Skip to main content

Field Notes

Production-data clones expose staging environments

Copying a production database into staging can quietly duplicate customer, employee, and transaction data into a weaker environment. Learn how the exposure happens, how to audit it safely, and how synthetic data, minimization, isolation, and verified cleanup reduce the risk.

Indirect prompt injection in AI automation

An AI assistant that reads emails, tickets, documents, webpages, or CRM records can mistake attacker-controlled text for instructions. Learn how indirect prompt injection crosses trust boundaries—and how deterministic policy, least privilege, exact approval, provenance, and monitoring keep model output from becoming unauthorized business authority.

0FZ: every route through NARROW-17

A complete, spoiler-marked walkthrough of 0FZ Transmission One, including every puzzle solution, optional record, casualty path, J-0 route, final choice, accessibility mode, and lesson hidden inside NARROW/17.

Forged webhooks and unsigned events

An endpoint that trusts incoming JSON can be tricked into marking orders paid, granting access, or launching automations. Learn how forged webhooks work and how signatures, replay controls, idempotency, account binding, and state validation protect the business.

Orphaned OAuth tokens after employee offboarding

Disabling a former worker’s main login may not revoke every session, OAuth grant, personal token, shared credential, or standalone account. Learn how lingering access works, how to audit it safely, and how to build offboarding that produces verifiable evidence.

Separate backup control from everyday administration

A backup can complete every night and still fail when the same compromised account can erase production, recovery copies, retention settings, or encryption keys. Learn the attack chain, run a safe local demonstration, and design a tested recovery boundary that survives loss of production control.

Mutable GitHub Actions and supply-chain risk

A workflow can execute different third-party code without any edit to your repository when an action is referenced by a movable tag. Learn the attack chain, reproduce it safely, assess the business impact, and harden the path from commit to production.

Dangling DNS and subdomain takeover

Deleting a hosted service without removing its DNS record can leave a trusted company subdomain pointing at a resource another party may be able to claim. Learn the attack chain, run a safe localhost demonstration, assess the business impact, and build a disciplined offboarding process.

Dependency confusion in private software builds

A mixed public-and-private package configuration can let an untrusted release outrank an approved internal dependency. Learn how dependency confusion works, reproduce it safely on localhost, assess the business impact, and harden the path from source code to release.

Hardcoded secrets: finding the forgotten API key

A single API key committed to source code can expose customer data, create fraudulent cloud costs, interrupt operations, and give an intruder a path into connected systems. Learn how the weakness works, reproduce it safely in a local lab, and fix it at the code, hosting, and process levels.