Alex Schapiro
About
Alex Schapiro

Alex Schapiro

Security researcher & CS student at Yale. I build stuff people use and break stuff to make sure it's safe. Currently running CourseTable.

Full Bio · LinkedIn · GitHub

Recent Posts

How I Reverse Engineered a Billion-Dollar Legal AI Tool and Found 100k+ Confidential Files

How I Reverse Engineered a Billion-Dollar Legal AI Tool and Found 100k+ Confidential Files

Zero authentication, full admin access, and a privacy nightmare for lawyers.

Update: This post received a large amount of attention on Hacker News — see the discussion thread.

December 02, 2025 securityvulnerability
Brute-Forceable Airline Reservation API Left  Millions of Passenger Records Vulnerable

Brute-Forceable Airline Reservation API Left Millions of Passenger Records Vulnerable

A 6-hour brute-force attack could have downloaded every Avelo Airline passenger's PII, Known Traveler Number, and payment data.

Timeline & Responsible Disclosure

November 20, 2025 securityvulnerability
How Broken OTPs and Open Endpoints Turned a Dating App Into a Stalker's Playground

How Broken OTPs and Open Endpoints Turned a Dating App Into a Stalker's Playground

Private messages, passport information, sexual preferences, and more left vulnerable in Cerca Dating App

Update: This post received a large amount of attention on Hacker News — see the discussion thread.

April 21, 2025 securityvulnerability

Subscribe via RSS

Alex Schapiro

  • Alex Schapiro
  • About
  • alex_dot_schapiro_at_yale_dot_edu
  • bearsyankees
  • aschap

Security research, ethical hacking, and building stuff.