I have worked in IT and security for many years. On this blog, I publish vulnerabilities I have discovered, security research and technical notes from my work. I am less interested in a red flag from a scanner than in understanding why something is vulnerable—and how to fix it properly.
I wanted to understand what passive data alone can reveal about the external attack surface of organizations operating in a DORA-relevant environment. To explore this, I examined 195 Austrian domains using Certificate Transparency and DNS data—without active scanning.
My background is technical, but today I also work on architecture, risk and organizational questions. Security becomes most interesting—and sometimes most challenging—where these areas meet.
faydin.blog is my personal blog. It is where I publish CVEs, analyses and technical notes that I find interesting or useful. It is not a corporate website or an editorial content calendar.
I share knowledge because good security does not end when a finding is reported. We need to understand why it happened and what actually needs to change.