Articles by bearsyankees
52

Reverse Engineering US Airline's PNR System and Accessing All Reservations (alexschapiro.com)

230

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files (alexschapiro.com)

1

Pwning OpenAI Atlas Through Exposed Browser Internals (hacktron.ai)

5

Low PNR Entropy: I accessed all airline bookings via simple math (alexschapiro.com)

6

Airline Left All Passenger Data Vulnerable Due to Missing Last-Name Check (alexschapiro.com)

3

Missing last name check left all Airline Passenger Data Vulnerable (alexschapiro.com)

1

Airline Reservation API Left All Passenger Records Vulnerable (alexschapiro.com)

2

Hacktron Hacks Supabase (hacktron.ai)

5

Nobel Peace Prize Sparks Insider Trading Questions on Prediction Sites (forbes.com/sites/brandonkochkodin)

3

New investment bank is almost entirely powered by AI -- and it works (ft.com)

1

The ancient invention that ignited game play (2021) (bbc.com)

247

Xfinity using WiFi signals in your house to detect motion (xfinity.com)

1

GerriScary: Hacking the Supply Chain of Popular Google Products (tenable.com)

1

Netflix Vulnerability: Dependency Confusion in Action (landh.tech)

290

I hacked a dating app (and how not to treat a security researcher) (alexschapiro.com)

11

Pakistan Says It Has Shot Down Five Indian Planes, Taken Soldiers Prisoner (bloomberg.com)

5

I hacked a dating app (Total account takeover) (alexschapiro.com)

1

Student exposes scary vulnerabilities in popular dating app (yaledailynews.com)

2

Hacking a Dating App: Private Chats, Passports and More Exposed (alexschapiro.com)

2

Student exposes scary vulnerabilities in popular dating app (yaledailynews.com)

3

Hacking a Dating App: Private Chats, Passports and More Exposed (alexschapiro.com)

3

The Global Right: From French Revolution-The American Insurrection (Yale Class) (coursetable.com)

1

From Cybersecurity to AI Interpretability (starseer.ai)

1

Smart Phish via GitHub – Stay Vigilant (twitter.com/hackingdave)

3

Mozilla: Temporal (Limited Availability) (developer.mozilla.org)

2

What Classes Would You Take as a Yale Undergrad? (coursetable.com)

2

Protecting Democracy from Itself: Plato's Lessons for Modern Democracies [pdf] (yale.edu)

6

First Tsunami Warning in Oregon in Years (oregonlive.com)

9

Ruler of Chechnya Claims Elon Musk Shut Down His Cybertruck (yahoo.com)

1

First Draft from Usaisi: Managing Misuse Risk for Dual-Use for Foundation Models [pdf] (nist.gov)

1

Optimizing Bot Traffic Handling for Link Previews (coursetable.com)

3

OpenAI Releases GPT-4o Mini – will replace 3.5 as default (bloomberg.com)

3

CourseTable: The Open-Source Powerhouse Behind Yale's Course Selection (coursetable.com)

1

Browse GPT auto encoder features (windows.net)

2

The obscure federal intelligence bureau that got Vietnam, Iraq and Ukraine right (vox.com)

2

Omni Hotels Hacked (techcrunch.com)

1

High Severity:Request smuggling leads to endpoint restriction bypass in Gunicorn (github.com/advisories)

1

The Meat Shower of 1876 (2014) (scientificamerican.com)

3

Cisco warns of large-scale brute-force attacks against VPN services (bleepingcomputer.com)

2

Up to a Trillion Cicadas Could Emerge in the U.S. Later This Spring (smithsonianmag.com)

2

This String Crashes Discord (not patched yet) (twitter.com/jonaslyk)

1

Show HN: Bot to See Cluster Buys, Beats VTI for 3 Month Hold on Average (twitter.com/clusterbuybot)

1

Airbnb Occupancy for Solar Eclipse (twitter.com/gregdaco)

1

Aston University researchers send data 4.5mm times faster than average broadband (eurekalert.org)

1

Yale's courses. What should be taught that isn't? (coursetable.com)

2

See what courses Yale offers its students (coursetable.com)

2

Show HN: Quist for querying JSON, simple, easy, and never has syntax errors (github.com/coursetable)