Personal Blog — Cybersecurity — Research — Technical Notes

Ferat Aydin

Penetration Tester · Security Architect · Security Researcher

I have worked in IT and security for many years. On this blog, I publish vulnerabilities I have discovered, security research and technical notes from my work. I am less interested in a red flag from a scanner than in understanding why something is vulnerable—and how to fix it properly.

Research

Latest CVEs

View all CVEs
  1. CVE-2026-79363 Cloudron Stored XSS Medium
  2. CVE-2025-60917 OpenAtlas XSS Medium
  3. CVE-2025-60916 OpenAtlas XSS (DOM) Medium
  4. CVE-2025-60915 OpenAtlas LFI / Path Traversal Critical
  5. CVE-2025-60914 OpenAtlas Broken Access Control (IDOR) High
Publications

Featured publication

All publications
About

How I approach security

My background is technical, but today I also work on architecture, risk and organizational questions. Security becomes most interesting—and sometimes most challenging—where these areas meet.

faydin.blog is my personal blog. It is where I publish CVEs, analyses and technical notes that I find interesting or useful. It is not a corporate website or an editorial content calendar.

I share knowledge because good security does not end when a finding is reported. We need to understand why it happened and what actually needs to change.

More about me