
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Shellvoide Blog - AI-Powered Cybersecurity, Compliance &amp; Penetration Testing</title>
      <link>https://shellvoide.com/blog/blog</link>
      <description>The Shellvoide security blog: AI-driven penetration testing, vulnerability research, and application security insights from the team behind KLUE.</description>
      <language>en-us</language>
      <managingEditor>info@shellvoide.com (Shellvoide)</managingEditor>
      <webMaster>info@shellvoide.com (Shellvoide)</webMaster>
      <lastBuildDate>Fri, 17 Jul 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://shellvoide.com/blog/tags/websocket-security/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://shellvoide.com/blog/blog/websocket-auth-bypass-bug-bounty-case-study</guid>
    <title>KLUE vs. a Hardened Target: One Bug, No Signature Required</title>
    <link>https://shellvoide.com/blog/blog/websocket-auth-bypass-bug-bounty-case-study</link>
    <description>A detailed bug bounty writeup. Our autonomous agent KLUE spent hours proving a hardened crypto-mining marketplace was hardened, then reverse-engineered its HMAC signing scheme, mapped a STOMP WebSocket buried in the authenticated app bundles, and discovered it performed no authentication at all, routing private per-tenant channels off a client-supplied parameter. An unauthenticated, cross-tenant data leak, responsibly disclosed and rewarded.</description>
    <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>klue</category><category>case-study</category><category>bug-bounty</category><category>ai-pentesting</category><category>websocket-security</category><category>broken-authentication</category><category>stomp</category><category>bola</category><category>idor</category><category>autonomous-security</category><category>appsec</category><category>pentesting</category>
  </item>

    </channel>
  </rss>
