First-hand investigations and vulnerability write-ups, revised from Hasaan's original Medium publications for clearer technical context, safer disclosure, and durable reference.
A time-bound threat-actor investigation covering public infrastructure, distribution channels, advertised capabilities, activity patterns, and defensive implications.
A first-hand account of escalating an apparently ordinary open redirect into account takeover by tracing an authentication token through the redirect flow.
A first-hand breakdown of how identifier enumeration, weak request binding, and unrestricted confirmation-code attempts combined into account takeover without victim interaction.