Selected research & disclosures
A curated view of the work. Some entries are anonymized or summarized where programs require confidentiality; full write-ups are linked where public.
IDOR chain leading to full account takeover
A predictable object reference combined with a weak authorization check allowed cross-tenant access and a complete takeover path.
SSRF reaching cloud instance metadata
A server-side request forgery primitive in an import feature reached the metadata endpoint, exposing scoped credentials.
Authorization bypass in a GraphQL resolver
A nested resolver skipped an ownership check, allowing authenticated users to read records outside their organization.
OAuth token theft via open redirect
A loosely validated redirect parameter in the authorization flow enabled exfiltration of access tokens to an attacker origin.
Public bucket exposing build artifacts and secrets
A misconfigured storage bucket exposed CI artifacts, revealing a long-lived credential that widened the blast radius.
Subdomain takeover via dangling CNAME
A dangling DNS record pointing to a deprovisioned service allowed content control on a trusted subdomain.
Continuous attack-surface monitoring suite
An internal automation pipeline for asset discovery, change detection, and prioritized alerting across large scopes.
Certificate-pinning bypass enabling traffic inspection
A weakness in the pinning implementation permitted interception of API traffic under a controlled test environment.
Have a program, a target, or a hard problem?
Whether you run a bug bounty program or need focused security research, Senvia can help. Reach out and let's talk scope.