·2409 words·12 mins
How an afternoon of poking a 3D printer firmware with a stick turned into full compromise.
·374 words·2 mins
From a popped shell to full Kubernetes cluster compromise — exploiting GCP metadata, kubelet credentials, and CSR auto-approval to bypass RBAC.
·275 words·2 mins
Abusing Python’s floating point arithmetic to forge JWT-like tokens — when float(‘inf’) meets type juggling.