
Hunting a ‘Critical’ Bug That Wasn’tThe art of hunting, finding the Holy Grail, and realizing it’s a plastic replica

Leaking Thousands of Government UsersI asked the server a simple question, and it responded with an entire phonebook.

How I Found a Critical Biometric 2FA BypassHow a Hardcoded Superadmin Key Led to a Biometric 2FA Bypass — and a Painful Duplicate