Breaking things
to make them secure.
Security analyst specializing in web, API, and mobile application security. I find vulnerabilities so they can be fixed before attackers find them first.
Naga Sai Kiran T.
Security Analyst at Digit Insurance with 3+ years of hands-on experience in vulnerability assessment and penetration testing. My day-to-day involves tearing apart web applications, REST APIs, and Android apps to uncover security flaws — from injection vulnerabilities to complex business logic issues.
I write about what I learn: CVE deep dives, CTF writeups, privilege escalation techniques, and curated security resources.
Security expertise
Web Application Security
Full-scope VAPT of web applications. Injection flaws, authentication bypasses, access control issues, and business logic vulnerabilities.
API Security Testing
REST and GraphQL API penetration testing. BOLA, BFLA, mass assignment, rate limiting, and auth flow analysis.
Mobile App Security
Android application security assessments. Static and dynamic analysis, reverse engineering, and SSL pinning bypass.
Source Code Review
Manual and SAST-assisted code review to identify vulnerabilities at the source level.
CTF & Research
Active CTF participant and security researcher. CVE hunting, HackTheBox challenge creation, and vulnerability research.
Security Architecture
Threat modeling, secure design review, and security recommendations for development teams.
Latest posts
Deep dives into vulnerabilities, CTF writeups, and security resources.
Cybersecurity Simplified: The OWASP Top 10 2025
Read → CTF WriteupHackDonalds Challenge Writeup
Read → CVE AnalysisMiddleware Mishap: Next.js CVE-2025-29927
Read → Privilege EscalationWindows Privilege Escalation
Read → Privilege EscalationLinux Privilege Escalation
Read → ResourcesEssential Resources for Red Team
Read →Experience
Security Analyst
VAPT of web applications, APIs, and Android apps. Source code reviews, SAST integration, and business logic testing across the insurance platform.
Security Research & CTF
CVE hunting, HackTheBox challenge creation, CTF competitions, and publishing security research.
Let’s connect
Interested in security collaboration, consulting, or just want to talk about the latest CVE?
Product Security, Offensive Security, and AI Security consulting roles.