Passionate about securing digital infrastructure and exploring vulnerabilities. Dedicated to learning cutting-edge security practices and protecting systems from emerging threats. Constantly evolving in the cybersecurity landscape.
Firewall configuration, IDS/IPS, and network monitoring
Vulnerability assessment and ethical hacking
Writing secure applications and reviewing code
Encryption, hashing, and secure communications
WAPT-AI is an AI-powered web application penetration testing framework that combines traditional vulnerability scanning with dynamic payload generation using Ollama (llama3.2:3b). It detects 23+ vulnerabilities, supports plugins, multi-threaded scanning, and generates detailed reports for security researchers.
ReconMind is an autonomous reconnaissance pipeline that chains subdomain enumeration, live host probing, crawling, and vulnerability sweeps into one workflow, using Claude to prioritise targets and summarise findings. It features graceful tool fallback, phase-level caching for resumable runs, and a live web dashboard for real-time progress tracking.
Responsibly disclosed vulnerabilities credited to me in the CVE program, all fixed by the vendor in the referenced releases.
Block name, alias, and memo fields are joined into the (( reference
autocomplete popup HTML without escaping in genHintItemHTML().
A crafted block self-fires on search, and since SiYuan's Electron windows run
with nodeIntegration enabled and no CSP, the XSS escalates to
OS command execution.
The file-tree picker's hover tooltip builds an aria-label from
document metadata without escaping in pathName.ts. A double
quote in a bookmark, alias, or memo field breaks out of the attribute and
injects an event handler, reaching child_process on hover.
Documents propagate via sharing, sync, or import.
confirmDialog() inserts package and notebook names into
innerHTML without escaping. A malicious bazaar package whose
name carries HTML executes when a user uninstalls a package or
unlocks an encrypted notebook.
CyberWarfare Labs
Issued: February 2026
Hands-on red teaming examination validating practical offensive security and adversary simulation skills.
Microsoft
Issued: August 2026
Validates skills in detecting, investigating, and responding to threats using Microsoft Defender and Microsoft Sentinel security operations tools.
The SecOps Group
Issued: January 2026
Practical network security examination validating skills in threat detection, defense configuration, and real-world security operations.
The SecOps Group
Issued: January 2026
Social engineering defense examination validating skills in detecting manipulation tactics and protecting organizations from deception attacks.
I'm always open to discussing new projects, creative ideas, or opportunities to be part of your visions. Feel free to reach out!