Skip to content
View skraft9's full-sized avatar

Block or report skraft9

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
skraft9/README.md

πŸ‘‹ Hi, I'm Seth

Cybersecurity professional with ~10 years of experience across IT engineering, vulnerability management, threat intelligence, threat detection and incident response.

In my free time, I hunt for zero-day software vulnerabilities and participate in bug bounty programs.

I was a GrrCON 2025 main stage speaker on independent vulnerability research, presenting on how I discovered my first CVE.

IMG_6450


πŸ” VDP Highlights

πŸ” BBP Highlights

  • πŸ•΅οΈ API Security – Discovered an unauthenticated IDOR vulnerability in a production API, allowing for the enumeration of over 300 active insurance policies.

  • πŸ‘οΈ Vulnerability Research – Reported seven vulnerabilities in Elastic software.

  • πŸ“‚ Sensitive Information Disclosure – Located sensitive data exposed via public S3 buckets.


πŸ›  Tools & Scripts

cybersecurity-research-tools


πŸ“œ My CVE Publications

cve-publications


🀝 Let's connect

Pinned Loading

  1. CVE-2025-29471 CVE-2025-29471 Public

  2. pfsense-security-research pfsense-security-research Public

    13

  3. nagios-log-server-dos nagios-log-server-dos Public

  4. cve-publications cve-publications Public

  5. librenms-security-research librenms-security-research Public

  6. CVE-2025-44823 CVE-2025-44823 Public