Skip to content
View Zureno's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report Zureno

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Zureno/README.md

Hi, I'm Pranshu 👋

@@%*-.      -*#%%@@@@@@@@@%#+:     .-*
%+:       .+@@@@@@@@@@@@@@@@@%*
.        -#@@@@@%%@@@@@@@@@@@@@#.
         #@@%*+==-=+*##*==*#%@@@+
         #@#=::::....::...:-=*%@*
         +%*--::::::..:::::--=#%=
         -#=--::..........::--+%.
         :*-=+++=-:....:-===+==#.
         :--=++*===-::-==+*++==+:
         :::::::::::.:::::------.
         :::.....::...-::....::-.
         .-:.....:--:---.....:--.
          .::::::-----=-:::::--.
           --:-++=-::--=++-:--:
           :=--::-------::--=-
           .==+=-::::::-===++:
            -=*#**+===+*%#*+=.
          :::::=+*######*+-:-:
         .-:.. ...:::::::...:-.
           .                ..

Python Java AWS Kubernetes Docker GitLab CI OSCP

Senior AI Application Security Engineer with 11+ years securing web, API, cloud-native, and AI-enabled systems across airlines, telecom, consulting, and financial services. I'm a builder, not just an auditor — I come from a production Python/Java development background and specialize in LLM security, prompt injection defense, agentic system trust boundaries, and AI-assisted development security.

🔐 What I Do

  • 🛡️ Own SAST/SCA/DAST pipelines end-to-end (Veracode, Checkmarx, Snyk, Semgrep, Burp Suite, OWASP ZAP)
  • 🤖 Secure agentic & LLM systems — prompt injection defense, jailbreak resistance, MCP scope governance, agent credential inheritance
  • 🧵 Run enterprise threat modeling programs using STRIDE
  • ⚙️ Build AI-assisted dev security tooling — deterministic gates for agent-generated code, Claude Code/Copilot/Cursor governance
  • ☁️ Design secure cloud-native architectures on AWS/GCP with IAM, KMS, Kubernetes/OpenShift

🧪 Independent Vulnerability Research

Responsible disclosure researcher (GitHub Security Advisories) against major open-source projects:

  • open-webui/open-webui — Client-side SSRF via chart rendering (CWE-918) — Acknowledged, CVE pending
  • langgenius/dify — Cross-tenant IDOR, unauthenticated impersonation, and info disclosure (3 findings)
  • mkdocs/mkdocs — Unsafe YAML deserialization, stored XSS, path traversal, and more (6 findings)
  • goauthentik/authentik — SAML XML signature wrapping, OAuth2 redirect_uri binding issue
  • FlowiseAI/Flowise — Mass assignment enabling billing field overwrite

🛠️ Open Source Projects

  • burp-jwt-analyzer — Burp Suite extension for detecting insecure JWT configs, weak validation logic, and token exposure
  • Burp_LLM_Tester — Burp Suite extension integrating LLM reasoning into HTTP analysis, vulnerability triage, and API security automation
  • StoryMagic — Full-stack generative AI storytelling platform (React Native + Node.js + Gemini) with content moderation and hallucination mitigation baked in
  • TokenTenancy — Full-stack rental/tenant management platform with secure auth, RBAC, and hardened API workflows

📌 Pinned

Pin these on your profile for best visibility: burp-jwt-analyzer (already public), plus Burp_LLM_Tester, StoryMagic, TokenTenancy once those repos are public. Go to a repo → the "⋯" menu (or your profile's Customize pins) → Pin repository.

🧰 Tech Stack

Languages: Python · Java · FastAPI · Bash Security Tools: Veracode · Checkmarx · Snyk · Semgrep · Burp Suite · OWASP ZAP · Sonatype Nexus · Prisma Cloud · Wiz Infra: Kubernetes/OpenShift · Docker · Terraform · Helm · GitLab CI/CD · Jenkins · Tekton Cloud: AWS (IAM, KMS, GuardDuty, Security Hub) · GCP AI/LLM Security: Prompt injection defense · Adversarial testing · OWASP Top 10 for LLMs · AI red teaming

📜 Certifications

OSCP · CCSP · CEH · Red Teaming LLM Applications · Certified API Security Analyst · Red Team Ops (Zero Point Security) · Databricks Generative AI · Generative AI on AWS Bedrock & SageMaker

📫 Reach Me

📧 p21raghav@gmail.com


🎓 MS, University of Maryland–Baltimore County

Popular repositories Loading

  1. burp-jwt-analyzer burp-jwt-analyzer Public

    Python 1

  2. Python Python Public

    Forked from Isomaniac/Python

    Python_ Security

    Python

  3. C-plus-plus-coding-repo C-plus-plus-coding-repo Public

    C++

  4. DubleDableDo DubleDableDo Public

    Python

  5. Algebra Algebra Public

    Algebra

    Python

  6. Health_Checker Health_Checker Public

    A tool to ping a list of hosts and output them in the form of files

    Python