Deev Pal

Deev Pal

Security Engineer

I'm a Security Engineer focused on product security, AI/ML security, and offensive research. I break things so they can be built back stronger.

This blog is where I publish detailed technical writeups — bug bounty findings with full attack chains, AI security research, vulnerability analysis, and the tools I build along the way. Every post is written to be actionable: real payloads, real targets, real lessons.

What I Work On

  • AI & LLM Security — Prompt injection, agent exploitation, model supply chain attacks, memory poisoning
  • Web Application Security — SSRF, SQLi, XSS, authentication bypass, API vulnerabilities
  • Bug Bounty Hunting — Active on HackerOne and Bugcrowd, focusing on AI/LLM targets
  • Security Tooling — Building AI-powered security automation and research tools

Achievements

Hall of Fame

OpenAI
OpenAI — Stored XSS via Insecure File Upload P2 (High) — $3,600 Bounty
Atlassian
Atlassian — Trello PowerUp Private Data Access P3 — $1,200 Bounty
Atlassian
Atlassian — Trello Workspace Self-Join Bypass via Slack P3 — $1,200 Bounty
Atlassian
Atlassian — Trello Board Deletion Bypass via Board Move API P3 — $1,200 Bounty
Atlassian
Atlassian — Trello Butler Automation Button Bypass P4 — $300 Bounty

Certifications

CompTIA
CompTIA Security+ CompTIA
Altered Security
Certified Red Team Professional (CRTP) Altered Security

This Blog

Every writeup follows the same structure: discovery (how I found it), exploitation (full attack chain with payloads), impact (what an attacker could do), and remediation (how to fix it). No fluff, no filler.

I also publish research breakdowns of interesting papers and conference talks, making complex security concepts accessible to anyone willing to learn.