I'm an Application Security specialist passionate about finding vulnerabilities before attackers do, and helping teams build safer digital products.
I specialize in Application Security and DevSecOps — helping teams integrate security practices directly into the development lifecycle. I enjoy automating security checks, building secure CI/CD pipelines, and making security an enabler rather than a blocker.
A practical e‑book that teaches you how to build Burp Suite extensions from scratch. Clear step‑by‑step examples, runnable code, and real-world exercises to automate and improve your testing workflow.
Created security guidelines and training material for developers to reduce common security mistakes.
I uncovered a new prototype pollution gadget in mongodb NPM package version 6.6.2, that results in Remote Code Execution (RCE).
Understand how security vulnerabilities can impact your company's reputation and bottom line.
In this blog, I want to shed light on common mistakes, which can inadvertently put the security of our data and money at risk.
In this article, I talk about a new data exfiltration technique, which allows to read files on victim’s machine using an Excel file.
How integrating security early in development helps prevent costly incidents.
Do you still believe hackers are only interested in spying on celebrities’ lives or stealing money from well-known companies?
Let's connect! You can reach me via email or social media.