Responsible disclosures
Reported a privilege-escalation vulnerability in Meta's WhatsApp platform through its official disclosure program.
Reported multiple access-control and information-disclosure issues in Microsoft Intune and the Exchange Admin Center to Microsoft's MSRC (cases VULN-150984, VULN-152882, VULN-152884) — including organisation member data served before authorization checks (a time-of-check/time-of-use gap spanning Intune, Entra, and Azure), and standard users bypassing 'restricted' policies to modify directory name fields and join closed groups through the Exchange admin portal.
Found a stored cross-site scripting vulnerability on the official Mumbai Police website and disclosed it responsibly in coordination with CERT-In.
Reported exposed staging infrastructure that could have allowed a full system compromise.
Reported a source-code and credential leak that opened the door to a potential CRM takeover.
Found a high-severity local file inclusion vulnerability in a banking client's web portal through manual code review during a R.U.D.R.A engagement, then automated detection with Nuclei.
Identified a high-severity broken-access-control vulnerability in the same banking portal, exposing restricted functionality to unauthorized users.
Defensive work
Hardened server infrastructure protecting the data of 16,000+ users.
Stopped a ransomware incident under pressure by rapidly deploying a backup-and-recovery setup.
Found something on a system I run? Report it at security@jkartik.in — see security.txt.