Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@parvesshrajh.bsky.socialOct 2, 2026, 3:56 PM

02.10.2026

#WebDevelopment

~dotenv
~Building a signup and signin workflow with jwt

#WebDevelopment #JavaScript #NodeJS #ExpressJS #JWT #Authentication #BackendDevelopment #dotenv #LearningInPublic

@pixoate.bsky.socialOct 1, 2026, 7:26 AM

Is that token expired, or is the bug somewhere else? Paste a JWT to see its decoded header, payload and expiry, then copy them. Local-only and free, no account.

pixoate.com/jwt-decoder

#JWT #WebDev

@threadlinqs.bsky.socialSep 27, 2026, 2:48 AM

An unsigned alg:none JWT let a researcher become admin inside Microsoft's internal Titan API. https://intel.threadlinqs.com/threat/TL-2026-2675 #ThreatIntel #Antares #Titan #JWT

Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows
@tkovalenko.bsky.socialSep 22, 2026, 8:57 AM

Securing an MCP Server on ASP.NET Core: OAuth 2.1, Scopes, and Token Audience
taraskovalenko.github.io/en/posts/sec...

#mcp #oauth2.1 #jwt #pkce

@parvesshrajh.bsky.socialSep 22, 2026, 7:56 AM

21.09.2026

#WebDevelopment

~Created app auth flow with JWT tokens in express
~ZOD in express

#WebDevelopment #ExpressJS #NodeJS #JWT #Authentication #Zod #JavaScript #BackendDevelopment #APIs #RESTAPI #WebSecurity #LearningInPublic

@parvesshrajh.bsky.socialSep 20, 2026, 5:10 AM

18.09.2026

#WebDevelopment

~Creating an express and authenticated end-point
~Tokens vs JWTS
~Express Auth application using JWT
~JWTS decode vs verify

#WebDevelopment #JavaScript #NodeJS #ExpressJS #Express #JWT #JSONWebToken #Authentication #Authorization #WebSecurity

@hasamba72.bsky.socialSep 17, 2026, 7:26 PM

Okta analyzed a 7GB infostealer dump: 555 JWTs for AI auth, 1,843 unexpired tokens, 17.7% with plaintext PII. Replayable sessions bypass MFA for Google, Anthropic, OpenAI, Notion. #infostealer #JWT #threataintel https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html?m=1

@thedailytechfeed.comSep 16, 2026, 1:48 PM

Syncope 3.0-4.1 had SQL, sandbox & JWT flaws letting admins escalate access—upgrade to 4.0.8/4.1.3 now. #SecurityNews #IdentityManagement #ApacheSyncope #CVE2026 #JWT #SQLInjection thedailytechfeed.com/apache-synco...

@thedailytechfeed.comSep 16, 2026, 1:16 PM

A hard-coded JWT key in Issabel PBX (CVE-2026-89026) enables unauthenticated OS command execution—urgent patch needed. #SecurityNews #PBX #CVE2026 #JWT #Issabel #Vulnerability #Cybersecurity thedailytechfeed.com/critical-cve...

@toolsura.bsky.socialSep 15, 2026, 3:21 PM

How SSL certificate chains link your site to a trusted root shows up everywhere but is usually explained in half-truths. Here's what it actually is, what it isn't, and why the difference matters.

#HowSSLCertificate #ECDSA #JWT #OpenSSL

@hugovalters.bsky.socialSep 14, 2026, 10:50 AM

Decode and validate JWTs from your terminal instead of pasting them into a website. 224 lines, beginner-friendly, PyJWT. Usage: python3 jwt_inspect.py --token $TOKEN --verify --key public.pem https://www.valtersit.com/python/jwt-token-decoder-and-validator/ #python #security #jwt

@michabbb.bsky.socialSep 13, 2026, 1:27 AM

📊 Findings attach to the exchange that proves them; projects export sanitized by default, with #HAR import/export, #SQLite backups and plugins for race conditions, request smuggling, #JWT and #CSRF workflows

@thedailytechfeed.comSep 9, 2026, 4:06 PM

Unexpired AI session tokens let attackers bypass MFA. Token replay attacks are real. #AI #Cybersecurity #TokenSecurity #MFA #Infostealer #AIThreats #JWT #APIKeys thedailytechfeed.com/ai-session-t...

@lestrrat.bsky.socialSep 8, 2026, 3:47 AM

Releases based on Security Advisory. v2 and prior will not receive patches. Please upgrade to v4 or v3 #golang #jwt

github.com/lestrrat-go/...
github.com/lestrrat-go/...