
AI Security
Security Researcher
Offensive security researcher and AI red-teamer. I find vulnerabilities in web applications and language models, then publish the findings so defenders can act on them.
Full server compromise through the formula/scripting engine.
Server-side template injection escalating to remote code execution.
Server-side request forgery in the Ghost publishing platform.
XSS, IDOR, and prompt injection across LMS and headless CMS.
Web framework audits, CVE disclosure, root-cause analysis.
Explore →LLM guardrail evaluation, jailbreak methods, mechanistic interpretability.
Explore →HackTheBox, TryHackMe, and competition walkthroughs.
Explore →Certifications, career notes, and industry observations.
Explore →