The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System
ID: 7dff64ba-4c67-5f63-b852-a69f08f2a063
STIX ID: report--7dff64ba-4c67-5f63-b852-a69f08f2a063
Feed Name: Wiz Blog
The report describes an automated Red Agent finding: a business-logic authorization bypass in a major B2B platform’s internal API where a client-supplied boolean flag (e.g., unmaskContactData) was trusted by the backend, allowing free-tier accounts to retrieve unmasked business and personal contact data at scale (600M+ contacts, 135M+ verified phone numbers, ~50% personal emails). The write-up outlines reconnaissance, schema analysis, parameter injection PoC, and notes the vendor remediated the issue within hours.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
