How is discovered a serious security bug on a mortgage software vendor serving major US bank

At the time of this writing, its be been over few months which gave the company involved time to fix the issue, which they did. I will not use real names of the parties involved in this post. I happened…