Intelligence Reports
// AUTHORED BY SERROS404
MEDIUM
Web Security2026-08-28
Dissecting IDOR: When Hidden Resources Are Still Accessible Through the API
A practical breakdown of Insecure Direct Object Reference (IDOR) — theory, a real-world private-album API case study, comparison with other disclosed reports, and detection/mitigation strategies.
SERROS404
CRITICAL
Web Security2026-01-28
Critical 10.0: Full BI Infrastructure Compromise via Default Credentials
A detailed write-up on how factory-default credentials on a MicroStrategy administrative panel led to a complete takeover of corporate Business Intelligence assets.
SERROS404
HIGH
Offensive Techniques2025-12-26
Abusing WhatsApp Desktop for Initial Access: Python ZipApp Reverse Shell
A technical analysis of how .pyz files can be used to bypass protections and establish a Reverse Shell via WhatsApp Desktop.
SERROS404