offensive security researcher. i hunt hostile-input bugs - the kind that pop when a security tool eats attacker-controlled data - and i run responsible disclosure campaigns against whoever ships them.
- π tool audits - i point scanners, frameworks and agents at themselves. recent reports: Tenable, Rapid7, Greenbone
- π₯ CVE PoCs - weaponized proof-of-concepts in my spare time (see below)
- βοΈ cloud red team - AWS / GCP attack paths, role juggling and privilege-escalation mazes
- π» hardware bench - Flipper Zero + ESP32 counter-surveillance: hunting Flock/ALPR cameras and rogue BLE trackers
- π languages - Python first, Ruby for module dev
score so far: 2 fixed (1 with a bounty π) - 1 partially fixed - 4 ghosted π» - 3 refused - 1 pending public writeup
these are feeding a security conference talk.
| vendor | channel | submitted | status |
|---|---|---|---|
| Tenable | HackerOne 3971365 | Aug 26 | |
| Rapid7 | support ticket #142316 | Aug 27 | |
| Greenbone Security | direct email | Aug 29 |
| CVE | PoC |
|---|---|
| CVE-2026-19626 | POC-CVE-2026-19626 |
| CVE-2026-19679 | POC-CVE-2026-19679 |
| CVE-2026-19681 | POC-CVE-2026-19681 |
more in the oven as disclosures clear.
full list of external repos (not mine) that i've sent PRs to:
593 upstream PRs to 25 external repos (repos i don't own), plus 25 collab PRs in friends' forks
metasploit module work usually starts in friends' forks before it lands upstream:





