{ "name": "Corey J. Ball", "author": "Hacking APIs", "creator": "APIsecU.com", "is_admin": true }

Grants Pass, OR
Filter
Exclude
Time range
-
Minimum likes
hAPI_hacker retweeted
Mr. Robot if he had AI
66
387
3,332
240,531
Absolutely incredible research by @garethheyes One email, two readers. :before and :after inject text into the page. An AI browser reading the message does not see that text. opacity:0.00000001 does the reverse. The victim cannot read the element, but the AI browser can. Read CSS:the bomb inside your inbox by Gareth to learn more 👇 portswigger.net/research/css…
1
14
57
5,215
hAPI_hacker retweeted
In less than 24 months there will be a clip of a high profile CRO explaining this reality to a (much smaller) room of sales reps.
There's nothing kind about letting good people live in a fantasy world that no longer exists. You have to tell them, even if it hurts. Because the sooner they accept reality, the sooner they can adapt to the future.
48
227
2,966
543,088
hAPI_hacker retweeted
It’s tonight 🎉 a hang with @canva @smolmachines, @tryscope_app & the community 🤠
🌉 Sept. 24: Join us at our next Agents & APIs SF Dev Meetup featuring: 👉 ​@mlhassett, Sr. Developer Advocate, @canva 👉 @binsquares, founder, @smolmachines (YC P26) 👉 ​​@poojamakes, Sr. Developer Advocate Enterprise Adoption, @astropods_ 👉 @anandPa94, founder, @tryscope_app (YC P26) Sign up here: luma.com/Sept-SF-Agents-APIS…
3
3
15
1,212
hAPI_hacker retweeted
Think you're late to AI security? The field is just starting..... Sat down with my friend Jason Haddix (@Jhaddix) the guy who literally defined AI pentesting methodology, to show you how to become an AI hacker/pentester from scratch! Watch the full video here --->   piped.video/_yfiUQSbdPY?si=qUEv…
14
57
539
19,414
hAPI_hacker retweeted
One slot left at apisec|CON. CFP closes midnight PT today. Oct 21. Single track, ~7 talks. Theme is exploitability — chains you've actually walked, not CVSS scores you've read. If you've got the talk, send it: conf.apisecuniversity.com/ @hAPI_hacker @apisecu
1
4
193
@apisec_ai One slot left at apisec|CON. CFP closes at midnight PT tomorrow. Oct 21. Single track, ~7 talks. Theme is exploitability — chains you've actually walked, not CVSS scores you've read. If you've got the talk, send it: conf.apisecuniversity.com/
1
1
95
hAPI_hacker retweeted
Jev is now available to everyone. No waitlist. Start using it here: console.typesafe.ai
733
2,411
22,678
3,138,241
A must read for anyone in Appsec! @HackWitHerr Bandana Kaur at @apisec_ai just released the most in-depth BOLA research, I've seen in years. The reality of BOLA findings does not match the reality of API testing. BOLA shows no meaningful decline from 2023 to 2026, a time where the most awareness of the problem peaked. So, the gap isn't knowledge, it's testing techniques and remediation. Check it out: labs.apisec.ai/research/bola…
2
16
1,005
Back to work! 🤖
4
601
Fantastic English, talk, and magic 🪄 🫡
1
3
155
@Microsoft patched a critical Entra bug, told me it was not a bug, and never told you it existed. A broken API authorization flaw was used on 15 separate @azuread Entra services. Any low-privileged authenticated user in your tenant could download all sorts of logs for the entire enterprise, with no role and no admin rights. That telemetry included source IP addresses, geolocation, MFA status, application access patterns, and the Conditional Access policies applied to every sign-in. Timeline: April 8: I reported it to MSRC as VULN-181669 with a video proof of concept attached. April 23: MSRC said they could not reproduce it and asked for a video. April 24: I confirmed the video was already in the original submission. April 27: They closed the case as below the bar for immediate servicing, with no CVE and no bounty, claiming the API enforced permissions server side and returned 403. April 29: I retested, and the endpoint that had returned a full log dump now returned a role-check error that did not exist when I filed. They closed the finding as not a bug, and then they shipped the fix for it on the side. That is the opposite of coordinated disclosure. A single export across the sign-in logs exposed user principal names for every account, source IPs with geolocation, MFA status per sign-in, the full application and service principal inventory, and Conditional Access policy results. In the instance of my finding this resulted in roughly 400 MB of tenant-wide authentication data from one service. The same flaw appeared in 14 more, including Provisioning Logs, ID Protection, Conditional Access, Authentication Methods, Billing - Licenses - Audit Logs and Certificate Authorities. This was not a single misconfigured endpoint. It was one broken authorization pattern repeated across the platform. The bug is gone now, and without notification, that is precisely the problem. You cannot reproduce it, and Microsoft has published no CVE and no advisory confirming it was ever there. Without that disclosure, you have no exposure window to investigate and no indicators of compromise to hunt. The exploit traffic would show up in your logs as 200 responses to auditLogs/signIns from users who never had read access, but nothing from Microsoft tells you where to look. Microsoft should reopen VULN-181669, notify affected customers, publish indicators of compromise, and issue the CVE. Full writeup: lnkd.in/gXSVwXgZ @InsiderPhD @DoerrfeldBill @chrishonda0716 @ryanrutan @EdwardLichtner @JoseHaroPeralta @nicfill
1
8
825
Cybersecurity architects work between all the rocks and all the hard places. Engineering. Legal. Finance. Executive leadership. Often without authority over any of them. The decisions made early in the design phase echo through the environment for years, long after the people who made them have moved on. I wrote the foreword for the second edition of Lester Nichols' Cybersecurity Architect's Handbook, releasing May 11, 2026. It covers foundations, governance, toolset decisions, career roadmaps, and adaptive strategy for the people holding that position in 2026. Read the full foreword on The Hab: hapilabs.ai/blog/cah Preorder the book to secure your copy. amazon.com/Cybersecurity-Arc…
2
8
52
3,153
Just joined @PortSwigger as an official Burp Suite Ambassador. 🧡🚀 Burp has been in my toolkit for over a decade. First tool I reach for, most referenced in Hacking APIs, recommended without hesitation. I get to be a part of this avenger-like team with: @rana__khalil @0xTib3rius @apps3c @soyel_mago. What sold me is what they're NOT asking for: no commercials, no product comparisons, no fluff. Collaboration towards the goal to help secure the web. This year: blog posts, Hacking APIs Conference, Bug Bounty Village at #DEFCON, and collaborating on API security content with their research team.
14
13
172
6,136
The Hacking APIs Conference is back for 2026! HAC NYC returns May 14th. CFP is open. Got a live API hack? A breach case study? Research that made a security team sweat? Submit it. Vulnerabilities that shipped. Exploits that worked. Defenses that held.
2
18
1,943
Replying to @HackingDave
The first Skynet Civil War has begun.
2
275
Replying to @writerofscratch
4
145
10,227