LESIS Bulletin #1
— Research, tools and insights
Introduction
This month we highlight recent research from the LESIS team, share an open-source tool designed for security investigations, and look at a development shaping the industrial cybersecurity landscape.
Research & Articles
Rocking the Gift Card Loop
In this research note, we explore how business logic flaws in e-commerce platforms can lead to unexpected exploitation scenarios involving gift cards and discount mechanisms.
Complex purchasing flows combined with promotional systems can unintentionally introduce primitives that allow attackers to manipulate credit generation or discounts.
Read the full articleStrengthening the Cybersecurity Community
As part of its long-term commitment to the development of Brazil’s cybersecurity ecosystem, LESIS supports initiatives focused on education and community development.
One example is the financial support provided to Mente Binária, an initiative dedicated to technology education and digital inclusion.
Supporting projects like Mente Binária helps strengthen the next generation of security professionals and contributes to building a more sustainable cybersecurity community.
Read article →Tool Spotlight
Kasumi — Slack Message Extractor
Kasumi is a tool designed to extract and index Slack messages from channels and direct conversations using captured user tokens during authorized security assessments.
This allows investigators to analyze communication patterns, search historical discussions, and better understand internal activity during incident response or threat hunting.
The project is open source and available for research and collaboration.
View on GitHub →Closing
LESIS is an independent research collective focused on offensive security, security engineering, and applied cybersecurity research.