Observed arrival · 2026-09-16
SickHaxx Tries to Break Your App’s Authorization Rules
An automated security agent tests whether the right users can read, write, update, or delete the right records in AI-built web apps.
Field notes
SickHaxx models authorization as an executable contract: a team states who should read, write, update, or delete a resource, then the system tests those rules under several identities. The homepage’s sample finding is unusually concrete, identifying SUPA-005, a rental_applications record, and a 200 OK response when Bob reads Alice’s row. The site says later steps can send the affected policy, route, or configuration to a coding agent and replay the same exploit after a proposed fix.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue