> whoami
Application Security & Offensive Security
About me
Operator profile // location, tooling, credentials, and selected output.
Location
Technologies
Certifications
Projects
20
Ongoing / 2
Framework
projects
Security tooling, research, and AI-assisted workflows most relevant to appsec and offensive security roles.

Leaflet
Pentest notes and engagement workspace with host tracking, findings, CVSS, credentials, and attack-chain documentation.

TeXploit
Local-first pentest report workspace for writing LaTeX or Markdown reports, managing findings, templates, and PDF compilation.
Blogs
Selected security articles and CVE breakdowns I wrote for Xentrika Blog.
CVE-2026-63030 (wp2shell): One Bad REST Batch, One WordPress Shell
A CVSS 9.8 WordPress Core vulnerability chain lets unauthenticated attackers turn REST route confusion and SQL injection into remote code execution. Public PoCs are available, with early signs of in-the-wild activity reported.
CVE-2026-53359 (Januscape): The 16-Year-Old KVM Bug That Lets a Guest Own the Host
Januscape is a Linux KVM/x86 use-after-free that can turn nested virtualization into host-root code execution. Red Hat scores it CVSS 7.8; a host-crash PoC is public, while the full escape exploit remains withheld.
Open channel
Have a security problem, engineering role, or project worth discussing? Send a concise brief.



