01 // WEB APPLICATION
Web Application Security
OWASP Top 10, injection vulnerabilities, authentication flaws, and secure development practices for modern web applications.
OWASP Top 10SQLiXSSCSRF
02 // API SECURITY
API Security
OWASP API Security Top 10, REST and GraphQL vulnerabilities, authentication bypass, and mass assignment attacks in modern API design.
OWASP API Top 10BOLAGraphQLREST
03 // CLOUD SECURITY
Cloud Security
Cloud-native attack surfaces, misconfiguration risks across AWS, Azure, and GCP, shared responsibility model, and zero-trust architecture.
AWSAzureGCPCSPM
04 // IAM & AUTHENTICATION
Identity & Access Management
OAuth 2.0 and OIDC implementation flaws, MFA bypass techniques, privilege escalation, and zero-trust identity architecture.
OAuth 2.0OIDCMFAZero Trust
05 // AI/LLM SECURITY
AI & LLM Security
Prompt injection, data leakage from AI systems, adversarial inputs, and security assessment of AI-powered applications in production.
Prompt InjectionLLMOWASP LLM Top 10
06 // SECURITY PROGRAMME
Offensive Security Programme Management
Building and managing security testing programmes — vulnerability disclosure, bug bounty programme design, and security engineering culture.
VDPBug BountySec Engineering