Bug Bounty Hunter · Vulnerability Researcher
- Identified and responsibly disclosed critical vulnerabilities — XSS, SQL Injection, authentication bypass, IDOR, and hardcoded credentials with employee PII exposure (CVSS 9.1 Critical) — across multiple production platforms on Bugcrowd, HackerOne, and Intigriti.
- Delivered a CVSS 9.1 critical-severity finding for a production client — SFS Group Schweiz AG (via Intigriti) — producing a clear, structured business-impact report for stakeholders.
- NASA VDP 2025: Letter of Appreciation for responsible disclosure on public-facing infrastructure.
- Actively hunting on Comolho for the past few months — expanding coverage across emerging programs.
- Built automated recon tooling adopted in daily bounty workflows — collapsing manual discovery time.
- Structured reports fusing OSINT, automated scanning & manual exploitation.