Articles
Security research. Practical guidance.
Writeups, case studies, bug bounty lessons, API security notes, and website security guidance written from hands-on testing.
-

NASA GLOBE Observer Stored XSS Case Study
How a mobile observation comment became stored XSS on a public NASA GLOBE web page, with verified impact, root cause, and remediation.
-

Intigriti 0526: Unintended Stored XSS Bypass
An unintended stored XSS path in Intigriti Challenge 0526 involving unsafe innerHTML, observed SCA Shield bypass behavior, and sink-side remediation.
-

Password Security Is a Trust Boundary Problem
Passwords are only one part of account security. Recovery, MFA, sessions, and authorization define the trust boundaries attackers test.
-

Ransomware Risk Starts Before Encryption
Ransomware defense starts with identity, remote access, segmentation, monitoring, and recoverable backups before encryption begins.
-

API Security Testing for Real Attack Paths
How manual API testing finds authorization, authentication, data exposure, workflow abuse, and endpoint inventory gaps.
-

Small Business Website Security Checklist
A practical small business website security checklist covering ownership, updates, admin access, backups, monitoring, and recovery.
-

AI Voice Scams: Verification Controls for Small Business
How small businesses can verify urgent voice, email, and video requests before impersonation becomes financial fraud.
-

AI-Assisted Bug Bounty With Manual Validation
How GK Data uses custom AI agents for reconnaissance and documentation while manually reproducing and validating every finding.
-

Blind Stored XSS Through a Text File Upload
How an accepted text file rendered as HTML became blind stored XSS inside an internal review workflow.