โ—‡ SESSION ACTIVE

@xghost123

PentestRed TeamExploit Dev AI SystemsPythonGo RustDevSecOpsBlockchain
xghost123@ghost:~ โ€” zsh
xghost123@ghost:~$ ./probe --identity
{
"handle": "@xghost123",
"roles": ["AI Engineer","Full-Stack Dev","Security Researcher","CEH"],
"focus": "Offensive Security ยท AI ยท Automation",
"status": "ACTIVE"
}
xghost123@ghost:~$ ./status --brief
Tools: 50+ ยท CVEs: โˆž ยท Projects: 10+ ยท Uptime: 100%
Type /help to explore the terminal
xghost123@ghost:~$
0
Years Building
0
Tools Built
0
Findings
CEH
Certified
0
Records Surfaced
0
Uptime
PROFILE

Building at the intersection of security and intelligence

Security researcher (CEH), AI engineer and full-stack developer. 15+ years building offensive tooling and AI-driven automation โ€” from single-supply exploitation chains to multi-territory platform engagements, always with responsible disclosure at the close.
๐Ÿ”

Security Research

Offensive security, vulnerability discovery and exploit development. AI-powered analysis pipelines and automated exploitation โ€” scaled across regulated institutions, credit bureaus and cloud estates.

PentestExploit DevWAF BypassRed Team
๐Ÿง 

AI Engineering

LLM-powered autonomous systems, agentic workflows and AI-driven security analysis. Integrating intelligence into every layer of the security stack โ€” including this page's live agent.

LLMsAgentic AIRAGAutomation
๐Ÿ’ป

Full-Stack Development

Production systems front-to-back. Python, Go, Rust, React โ€” engineered with security as a foundational principle, not an afterthought.

PythonGoRustReact
๐Ÿ›ก๏ธ

Certified Ethical Hacker

CEH certified. Deep expertise in network pentesting, web security, social engineering and red-team operations.

CEHWeb SecurityNetworkOSINT
Penetration Testing95%
Python95%
AI / ML88%
Web Security92%
Go80%
React / Frontend78%
Rust72%
DevOps / Cloud82%
FINDINGS // vulnerability research

