The Greywatch Journal

Real attacks, taken apart. Every target anonymized, every technique intact - how we got in, why the gap was there, and exactly how to close it.

Why AI-Generated Code Ships Insecure by Default

AI writes most startup code now, and it reproduces the insecure patterns in its training data at machine speed.

9 min·
The MCP Server That Ran Production

On a cloud-telephony platform.

8 min·
The Cloud Database With the Door Left Open

Managed databases and buckets leak data when rules check that a caller is logged in but never that they own the record.

8 min·
The Payment Key Anyone Could Spend

On a crypto-neobank.

8 min·
The Sibling Service That Skipped Authentication

The main app enforces auth well, but a sibling service on the same estate does not.

8 min·
The Mental-Health Records Anyone Could Read

On a healthcare care-navigation startup.

8 min·
Chaining: Where Real Severity Comes From

Individually-medium findings combine into a critical breach.

8 min·
The Helper Proxy That Owned the Cloud

On a contract-AI SaaS.

9 min·
Email Is Not Identity

When a server trusts a caller-supplied email, domain, or identity claim as proof of who you are, anyone can become anyone.

8 min·
One Signup, Another Bank's Loan Book

On an AI lending platform.

8 min·
The Unauthenticated MCP Server

MCP servers expose powerful tools to AI agents.

7 min·
The Social Login That Trusted the Client

On a customer-support AI startup.

8 min·
When New Accounts Are Born as Admin

Self-registration that trusts a client role field or defaults new accounts to admin hands attackers privilege on signup.

8 min·
No Lock on the GPU

On an AI voice-agent platform.

8 min·
The Secret in the Page Source

A live key shipped in a JS bundle, an APK, or a public repo is public.

8 min·
The Password Reset That Emailed the Attacker

On a property-management SaaS.

8 min·
Prompt Injection and the Abusable AI Surface

Shipping AI features creates attack surfaces classic appsec misses.

9 min·
The Sandbox That Trusted Its Parent

On an insurtech company.

8 min·
The OTP That Never Dies

An OTP with no rate limit, no expiry, and a code that never rotates makes brute force a certainty.

8 min·
The Document Vault Behind a Default Password

On a legal-AI platform for law firms.

9 min·
New Accounts Born as Executives

On a student-housing CRM.

8 min·
The Billing API With No Front Door

On a cardiac-telehealth clinic.

8 min·
One Traversal, Every Tenant

On a veterinary clinic-management SaaS.

9 min·
The Maintenance API That Ran the Network

On an EV-charging network.

9 min·
Sign Up, Then Read Every Patient

On a healthcare voice-AI company.

8 min·
The .git Folder That Leaked the CRM

On a real-estate CRM.

9 min·
Phone Number In, Cardholder Data Out

On a payments-orchestration platform.

8 min·
The Signup Form That Made Me an Admin

On an AI-accounting fintech.

8 min·
When the Trust Boundary Is the Whole Domain

On a durable-medical-equipment marketplace.

8 min·
A Case-Sensitive Lock on a Case-Insensitive Door

On a coliving operator.

8 min·
The Onboarding Link That Was a Skeleton Key

On a merchant-underwriting fintech.

8 min·
The Test Token That Shipped to Production

On a diagnostics-AI company.

8 min·
Directory Listing on the Document Store

On a furnished-housing platform.

8 min·
The Login Flow That Was Supposed to Be Off

On a healthcare recognition platform.

8 min·
Batching Past the Rate Limit

On a large property marketplace.

8 min·