CVE-2026-40103
Scoped API token authorization mismatch in Vikunja. The write-up documents the background-delete case I validated and the fix in 2.3.0.
ACyberSecure is my independent security practice. Before going independent, I personally delivered 300+ security projects and 125+ penetration testing engagements across in-house and consulting roles — cloud and M365 reviews, phishing work, and findings readouts for engineers and executives.
Projects delivered across in-house, consulting, and independent roles.
About ACyberSecure
ACyberSecure is my independent consulting practice, focused on penetration testing, cloud and M365 reviews, gap assessments, phishing-related engagements, and security advisory. Before going independent, I delivered 300+ security projects and more than 125 penetration tests through in-house and consulting roles.
I've rebuilt report templates and assessment tooling over that time, which cut writing time and made findings easier to act on.
You work with me from scoping through readout — no sales handoff or account layers.
Penetration tests, cloud reviews, identity work, and advisory engagements are scoped to fit your budget, your deadline, and what your team can actually fix.
Every report has a short executive summary and a technical section with reproduction steps and fixes, in that order.
Relevant Experience
Examples of organizations and environments I've worked within, through in-house and consulting engagements. The work has included internal and external penetration tests, cloud and M365 reviews, gap assessments, phishing-related work, and findings readouts.
Security work inside a global customer-experience organization.
Assessments within a regulated payer environment.
Assessment work within a major content and IP portfolio.
Security work within public-sector operations.
Reviews within temperature-controlled logistics operations.
Security work supporting essential utility services.
Sizes are approximate and describe the organizations I worked within, not named clients — industry and scale only.
Core Services
Penetration testing, continuous testing, red and purple teaming, gap assessments, cloud and identity reviews, and short implementation projects. I also run a small number of autonomous AI-driven penetration tests each year.
Web, API, internal, external, cloud, and mobile testing, plus Active Directory work when relevant, with clear reporting and prioritized remediation.
Request ScopeRecurring test cycles, retest support, and release validation to find regressions before release, on a cadence that matches your release cycle.
Discuss this serviceScoped adversary emulation and collaborative exercises to test detection and response, including phishing and social engineering scenarios when appropriate.
Discuss this serviceBaseline your current state against NIST CSF or CIS Controls, then rank the gaps and give you a roadmap with separate technical and executive views.
Discuss this serviceAzure, M365, and identity-focused reviews covering IAM, Entra ID, MFA, logging, admin risk, and control validation across cloud environments.
Discuss this serviceShort-window support for Okta-to-Entra ID migration planning, licensing reviews, MFA and security configuration changes, endpoint security transitions, vulnerability triage, and related admin tasks.
Discuss this serviceProof
5+ years of hands-on security work in in-house and consulting roles, across penetration testing, cloud/M365 reviews, and security support.
Sample report available on request.
CCSP (ISC2), eJPT, AZ-900, and SC-900.
Research & Disclosures
Public vulnerability research and coordinated disclosure notes from work I identified and reported, with direct links when there is a public technical write-up worth reading.
Scoped API token authorization mismatch in Vikunja. The write-up documents the background-delete case I validated and the fix in 2.3.0.
Contact
If you need a pentest, cloud/M365 review, gap assessment, or short-window identity/security support, send a note with your environment, target scope, timing, and constraints. I'll follow up with next steps.
Typical response time: 1 business day.
Remote-first, on-site by request
Flexible scheduling based on scope
Pentesting, cloud/M365, identity, advisory