Skip to content
View skraft9's full-sized avatar

Block or report skraft9

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
skraft9/README.md

Hi, I'm Seth

Cybersecurity professional with over 10 years of experience across IT engineering, vulnerability management, threat intelligence, threat detection and incident response.

In my free time, I hunt for software vulnerabilities and participate in bug bounty programs.

I was a GrrCON 2025 main stage speaker, presenting on how I discovered my first CVE.

IMG_6450


VDP Highlights

BBP Highlights

  • Application Security – Discovered over a dozen vulnerabilities in Elastic software. Ranked #20 on the Elastic all-time leaderboard on HackerOne. Ranked #1 on the 2026 Elastic leaderboard.
image
  • API Security – Found a vulnerability in a production API that allows for the enumeration of over 300 active insurance policies.

  • Sensitive Information Disclosure – Located sensitive data exposed via public S3 buckets.


Tools & Scripts

cybersecurity-research-tools


CVE Publications

my-cve-publications

Pinned Loading

  1. cybersecurity-research-tools cybersecurity-research-tools Public

    Shell 1

  2. pfsense-security-research pfsense-security-research Public

    15

  3. my-cve-publications my-cve-publications Public

  4. CVE-2025-29471 CVE-2025-29471 Public

  5. CVE-2025-44823 CVE-2025-44823 Public

  6. nagios-log-server-dos nagios-log-server-dos Public