Public research efforts
Data-driven security initiatives focused on global threat signaling, vulnerability prioritization, and machine-learning driven offensive automation.
Active projects
Continuous ingestion and analysis of global threat feeds to generate high-fidelity metrics and attribution insights. Mapping the shift from raw signal to actionable defensive signal.
Explore metrics →
Automated parsing and prioritization of the US DHS National Vulnerability Database. Focused on remediation efficiency and the delta between disclosure and patch saturation.
View vuln data →
Hardening the software lifecycle through automated attack simulation — a curated library of adapters and testing plans designed to be mean to your code before production deployment.
View test plans →
A machine-learning framework designed to pass the Hacker Turing Test. Genetic algorithms and deep neural networks automating complex offensive security workflows with human-like precision.
Vulnerability disclosures & presentations
Open Source Fairy Dust
Research revealing flaws in internet infrastructure architecture and their economic and national security impacts.
Presentation →Backdooring Git & version control
Cryptographic weaknesses and supply chain attacks via Git internals — how code breaches jeopardize development pipelines.
Presentation →Basecamp infrastructure analysis
Discovered and responsibly disclosed critical vulnerabilities within Basecamp and 37signals infrastructure.
Disclosure →Apache Solr & Jetty vulnerability
Identified a critical vulnerability (SOLR-4861) affecting Apache Jetty and Solr, coordinating a secure resolution.
Advisory →Security Onion CapMe vulnerability
Uncovered vulnerabilities within the Security Onion CapMe interface, patched before adversaries could leverage them.
Advisory →Scalr infrastructure SQLi
SQL injection and input validation vulnerabilities within the Scalr cloud management platform.
Research →Pandora DDoS botnet nullification
Investigated the command-and-control infrastructure of the Pandora botnet, revealing vulnerabilities to dismantle its operations.
Research →IS administration & architecture
Technical editor for Organizational, Legal, and Technological Dimensions of IS Admin — a reference work bridging IT system administration with legal considerations.
Publication →LDAP Tool Box XSS
Cross-site scripting vulnerabilities within the LDAP Tool Box self-service password application.
Advisory →Keywhiz secret management
Vulnerabilities within Block’s Keywhiz secret management system regarding secret sanitation and handling.
Pull request →jQuery core XSS vulnerability
A widespread cross-site scripting vulnerability within the core jQuery library (ticket #12254), impacting millions of deployments.
Bug report →Hack The Box Elite Hacker
Reached Elite Hacker rank in competitive exploitation across Solaris, FreeBSD, Linux, and Windows environments.
Profile →HTTP cookie DoS vulnerabilities
Analyzed anomalies in HTTP and cookie RFC implementations to uncover novel denial-of-service attack vectors.
Research →Google Translate sandbox breakout
Critical vulnerabilities allowing a sandbox breakout within Google Translate’s infrastructure.
Research →Google Glass & AR/VR 0-days
Deep attack surfaces in Google Glass and early AR/VR hardware, disclosing DoS and XSS vulnerabilities to the Glass team.
Malicious mobile power stations
Novel attack vectors exploiting public USB charging stations to compromise smartphones via hidden hardware.
Research →Firesale botnet analysis
A comprehensive evaluation of the Firesale botnet panel to uncover exploitable flaws in the threat actor’s infrastructure.
Research →Cloud9 IDE remote code execution
Unpatched XSS and potential remote code execution vulnerabilities within the Cloud9 online development environment.
Research →Carberp botnet cryptography
Reverse-engineered the Carberp banking trojan, discovering critical vulnerabilities and broken cryptographic implementations in the C2.
Research →Wikipedia core XSS
Analyzed MediaWiki infrastructure and disclosed a cross-site scripting vulnerability (CVE-2015-6729).
View CVE →CNN digital infrastructure XSS
Critical cross-site scripting vulnerabilities in CNN’s digital infrastructure brought to light for prompt resolution.
Research →Building Security In Maturity Model
Contributed to the BSIMM program, building and improving software security maturity benchmarks for enterprise organizations.
View BSIMM →Bug bounty & external scrutiny
On the strategic importance of external scrutiny and bug bounty programs to enhance institutional security postures.
Presentation →BlackEnergy botnet neutralization
Analyzed the BlackEnergy botnet C2 infrastructure to identify exploitable vulnerabilities and safely neutralize the threat.
Research →Apache Batik DoS vulnerability
A denial-of-service vulnerability (BATIK-1023) within the Apache Batik SVG toolkit, enabling rapid mitigation.
Advisory →Private R&D
Stealth-mode initiatives in systems-inspired defense, autonomous architectures, ZK/MPC, and cryptographic protocol resilience.