Open source & public labs

Public research efforts

Data-driven security initiatives focused on global threat signaling, vulnerability prioritization, and machine-learning driven offensive automation.

Active projects

Four labs
Threat Intelligence Metrics

Continuous ingestion and analysis of global threat feeds to generate high-fidelity metrics and attribution insights. Mapping the shift from raw signal to actionable defensive signal.

Explore metrics →
Vulnerability & remediation

Automated parsing and prioritization of the US DHS National Vulnerability Database. Focused on remediation efficiency and the delta between disclosure and patch saturation.

View vuln data →
Rugged SecDevOps testing

Hardening the software lifecycle through automated attack simulation — a curated library of adapters and testing plans designed to be mean to your code before production deployment.

View test plans →
Gyoithon: AI-driven pentesting

A machine-learning framework designed to pass the Hacker Turing Test. Genetic algorithms and deep neural networks automating complex offensive security workflows with human-like precision.

Commercial access only

Vulnerability disclosures & presentations

26 entries
DEF CON

Open Source Fairy Dust

Research revealing flaws in internet infrastructure architecture and their economic and national security impacts.

Presentation →
DEF CON

Backdooring Git & version control

Cryptographic weaknesses and supply chain attacks via Git internals — how code breaches jeopardize development pipelines.

Presentation →
37signals

Basecamp infrastructure analysis

Discovered and responsibly disclosed critical vulnerabilities within Basecamp and 37signals infrastructure.

Disclosure →
Apache Foundation

Apache Solr & Jetty vulnerability

Identified a critical vulnerability (SOLR-4861) affecting Apache Jetty and Solr, coordinating a secure resolution.

Advisory →
Security Onion

Security Onion CapMe vulnerability

Uncovered vulnerabilities within the Security Onion CapMe interface, patched before adversaries could leverage them.

Advisory →
Scalr

Scalr infrastructure SQLi

SQL injection and input validation vulnerabilities within the Scalr cloud management platform.

Research →
Threat research

Pandora DDoS botnet nullification

Investigated the command-and-control infrastructure of the Pandora botnet, revealing vulnerabilities to dismantle its operations.

Research →
Publication

IS administration & architecture

Technical editor for Organizational, Legal, and Technological Dimensions of IS Admin — a reference work bridging IT system administration with legal considerations.

Publication →
LDAP Tool Box

LDAP Tool Box XSS

Cross-site scripting vulnerabilities within the LDAP Tool Box self-service password application.

Advisory →
Block (Square)

Keywhiz secret management

Vulnerabilities within Block’s Keywhiz secret management system regarding secret sanitation and handling.

Pull request →
jQuery

jQuery core XSS vulnerability

A widespread cross-site scripting vulnerability within the core jQuery library (ticket #12254), impacting millions of deployments.

Bug report →
Hack The Box

Hack The Box Elite Hacker

Reached Elite Hacker rank in competitive exploitation across Solaris, FreeBSD, Linux, and Windows environments.

Profile →
RFC research

HTTP cookie DoS vulnerabilities

Analyzed anomalies in HTTP and cookie RFC implementations to uncover novel denial-of-service attack vectors.

Research →
Google

Google Translate sandbox breakout

Critical vulnerabilities allowing a sandbox breakout within Google Translate’s infrastructure.

Research →
Google

Google Glass & AR/VR 0-days

Deep attack surfaces in Google Glass and early AR/VR hardware, disclosing DoS and XSS vulnerabilities to the Glass team.

Threat research

Malicious mobile power stations

Novel attack vectors exploiting public USB charging stations to compromise smartphones via hidden hardware.

Research →
Threat research

Firesale botnet analysis

A comprehensive evaluation of the Firesale botnet panel to uncover exploitable flaws in the threat actor’s infrastructure.

Research →
Cloud9

Cloud9 IDE remote code execution

Unpatched XSS and potential remote code execution vulnerabilities within the Cloud9 online development environment.

Research →
Threat research

Carberp botnet cryptography

Reverse-engineered the Carberp banking trojan, discovering critical vulnerabilities and broken cryptographic implementations in the C2.

Research →
Wikimedia Foundation

Wikipedia core XSS

Analyzed MediaWiki infrastructure and disclosed a cross-site scripting vulnerability (CVE-2015-6729).

View CVE →
CNN

CNN digital infrastructure XSS

Critical cross-site scripting vulnerabilities in CNN’s digital infrastructure brought to light for prompt resolution.

Research →
BSIMM

Building Security In Maturity Model

Contributed to the BSIMM program, building and improving software security maturity benchmarks for enterprise organizations.

View BSIMM →
ISC²

Bug bounty & external scrutiny

On the strategic importance of external scrutiny and bug bounty programs to enhance institutional security postures.

Presentation →
Threat research

BlackEnergy botnet neutralization

Analyzed the BlackEnergy botnet C2 infrastructure to identify exploitable vulnerabilities and safely neutralize the threat.

Research →
Apache Foundation

Apache Batik DoS vulnerability

A denial-of-service vulnerability (BATIK-1023) within the Apache Batik SVG toolkit, enabling rapid mitigation.

Advisory →

Private R&D

Stealth-mode initiatives in systems-inspired defense, autonomous architectures, ZK/MPC, and cryptographic protocol resilience.

Redacted research