Publications & CVEs

Publications & CVEs

A running index of vulnerabilities I’ve discovered, advisories I’ve published, and other research output. Each entry links to the full writeup where one exists.

Coordinated disclosure: details for a given issue are published only after a patch is available or the disclosure window has elapsed.

CVEs & advisories

CVEs I discovered and disclosed (credited in NVD):

CVE / IDProductClassImpactDisclosedWriteup
CVE-2019-12176HTC VIVEPORT Desktopinsecure service permissionsLPE2019-05-24link
CVE-2019-12177HTC VIVEPORT DesktopDLL hijackingLPE2019-05-24link

Vulnerability analysis

Independent root-cause / reverse-engineering writeups of vulnerabilities discovered by others — not my discoveries; credit to the original finders is given in each post.

CVE / IDProductClassMy contributionWriteup
CVE-2026-41089Microsoft Windows (netlogon.dll / AD DC)stack-overflow (DoS)independent root-cause + patch-diff analysisin revision

Papers

  • Iron Net: Proactive Remediation of Network-Level Lateral Movement Attack Paths in Windows Active Directory Environments — CS6727, Georgia Institute of Technology, 2026. pdf · code

Courses

Reading booklets exported from TheRange, a self-hosted training platform that renders and grades these courses. Each PDF is one course’s concept cards, in course order.

Course content is AI-generated and reviewed by me (in progress/ongoing); the platform is open source.

CourseBooklet
Applied Cryptography — Foundationspdf
Firmware & Hardware Securitypdf
Reverse Engineering — Ghidra, x86-64 and RISCpdf
Vulnerability Research — classes, signatures and mitigationspdf
Web-App Assessment — pentest tradecraft as Pythonpdf
Python for Security Tooling — RE, VR and analysispdf

Bug bounties / acknowledgements

None yet.