[ BLOG ]
PUBLISHED WORK
Security research, CVEs we found, and interesting vulnerabilities. Everything here is written from experience.
SSRF Redirect Bypass in Sonatype Nexus, Stealing Cloud Credentials Through a Proxy Repository (CVE-2026-14646)
Sonatype Nexus Repository Manager had SSRF protection that blocked requests to cloud metadata endpoints. But it only validated the initial URL. A single HTTP redirect bypassed everything. Full technical breakdown of CVE-2026-14646.
Cart Swap Attack on Stripe for WooCommerce, From Session Hijack to Full Payment Bypass
A deep dive into how a missing ownership check on a single WooCommerce AJAX endpoint let attackers rewrite Stripe payment amounts mid checkout. Includes the full attack flow, root cause analysis, and what every developer should learn from it.
31 CVEs in Adobe Content Credentials SDK & Adobe Commerce
We spent months digging into Adobe's Content Credentials SDK and Adobe Commerce. Ended up with 31 CVEs across three security bulletins.
Welcome to TFSec
Who we are, what we do, and what you can expect from this blog.