It has been 1 day since the last alg:none JWT vulnerability.
Et tu, AWS? TIL that AWS has their own version of Wheel Decide, Ops Wheel. Like Wheel Decide, Ops Wheel lets you spin a wheel to pick where to go for lunch. Unlike Wheel Decide, Ops Wheel — via not checking JWT signatures — allowed attackers to get administrator access to the application, delete all application data across tenants, and manage Cognito user accounts?! Christ. I think I might retire and go live on a boat.