How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
gist.github.com·10h·
Discuss: Hacker News
🧠Obsidian
Preview
Report Post

How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack

hi, i’m daniel. i’m a 16-year-old high school senior. in my free time, i hack billion dollar companies and build cool stuff.

about a month ago, a couple of friends and I found serious critical vulnerabilities on Mintlify, an AI documentation platform used by some of the top companies in the world.

i found a critical cross-site scripting vulnerability that, if abused, would let an attacker to inject malicious scripts into the documentation of numerous companies and steal credentials from users with a single link open.

(go read my friends’ writeups (after this one)) [how to hack discord, vercel, and more with one easy trick (eva)](https:/…

Similar Posts

Loading similar posts...