aug 13
a talk on ssrf — from a single google cloud finding to a class of bypasses affecting 5 major open-source projects.
i'm a product security engineer at mindbody/classpass. day to day i work on security pipelines, automation, secret scanning, responsible disclosure program, occasional pentests, and ai-augmented analysis of security tool output.
into appsec, supply chain security, bug bounty, and security research. i look for the small detail that makes the whole thing fall apart.
22 cves published. acknowledged by apple, microsoft, and the u.s. department of health and human services.