api 7
- I Can Read Everyone's Invoices (and Found a Backdoor Inside)
- The Refresh Token That Wouldn't Die
- It's 3 AM and I'm Creating a Thousand Invoices
- I Just Sent XSS Payloads to the Support Team
- When Your Internal Fields Aren't Internal: The Day I Deleted My Own Account
- The CORS Rabbit Hole I Didn't Want to Go Down
- 5,000 Attack Vectors Later: What I Learned From Testing Everything