About
Cybersecurity professional with 16 years of experience across offensive security, threat intelligence, digital forensics, and incident response. I've conducted penetration tests, reverse engineered applications, developed custom exploits, and hunted threats across critical infrastructure environments. Recognized by 19 major organizations — including Apple, Adobe, Netflix, GitHub, and Red Hat — for responsibly disclosing security vulnerabilities. I hold elite offensive certifications including OSCE, OSCP, CRTE, and CRTL, and actively compete in CTF events.
Skills
Certifications
Bug Bounty Hall of Fame
Listed in the security hall of fame or acknowledgement pages of 19 organizations for responsible vulnerability disclosure.
Honors & Awards
CVEs
Heap-buffer-overflow in GIMP's APNG loader (file-png.c) when the
fcTL frame width exceeds the IHDR width, writing pixel
data past the end of a heap allocation. A second heap overflow in the DDS plug-in's
load_layer() stems from a BPP mismatch. Both are reachable by opening
a crafted image and can lead to code execution. Credited by Red Hat.
Publications