#JWT
JWT logout is often an illusion.

Deleting the token only removes it from the client. Any copied token still works until it expires.

That’s the tradeoff of stateless auth: the server tracks nothing.

The usual fix is a blocklist, which makes the system stateful again

#SoftwareEngineering #Security
October 1, 2026 at 4:06 PM
Y es que NO validaba la firma del JWT. Así que pudo crear un token sin firma, poner upn: "admin" y ya está.

Resultado: acceso como administrador y capacidad para ejecutar SQL.

Toda la historia la tienes aquí:
How I Could’ve Accessed 17 Trillion Microsoft Records
How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach.
blog.faav.net
October 1, 2026 at 2:04 PM
🔴 Estrategias de Protección de una API REST en Laravel con Fingerprinting en los JWT Tokens
🔴 Veremos una estrategia para proteger el robo de los JWT creando una firma digital que corresponda exclusivamente al usuario. Video: youtu.be/bXx605f9EBI
October 1, 2026 at 10:59 AM
JSON, YAML, regex, hashing, JWT, cron — devtul packs 12 dev tools that run 100% in your browser. No upload, no account, no ads, works offline. Try devtul.fun.
devtul.fun — Free Developer Tools. Fast, Local, Private.
Free online developer tools: JSON Viewer, YAML Viewer, Markdown Viewer, Regex Tester, Diff Checker, UUID Generator, Cron Generator, JWT Decoder and Base64 Encoder, plus eleven regex reference pages. P...
devtul.fun
October 1, 2026 at 9:02 AM
💻 Developer IT-Tools

A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax

🔗 https://dev.dailytoolbox.org

#DevTools #Programming #WebDev
Developer IT-Tools - DailyToolbox
Free, fast, and privacy-first web utilities with no paywalls.
dev.dailytoolbox.org
October 1, 2026 at 9:00 AM
Is that token expired, or is the bug somewhere else? Paste a JWT to see its decoded header, payload and expiry, then copy them. Local-only and free, no account.

pixoate.com/jwt-decoder

#JWT #WebDev
JWT Decoder – View Token Payload & Expiry Instantly
Paste a JSON Web Token to see and copy its decoded header, payload and expiry instantly. Local-only and free to use with no account.
pixoate.com
October 1, 2026 at 7:26 AM
🚨 EUVD-2026-90492
📊 9.3/10
🏢 Hitachi Industrial Equipment Systems

📝 Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90492

#cybersecurity #infosec #cve #euvd
October 1, 2026 at 6:01 AM
The JWT detail is the interesting part — "authorization was there" but a teenager walked through it anyway. That's the classic gap between having auth and having correct auth: token validation, audience/scope checks, and object-level authorization are where these bugs live. AuthN is not authZ.
October 1, 2026 at 4:31 AM
점심 먹고 와서 오전에 AI랑 작업한 거 보는데, 내가 뭘 요청했고 왜 그랬는지 헷갈릴 뻔함.
다행히 '/AI업무보고' 치니 로그인 기능, 세션 관리 복잡해서 요청한 것, JWT 발급까지 진행된 상황이 딱 나옴.
내일은 토큰 만료 처리하면 될 듯. 이런 게 자동으로 정리됨.
https://github.com/jyoung9154/AIAgent_Report #AI개발 #업무보고서 #광고
October 1, 2026 at 3:16 AM
method. You can name an API key security scheme in tools-list.security, in addition to a JWT security scheme. For more information, see Configure Model Context Protocol.
October 1, 2026 at 1:20 AM
Open source. Supports ngrok, tmux, and Claude Code. PWA install + QR/JWT auth docs on the listing. www.everydev.ai/tools/clsh
clsh - Mobile Terminal Server for Mac | EveryDev.ai
clsh is an open-source tool that turns your Mac into a pocket-sized terminal server. Run `npx clsh-dev`, scan the QR code on your phone, and you have…
www.everydev.ai
October 1, 2026 at 1:01 AM
CVE-2026-28802 is trending. Hype score 3, currently #8 on cvemon.

