JWT Security: alg=none, Key Confusion and Why the Header Lies
The JWT vulnerability class explained: alg=none, RS256/HS256 key confusion, jwk and kid injection — and the RFC 8725 defenses.
The JWT vulnerability class explained: alg=none, RS256/HS256 key confusion, jwk and kid injection — and the RFC 8725 defenses.
A practical analysis of API security authorization flaws behind modern breaches. Covers BOLA, BFLA, IDOR, mass assignment, shadow APIs, and defense strategies for API-first architectures.
On September 25, 2024, researchers Karan Saini and Sam Curry published an access-control flaw in Kia’s dealer and consumer web infrastructure: given only a license plate, an attacker could register an account with remote lock, unlock, start, stop, locate and horn control over 2014-2025 connected vehicles they did not own. Kia patched in August before disclosure. This account walks the plate-to-command chain, the ownership-verification gap, the threat model for tracking and theft, and the automotive-API authorization lesson that outlasts the brand.
DragonForce’s Backdoor.Turn routes ransomware C2 through Microsoft Teams TURN relays using anonymous visitor tokens — LOTI, living off trusted infrastructure. Why network detection dies and what still works.
A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.
Australia’s second-largest telco exposed ~9.8M customer records via an API left unauthenticated in production. No zero-day, no phishing — just enumeration.
No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.