emilloc

whoami

field notes

journal

  • nothing posted yet.

disclosures

elsewhere

settings

esc back

whoami

emilloc. adversarial operator @Bishop Fox. focused on vulnerability research, reverse engineering, and AI x security, bug bounty on the side.

i find and disclose vulns in open-source and enterprise software (CVE-2026-18798, CVE-2026-25087, CVE-2026-9087), built snowpick to hunt public data exposure in ServiceNow, and have multiple acknowledgements from Apple's web server security team.

DISCLAIMER: these are my field notes, written for me and public in case they're useful to others. they keep me honest and visible (plus they help me remember all the things i want to test, lol).

if you found this helpful, share it, and send tips my way.