RESEARCH & AWARDS

CVE-2025-23015

Apache Cassandra

2025

Discovered a privilege escalation vulnerability where users with MODIFY permissions could perform unsafe actions on system resources to gain superuser access.

CVE-2025-26467

Apache Cassandra

2025

Identified a regression in the patch for CVE-2025-23015, allowing low-privileged users to escalate to superuser via similar unsafe resource manipulation.

CVE-2024-38346

Apache CloudStack

2024

Found a critical flaw in the unauthenticated cluster service port that allowed attackers to execute arbitrary commands on management server hosts.

CVE-2024-39864

Apache CloudStack

2024

Revealed an improper initialization logic that caused the integration API service to listen on a random port, exposing the system to remote code execution.

CVE-2024-41107

Apache CloudStack

2024

Demonstrated a SAML authentication bypass where attackers could submit unsigned, spoofed SAML responses to compromise user accounts.

CVE-2024-42015

Reserved

2024

Details currently under embargo or reserved.

1st Place - Internal Hackathon

State Farm

2018

1st place out of 200 teams.

CVE-2018-12883

Respondus

2018

Uncovered CVE-2018-12883, demonstrating a fundamental failure in Respondus's environment detection that allowed users to circumvent the application's primary function and restore full system privileges.

2018
1st Place - Raytheon CTF

BSides Jacksonville

2017

1st Place - Internal Hackathon

State Farm

2017

1st place out of 165 teams.

3rd Place - Defense Competition

Florida Center for Cyber Security

2017