Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

How I Mapped an Undocumented Vendor API in 2 Days With Claude Code

TL;DR A vendor handed us a sandbox key, a 6-page PDF, and no OpenAPI spec. I used Claude Code to turn ~40 exploratory requests into an inferred schema, a typed client, and a contract test suite in two…

  • Author mapped undocumented vendor API in 2 days
  • Used Claude Code to trace actual HTTP responses
  • Discovered 31 fields in invoice object vs 6 per PDF

Your Stripe key is on GitHub. Do this now, in this order.

Deleting the file doesn't help. The key is still live until you rotate it, and it's still readable in git history until you remove it from there too. Here's the order that actually matters.

  • Rotate Stripe secret key immediately in Stripe dashboard.
  • Remove key from Git history to prevent ongoing access.
  • Monitor for unusual activity; seek Stripe support if needed.

How I Found a postMessage Origin Bypass in an OAuth SDK

I spend a lot of time reading other people's code. Not because I enjoy it—though honestly, I kind of do—but because that's where the interesting bugs live.

  • Security researcher found postMessage bypass vulnerability in OAuth SDK
  • Lack of origin check allowed attackers to spoof messages from OAuth popup
  • Adding origin check to message event listener fixed the issue

More from Friday 28 August →