CASE FILE: SAR-2026-0404 // TOP SECRET
SECURITY ASSESSMENT REPORT

Security Engineer

Seattle, WA · nitish.yaddala@gmail.com

CONFIDENTIAL
0+
FINDINGS
0
TARGETS
0
PLATFORMS
0
SEVERITY
0
CLEARANCE
CLEARANCE: OSCP· STATUS: ACTIVE · CLASSIFICATION: TOP SECRET
DECLASSIFY REPORT
SECTION 01 // EXECUTIVE BRIEFING

EXECUTIVE SUMMARY

0+
VULNERABILITIES
0
TARGETS
0+
YEARS
CLASSIFIED
INTELLIGENCE BRIEFING
PREPARED: APRIL 2026 // DISTRIBUTION: LIMITED
PREPARED FOR: D█R█CT█R — N██ION█L S█CUR██Y

4+ years hunting vulnerabilities across web apps, cloud infrastructure, mobile platforms, and AI systems. 200+ findings, 177 targets, every single one found by hand. From a 4-step invisible XSS chain that hijacked accounts without a single click, to an empty signature list that bypassed an entire blockchain's consensus mechanism; I find what automated tools simply can't. Currently operating as Security Engineer at Bureau Veritas, doing cloud security assessments for a major cloud provider. OSCP certified.

“This volume is unusual for a single operator.”
SUBJECT SPECIALIZATIONS
APPSEC
CLOUD
AI/LLM
MOBILE
CODE REVIEW
THREAT MODELING
SECTION 02 // THE JOURNEY

THE JOURNEY

FILE #001 // STAPLE

ISRO

Security Trainee

Sriharikota

SERVICE PERIOD
Nov
Dec 2019
CASE CLOSED
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Reduced network attack surface by 30+ services across 20 production devices through Wireshark traffic analysis

Led decommissioning of legacy protocols (FTP, Telnet) based on findings from independent investigation

Enabled early threat detection by building custom monitoring for 30 critical assets

Identified anomalous traffic patterns and unexpected service exposure that hadn't been previously flagged

MILESTONE // 002

SRM Institute of Science and Technology

BTech Computer Science

2018 – 2022
Chennai
COMPLETED
FILE #003 // TAPE STRIP

HighRadius

Security Consultant

Hyderabad

SERVICE PERIOD
Jul 2021
Feb 2022
CASE CLOSED
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Eliminated cross-tenant data exposure in Fortune 500 financial workflows by identifying IDOR and auth bypass across collections, cash application, and credit management

Discovered broken auth,improper token handling, missing session invalidation, weak credential enforcement traced to code root cause

Identified business logic flaws in financial workflows by abusing request ordering, state transitions, and retry behavior

Found injection vulnerabilities (SQLi, XSS, CSRF) and API misconfigs across REST endpoints using Burp Suite Pro

Detected sensitive data exposure,financial PII, credentials, and transaction details in API responses without access controls

Prevented insecure releases by conducting secure design reviews on data flows and trust boundary assumptions

Mapped privilege escalation paths using BloodHound and validated with Metasploit under scoped rules of engagement

FILE #004 // PAPER CLIP

HP Inc.

Cybersecurity Engineer

Bangalore

SERVICE PERIOD
Feb
Jul 2022
CASE CLOSED
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Exposed 20+ critical vulnerabilities including SQLi, XSS, CSRF, AuthN/AuthZ bypass, XXE, and race conditions by pentesting 6 production apps

Traced root causes deeper than Veracode by performing manual code-level analysis and correlating SAST against runtime behavior

Identified business logic flaws by manipulating multi-step workflows, request ordering, and retry behavior

Demonstrated horizontal and vertical privilege escalation by abusing role boundaries and insufficient access control

Standardized transport security validation by building Python automation for TLS/SSL checks across all 6 apps

Produced developer-friendly reports with CWE, CVSS, reproduction steps, and retested every fix post-implementation

Performed manual code review identifying insecure patterns, missing validation, and access control gaps SAST missed

