Identity and access management|Azure ,(Cloud SOC) Analyst| IAM Engineer | Young Cybersecurity professional and student | Blue Team, Security operations.
hello everyone, its been a while and i haven't introduced myself yet, so my name is sam unique and you can call me the πππ πππ,currently a cyber security undergraduate specializing in identity and access management as an IGA engineer, would love to connect with professional
A security researcher just spent days auditing INEC's election infrastructure ahead of 2027.
The findings should concern every Nigerian.
The API serving 400 elections across all 36 states responds with HTTP 200 and no authentication. No token. No rate limit. Full internal schema exposed including MongoDB ObjectIDs and model structure. Anyone can query it.
The official S3 buckets where result documents are supposed to live return NoSuchBucket. They do not exist. Nobody owns them. That means anyone with an AWS account can register those exact bucket names today and serve fake EC8A result forms directly through INEC's official portal on election night. The bucket names are in the code. They are unregistered. The window is open right now.
The admin portal's device security is a User-Agent header check. Change your browser string and you are in. That is not security. That is a sign on a door that says authorised personnel only.
Login forms have no CSRF tokens. Session cookies have no SameSite flags. One phished admin account gives full voter register access with no 2FA standing between an attacker and the ability to add, delete, or bulk import voters.
The BVAS server handling biometric data for over 90 million citizens serves a TLS certificate belonging to an unrelated domain. The main site's TLS certificate expires in days.
Then there is the compliance problem.
The Nigeria Data Protection Act 2023 prohibits transferring citizen data abroad without approved mechanisms. BVAS biometric data sits on DigitalOcean in New Jersey. Voter identities on Google Cloud in Kansas City. The voter registration API on AWS in London. Six of eight core systems are offshore. No published Data Protection Impact Assessment exists. No approved transfer framework.
90 million Nigerians' fingerprints and facial data are sitting on foreign cloud infrastructure in violation of Nigerian law with no documented legal basis for being there.
0xrobotbick states this research was entirely passive and read-only. Nothing was modified or exploited. A full report with logs and timestamps is ready for INEC and the NDPC.
17 days before public disclosure if nothing is fixed.
INEC already confirmed a voter data access incident in June 2026. DSS is already investigating insider threats. The infrastructure problems 0xrobotbick found are not isolated findings. They sit inside a system that has already demonstrated it cannot protect the data it holds.
2027 is not far away.
I worked on this Brand Identity project for Cassia Homes Foundation some months agoβ¨
I enjoyed every bit of the processππΎ
The full project is out on Behance
Click on the link below and you'll be redirected to Behance
https://t.co/nzuL3PbLDg
Iβve had this X account for a while but never really took it seriously.
Now Iβm back and ready to stay consistent
My goal is to build, grow, connect, and inspire while sharing my journey and my works here.
If youβre into graphic design, branding, or creativity, letβs connectπ€
CYBERSECURITY 2026 ROADMAP: FOR ASPIRING PROFESSIONALS
If I had to restart my cybersecurity journey today, this is EXACTLY how Iβd do it (based on whatβs actually worked for me):
[A thread π§΅]
Iβve spent a lot of time online building, learning, and watching how little privacy regular people actually have.
Every click logged somewhere. Every connection visible to someone. Every day people trade security for convenience without knowing it.
That bothered me more than it should have.
So I decided to build something myself.
TurnipVPN came from wanting better privacy, better control, and a cleaner internet experience.
Itβs live now.
https://t.co/UNNYwQiPM5