Joshua Martinelle

Security Engineer @ Tenable | Bug Hunter

zsh — 80x24
root @ jomar :~$ whoami
> Security Researcher focusing on Web Security
root @ jomar :~$

Latest Intelligence

View all work
HIGH

TRA-2025-34

SSRF Bypass discovered in BentoML.

Reported: 2025

Hookd

A lightweight, high-performance interaction server for capturing DNS and HTTP callbacks.

Go
Investigating a Compromised WordPress Site
WordPress
Jan 7, 2026

Investigating a Compromised WordPress Site

Diagnosing a WordPress site compromise that was redirecting visitors to adult content and pharmaceutical spam through injected malicious scripts.

Read Article