Technical deep-dives, vulnerability advisories, and security analyses.
Written for practitioners — not press releases.
2024 · Browser Security
RomCom APT: Full Chain Analysis of CVE-2024-9680
Complete technical dissection of the Firefox zero-day exploited in the wild by RomCom APT — WASM type
confusion triggering JIT compiler hijacking, chained with Win32k.sys UAF for SYSTEM-level RCE. Includes
decoded JavaScript, disassembled WebAssembly, reconstructed shellcode sequences, and full MITRE ATT&CK TTP
mapping.
Security analysis of networked vending machines running embedded Linux and
Windows IoT — from unauthenticated cashless payment APIs to remote code execution via unpatched telemetry
agents. Demonstrated full compromise of MDB (Multi-Drop Bus) payment interfaces, manipulation of product
pricing logic, and persistent implants surviving reboot cycles. Findings cover 5+ major vending platforms
and responsible disclosure outcomes with vendors.
Discovered 25+ LLM vulnerabilities with 80% guardrail bypass rate across major
AI platforms. Includes adversarial prompting methodology, model behaviour taxonomy, and responsible
disclosure timeline.
MQTT fuzzing campaign against 100+ IoT device types identifying 12 critical
vulnerabilities in smart home infrastructure. Full disclosure with vendor coordination, exploitation PoCs,
and remediation guidance.