← Home

Security research

Responsible disclosures and defensive work. Findings are reported through official programs or coordinated channels — details here are kept high-level on purpose.

Responsible disclosures

WhatsApp (Meta)Privilege escalation

Reported a privilege-escalation vulnerability in Meta's WhatsApp platform through its official disclosure program.

MicrosoftAccess control · via MSRC

Reported multiple access-control and information-disclosure issues in Microsoft Intune and the Exchange Admin Center to Microsoft's MSRC (cases VULN-150984, VULN-152882, VULN-152884) — including organisation member data served before authorization checks (a time-of-check/time-of-use gap spanning Intune, Entra, and Azure), and standard users bypassing 'restricted' policies to modify directory name fields and join closed groups through the Exchange admin portal.

Mumbai PoliceStored XSS · via CERT-In

Found a stored cross-site scripting vulnerability on the official Mumbai Police website and disclosed it responsibly in coordination with CERT-In.

The Souled StoreInfrastructure exposure

Reported exposed staging infrastructure that could have allowed a full system compromise.

Belgian Waffle Co.Credential leak

Reported a source-code and credential leak that opened the door to a potential CRM takeover.

Banking clientLFI · High severity · via R.U.D.R.A

Found a high-severity local file inclusion vulnerability in a banking client's web portal through manual code review during a R.U.D.R.A engagement, then automated detection with Nuclei.

Banking clientBroken access control · High severity

Identified a high-severity broken-access-control vulnerability in the same banking portal, exposing restricted functionality to unauthorized users.

Defensive work

Infrastructure hardeningBlue team

Hardened server infrastructure protecting the data of 16,000+ users.

Ransomware responseBlue team

Stopped a ransomware incident under pressure by rapidly deploying a backup-and-recovery setup.

Found something on a system I run? Report it at security@jkartik.in  — see security.txt.

← Back home