3 sensitive subdomains publicly discoverable
warningPublic Certificate Transparency logs reveal internal-looking hostnames under firecrawl.dev: api.staging.firecrawl.dev, mcp.staging.firecrawl.dev, work.staging.firecrawl.dev. Names like staging, dev, and admin are found by attackers the same way we found them here — from public logs, no scanning required — and these hosts are often left less protected than production.