Xanlar Agamalizade
Cybersecurity Researcher
Penetration Tester
OSINT Analyst
Cyber Threat Intelligence
Security Advisories & CVEs
ArcadeDB — Unauthenticated Database Access CVE
The Redis wire-protocol plugin bound no authenticated principal, exposing every database to remote read, write, and delete.
WordPress — Broken Access Control CVE
An AJAX handler in the WP Maps plugin shipped without a capability check or nonce, letting subscribers write unbounded autoloaded options.
OpenClaude — OAuth State Bypass CVE
Missing state-parameter validation in the OAuth callback allowed remote termination of authenticated sessions.
OpenNMS — JEXL Sandbox Bypass CVE
A crafted expression submitted to the Measurements REST API escaped the sandbox and loaded arbitrary Java classes.
FileRise — Hardcoded Encryption Key CVE
A configuration fallback silently accepted a published default key, exposing TOTP seeds, OIDC secrets, and storage credentials.
Enterprise Security Acknowledgements Bug Bounty
Acknowledged and thanked for identifying and reporting critical security vulnerabilities.
Technical Skills
Red Team
Simulation
Simulating real-world attack scenarios to test organizational defense capabilities and conducting stealth operations.
Active Directory
Security
Deep AD analysis focused on privilege escalation paths, lateral movement, and domain dominance scenarios.
Web Application
Security
Offensive assessments aligned with OWASP Top 10 standards. Vulnerability discovery and technical reporting.
Open Source
Intelligence (OSINT)
Digital profiling and intelligence reports through the collection and analysis of open-source data.
Geospatial
Intelligence (GEOINT)
Analysis of satellite imagery and geographic data. Geolocation identification and visual data verification.
Social Media
Intelligence (SOCMINT)
Tracking digital footprints across social platforms. Behavioral modeling and network mapping.
Cyber Threat
Intelligence (CTI)
Monitoring threat actors and attack vectors. Processing intelligence data for strategic decision-making.
Threat Actor
Profiling
Analysis of TTPs (Tactics, Techniques, and Procedures) of APT groups and individual actors. Motivation-based profiling.
Dark Web
Monitoring
Proactive monitoring of data leaks on the dark web. Analysis of stolen credentials and leaked corporate data.