Featured image of post What the Server Knows, the Browser Shouldn't Get: Mapping the Frontend Secret-Leakage Surface

What the Server Knows, the Browser Shouldn't Get: Mapping the Frontend Secret-Leakage Surface

A black-box report surfaced two high-risk findings: Next.js __NEXT_DATA__ leaked server-side config into the browser, and secp256k1 key material turned up in the client bundle. From hydration mechanics to env-var inlining, source maps, CI/CD and Git history, this post maps the eight layers of the modern web's secret-leakage surface — and explains why the AI-coding era is erasing that boundary faster, with a practical checklist.

Featured image of post How a Monitoring Probe Became a Master Key: The Nezha Panel Compromise, Retraced in Full, with a Cross-Domain Table of Major Vulnerabilities

How a Monitoring Probe Became a Master Key: The Nezha Panel Compromise, Retraced in Full, with a Cross-Domain Table of Major Vulnerabilities

In January 2025, a wave of Nezha Monitoring panels were seized in bulk. The attackers took the panel and issued malicious scheduled tasks to every monitored server, planting crypto miners on machines they'd never touched directly. This post retraces the complete kill chain, explains — with the CVEs from the official 2026 audit — why a monitoring panel is a natural aggregation point of super-privilege, then lays out a cross-domain table of historical major vulnerabilities and uses CISA KEV and the Five Eyes annual lists to answer 'which domain breaks most often', finishing with a defense checklist self-hosters can actually follow.

(1 - 72)
Enter Press Enter to jump