2026-09-12We Keep Updating AI, But Not the Abstractions Beneath It (external)AI · Architecture · Computing
2026-09-12 AI · Architecture · Computing
We Keep Updating AI, But Not the Abstractions Beneath It (external)Application security engineer with 10+ years in offensive and application security across banking, telecom, aviation, insurance and e-commerce. Web, API and mobile security testing, threat modeling and CI/CD security. Bugcrowd Top 100 (2018), 150+ validated vulnerabilities, credited for CVE-2026-31974 (OpenProject). OSCP+, eWPTx, eMAPT, CASP.
Blind SSRF through webhooks and the SMTP test endpoint. Reported independently through the YesWeHack OpenProject program and credited in the advisory. Fixed in v17.2.0.
Public exploit tool for pre-authentication SQL injection in Fortinet FortiWeb Fabric Connector (CVSS 9.8). Detects vulnerable instances and demonstrates impact.