
Security Research

Security Research
4 articles • newest first
A case study on how Binance's listenKey design bypasses IP whitelisting, why Bugcrowd dismissed it, and what this teaches us about API security in 2025. Update (2026-04-20): This article was original
2026-04-29 — A fake recruiter tried to walk me into opening a malicious VSCode workspace.I refused, preserved the artifacts, mapped the infrastructure, and submitted the IOCs to public threat-intel fe
I wanted to re-open an old Binance API security issue. Not because I enjoy re-litigating old reports. Because the last thirteen days made the threat model painfully concrete. I found or stumbled into
Operation Endgame disrupted 326 servers and 142 domains. Three months after disclosure, the StealC malware routes I documented still respond.