惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Hacker News: Ask HN
Hacker News: Ask HN
The Hacker News
The Hacker News
S
Security Affairs
T
Tor Project blog
N
News | PayPal Newsroom
V2EX - 技术
V2EX - 技术
Microsoft Security Blog
Microsoft Security Blog
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
P
Palo Alto Networks Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Vercel News
Vercel News
W
WeLiveSecurity
Y
Y Combinator Blog
TaoSecurity Blog
TaoSecurity Blog
MongoDB | Blog
MongoDB | Blog
Cloudbric
Cloudbric
大猫的无限游戏
大猫的无限游戏
Blog — PlanetScale
Blog — PlanetScale
G
GRAHAM CLULEY
博客园 - 聂微东
月光博客
月光博客
T
The Exploit Database - CXSecurity.com
C
Cyber Attacks, Cyber Crime and Cyber Security
Latest news
Latest news
H
Help Net Security
U
Unit 42
P
Privacy & Cybersecurity Law Blog
The GitHub Blog
The GitHub Blog
S
Securelist
The Last Watchdog
The Last Watchdog
Stack Overflow Blog
Stack Overflow Blog
H
Hacker News: Front Page
C
Check Point Blog
Schneier on Security
Schneier on Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Schneier on Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
A
Arctic Wolf
P
Privacy International News Feed
WordPress大学
WordPress大学
T
Threatpost
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
Secure Thoughts
Simon Willison's Weblog
Simon Willison's Weblog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI

