Catchify Blog

Expert insights on cybersecurity, penetration testing, and protecting your digital assets

Leaking 2M+ Records and Documents Without Attacking Core Application
Security Research
December 15, 2025

Leaking 2M+ Records and Documents Without Attacking Core Application

How misconfigured Salesforce Aura endpoints and Zendesk integrations led to mass PII disclosure of 2M+ records and full takeover of WhatsApp, email, X DMs, and chatbot support channels.

Catchify SecurityRead More
CVE-2025-52665 - RCE in Unifi Access ($25,000)
Vulnerability Research
November 2, 2025

CVE-2025-52665 - RCE in Unifi Access ($25,000)

During a security assessment, we identified a critical unauthenticated Remote Code Execution vulnerability in UniFi OS that was rewarded $25,000. This write-up details the discovery process, exploitation, and remediation of this critical security flaw.

Abdulaziz AlruwaybikhRead More