← nvnda.dev

Blog

All posts — security, personal, and everything in between.

Two Walls and a Google: Pentesting a Flutter App
Flutter doesn't use your proxy or trust your cert. Here's how we intercepted it anyway, and why the hardest wall wasn't one we were allowed to break.
Article
Project Glasswing: Who Gets to Hold Mythos, and Why It Matters
Anthropic gated Mythos to twelve partners. The decision behavior signals industrial unilateralism — what it means for builders and attackers in the gated era.
Article
Part 2: nmap dissected — don't blow your cover before you've even started
Going beneath the hood: how nmap actually discovers hosts, what changes across subnet boundaries, and why the default 'stealth' flags aren't as stealthy as they sound.
Article
Part 1: nmap — why it's everyone's first scan
Almost every engagement starts the same way: an nmap scan. Here's what nmap actually does, why everyone runs it first, and where depth and stealth start pulling in opposite directions.
Article
I Updated My LinkedIn. Two Days Later, Someone Impersonated My CEO.
It's been one month since I joined Cymetrics, and I don't think I'll forget how warm those first few weeks were — or the phishing email that arrived two days after I updated my LinkedIn.
Article
Cybersecurity, Scammers, and Confidence
Guest on 她Ta Zhi Dao — how scammers collect your data, social engineering in Asia, and building confidence as a woman in security.
Podcast
My First On-Chain Hacking: Fallback
Solving Ethernaut's Fallback challenge — claiming contract ownership and draining funds by exploiting how Solidity handles fallback functions.
Article
Breaking into Web3: Hacking On-Chain Smart Contracts
An introduction to smart contract security — how the EVM works, where vulnerabilities hide, and a step-by-step breakdown of a classic reentrancy exploit.
Article
Serendipity in Giving
Volunteering at the Women in Tech Global Summit 2025 in Osaka — how showing up and giving fully turns serendipity into something tangible.
Medium