Team Triada
All Research
Every blog post, whitepaper, and research note, in one place.
Client-Side Secret Exposure in Modern SPA/JAMstack Applications
How we found hardcoded signing keys and BaaS credentials in production JS bundles across two separate engagements, and how we triaged them.
2026-07-02·5 min read
methodologysecretsspa
Old Commits, Live Credentials: The Git History Blind Spot
Why secret scanning limited to HEAD misses a whole class of long-lived exposure, and the sweep methodology we now run on every engagement.
2026-06-25·4 min read
researchsecretsgit
SSRF via WordPress XML-RPC Pingback: A Recurring Finding
How we found and confirmed SSRF and brute-force amplification through a decade-old WordPress endpoint during a recent web assessment.
2026-06-10·5 min read
ssrfwordpressweb


