XANLAR A. _

Xanlar Agamalizade
Cybersecurity Researcher Penetration Tester OSINT Analyst Cyber Threat Intelligence

Security Advisories & CVEs

ArcadeDB — Unauthenticated Database Access CVE

The Redis wire-protocol plugin bound no authenticated principal, exposing every database to remote read, write, and delete.

WordPress — Broken Access Control CVE

An AJAX handler in the WP Maps plugin shipped without a capability check or nonce, letting subscribers write unbounded autoloaded options.

OpenClaude — OAuth State Bypass CVE

Missing state-parameter validation in the OAuth callback allowed remote termination of authenticated sessions.

OpenNMS — JEXL Sandbox Bypass CVE

A crafted expression submitted to the Measurements REST API escaped the sandbox and loaded arbitrary Java classes.

FileRise — Hardcoded Encryption Key CVE

A configuration fallback silently accepted a published default key, exposing TOTP seeds, OIDC secrets, and storage credentials.

Enterprise Security Acknowledgements Bug Bounty

Acknowledged and thanked for identifying and reporting critical security vulnerabilities.

Microsoft DeepSeek AI NASA Harvard UNESCO Cisco Ferrari Land Rover Jaguar + More

Technical Skills

Red Team
Simulation

Simulating real-world attack scenarios to test organizational defense capabilities and conducting stealth operations.

Active Directory
Security

Deep AD analysis focused on privilege escalation paths, lateral movement, and domain dominance scenarios.

Web Application
Security

Offensive assessments aligned with OWASP Top 10 standards. Vulnerability discovery and technical reporting.

Open Source
Intelligence (OSINT)

Digital profiling and intelligence reports through the collection and analysis of open-source data.

Geospatial
Intelligence (GEOINT)

Analysis of satellite imagery and geographic data. Geolocation identification and visual data verification.

Social Media
Intelligence (SOCMINT)

Tracking digital footprints across social platforms. Behavioral modeling and network mapping.

Cyber Threat
Intelligence (CTI)

Monitoring threat actors and attack vectors. Processing intelligence data for strategic decision-making.

Threat Actor
Profiling

Analysis of TTPs (Tactics, Techniques, and Procedures) of APT groups and individual actors. Motivation-based profiling.

Dark Web
Monitoring

Proactive monitoring of data leaks on the dark web. Analysis of stolen credentials and leaked corporate data.

Offensive Tools

Cobalt Strike
Burp Suite
Maltego
SpiderFoot
MISP
ThreatStream