GT
MILESTONE // 005

Georgia Institute of Technology

MS Cybersecurity

2022 – 2023
Atlanta, GA
Coursework: Applied Cryptography, Network Security, Binary Exploitation, Secure Systems Design[FULL TRANSCRIPT IN SECTION 08]
COMPLETED
ACTIVE ASSIGNMENT // 006

Bureau Veritas

Security Engineer

Seattle, WA

Mar 2024 – Present
ACTIVE
CONTINUES IN NEXT SECTION →
SECTION 03 // PRIMARY CASE FILE

BUREAU VERITAS, MAJOR CLOUD PROVIDER

CASE FILE: BV-CLOUD-2024 // PRIORITY: HIGH

Cloud Security Assessments

Mar 2024 – Present · Security Engineer · Seattle, WA

ACTIVE
40+SERVICES ASSESSED
100+FINDINGS
20+HIGH SEVERITY
7DOMAINS
SEC-01

WEB / API

10documented findings & activities

by abusing IAM trust relationships, undocumented API parameters, and role assumption chains

Validated real exploitability of SQLi, XXE, command injection, SSTI, and CRLF across all user-controlled surfaces,beyond scanner output

Exposed CORS misconfigurations enabling credential-bearing cross-origin requests by testing wildcard origins and null origin reflection

Revealed full GraphQL schemas and unauthorized resolver access through introspection abuse, batching, and missing depth limits

Discovered systemic business logic chains by manipulating request ordering, state transitions, and cross-API interactions

Identified mass assignment and parameter pollution by injecting unexpected fields and observing server-side model behavior

Assessed cryptographic implementations for weak algorithms, insecure randomness, and improper certificate handling

Detected second-order vulnerabilities by tracing stored payloads that executed in different contexts

Identified subdomain takeover risks through dangling DNS records pointing to deprovisioned resources

Tested authentication for brute force gaps, MFA bypass, session fixation, and token entropy weaknesses

WEB API
CASE BV-CLOUD-2024 // 7 ASSESSMENT DOMAINS // Mar 2024 – PresentPAGE 1 OF 7
SECTION 04 // FORM NO. OA-2026

OPERATOR CAPABILITY ASSESSMENT

STANDARDIZED CAPABILITY ASSESSMENT FORM // OA-2026
SUBJECT: YADDALA, M.N.K. // ASSESSOR: REDACTED
CLEARED
20DOMAINS
7EXPERT RATED
271TOTAL SKILLS
84%AVG PROFICIENCY
EXPERT (90-100%)
PROFICIENT (80-89%)
COMPETENT (70-79%)
FAMILIAR (<70%)
A. OFFENSIVE OPERATIONS
01APPLICATION SECURITYEXPERT
02API SECURITYEXPERT
03AUTH TESTINGEXPERT
04VULNERABILITY CLASSESEXPERT
"Strongest domain; offensive instincts are sharp."
B. CLOUD & INFRASTRUCTURE
05CLOUD AWSEXPERT
06CONTAINER & K8SPROFICIENT
07TRANSPORT & NETWORKCOMPETENT
"Deep AWS knowledge. 40+ services assessed firsthand."
C. INTELLIGENCE & ANALYSIS
08AI/LLM SECURITYPROFICIENT
09CODE REVIEWEXPERT
10SECURE DESIGNPROFICIENT
11LOG & FORENSICSCOMPETENT
12RUNTIME & DETECTIONCOMPETENT
"Unusual; combines AI/LLM testing with code-level depth."
D. SPECIALIZED DOMAINS
13MOBILE SECURITYPROFICIENT
14ENTERPRISE ADCOMPETENT
15BINARY & LOW-LEVELCOMPETENT
16WORDPRESS & CMSPROFICIENT
17BROWSER SECURITYPROFICIENT
18CRYPTOGRAPHYCOMPETENT
"Rare breadth: mobile + browser + crypto + WordPress."
E. PROGRAM & REPORTING
19SECURE SDLCPROFICIENT
20REPORTINGEXPERT
"Reports are engineering-ready. Peer reviews are thorough."
ASSESSMENT COMPLETE
ASSESSOR SIGNATURE
REDACTED
DATE OF ASSESSMENT
APRIL 2026
FORM OA-2026 // PAGE 1 OF 1
SECTION 05 // THE EVIDENCE