Hacker News: Front Page

SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads GitHub - GainSec/AutoProber: Hardware hacker’s flying probe automation stack for agent-driven target discovery, microscope mapping, safety-monitored CNC motion, probe review, and controlled pin probing. Introducing Claude Opus 4.7 Qwen Studio The Future of Everything is Lies, I Guess: Where Do We Go From Here? GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh Virginia Bans Sale of Geolocation Data Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis Ancient DNA reveals pervasive directional selection across West Eurasia [pdf] AI cybersecurity is not proof of work Moving a large-scale metrics pipeline from StatsD to OpenTelemetry / Prometheus GitHub - Nightmare-Eclipse/RedSun: The Red Sun vulnerability repository GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. A Better Ludum Dare; Or, How to Ruin a Legacy GitHub - macOS26/Agent: Any AI, replaces Claude Code, Cursor, OpenClaw. Over 18 LLM providers (Claude, OpenAI, Gemini, Ollama, Zai, HF, Qwen) wired into a native Mac app that writes code, builds Xcode projects, bumps versions, manages git, automates Safari, use AppleScript, JS or Accessibility, extend Agent! w/ MCP Servers, run tasks from your iPhone via Messages. YouTube now lets you turn off Shorts I Made a Terminal Pager Burgers | マクドナルド公式 Commands — HackerNews CLI documentation ChatGPT for Excel PiCore - Raspberry Pi Port of Tiny Core Linux Live Nation illegally monopolized ticketing market, jury finds Google Broke Its Promise to Me. Now ICE Has My Data. Founding Engineer at Adaptional | Y Combinator CRISPR takes important step toward silencing Down syndrome’s extra chromosome GitHub - saffron-health/libretto: The AI toolkit for building reliable browser automations US v. Heppner (S.D.N.Y. 2026) no attorney-client privilege for AI chats [pdf] Unexpected €54k billing spike in 13 hours: Firebase browser key without API restrictions used for Gemini requests Fragments: April 14 Cal.com Goes Closed Source: Why AI Security Is Forcing Our Decision | Cal.com - Scheduling Software for Online Bookings Laravel raised money and now injects ads directly into your agent Codex Hacked a Samsung TV Tech Valuations Back to Pre-AI Boom Levels A perfectable programming language — Soter GitHub - halfwhey/claudraband: Claude Code for the Power User Partnership through Play: Investigating How Long-Distance Couples Use Digital Games to Facilitate Intimacy Textbooks and Methods of Note-Taking in Early Modern Europe (2008) Eternity in six hours: Intergalactic spreading of intelligent life (2013) Seven countries now generate 100% of their electricity from renewable energy Tell HN: OpenAI silently removed Study Mode from ChatGPT Pro Max 5x Quota Exhausted in 1.5 Hours Despite Moderate Usage Show HN: Oberon System 3 runs natively on Raspberry Pi 3 (with ready SD card) Tell HN: docker pull fails in spain due to football cloudflare block Bring Back Idiomatic Design No one owes you supply-chain security GitHub - xsawyerx/curl-doom: DOOM, played over cURL Apple update turns Czech mate for locked-out iPhone user The Grand Line Cache TTL silently regressed from 1h to 5m around early March 2026, causing quota and cost inflation Building a Z-Machine in the worst possible language The peril of laziness lost Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda AI Will Be Met With Violence, and Nothing Good Will Come of It GitHub - duguyue100/midnight-captain: Inspired by Midnight Commander, tailored to my taste. How to build a `git diff` driver · Jamie Tanna | Software Engineer Center for Responsible, Decentralized Intelligence at Berkeley The Local Universe’s Expansion Rate Is Clearer Than Ever, but Still Doesn’t Add Up - A new synthesis of astronomical measurements confirms a persistent mismatch that could point to physics beyond current models The disturbing white paper Red Hat is trying to erase from the internet – OSnews NetBlocks (@netblocks@mastodon.social) The Future of Everything is Lies, I Guess: Annoyances ‘Abhorrent’: the inside story of the Polymarket gamblers betting millions on war Productive procrastination — Max van IJsselmuiden maps, territory and LMs 447 Terabytes per Square Centimetre at Zero Retention Energy: Non-Volatile Memory at the Atomic Scale on Fluorographane Show HN: Pardonned.com – A searchable database of US Pardons 20 Years on AWS and Never Not My Job The Seasons are Wrong The FAA wants gamers to apply for air traffic control jobs Artemis II crew splashes down near San Diego after historic moon mission Why weekends are under threat We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs How a dancer with ALS used brainwaves to perform live On filing the corners off my MacBooks Installing every* Firefox extension OpenClaw’s memory is unreliable, and you don’t know when it will break Steve Blank Nowhere Is Safe Chimpanzees in Uganda locked in vicious 'civil war', say researchers watgo - a WebAssembly Toolkit for Go linux/Documentation/process/coding-assistants.rst at master · torvalds/linux GitHub - callumlocke/json-formatter: Makes JSON easy to read. Founding Product Engineer at Bild AI | Y Combinator A compelling title that is cryptic enough to get you to take action on it GitHub - Keychron/Keychron-Keyboards-Hardware-Design: Industrial design files for Keychron keyboards and mice. 100+ models with CAD assets in STEP, DXF, DWG, and PDF. Source-available, with commercial use allowed for original compatible accessories within the license terms. [ANNOUNCE] WireGuardNT v0.11 and WireGuard for Windows v0.6 Released 1D-Chess Helium Is Hard to Replace Keeping a Postgres queue healthy — PlanetScale Serenity Forge (@serenityforge.com) Our response to the Axios developer tool compromise Do Americans read print books, e-books or audiobooks more? Uncharted island soon to appear on nautical charts The Problem That Built an Industry Fragments: April 2 Python Release Python install manager 26.1 Bitcoin miners are losing $19,000 on every BTC produced as difficulty drops 7.8% God sleeps in the minerals Harness engineering: leveraging Codex in an agent-first world Apple Silicon and Virtual Machines: Beating the 2 VM Limit What have been the greatest intellectual achievements? The APL Programming Language Source Code
Exploiting vulnerabilities in Johnson & Johnson web apps
Eaton · 2026-06-25 · via Hacker News: Front Page

Eaton

Today I am revealing vulnerabilities I found in 2 very different Johnson & Johnson web apps. One is a vulnerability in a college campus recruiting system that exposed details of nearly 1,000 students, and the other is an admin takeover of an internal audit system used by 20 companies. Let’s dive in!

#1: Campus Recruiting

You know those career fairs and recruiting events on college campuses? JnJ likes to go to these to scout new talent. They built a “Campus Recruiting” website to manage these events:

Students are given an event key and they use it to submit their information:

Nothing particularly exciting… until you look at the underlying code of the website, where you can find some interesting private recruiter routes!

When you go to “/recruiter”, you are sent to the Microsoft SSO login page, confirming this part of the site is restricted to JnJ employees:

The authentication setup is really simple. The Microsoft Authentication Library (MSAL) is integrated into the frontend and it is in charge of making sure an employee is logged in:

One client-side trick that often helps me expose insecure web apps is to hack MSAL into always thinking someone is logged in. If there are underlying APIs that do not use the token correctly, this helps discover such issues quickly. In this case, all I had to do was modify the MSAL code to always return details of 1 account that is “logged in”:

Once done, the private recruiter routes were accessible. You could manage the events, create new ones, and view all the students’ information. The recruiter dashboard also lets you see the ratings and notes they give to specific students they interview:

What went wrong: the MSAL token was not actually used anywhere. Instead, a hardcoded API key was used to authenticate to their AWS APIs:

There were nearly 1,000 students impacted.

