$ whoami
Cyber Security Analyst
Hi, my name is Karsten Soenderup. I look for security vulnerabilities in open source software and through bug bounty programs, and report them responsibly so they get fixed before they can be abused.
$ cat focus.txt
Open source security research
Reviewing the source of widely used open source projects for vulnerabilities — from memory safety and injection bugs to logic flaws in authentication and access control.
Coordinated disclosure
Findings are reported privately to maintainers first. I help reproduce the issue, review the fix and agree on a disclosure timeline before anything is made public.
Bug bounties
Testing within the scope and rules of public bug bounty and vulnerability disclosure programs.
$ ./contact.sh
Did you receive a report from me, or want to discuss a finding? Maintainers, security teams and program triagers are welcome to get in touch — for more details, a proof of concept, help verifying a fix or coordinating a CVE and disclosure date. Everything you send is treated as confidential.