2026-02-25APIs: From Subroutine Libraries to Zero Trust — A Technical History (external)API · Architecture · Security
2026-02-25 API · Architecture · Security
APIs: From Subroutine Libraries to Zero Trust — A Technical History (external)OSCP+ certified Application Security & Red Team Engineer with 8+ years across banking, telecom, aviation, insurance, and e-commerce. Bugcrowd Top 100 (2018) with 400+ reports submitted, 150+ validated. Published CVE (CVE-2026-31974). Hands-on across penetration testing, API security, threat modeling, secure SDLC, DevSecOps automation, and AI/LLM security.
Server-Side Request Forgery in OpenProject. Coordinated disclosure with the OpenProject security team; fix merged upstream in v17.2.0.
Public exploit tool for pre-authentication SQL injection in Fortinet FortiWeb Fabric Connector (CVSS 9.8). Detects vulnerable instances and demonstrates impact.