Alex Manson
Publishes 1 feed
Alex Manson
Security researcher and SRE. Writing about vulnerability research, AI, and the practical stuff I figure out along the way.
10 posts · theirs
Lately
Sixteen strangers and a shared obfuscator: mapping the wool scene
The Trade Desk is on your health portal, your bank, and the lottery
Forging the government’s lottery: China’s civic apps run on a shared reward backend with no real secret
Farming the farmers: smallfawn’s JD login tool routes harvested credentials to their own server
A weekend in the wool: mapping a Chinese reward-farming underground from one GitHub repo
The wool DRM, part 2: the Rust wall I didn’t crack
The wool DRM, part 1: the Cython loader I cracked
DragonflyDB Lua sandbox escape via getmetatable(_G) metatable override
HashiCorp Nomad FIFO symlink attack (CVE-2026-6959, CVE-2026-8052)
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
Everything on this page was read from markup Alex Manson published — a rel="me" link, an h-card, or the feed’s own author element. Nothing was inferred from anywhere else. To correct or remove it, get in touch. Machine-readable: JSON
