| |
A security researcher discovered vulnerabilities in an electric scooter company's infrastructure by analyzing their web services and mobile app backend. Through subdomain enumeration, the researcher identified an unprotected operator panel containing an Angular application with 83 API endpoints controlling vehicles, users, trips, and financial systems, though direct access attempts were blocked by authentication measures. The investigation revealed the company's security relied primarily on authentication checks, leaving other potential attack vectors unexplored.
Read Full Article →
← More Tech news