--:--

sky — security engineer · bug hunter · writer

Breaking & exploting the modern web.

I'm a security engineer who finds vulnerabilities in modern web applications, builds tooling to automate the boring parts, and writes my bugs somethimes in free time.

now breaking — APIsAuth flowsCloud misconfigs

found bugs in · 15 platforms

01

Writeups

/ recent posts
02

Pentesting Services

/ break it. fix it. secure it.
/ 01 black box

Web Application Pentesting

No source, no docs — we attack it the way bad actors do.

Every vulnerability class reachable from the outside gets tested: authentication & session management, access control & IDOR, injection (SQL, NoSQL, command, SSRF, XXE), file uploads, business logic, rate limiting and misconfigurations — mapped against the OWASP Top 10 & WSTG.

  • Authenticated & unauthenticated testing across every role
  • Web, API & mobile-backed endpoints in scope
  • Manual exploitation of every finding — no scanner-only results
// you provide

Just the application URL and a test account. We handle the rest.

Book a black box engagement →
/ 02 white box

Web Application Testing — White Box

We go inside the codebase and hunt what black box can never reach.

Full source review for the flaws that hide in logic: broken authorization & privilege escalation, business-logic bypasses, injection sinks, crypto misuse, hardcoded secrets, dependency & supply-chain risks, and insecure architecture decisions.

  • Line-level findings tied to the exact code
  • Architecture & threat-model review included
  • SAST, dependency scanning & manual deep-dive combined
// you provide

Source code access — plus environment credentials if needed. We map the rest.

Book a white box review →
included in both plans

Manual + Automated + AI

Human expertise, tooling and AI-assisted analysis on every engagement.

Detailed report

Comprehensive, prioritized findings with clear, actionable recommendations.

We fix with your team

We sit with your developers and work through remediations — not just a PDF.

Re-testing

We verify every fix actually holds before you call the engagement done.

03

About

/ whoami

Security isn't a checklist — it's a mindset. For 6.5+ years I've been finding the bugs before the bad guys do — so your users never have to.

Hi, I'm Akash — a Senior Product Security Engineer at ConnectWise and a former Cybersecurity Consultant at Ernst & Young, where I helped secure 60+ clients, mostly Nifty 50 companies. Across 160+ bug bounty reports, my findings have been acknowledged by Goldman Sachs, Google, OYOrooms, and Starbucks — and have helped protect the data of 3.2 million users, eight separate times.

From web and mobile apps to APIs and cloud, I hunt what scanners miss and fix what matters. I'm an OSCP, AWS Security Specialty, and CEH certified professional — but the credential I'm most proud of is the trust teams place in me to harden what they've built. If it runs on the internet, I want to make sure it survives it.

Web Pentest Android Pentest Bug Bounty Secure Code Review Cloud Security API Security Threat Modeling Mobile AppSec OSCP AWS Certified CEH
skypentest.typedream.app ↗
Experience
6.5+ years
Bugs reported
160+ (60+ critical/high)
PII protected
3.2M users · 8 leaks
Leaderboard
#1 OYOrooms · 2020–2023
Status
Available
Coffee
Yes. Always.
160+
bugs reported
via real bug bounty programs
60+
critical & high severity
findings on live applications
3.2M
PII records protected
across 8 separate leaks
6.5+
years experience
appsec · VAPT · cloud security
#1
OYOrooms leaderboard
bug bounty · 2020–2023

certifications

OSCP

Offensive Security Certified Professional

Hands-on penetration testing — exploited live machines from zero to root.

OffSec
AWS

AWS Certified Security — Specialty

Designing & hardening cloud architectures against real-world threats.

Amazon Web Services
CEH

Certified Ethical Hacker

A hacker's toolkit, mastered — and used strictly on the right side.

EC-Council
04

Contact

/ say hi

Got a project or application which require pentest?

Security finding, research idea, or just want to trade bug bounty stories — my inbox is open.