Web & API Security
Vulnerability discovery, application security testing, API security, authentication, authorization, injection, and exploit development.
Security researcher and offensive security engineer focused on vulnerability discovery, exploit development, reverse engineering, and real-world attack chains across web applications, APIs, mobile, Active Directory, cloud environments, and native binaries.
Selected vulnerability research and publicly disclosed CVEs.
| CVE | Year | Vendor | Vulnerability | Severity | Advisory |
|---|---|---|---|---|---|
| CVE-2025-64488 | 2025 | SuiteCRM | Authenticated SQL Injection | High | GitHub |
| CVE-2025-11135 | 2025 | PMTicket | Authentication Bypass | Crit | MITRE |
| CVE-2025-7886 | 2025 | PMTicket | SQL Injection | Medium | MITRE |
| CVE-2024-10195 | 2024 | Tecno 4G Router | SQL Injection | Medium | MITRE |
| CVE-2023-6304 | 2023 | Tecno 4G Router | Authenticated Remote Code Execution | Crit | MITRE |
Vulnerability discovery, application security testing, API security, authentication, authorization, injection, and exploit development.
Kerberos attacks, delegation abuse, credential attacks, privilege escalation, lateral movement, and domain compromise.
Android application analysis, reverse engineering, IPC and intent abuse, runtime instrumentation, and mobile exploit development.
AWS, Azure, and GCP security assessment, identity abuse, privilege escalation, and cloud attack-path analysis.
Memory corruption, heap exploitation, ROP, format strings and exploit development.
Static and dynamic analysis, patch diffing, vulnerability discovery, binary analysis, and exploit research.
Selected results from CTFs and cybersecurity competitions..