Marine, then gang investigator, now DevOps security. I work on CI/CD, supply chain and runtime detection, and I hunt CVEs in open-source packages.
I hunt vulnerabilities and malicious code in the open-source supply chain, then get them fixed. My own pipeline watches npm, PyPI, RubyGems, crates.io, Packagist and Go as new releases ship. Each artifact is unpacked in a rootless, network-less container and never executed. Taint-tracking rules and dependency scanners run over it, and the results are deduplicated against OSV, GitHub Advisories, NVD and Red Hat. Every candidate is then validated by hand against the shipped code before it goes into a static CVE ledger. Most automated hits are noise; the job is proving which ones aren't.
- CVE discovery & coordinated disclosure: command injection, credential exposure, SSRF, missing authentication, unsafe deserialization and sandbox escapes in libraries, SDKs and AI-agent tooling. Every finding goes to the maintainer privately, with affected versions, a suggested fix and a CVSS score, before anything is published.
- Malicious code analysis: install-time payloads, obfuscated droppers, typosquats and suspicious package behaviour, caught before they reach a build.
- Container & repository research: image layers, CI/CD workflows, leaked secrets and vulnerable dependencies across public repositories and registries.
- Signature matching: YARA, Semgrep and IOC rules written, tuned against false positives, and shipped as detections.
Disclosure policy: private report first, 90 days or a fixed release (whichever comes first), then public. Published advisories will be listed here as they go live.