About
I'm Kaya Emre Arıkan — an independent security researcher. I spend most of my time reading source code, tracing patch diffs, and looking for the class of bugs that survive a code review because nobody thought to check the boundary condition: auth bypasses, injection, deserialization, race conditions, and the odd firmware-level RCE.
My research spans open-source ecosystems — web frameworks, cloud SDKs, container runtimes, CI tooling, and the occasional piece of embedded firmware — reported through coordinated disclosure to maintainers, CNAs, and bug bounty programs (HackerOne, Bugcrowd, GitHub Security Advisories, MSRC, Google OSS VRP).
What's on this site
Writeups of my own findings — published only after the vendor's own advisory (CVE / GHSA / security bulletin) is already public. Nothing here pre-empts a disclosure still in progress.