What I do
I have spent many years working in IT and information security. Today, my main areas of focus are penetration testing, security architecture and vulnerability research.
When I find a vulnerability, I want to know more than whether it can be exploited. I want to understand why it exists, what path an attacker could take and what a sustainable fix looks like. Scanners can help, but they are not the answer.
Where technology meets management
A large share of security problems are not caused by missing tools but by communication. Technical teams speak in technical details; management hears risk, effort and deadlines. Sometimes both sides even mean the same thing but use different language.
I try to bridge that gap: explain technical risks in a way that supports decisions without watering down the engineering. Technical teams must also accept that not every good solution can be implemented immediately. When both sides meet halfway, cybersecurity becomes much more effective.
Why this blog exists
faydin.blog is my personal website, not a corporate presence, product page or content calendar. I publish things I find interesting or useful: CVEs, research, longer analyses and sometimes a technical note I want to be able to find again later.
I enjoy sharing knowledge and disclosing vulnerabilities responsibly. Not because every observation needs a big story, but because clear, reproducible technical details can help others.
Research & Responsible Disclosure
For published findings, I try to provide enough context to understand the problem: affected versions, CVSS/CWE, a disclosure timeline and references. I add new CVEs over time.
Explore my CVE research