THE EVIDENCE

200+ documented vulnerabilities across professional engagements and independent research

CLASSIFIED
CLASSIFIED FIELD RECORD // PROFESSIONAL ENGAGEMENTSRESTRICTED
0+FINDINGS
PROFESSIONAL FINDINGS
Across 4 organizations · NDA-protected engagements
BUREAU VERITAS,AWS
100+
HP INC.
20+
HIGHRADIUS
15+
ISRO
5+

Individual findings under NDA. Aggregate impact documented.

DOMAINS
Web/APICloud/IAMAI/LLMMobileContainerCode ReviewThreat Modeling
[REDACTED][REDACTED]
INDEPENDENT RESEARCH,FULLY DOCUMENTED

60 findings · 5 platforms · All individually verified

0
INDEPENDENTLY DOCUMENTED FINDINGS
W
9.9 Widget Options,RCE via eval Bypass
8.2 WPForms (6M+),PayPal Webhook Forgery
WORDPRESS
28
28 documented
Widget Options,RCE via eval Bypass
W3 Total Cache,mfunc Command Injection
AWS
9.8 SDK,SSRF via bucketEndpoint Option
8.2 CloudFormation CLI,Command Injection Docker
AWS SDK
13
13 documented
CloudFormation CLI,Command Injection Docker
CloudFormation CLI,SSRF + File Read Schema
9.1 Hardcoded Airship Credentials
7.5 Facebook App ID + Client Token
ANDROID DIBZ
8
8 documented
Hardcoded Airship Credentials
Facebook App ID + Client Token
8 Tor Transport Missing Integrity Verification
7.5 Trusted Types CSP Bypass
BRAVE BROWSER
4
4 documented
Trusted Types CSP Bypass
Enclave Key Sync State Corruption
H1
8.6 Tron,PBFT Zero-Signature Bypass
7.5 Airtable,AI Chat IDOR
HACKERONE
7
7 documented
Vercel @vercel/flags Prototype Pollution
Vercel Next.js Host Header SSRF
INDEPENDENT VULNERABILITY MAP,EACH DOT REPRESENTS ONE FINDING
CRITICAL
HIGH
MEDIUM
LOW
TOTAL DOCUMENTED IMPACT: 140+ professional + 60 independent = 200+ vulnerabilities
SECTION 06 // MOST WANTED BOARD

MOST WANTED

Top 10 highest-impact vulnerabilities,ranked by severity and real-world consequence

MOST WANTED
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
9.3CVSS v3.1
#1
ALIAS

postMessage XSS → ATO

BUREAU VERITASCRITICAL

Demonstrated a 4-step invisible chain that no automated scanner could detect,each link harmless alone, devastating together. Found through manual code review during a cloud security engagement.

CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
8.2CVSS v3.1
#2
ALIAS

Prototype Pollution

BUREAU VERITASHIGH

Proved that a single polluted prototype key could compromise application-wide state across every user session simultaneously. No automated tool flagged it.

CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
9CVSS v3.1
#3
ALIAS

Stored XSS → Headless Admin

HP INC.CRITICAL

Showed that a single user comment could silently hijack an admin-level automated agent,zero interaction required, full privileged access gained. The attack required only a standard user account.

