Post #3922145
2026-07-18 23:17 UTC
whats this? another post on the chinese wool-farming underground, and this time the targets are state-owned media and govt-adjacent civic apps :P
turns out a pile of these apps share one reward + lottery backend, and the secret thats meant to make claims unforgeable is just… sitting in the client. recover it and you can forge a valid claim the backend accepts.
read-only, walked it from one github repo. part of an ongoing series.
https://neurowinter.com/security/2026/07/16/forging-the-government-lottery/
#infosec #threatintel #CTI #OSINT #reverseengineering #China #security #appsec
Replies (0)
No replies.