Got Blog Posts?

Security research, industry commentary, and stories from the field.

I Accessed Warner Bros' Internal Network From Their Studio Tour Free Wi-Fi

I connected to the guest Wi-Fi at the Warner Bros Studio Tour and their London HQ. Both gave me access to internal systems, unreleased titles, and production details.

4 min read

Your Google Calendar Is Probably Public. Here's Why That's Terrifying.

143,000 meetings scraped in hours using nothing but email addresses. Zoom passwords, internal docs, government schedules, and celebrity addresses.

3 min read

Your Lowest-Paid Employee Can Probably See Everything

I've found this pattern at multiple Fortune 500 companies. A basic employee account can access tools meant for executives. Nobody checks.

4 min read

The Fix That Wasn't: Why Outsourced Dev Teams Are Your Biggest Security Risk

Agencies ship fast and break everything. Open databases, fake authentication, and the retest cycle from hell.

4 min read

You Paid $50K for a Pentest. You Didn't Get One.

Three companies that passed security assessments. Three disasters I found in minutes.

5 min read

If It's on the Internet, It Will Get Attacked

I found and reported vulnerabilities in two apps. Both ignored me. Both got breached by someone else. Their users ended up on 4chan and in the press.

4 min read