Featured write-up
Account Takeover in an Android App via OTP Bypass
A healthcare Android app trusted the OTP-verification result that its own client rendered. Flip one byte in the server response and the authentication gate opened, straight into medical records.