Confirmed, disclosed, classified

Select engagements from the current campaign. Each target was fully validated, documented and disclosed through the responsible-disclosure process. Impact figures are de-identified; no credentials or third-party PII are reproduced.
All Critical High
#01Carret Private Capital / Alpha CalibrationNEWCRITICAL
Hong Kong SFC-licensed wealth manager. ~$2.25B AUM across 270+ client accounts, 645 client records, 500+ unique bank account numbers, a live operations mailbox (20K+ emails) and 15 live bank statement / SFTP data channels. Fully living compromise of a regulated institution.
HK ยท Regulated$2.25B AUM645 clients15 bank channels
#02Flexiplan Regional / Equifax LatAmNEWCRITICAL
El Salvador fintech with working access to the Equifax LatAm consumer credit-bureau API. 815 national ID numbers exposed in source. Live transactional credit-data plane of a national credit bureau.
El SalvadorCredit bureau API815 national IDs
#03KalsteinNEWCRITICAL
Exposed VCS configuration escalated to private source code, live cloud service accounts and 1,500+ customer quote documents across three cloud tenancies. Full private-source-to-customer-data chain.
Source + cloud3 service accounts1,500+ customer docs
#04Feiyue / SwiCode โ€” WeChat EcosystemCRITICAL
China e-commerce + sports-training group. 45 applications compromised, 22K users surfaced, 4 WeChat Pay merchants, Tencent Cloud and Alibaba SMS configurations exposed.
China45 apps22K users4 WeChat Pay merchants
#05OrderTaker SaaSCRITICAL
India ordering SaaS. ~18K customer PII records, 35 stores, ~โ‚น1.1Cr revenue footprint, live payment gateways and root-level platform access.
India18K PIIโ‚น1.1Cr rev35 stores
#06AllMySMS SOAP Auth BypassCRITICAL
Pre-authentication remote code execution class flaw โ€” uninitialised handler evaluated before the auth gate in a messaging gateway.
Pre-auth RCEGateway
#07CSAT SSO Token LeakCRITICAL
Authentication bypass in a major car-telematics single sign-on โ€” leaked SSO tokens allow full account takeover.
Automotive SSOAuth bypass
#08DVR Cloud Storage ExposureCRITICAL
MinIO presigned-URL disclosure exposing dashcam footage of a fleet via misconfigured S3 access.
MinIOPresigned URLS3
#09Bhavani Server TakeoverHIGH
13 databases, 3.7M records, full cloud-object-storage read/write/delete, leaked SSH relationships.
13 databases3.7M recordsStorage R/W/D
#10Multi-Provider Cloud API Key LeakHIGH
DigitalOcean, Tencent Cloud and Alibaba API keys exposed in public configuration files.
DOTencentAlibaba
#11EAD-Fiocruz (NEAD)NEWHIGH
Brazilian public-health training platform. Write-capable API token โ€” user create, role assignment, file upload and course modification on a national health institution's LMS.
Brazil ยท HealthWrite-capable API
#12IIPD GlobalNEWHIGH
UAE/Saudi training & certification. CRM administrative webhook surface exposing 3,758 leads and 229 contacts with full contact PII and financial opportunity data.
UAE ยท KSA3,758 leads229 contacts
#13KREISSNEWHIGH
AWS object store sweep โ€” 49 buckets / ~6.3GB incl. a careers bucket (~2.2GB of applicant CVs) and live customer chat transcripts.
AWS S349 buckets6.3GBCV PII
#14Sensitive TransportesNEWHIGH
Brazilian logistics. Remote database (1,670 client records) plus a live WhatsApp message-router surfacing 1,049 contacts.
Brazil1,670 clientsWA router
CRITICAL HIGH โ€” verified & disclosed; de-identified
WORK

Open source security tooling

AURA Pentest Framework v3.0

AI-powered web pentesting. 50+ scan modules, automated exploitation, AI-driven analysis, AD assessment, Telegram bot, CVE-matching engine, false-positive reduction and dark-themed HTML reports.

The research behind this portfolio is driven through AURA โ€” from exposed-config discovery through validation and disclosure reporting.

50+ ModulesAI AnalysisTelegram BotCVE MatcherAD AssessmentOpen Source
โ—‡ GitHub โ†’
CAPABILITIES
๐Ÿ•ธ๏ธWeb App PentestBlack/grey-box, API, auth โ˜๏ธCloud / InfraAWS, Alibaba, GCP, S3 ๐ŸŒSource / ConfigEnv, VCS, API keys ๐Ÿค–AI AutomationAgentic pentest, RAG ๐ŸฆRegulated FintechWealth mgmt, payments ๐Ÿ“ฎMessagingMail, SMS, push rails
PATH

Evolution timeline

2026

AURA Pentest Framework v3.0

AI-powered pentesting with Telegram bot, CVE matcher and 50+ modules. Open-sourced on GitHub.

2026

Regulated-Platform Engagements

Wealth-management, credit-bureau and health-platform findings โ€” scored, validated, disclosed.

2025 โ€” 2026

Critical Vulnerability Research

SSO token leaks, pre-auth RCEs and cloud storage exposures across major platforms.

2024

AI Security Tooling

Integrating LLMs into penetration testing. Building autonomous security agents (including this site's GHOST agent).

2022 โ€” 2024

Full-Stack & Security Engineering

Production systems across the stack while advancing offensive-security expertise.

CEH

Certified Ethical Hacker

Professional certification in ethical hacking and penetration testing.

CONNECT

Drop a message

Open for security-research collaborations, pentest engagements and interesting projects.

โœ‰๏ธ admin@xghost123.dev โ—‡ GitHub โœˆ๏ธ Telegram โ˜• Buy Me a Coffee
โ—‡ GHOST // AI agent
โ— ONLINE
Who is he? AURA? Findings Contact