// based in islamabad, pk // utc+5 available for engagements

SUBHAN UMER.

$ whoami → application security engineer

I break authentication systems used by millions, then ship the fixes. 6 published CVEs & advisories across better-auth, n8n, SAP and oauth2-server. Findings validated by Twilio, SAP and FusionAuth.

0 CVEs & advisories
0 validated bounty findings
0 vulns remediated in prod
0 CTF team in Pakistan
scroll
01

Breaking things,then fixing them.

I'm an application security engineer who lives in the gap between offense and engineering. I find exploitable flaws in hardened enterprise targets — auth bypass, business-logic abuse, crypto downgrades — and translate them into developer-ready fixes that actually ship.

By day I run authorized penetration tests as a VAPT engineer at Snskies, build adversary-simulation tooling on MITRE Caldera, and develop offensive research tools at FAST (NUCES). By night I audit open-source auth frameworks — which is how a 27K-star library used by millions ended up patching a critical refresh-token replay I reported.

Before security, I shipped production MERN applications — so I write findings the way developers want to read them, and I wire SAST/SCA gates into the same CI/CD pipelines I once deployed through.

02

Security impact.

// published CVEs & advisories — patched upstream

CRITICAL · CVSS 9.1 CVE-2026-53512 ↗

better-auth — OAuth Refresh-Token Replay

The confidential client secret was never verified during the OAuth refresh-token grant on the oidc-provider and MCP plugins (CWE-306), so a leaked refresh token plus the public client ID could be replayed to mint fresh access and refresh tokens indefinitely. Reported in a 27K-star auth framework with millions of npm downloads; published as CVE-2026-53512 (CVSS 9.1), fix shipped in 1.6.11.

CWE-306OAuth 2.0published CVE
HIGH · CVSS 8.7 GHSA-9h47-pqcx-hjr4 ↗

better-auth — OIDC Crypto Defaults

Exposed alg=none acceptance and silent PKCE downgrade in the OIDC provider, violating OAuth 2.1 / RFC 9700 (CWE-327). Fix merged upstream.

CWE-327OIDCfix merged

n8n — OAuth Authorization Bypass

Missing state-parameter ownership verification in a 190K-star automation platform (100M+ Docker pulls), enabling attacker-controlled credential binding (CWE-863). Patch released.

CWE-863published CVEpatched
SAP HoF May 2026

SAP — Security Hall of Fame

Recognized on the SAP Security Hall of Fame (May 2026) for a validated server-side vulnerability found through source review.

SAPsource reviewvalidated

oauth2-server (Node.js)

Manual source-review finding in the popular Node.js OAuth2 framework, published as a Snyk advisory.

advisorynode.js
HackerOne validated

Twilio — Validated Finding

Finding validated via HackerOne on the NYSE-listed cloud-communications platform. 15+ further validated findings across public and private programs including SAP, RSR Group and FusionAuth; details under NDA.

hackeroneNDA programs
03

Experience.

jan 2026 → present

VAPT Engineer @ Snskies — Cybersecurity Services (PK & UAE)

  • Validated & drove remediation of 30+ vulnerabilities across web apps, APIs and corporate network infrastructure with reproducible PoCs and developer-ready fix guidance.
  • Uncovered exposed employee PII, leaked credentials and misconfigured assets via internal OSINT; coordinated takedown and hardening.
  • Built an offensive attack-simulation platform on MITRE Caldera with custom adversary profiles & plugins for automated purple-team exercises.
may 2026 → present

Research Assistant — Security Tooling @ FAST (NUCES)

  • Developing offensive security tools and adversary-simulation capabilities for internal research (Python / C++).
feb 2025 → jan 2026

Backend Developer (MERN) @ Flush It

  • Built & deployed the full-stack MERN application, configured the email stack, and added Semgrep SAST + npm-audit SCA gates in GitHub Actions CI.
2024 → present

Independent Security Researcher @ Bug Bounty / Contract

  • Trusted-researcher status in NDA-backed enterprise programs (SAP Private, RSR Group, FusionAuth); bounties via high-signal manual testing focused on auth bypass, business-logic abuse and exploit-chain validation.
04

Selected work.

/01

Threat-Intelligence Platform

Automated credential-leak and actor-relationship detection across Tor, Telegram and Discord using ML correlation and graph analysis — actionable intel from unstructured dark-web data.

pythonmlgraph analysis
/02

Caldera Attack-Simulation Toolkit

Extended MITRE Caldera with custom plugins, adversary profiles and environment-specific payloads; benchmarked detection coverage against EDR/SIEM baselines to surface SOC tuning gaps.

pythonmitre att&ckpurple team
/03

Production MERN Apps & APIs

Full-stack applications with security-by-design auth, RBAC, input validation and CI-integrated SAST scanning — built to be attacked.

node.jsreactmongodbci/cd
#1

Schrödinger Bears — top-ranked CTF team in Pakistan on CTFtime, core member

1st

AirTech CTF 2025 & National CyberMuhafiz CTF 2025

BH

Black Hat MEA finalist — Middle East & Africa

05 // contact

Got something worth breaking?

Pentest engagements, AppSec roles, security research collabs — my inbox is open.

subh4num3r@gmail.com