CLICK FOR FULL DOSSIER
ADDITIONAL SUSPECTS
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
8.6CVSS v3.1
#4
ALIAS

State Government IDOR

RESPONSIBLE DISCLOSUREHIGH
CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
8.2CVSS v3.1
#5
ALIAS

CloudFormation CLI Injection

AWS VDPHIGH
CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
9.1CVSS v3.1
#6
ALIAS

DIBZ Hardcoded Credentials

HACKERONE / FLUTTERCRITICAL
CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
9.8CVSS v3.1
#7
ALIAS

SDK SSRF via bucketEndpoint

AWS VDPCRITICAL
CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
8.6CVSS v3.1
#8
ALIAS

Tron PBFT Bypass

HACKERONEHIGH
CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
8.2CVSS v3.1
#9
ALIAS

WPForms Webhook Forgery

WORDFENCEHIGH
CLICK FOR FULL DOSSIER
WANTED
DEAD OR ALIVE,VULNERABILITY BOUNTY
7.5CVSS v3.1
#10
ALIAS

Trusted Types CSP Bypass

BRAVE VDPHIGH
CLICK FOR FULL DOSSIER
4 CRITICAL · 6 HIGH · AVG CVSS: 8.7
SECTION 07 // SOP-AWS-7P-2024

STANDARD OPERATING PROCEDURE

PLATFORM-ADAPTED 7-PHASE METHODOLOGY,SELECT PLATFORM, THEN INSPECT PHASES

CLASSIFIED // ASSESSMENT METHODOLOGYCLOUD
SELECT PLATFORM
01RECONNAISSANCE02THREAT MODEL…03VULNERABILIT…04EXPLOITATION05POST-EXPLOIT…06REPORTING07VERIFICATION7-PHASEKILL CHAIN↻ CONTINUOUS
SELECT A PHASE NODE ABOVE TO INSPECT DETAILS
WHAT AUTOMATED SCANNERS ACTUALLY COVER
THE GAP IS WHERE MANUAL EXPERTISE MATTERS
RECON
60%
THREAT MODEL
10%
DISCOVERY
35%
EXPLOITATION
15%
POST-EXPLOIT
5%
REPORTING
20%
VERIFICATION
10%
SCANNER COVERS
REQUIRES MANUAL EXPERTISE
SECTION 08 // CREDENTIALS & TRAINING

THE CREDENTIALS

Academic training, professional certifications, and competition records

CLASSIFIED // PERSONNEL DOSSIERBACKGROUND VERIFICATION
A. ACADEMIC RECORD
GRADUATE PROGRAM // MASTER'S THESIS TRACK

Georgia Institute of Technology

MS Cybersecurity

GRADUATED
2023
2022 – 2023
"Top performer in Applied Cryptography,directly applicable to field operations."
CONFERRED BY THE BOARD OF REGENTS // GEORGIA INSTITUTE OF TECHNOLOGY // ATLANTA, GA
UNDERGRADUATE FOUNDATION // 4-YEAR PROGRAM

SRM Institute of Science and Technology

BTech Computer Science

2018 – 2022
"Foundation years. Built the engineering base for everything after."
B. PROFESSIONAL CERTIFICATIONS
OSCP

Offensive Security Certified Professional

Offensive Security · 2023

ELITE
PNPT
Practical Network Penetration Tester
TCM Security · 2022
PRO
CC
Certified in Cybersecurity
ISC² · 2023
FOUNDATION
CEH
Certified Ethical Hacker
EC-Council · 2021
PRO
CND
Certified Network Defender
EC-Council · 2021
FOUNDATION
C. COMPETITION RECORDS,MISSION DEBRIEFS
S
OPERATION GRID

Flipkart Grid

Semi-finalist
/ 3000+ teams
MULTI-DOMAIN CTF

National-level competition by Flipkart. Advanced through multiple rounds against 3000+ teams to semi-finals.

Web ExploitationReverse EngineeringCryptography
TT
OPERATION NAHAM

NahamCon CTF

Top Third
JEOPARDY-STYLE CTF

International online CTF. Placed in top third across web exploitation, binary analysis, and forensic challenges.

Binary ExploitationWebForensicsOSINT
5P
OPERATION RED

Red Team Academy

5th Place
/ 50+ teams
RED TEAM EXERCISE

Simulated enterprise red team engagement. Achieved 5th place through AD exploitation and lateral movement chains.

Active DirectoryPrivilege EscalationLateral Movement
5 CERTIFICATIONS · 2 DEGREES · 3 COMPETITIONS · BACKGROUND VERIFIED

"The next breach is already happening.

The question is who finds it first."