Publications & CVEs
A running index of vulnerabilities I’ve discovered, advisories I’ve published, and other research output. Each entry links to the full writeup where one exists.
Coordinated disclosure: details for a given issue are published only after a patch is available or the disclosure window has elapsed.
CVEs & advisories
CVEs I discovered and disclosed (credited in NVD):
| CVE / ID | Product | Class | Impact | Disclosed | Writeup |
|---|---|---|---|---|---|
| CVE-2019-12176 | HTC VIVEPORT Desktop | insecure service permissions | LPE | 2019-05-24 | link |
| CVE-2019-12177 | HTC VIVEPORT Desktop | DLL hijacking | LPE | 2019-05-24 | link |
Vulnerability analysis
Independent root-cause / reverse-engineering writeups of vulnerabilities discovered by others — not my discoveries; credit to the original finders is given in each post.
| CVE / ID | Product | Class | My contribution | Writeup |
|---|---|---|---|---|
| CVE-2026-41089 | Microsoft Windows (netlogon.dll / AD DC) | stack-overflow (DoS) | independent root-cause + patch-diff analysis | in revision |
Papers
- Iron Net: Proactive Remediation of Network-Level Lateral Movement Attack Paths in Windows Active Directory Environments — CS6727, Georgia Institute of Technology, 2026. pdf · code
Courses
Reading booklets exported from TheRange, a self-hosted training platform that renders and grades these courses. Each PDF is one course’s concept cards, in course order.
Course content is AI-generated and reviewed by me (in progress/ongoing); the platform is open source.
| Course | Booklet |
|---|---|
| Applied Cryptography — Foundations | |
| Firmware & Hardware Security | |
| Reverse Engineering — Ghidra, x86-64 and RISC | |
| Vulnerability Research — classes, signatures and mitigations | |
| Web-App Assessment — pentest tradecraft as Python | |
| Python for Security Tooling — RE, VR and analysis |
Bug bounties / acknowledgements
None yet.