Skip to main content

// Research

Threat Intelligence & Disclosures

Security advisories published by our offensive research team. Every disclosure follows coordinated responsible disclosure standards - vendors are contacted and given reasonable remediation time before publication.

MEDIUMAugust 2026

SDX-2026-005

Batch Timeout Race Condition in PeggyJV Gravity Bridge

During an independent protocol architecture review, SDX Shadow Labs identified a subtle but highimpact statesynchronization race condition ...

Race ConditionWeb3Cross-Chain BridgeBusiness Logic
CRITICALAugust 2026

SDX-2026-004

Unauthenticated Exposure of Active Security Researcher Infrastructure: Remote Code Execution, AI API Key Leakage, and Full Operational Intelligence Disclosure

Executive Summary During routine passive reconnaissance research, the SDX Shadow Labs research team identified an openly accessible perso...

Unauthenticated AccessRemote Code ExecutionAPI Key ExposureOperational SecurityResearcher InfrastructureBug BountyOPSEC Failure
CRITICALAugust 2026

SDX-2026-003

Unauthenticated API Gateway Collapse: Mass PII Exfiltration, Unauthenticated Database Mutations, and Infrastructure SMS Abuse in Hyperlocal HealthTech Platform

Executive Summary SDX Shadow Labs conducted an indepth security analysis of the core microservice architecture powering a major Indian He...

Broken Access ControlMass Data LeakUnauthenticated Write OperationsSMS AbuseHealthTechDPDP Act
CRITICALJuly 2026

SDX-2026-002

Firebase Authentication Bypass & Paywall Defeat in Major Short Video & Audio Streaming Platform

Overview SDX Shadow Labs recently identified a critical chain of vulnerabilities in a major audio and short video streaming platform (Tar...

Authentication BypassBFLAAPI SecurityData Leak
CRITICALJuly 2026

SDX-2026-001

Authentication Bypass via SAML Signature Algorithm Confusion in miniOrange SAML SSO

Executive Summary In July 2026, during a security assessment of a target organization's web infrastructure, the SDX Shadow Labs research ...

SAMLAuthentication BypassWordPressCryptographyCWE-347
CRITICALNov 2025

SDX-2025-002

Chained SQL Injection Vulnerabilities in Large Private Educational Technical Support System

Executive Summary In November 2025, during an authorized security assessment, the SDX Shadow Labs offensive research team analyzed a centr...

SQL InjectionPII LeakMobile API
CRITICALJuly 2025

SDX-2025-001

Remote Code Execution (RCE) via Unauthenticated Redis Exposure on EdTech Server

Executive Summary In July 2025, during a blackbox infrastructure security assessment for an earlystage educational technology startup, the...

RCEData ExfiltrationServer SecurityRedis
CRITICALDec 2024

SDX-2024-002

Remote Code Execution (RCE) and System Compromise in University Administration Portal

Executive Summary In December 2024, the SDX Shadow Labs research division performed a vulnerability assessment of a public university admi...

CWE-502Insecure DeserializationRCELateral MovementMSRPC
HIGHJuly 2024

SDX-2024-001

Premium Course Access and Certification Generation Bypass on EdTech Platform

Executive Summary In July 2024, the SDX Shadow Labs offensive security team identified a critical Broken Access Control (BAC) vulnerabilit...

Auth BypassBusiness LogicEdTechBroken Access Control

// Subscribe

Get notified when we publish new advisories.

By subscribing, you agree to receive security advisories per our Privacy Policy. No spam. Unsubscribe anytime.