- 👨💻 All of my projects are available at https://github.com/herdiyana256
- 💬 Ask me about Web Security, Android Dev, DevSecOps, CI/CD Pipeline Security
- 📫 How to reach me herdiyan@supernesia.id
- 👨💻 My Business Supernesia Creative Technology
| Organization | Finding | Platform | Year |
|---|---|---|---|
| 🔬 Google OSS VRP (osv-scalibr) | Ecosystem misclassification fix causing zero CVE matches for Wolfi OS and Chainguard container images | Google OSS VRP | 2026 |
| 🚀 NASA (globe.gov) | Information Disclosure on official government platform | Bugcrowd VDP | 2026 |
| 🌐 Google OSS VRP (Angular) | Critical vulnerability in CI/CD pipeline affecting widely used open source project | Google OSS VRP | 2026 |
| 🔑 OpenProject (CVE-2026-27722) | Improper Access Control leading to unauthorized cross-project data manipulation | YesWeHack | 2026 |
| 📋 OpenProject | Authentication logic flaw enabling account compromise | YesWeHack | 2026 |
| 📊 OpenProject | Improper Access Control on sensitive reporting module | YesWeHack | 2026 |
| 💳 PayPal | Business Logic vulnerability in payment processing workflow | HackerOne | 2026 |
| 🏨 Shiji Group | Broken Access Control on enterprise hospitality management platform | YesWeHack | 2026 |
| 📰 Geenius Meedia | Multiple Business Logic vulnerabilities across subscription and content delivery systems | YesWeHack | 2026 |
| 🔧 cURL | Functional regression in core authentication implementation | HackerOne | 2026 |
| 🎯 YesWeHack Dojo #49 | Challenge Winner — exploitation chain achieving restricted file access | YesWeHack Dojo | 2026 |
| 🎯 YesWeHack Dojo #50 | Challenge Winner — bypass of security controls with bonus points awarded | YesWeHack Dojo | 2026 |



