Skip to content
View skraft9's full-sized avatar

Block or report skraft9

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
skraft9/README.md

πŸ‘‹ Hi, I'm Seth

Cybersecurity professional with ~10 years of experience across IT engineering, vulnerability management, threat intelligence, threat detection and incident response.

In my free time, I hunt for zero-day software vulnerabilities and participate in bug bounty programs.

I was a GrrCON 2025 main stage speaker on independent vulnerability research, presenting on how I discovered my first CVE.

IMG_6450


🀝 Let's connect


πŸ” VDP Highlights

πŸ” BBP Highlights

  • πŸ•΅οΈ Data Exfiltration – Recovered 300+ insurance policies from a misconfigured system at a Fortune 500 organization.

  • πŸ‘οΈ Vulnerability Research – Discovered three vulnerabilities in Elastic software.

  • πŸ“‚ Sensitive Information Disclosure – Located sensitive data exposed via public S3 buckets.

  • 🧾 Privacy Flaws – Discovered user privacy risks via exposed PII through metadata from API endpoints on a widely used digital content platform.


2025-09-29 17_52_00-NVIDIA GeForce Overlay
2025-09-29 17_53_13-NVIDIA GeForce Overlay

πŸ›  Tools & Scripts

cybersecurity-research-tools


πŸ“œ My CVE Publications

cve-publications

Pinned Loading

  1. CVE-2025-29471 CVE-2025-29471 Public

  2. pfsense-security-research pfsense-security-research Public

    13

  3. nagios-log-server-dos nagios-log-server-dos Public

  4. cve-publications cve-publications Public

  5. librenms-security-research librenms-security-research Public

  6. CVE-2025-44823 CVE-2025-44823 Public