Available for engagements

Franck FERMAN

CyberSecurity Engineer

Pentest Red Team Malware Dev SOC Governance
Research & CVEs // responsible disclosure
CVE-2025-67906 Stored XSS in MISP Workflow Engine. Unsanitized name field rendered via doT.js — payload executes in any user viewing the workflow, including admins. Enables privilege escalation and threat intelligence exfiltration.
CVSS 9.0 Critical Patched

Critical 0-Days  /  GovTech & Enterprise SaaS Blind SQLi + Zero-Click Stored XSS. Unauthenticated DB exfiltration (PII, admin creds, live MFA tokens) + super-admin session takeover without user interaction.
Critical NDA

Critical 0-Day  /  Fortune 500 Payment Infrastructure Cryptographic failure + business logic flaw. Transaction integrity bypass across the entire global payment network.
Critical NDA

Xelians  /  Government Archives Multiple chained vulnerabilities leading to full account takeover across the platform and all client tenants.
CVSS 9.3 Critical

DINUM  /  Government Digital Platform Chained enumeration and authentication bypass — exposing highly confidential government data at national scale.
CVSS 7.5 High

Qwant  /  Privacy Search Engine Cross-origin exfiltration of authenticated data via CORS origin reflection and regex suffix bypass.
CVSS 7.4 High

Caisse Nationale d'Assurance Maladie  /  Healthcare Unauthenticated access to sensitive internal healthcare data.
CVSS 7.5 High
Skills
Offensive Pentest · Red Team · Malware Dev · Exploit Writing · AD attacks · OPSEC
Languages C · Python · Rust · Go · PowerShell · Bash · Assembly x86-64
Blue Team SOC · Threat Hunting · DFIR · Wazuh · Splunk · YARA · Sigma · MISP
Governance CISO · ISMS · EBIOS RM · ISO 27001 · ANSSI · GDPR · PCI-DSS
Infra Active Directory · Cisco · Palo Alto · Proxmox · Docker · Terraform