RESEARCH & AWARDS
Apache Cassandra
Discovered a privilege escalation vulnerability where users with MODIFY permissions could perform unsafe actions on system resources to gain superuser access.
Apache Cassandra
Identified a regression in the patch for CVE-2025-23015, allowing low-privileged users to escalate to superuser via similar unsafe resource manipulation.
Apache CloudStack
Found a critical flaw in the unauthenticated cluster service port that allowed attackers to execute arbitrary commands on management server hosts.
Apache CloudStack
Revealed an improper initialization logic that caused the integration API service to listen on a random port, exposing the system to remote code execution.
Apache CloudStack
Demonstrated a SAML authentication bypass where attackers could submit unsigned, spoofed SAML responses to compromise user accounts.
CVE-2024-42015
Reserved
Details currently under embargo or reserved.
1st Place - Internal Hackathon
State Farm
1st place out of 200 teams.
CVE-2018-12883
Respondus
Uncovered CVE-2018-12883, demonstrating a fundamental failure in Respondus's environment detection that allowed users to circumvent the application's primary function and restore full system privileges.
CrimsonHacks
SECCDC
BSides Jacksonville
1st Place - Internal Hackathon
State Farm
1st place out of 165 teams.
Florida Center for Cyber Security