fernandobortotti (Fernando Bortotti) · GitHub
Skip to content
View fernandobortotti's full-sized avatar
💭
I may be slow to respond.
💭
I may be slow to respond.
  • Brasil

Block or report fernandobortotti

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
fernandobortotti/README.md

matrix rain header


root@matrix:~# whoami
operator:      [ REDACTED ]
class:         Offensive Security / Red Team
focus:         [ Web AppSec, Mobile AppSec, Cloud (AWS), Bug Bounty ]
credentials:   6x CVE author  //  bug bounty researcher
blog:          https://fernandobortotti.github.io/artigos/
status:        > actively hunting_

Atuo como pentester e bug hunter, com ampla experiência na identificação e exploração de vulnerabilidades em aplicações web e mobile. Minha atuação em programas de bug bounty resultou na descoberta e reporte de diversas falhas críticas — e no registro de 6 CVEs com impacto real (RCE, XSS armazenado, path traversal e bypass de autenticação).

📖 Publico writeups e análises técnicas no meu blog: fernandobortotti.github.io/artigos


> CVE_DATABASE // exploits publicados

Pesquisa de segurança no pgAdmin 4 — 2 vulnerabilidades CRITICAL com execução remota de código.

CVE Vulnerabilidade Tipo CVSS
CVE-2026-12046 Unauthenticated pickle deserialization → RCE CWE-306 / 502
CVE-2026-12048 Stored XSS via html-react-parser CWE-79
CVE-2026-7819 Symlink path traversal → arbitrary file write CWE-61 / 22
CVE-2026-7818 Unsafe deserialization → RCE CWE-502
CVE-2026-7820 Account-lockout bypass (Flask-Security) CWE-307
CVE-2026-12047 HTML injection em endpoints de cloud CWE-79 / 116

> ARSENAL // ferramentas & táticas

Burp Suite OWASP ZAP Nmap Metasploit SQLmap ffuf AWS Custom Tooling

Domínio Táticas
Web AppSec Interceptação e análise de tráfego HTTP, exploração de OWASP Top 10, fuzzing e descoberta de conteúdo (ffuf), automação de SQLi (SQLmap)
Recon & Exploit Mapeamento de rede e enumeração de serviços (Nmap), desenvolvimento e execução de exploits (Metasploit)
Cloud Security Exploração e hardening de ambientes AWS, enumeração de buckets S3, abuso de APIs
Tooling próprio Ferramentas customizadas em Python para enumeração e exploração automatizada

> STATS // telemetria

> STACK

Python   JavaScript   TypeScript   Node.js   React   HTML5   AWS   Linux


> CONTACT // uplink



footer

Pinned Loading

  1. artigos artigos Public

    SCSS 2

  2. search_cve search_cve Public

    Shows a summary of the cve and whether an exploit exists.

    Shell 3

  3. CVE-2024-24919 CVE-2024-24919 Public

    Python 1

  4. jaci-theme-vscode jaci-theme-vscode Public

    1

  5. CPF-Tools CPF-Tools Public

    Python 58 21

  6. jaci-theme-insomnia jaci-theme-insomnia Public

    JavaScript 4