<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>MemCyber — Research</title><description>Technical writeups, vulnerability research, and methodology notes from MemCyber engagements. Sanitized and published for the engineering community.</description><link>https://www.memcyber.com/</link><language>en-us</language><item><title>Chaining IDOR and Object Metadata Leaks in Fintech APIs</title><link>https://www.memcyber.com/research/idor-chaining-fintech/</link><guid isPermaLink="true">https://www.memcyber.com/research/idor-chaining-fintech/</guid><description>How combining a seemingly low-impact IDOR with an object-metadata leak escalated to cross-tenant financial data access on a Series B fintech. Sanitized writeup and defenses.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>API</category><category>IDOR</category><category>BOLA</category><category>fintech</category><category>chaining</category><author>Atilla Mammadli</author></item><item><title>Capability-Model Pitfalls in Move: Three Patterns We See in Audit</title><link>https://www.memcyber.com/research/move-capability-model-pitfalls/</link><guid isPermaLink="true">https://www.memcyber.com/research/move-capability-model-pitfalls/</guid><description>Move&apos;s capability and object model is safer than Solidity by default, but it has its own footguns. Three patterns that repeatedly show up during our audits of Sui and Aptos protocols.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>Smart Contract</category><category>Move</category><category>Sui</category><category>Aptos</category><category>capabilities</category><category>audit</category><author>Atilla Mammadli</author></item><item><title>Webhook Signature Validation: The Five Bugs We Find Most</title><link>https://www.memcyber.com/research/webhook-forgery-signature-validation/</link><guid isPermaLink="true">https://www.memcyber.com/research/webhook-forgery-signature-validation/</guid><description>Webhook handlers look simple and therefore get written carelessly. A quick tour of the signature-validation bugs we find over and over again across fintech and SaaS engagements.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>Web App</category><category>webhooks</category><category>signatures</category><category>HMAC</category><category>replay</category><author>Atilla Mammadli</author></item></channel></rss>