The Campus Recruiting site has since been updated to replace API key authentication with Bearer token (MSAL) authentication.

#2 Audit Tracking Management System

The Audit Tracking Management System (ATMS) is an internal web app to aid in managing audits across all of JnJ and their associated companies:

  1. LifeScan
  2. Ethicon, Inc
  3. Biosense Webster
  4. ITS
  5. Depuy
  6. Ethicon-Endo
  7. Janssen
  8. Vistakon
  9. Acclarent
  10. JDx
  11. Sterilmed
  12. CLS
  13. JJSV
  14. Cerenovus
  15. EQ
  16. Janssen UK & Ireland
  17. RAD
  18. Abiomed Inc.
  19. CQ MedTech
  20. V-Wave

This one required a bit more work to get into compared to Campus Recruiting. Immediately when visiting the site, you are redirected to the Microsoft SSO login page. Before this happens, the ReactJS app is downloaded and many interesting APIs could be found:

I decided to visit the “getAllUsers” API to see what would happen. It returned a list of 13.6k JnJ employees:

That was huge because it indicated all the APIs were unauthenticated, and it was just a matter of hacking up the client-side code to get full access to everything.

This is what the authentication code looked like. Like Campus Recruiting, it uses MSAL to authenticate the user using Microsoft SSO, and then it sets some values to local storage. There is no sign of it using the Bearer token, which is good for us!

For a user spoof to work correctly, I needed to find a username and WWID of a valid JnJ employee that uses this system. Preferably one with a lot of permissions. I came across the help page that gave me the details of the system administrator:

Searching that name against users in the getAllUsers API revealed the information I needed, and a patch was devised:

This stops the login redirect and sets hardcoded values into local storage as if a valid login had just taken place. This resulted in something new showing up:

Clicking OK was not the solution. Back into the code we go…

That is the code that creates a session. It is just a GET request to an API that returns a session GUID, and sets a timestamp for the purpose of calculating its expiry. Visiting that API, it returned a valid session ID:

I then plugged that in manually with a valid timestamp…

Refreshed, and I was in!

You can use the drop-down to switch between companies:

As admin, I had access to a special menu:

And that is about the extent of what I explored. The system is packed full of presumably confidential information and transcripts. Even from all the way over in Russia. Due to various confidentiality warnings, I have opted to not show any internal meeting minutes or transcripts here.

Bonus: they used a rather dumb client-side encryption scheme to try and obscure some secret values. Ironically, it seems this auditing system never received an audit itself if code like this ends up being published:

Timeline

The last time I reported a security vulnerability to JnJ was back in 2024. The experience I had back then was stellar – they took immediate action and were a true pleasure to work with. Fast forward to reporting these 2 vulnerabilities, the experience was less positive.

Both vulnerabilities were reported to them in October 2025. By the end of the month, they had resolved the Campus Recruiting vulnerability. However, the ATMS vulnerability was never acted upon. I followed up for months until April 2026, which is when I asked a journalist friend if they could help move things along. As predicted, their email to JnJ’s media relations finally got them to fix it. It was a bit perplexing that it took press involvement to address what I believed was a serious internal data breach waiting to happen.

Full timeline:

  • October 6, 2025: Reported to JnJ’s Vulnerability Reporting Program.
  • October 16, 2025: Followed up after no response and no action.
  • October 17, 2025: First response from JnJ received confirming they will look into the findings.
  • October 31, 2025: Campus Recruiting vulnerability fixed; I ask about ATMS.
  • November 17, 2025: Followed up after no response and no action on ATMS.
  • December 22, 2025: Followed up after no response and no action on ATMS.
  • January 22, 2026: Followed up after no response and no action on ATMS.
  • April 8, 2026: Journalist contacted.
  • April 21, 2026: ATMS vulnerability finally fixed.
  • June 24, 2026: Published

Not the best showing for JnJ here. It seemed they were a lot more effective at handling vulnerabilities back in 2024 compared to 2025. I hope they correct whatever broke down in this process so they can return to the amazing reporting experience I had with them back in 2024.

Subscribe to new posts

Get an email notification every time something new is published.