DIRECTORY_INDEX()
Security Research
In-depth security research and analysis
OBJECTS003SORTED BY DATE ↓
/RESEARCH
Published files
Real findings, reproducible techniques, and lessons from production systems.
CASE_007CRITICAL
RESEARCH / BUGBOUNTY
Hunting Account Takeovers in the Wild West of MCP OAuth Servers
How misconfigured Dynamic Client Registration in MCP OAuth servers enables one-click account takeover attacks against AI-integrated platforms
2026-01-24 · 7 MINREAD_REPORT() ↗
CASE_005HIGH
RESEARCH / RECON
Abusing URL Shorteners for Fun and Profit
Mining archived short links to recover private invitations, tokens, and forgotten application flows.
2025-02-26 · 3 MINREAD_REPORT() ↗
CASE_006CRITICAL
RESEARCH / ATO
Account Takeover via an Unsanitized Facebook OAuth Redirect Scheme
How a one-character mutation in a mobile OAuth redirect scheme allowed authentication tokens to be intercepted by a malicious app.
2023-09-01 · 4 MINREAD_REPORT() ↗