999.0.4: The Version Number That Got Me Root Inside a Bank

Reported through the bank’s bug bounty program, triaged as critical, marked valid and rewarded. Every name, host and package in this post is a placeholder, so the commands here won’t reproduce against the real target. I never sent a payload to the bank. I uploaded a file to a public website, went to make coffee, and by the time I came back I had code execution on their build server, root on production containers in three different clouds, and a shell on some poor developer’s Windows laptop. ...

July 26, 2026 · 9 min · 1916 words · Jesus Lujan

Hacking eToro's AI Assistant: Stealing Any User's Financial Data With a Single Tweet

All issues were responsibly reported to eToro through Bugcrowd and have been acknowledged. Hi, I’m back. This time I wandered somewhere I hadn’t planned to go. I wasn’t hunting for AI bugs at all. I was poking at eToro’s trading platform, the usual stuff, IDOR on portfolio endpoints, parameter tampering, when a little chat bubble caught my eye down in the corner. Torii, eToro’s AI assistant. Ask it about your portfolio, your balances, the market, and it just answers. ...

July 13, 2026 · 7 min · 1443 words · Jesus Lujan

From Redirect to Merchant Administration Takeover at a Major Bank

Disclaimer This blog post is shared for educational and academic purposes only. All issues described here were responsibly reported to the affected company and have since been verified. The intention of this write-up is to raise awareness, improve security practices, and share lessons learned with the community. Since I was back in Korea and looking for my next role, I decided to spend this month fully focused on bug bounties again. It’s always a mix of frustration and small breakthroughs. One of the simple but surprisingly interesting bugs I uncovered was this cross-domain redirect flaw in a bank’s core application. ...

February 22, 2026 · 5 min · 981 words · Jesus Lujan

Tickets and Popcorn please!, The Day main.js Became the Key Vault

Disclaimer This blog post is shared for educational and academic purposes only. All issues described here were responsibly reported to the affected company and have since been fixed and verified. Permission to publish was granted by the company. The intention of this write-up is to raise awareness, improve security practices, and share lessons learned with the community. Act I — The Setup It all started on a lazy evening in April. I wasn’t trying to hack anything major, just poking around a movie ticketing site which I’m client of with DevTools open. As I added a ticket to my cart, something odd caught my eye: a POST request carrying a mysterious parameter named encInfo. ...

August 25, 2025 · 7 min · 1431 words · Jesus Lujan