Web security & vulnerability research

Beneaththe surface.

I’m Joshua, a security engineer at Tenable.
I research web vulnerabilities, build tools,
and write about what I find.

Explore my research
FIG. 01 — FROM CLICK TO PATCH
Click. Break. Patch. Hover to take the cursor.
A public record of asking questionsResearch archive
Published CVEs
66
Critical findings
15
Products affected
29
Years disclosing, since 2020
6+
02 / SELECTED WORK

Following the evidence.

All disclosures
03 / FROM THE NOTEBOOK

Research, written down.

All writing
28 MIN READ

Bugbounty agent benchmark

Six models. Seven harnesses. One browser. What actually makes a bug bounty agent better?

From the article
“I wrote the specification before any code. Goals and non-goals, vocabulary, the invariants a proof has to satisfy, the scoring rule, the analysis plan.”
aibugbountyRead article
04 / BUILT ALONG THE WAY

Tools for the work.

All tools
05 / GET IN TOUCH

Let’s compare notes.

A question about a finding, an idea to explore, or a speaking invitation?

contact@jomar.fr