All Articles
78 guides, CVE analyses, and security research articles — page 3 of 7.
-
Hardcoded password in a Swiss medical SaaS JS bundle: what the code actually looked like
JS bundle analysis on OneDoc's professional portal found a hardcoded password in a function that provisions medical assistant accounts.
Read article → -
Clickjacking and CORS on Personio's whistleblowing platform: two findings on the wrong target
SecurityClaw found HIGH clickjacking and MEDIUM CORS reflection on Personio's whistleblowing platform — the tool employees use to report misconduct.
Read article → -
SecurityClaw pricing in 2026: what you get at each tier
SecurityClaw's agentic security testing platform — what's in the free tier, what the paid plans cover, and whether the cost makes sense for your workflow.
Read article → -
CORS wildcard on Telenor Sweden's API namespace: what the headers said and what it means
SecurityClaw found ACAO: * on every path under /api/* at www.telenor.se, plus an exposed Spring Boot actuator and missing HSTS on Ownit.
Read article → -
When your scanner can't get through the front door: Cloudflare bot protection and bug bounty hunting
Cloudflare's bot fight mode uses JA3/JA4 TLS fingerprinting to block automated clients — even from residential IPs. What the cf-mitigated header means, why rotating your User-Agent doesn't help, and what to do instead.
Read article → -
When Your Scanner Can't Get Through the Front Door: Cloudflare Bot Protection and the Modern Bug Bounty Hunter
Doctolib blocks curl at the TLS layer, not the IP layer. How Cloudflare bot fight mode works and what to do when standard scanner tooling can't get through.
Read article → -
CORS misconfiguration hunting on EU bug bounty targets: one real finding out of five
One CORS HIGH out of five EU targets: RIPE NCC's wildcard ACAO with write methods. What it looked like, how SecurityClaw found it, and how to spot it.
Read article → -
Why your open redirect scanner is lying to you
Three false positive patterns that trip automated scanners on EU bug bounty targets, and how to tell a real open redirect from noise.
Read article → -
320 findings, 4 submittable: inside a bug bounty campaign dashboard
320 raw findings, 4 submittable. How SecurityClaw tracks bug bounty campaigns at scale — dashboard architecture, submission rates, and triage layer.
Read article → -
Best tools for bug bounty hunters in 2026
The tools security researchers actually use for recon, scanning, exploitation, and reporting. No filler. Just what works on live programs in 2026.
Read article → -
June 2026 CVE opportunity analysis: 10 high-bounty vulnerabilities to hunt now
138 web/API CVEs cross-referenced against 128 active BB programs on Intigriti and YesWeHack, ranked by exploitability, bounty ceiling, and in-scope likelihood.
Read article → -
When CRITICAL Doesn't Mean Critical: False Positive Triage in JS Bundle Recon
Automated scanners flag 'CRITICAL' findings in JS bundles that turn out to be UI placeholders. Here's how to tell the real secrets from the noise.
Read article →