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg:…

https://cvemon.intruder.io/cves/CVE-2026-28802
September 30, 2026 at 11:56 PM
A 16-year-old security researcher discovered a critical vulnerability in a Microsoft analytics service called Titan. By exploiting an unsigned JWT, the researcher gained unauthorized SQL access to 17.3 trillion rows of data. Microsoft has since patched the flaw.
I Could've Accessed 17T Microsoft Records (201)
How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach.
news.ycombinator.com
September 30, 2026 at 8:49 PM
💻 Developer IT-Tools

A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax

🔗 https://dev.dailytoolbox.org

#DevTools #Programming #WebDev
Developer IT-Tools - DailyToolbox
Free, fast, and privacy-first web utilities with no paywalls.
dev.dailytoolbox.org
September 30, 2026 at 8:45 PM
Microsoft 레코드 17조 건에 접근할 수 있었다

Microsoft 내부 분석 서비스 Titan 이 로그인 JWT의 서명을 검증하지 않아, 실제 자격 증명 없이 관리자 신원을 사칭하고 SQL을 실행할 수 있었음 테넌트, 대상 서비스, 애플리케이션 검사는 존재했지만 서명 없는 토큰도 통과했으며, upn 을 admin ...
Microsoft 레코드 17조 건에 접근할 수 있었다
Microsoft 내부 분석 서비스 Titan 이 로그인 JWT의 서명을 검증하지 않아, 실제 자격 증명 없이 관리자 신원을 사칭하고 SQL을 실행할 수 있었음 테넌트, 대상 서비스, 애플리케이션 검사는 존재했지만 서명 없는 토큰도 통과했으며, upn 을 admin ...
news.hada.io
September 30, 2026 at 8:00 PM
Microsoft's internal Titan analytics service never verified JWT signatures, so a forged admin token allowed SQL queries across an estimated 17.3 trillion rows. Endpoint locked Sept 9.

#InfoSec #BugBounty #JWT #Microsoft
How I Could’ve Accessed 17 Trillion Microsoft Records
How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach.
blog.faav.net
September 30, 2026 at 6:43 PM
💻 Developer IT-Tools

A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax

🔗 https://dev.dailytoolbox.org

#DevTools #Programming #WebDev
Developer IT-Tools - DailyToolbox
Free, fast, and privacy-first web utilities with no paywalls.
dev.dailytoolbox.org
September 30, 2026 at 4:00 PM
En esta guía completa para la creación de una REST API empleando Laravel (puedes adaptar los conceptos a cualquier otro lenguaje:

www.desarrollolibre.net/blog/laravel...

Técnicas:

Unificación de endpoints
Firma digital de peticiones
Fingerprinting para JWT
Rate Limiting (Límite de peticiones)
Crear una API REST escalable, modular y protegida en Laravel 13
Aprende que es una Rest API, porqué son imprescindibles para interconectar sistemas, creamos la primera tipo CRUD, hablamos sobre como modularizarlas y PROTEGERLAS.
www.desarrollolibre.net
September 30, 2026 at 2:57 PM
#後で読む 用メモです→
パスキーMFATOTPOIDCJWT は何が違うのかブラウザで動く DB エディタにパスキーを入れて学んだこと
パスキー、MFA、TOTP、OIDC、JWT は何が違うのか:ブラウザで動く DB エディタにパスキーを入れて学んだこと
zenn.dev
September 30, 2026 at 2:10 PM
When auth.uid() returns null in Supabase policies, it is usually because the request hit an endpoint without a valid JWT or used the service role key, bypassing user context entirely.

https://rowshield.dev/audit?utm_source=bluesky&utm_campaign=developer-education&utm_medium=social
September 30, 2026 at 1:46 PM
만약 오늘 퇴근 전에 '/AI업무보고'를 쳤다면
AI한테 로그인 기능 요청함, 세션 관리 엉망이라 그랬음. JWT 발급까지 완료, 내일 토큰 만료 처리 남았다는 게 정리됐을 듯.
뭘 고쳤고 왜 `try-catch` 넣었는지도 다 나왔을 수 있음.
https://github.com/jyoung9154/AIAgent_Report #개발로그 #퇴근전 #광고
September 30, 2026 at 10:09 AM
📦 huyct/login-module v1.1.1

Login module for nwidart/laravel-modules: CMS login (CoreUI admin layout) and device-based JWT authentication for mobile APIs.

🔗 https://github.com/huydevct/login-module
September 30, 2026 at 9:26 AM
I gave Claude Code access to my Auth0 tenant to audit my JWT validation.

It found a bug no linter could: my tenant was already rotating signing keys, and my app only checked the first one.

I wrote up what worked (and the guardrails) for @auth0byokta.bsky.social 👇

auth0.com/blog/integra...
September 30, 2026 at 6:51 AM