It has been 2 days since the last alg:none JWT vulnerability.
Microsoft's "internal" analytics platform, Titan, exposed a database query API over the public internet to anyone who presented it with a JWT, no signature required. It's not even been two months since the last one, Microsoft. What are we doing here? What's going on?