frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Munshig – catches the API bug that cost Facebook 50M accounts

2•shaikhzaynsaif•2h ago
Hey HN

I built munshig, a zero-config runtime API security proxy that monitors your API during development and automatically detects vulnerabilities like Broken Access Control (BOLA), missing authentication, SQL injection, and PII leaks — before they reach production.

It’s inspired by tools like Salt Security ($500k/year enterprise products), but designed to run in 30 seconds with a single command:

npx munshig

It sits in front of your dev API (e.g. :3001 → :3000), analyzes real requests/responses, and surfaces runtime security issues right in your terminal — with detailed remediation steps.

GitHub: https://github.com/shaikhzaynsaif/munshig

npm: https://www.npmjs.com/package/munshig

I built this because I kept seeing APIs with BOLA bugs even in large companies — most scanners miss them since they analyze code statically, not behavior at runtime.

Would love feedback from other developers — especially:

Does the zero-config proxy approach make sense for your workflow?

What kinds of vulnerabilities would you want it to detect next (XSS, SSRF, JWT misuse...)?

Thanks!

— ZaynSaif (Author)

Comments

mickeyjones22•27m ago
sounds great , I tried and it's just great I would,and would advise you to keep going and improve the Bola Detection feature. Good wishes

Learning Ruby as a Pythonista

https://tech.stonecharioteer.com/posts/2025/ruby/
1•thunderbong•5m ago•0 comments

Show HN: Refx a CLI tool made for go developpers

https://github.com/Lunaryx-org/refx
1•lunaryx-org•5m ago•0 comments

Systems as Mirrors

https://iamstelios.com/blog/systems-as-mirrors/
1•i8s•5m ago•0 comments

The next era of social media is coming. And it's messy so far

https://www.cnn.com/2025/10/11/tech/openai-sora-2-meta-ai-slop-social-media
1•TowerTall•6m ago•0 comments

Updating Desktop Rust

https://tritium.legal/blog/update
1•piker•6m ago•0 comments

Quintessentially American, drive-in cinemas are going dark

https://www.rte.ie/entertainment/2025/1011/1538028-quintessentially-american-drive-in-cinemas-goi...
1•austinallegro•8m ago•0 comments

Three ways "formally verified" can go wrong

https://buttondown.com/hillelwayne/archive/three-ways-formally-verified-code-can-go-wrong-in/
1•todsacerdoti•9m ago•0 comments

"Typing is not the bottleneck" – illustrated

https://blog.robbowley.net/2025/08/15/typing-is-not-the-bottleneck-illustrated/
1•codeclimber•10m ago•0 comments

Show HN: A professional decibel meter that runs in the browser

https://www.decibelmeter.org/
1•Oscar_Hall•13m ago•0 comments

Show HN: Compression-Resistant Data Transfers

https://github.com/ianling/steg-experiments
1•iaaan•17m ago•1 comments

Ksmbd – Exploiting CVE-2025-37947

https://blog.doyensec.com/2025/10/08/ksmbd-3.html
2•Bogdanp•25m ago•0 comments

PSOS-C and the Full Attribution Chain

https://www.aivojournal.org/closing-the-loop/
1•businessmate•28m ago•1 comments

Not Another GPT Wrapper

https://genorimo.com
1•robbschmidt•34m ago•1 comments

BalCCon2k25: Syd, an Advanced Introduction to Secure Application Sandboxing [video]

https://www.youtube.com/watch?v=B5cN9LrUYTE
1•hayali•43m ago•0 comments

A Tokyo commuters' poetic take on life [video]

https://www.youtube.com/watch?v=FM1GtQuSXP4
2•pbd•46m ago•0 comments

Spyware maker NSO Group confirms acquisition by US investors

https://techcrunch.com/2025/10/10/spyware-maker-nso-group-confirms-acquisition-by-us-investors/
27•corvad•47m ago•2 comments

Symposium: Exploring New AI Workflows

https://smallcultfollowing.com/babysteps/blog/2025/09/24/symposium/
2•aktuel•48m ago•0 comments

IPv6 neighbor discovery on EdgeRouter is not usable in real scenarios

https://github.com/urnetwork/ndppd
5•mulchpower•49m ago•1 comments

Thinking Machines Lab Co-Founder Andrew Tulloch Heads to Meta

https://techcrunch.com/2025/10/11/thinking-machines-lab-co-founder-andrew-tulloch-heads-to-meta/
2•jkw•57m ago•0 comments

The Alignment Problem Isn't Theoretical

https://www.lesswrong.com/posts/TKTijrrwtEFytAbhh/the-alignment-problem-isn-t-theoretical
1•AustinLikesAI•57m ago•0 comments

Famous Last Words Dr. Jane Goodall

https://www.netflix.com/title/82053197
1•rasengan0•59m ago•0 comments

Art about Mathematics (Rinus Roelofs)

https://www.nytimes.com/2025/10/10/science/mathematics-art-roelofs.html
3•gtsnexp•1h ago•2 comments

Monads are too powerful: The Expressiveness Spectrum

https://chrispenner.ca/posts/expressiveness-spectrum
3•hackandthink•1h ago•0 comments

The Case for Separating Thinking (GPU) and Compute (CPU)

https://www.gojiberries.io/decoupling-reasoning-from-compute/
2•neehao•1h ago•0 comments

Long Beach mandates staffing ratios at self-checkout lanes

https://www.latimes.com/business/story/2025-10-11/long-beach-checkout-lane-ordinance
2•ilamont•1h ago•0 comments

Pipelining in psql (PostgreSQL 18)

https://postgresql.verite.pro/blog/2025/10/01/psql-pipeline.html
10•tanelpoder•1h ago•0 comments

Gemini CLI Extensions for Figma

https://aicloudlab.substack.com/p/gemini-cli-extensions-for-figma
3•arjunprabhulal•1h ago•0 comments

Figure 03 [video]

https://www.youtube.com/watch?v=Eu5mYMavctM
2•LordNibbler•1h ago•1 comments

The Boundless Deep by Richard Holmes review – wild times with young Tennyson

https://www.theguardian.com/books/2025/oct/06/the-boundless-deep-by-richard-holmes-review-wild-ti...
6•lermontov•1h ago•0 comments

Welcome Floating design, Goodbye Flat design

https://blog.terrydjony.com/welcome-floating-design/
3•terryds•2h ago•1 comments