, 2022
  • Post category:Identity & Phishing/Security/Web & API Security

Australia's second-largest telco exposed ~9.8M customer records via an API left unauthenticated in production. No zero-day, no phishing — just enumeration.

Continue ReadingOptus 2022: 9.8M Records, One Unauthenticated API, Zero Exploits
Read more about the article Twitter’s 5.4M Scrape: When an API Becomes a Breach Oracle

Twitter’s 5.4M Scrape: When an API Becomes a Breach Oracle

  • Post author:Hmmnm
  • Post published:July 23, 2022
  • Post category:Identity & Phishing/Security/Web & API Security

A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.

Continue ReadingTwitter’s 5.4M Scrape: When an API Becomes a Breach Oracle
Read more about the article Follina in the Wild: TA413, Patch Gaps and Zero-Day Economics

Follina in the Wild: TA413, Patch Gaps and Zero-Day Economics

  • Post author:Hmmnm
  • Post published:June 13, 2022
  • Post category:Security/Web & API Security

Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.

Continue ReadingFollina in the Wild: TA413, Patch Gaps and Zero-Day Economics
Read more about the article Confluence CVE-2022-26134: OGNL Injection RCE Under Fire

Confluence CVE-2022-26134: OGNL Injection RCE Under Fire

  • Post author:Hmmnm
  • Post published:June 4, 2022
  • Post category:Cloud & Infrastructure/Security/Web & API Security

Exploited in the wild two days before the patch existed. How OGNL injection turned Confluence into June 2022's internet-scale fire drill — and the playbook it left behind.

Continue ReadingConfluence CVE-2022-26134: OGNL Injection RCE Under Fire
Read more about the article Follina: The Office Zero-Day That Needed No Macros

Follina: The Office Zero-Day That Needed No Macros

  • Post author:Hmmnm
  • Post published:May 27, 2022
  • Post category:Security/Web & API Security

A protocol handler, a remote template, a signed diagnostic tool — CVE-2022-30190 executed PowerShell from a Word file with macros fully disabled.

Continue ReadingFollina: The Office Zero-Day That Needed No Macros
Read more about the article Spring4Shell: The RCE That Wasn’t Log4Shell (but Still Bit Hard)

Spring4Shell: The RCE That Wasn’t Log4Shell (but Still Bit Hard)

  • Post author:Hmmnm
  • Post published:April 4, 2022
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A JDK 9 property path reopened a 2010-era bug class in Spring's data binder — and gave every Tomcat admin a very bad 48 hours.

Continue ReadingSpring4Shell: The RCE That Wasn’t Log4Shell (but Still Bit Hard)
Read more about the article Apache httpd CVE-2021-44790: The RCE After Log4Shell

Apache httpd CVE-2021-44790: The RCE After Log4Shell

  • Post author:Hmmnm
  • Post published:December 20, 2021
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A mod_lua multipart buffer overflow announced ten days after Log4Shell. Narrow exposure, but a masterclass in triage under fatigue.

Continue ReadingApache httpd CVE-2021-44790: The RCE After Log4Shell
  • Go to the previous page
  • 1
  • 2
  • 3
  • 4
  • 5
  • Go to the next page
Press Escape to close the search panel.

Categories

  • Experience (3)
  • Security (325)
  • Technology (49)

Recent Posts

  • What Is an Electronic Flight Bag (EFB)? The Complete 2026 Guide
  • What Studying 33 Historic Cyberattacks Taught Me About Defending Systems Today
  • Securing AI Agents in Production: A Practical Checklist After a Year of Real Deployments
  • Passwordless in 2026: Why Passkeys Are Finally Killing the Password (and How Attackers Are Adapting)
  • 2022–2024: Lapsus$, Change Healthcare & the XZ Backdoor
  • 2020–2021: SolarWinds, Colonial Pipeline & the Ransomware Wave
  • 2016–2019: WannaCry, NotPetya & Mirai
  • 2009–2015: Stuxnet, Sony & the Age of Cyber Weapons
  • The 2000s: Love Bug, Estonia & the Card Heists (2000–2008)
  • The Early Era: Morris Worm & Kevin Mitnick (1988–1999)
  • The 33 Biggest Cyberattacks & Hacks in History (1988–2024)
  • How to Read Research Papers With AI: The Nine-Pass Protocol
  • How AI Agents Break Containment: Sandbox Escape Mechanisms and Defenses
  • Forward Deployed Engineering: The Role AI Companies Can’t Hire Fast Enough
  • AST09 & AST10: Governance and Cross-Platform Reuse

Archives

  • September 2026 (4)
  • August 2026 (28)
  • July 2026 (9)
  • June 2026 (10)
  • May 2026 (9)
  • April 2026 (6)
  • March 2026 (7)
  • February 2026 (6)
  • January 2026 (5)
  • December 2025 (3)
  • November 2025 (4)
  • October 2025 (3)
  • September 2025 (4)
  • August 2025 (4)
  • July 2025 (3)
  • June 2025 (4)
  • May 2025 (3)
  • April 2025 (3)
  • March 2025 (3)
  • February 2025 (4)
  • January 2025 (4)
  • December 2024 (3)
  • November 2024 (5)
  • October 2024 (5)
  • September 2024 (3)
  • August 2024 (4)
  • July 2024 (4)
  • June 2024 (5)
  • May 2024 (3)
  • April 2024 (5)
  • March 2024 (3)
  • February 2024 (5)
  • January 2024 (3)
  • December 2023 (4)
  • November 2023 (4)
  • October 2023 (4)
  • September 2023 (4)
  • August 2023 (4)
  • July 2023 (4)
  • June 2023 (5)
  • May 2023 (4)
  • April 2023 (4)
  • March 2023 (4)
  • February 2023 (4)
  • January 2023 (4)
  • December 2022 (6)
  • November 2022 (2)
  • October 2022 (4)
  • September 2022 (4)
  • August 2022 (5)
  • July 2022 (3)
  • June 2022 (4)
  • May 2022 (4)
  • April 2022 (4)
  • March 2022 (5)
  • February 2022 (3)
  • January 2022 (4)
  • December 2021 (4)
  • November 2021 (4)
  • October 2021 (4)
  • September 2021 (4)
  • August 2021 (4)
  • July 2021 (4)
  • June 2021 (4)
  • May 2021 (4)
  • April 2021 (4)
  • March 2021 (4)
  • February 2021 (4)
  • January 2021 (4)
  • March 2020 (4)
  • February 2020 (4)
  • January 2020 (4)
  • January 2019 (1)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Terms of Service
  • Disclaimer
  • Security Products

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact