Md Shariar Shanaz Shuvon, a 17-year-old self-taught ethical hacker from Bangladesh, has made headlines by identifying a serious security vulnerability within NASA's cybersecurity system. In recognition of his discovery, the US space agency formally acknowledged his contribution and sent him an official letter of appreciation. Hailing from Jhenaigati in Sherpur, Shuvon completed his SSC from Jhinaigati Government Model Pilot High School. He later moved to Malaysia, where he enrolled at the University of Cyberjaya. There, he is currently pursuing a diploma in Information Technology. Alongside his academic journey, he holds the position of Information Security Analyst at ERTH (Blue Bee Technologies Sdn. Bhd.), a company that specializes in providing cybersecurity solutions. Shuvon's passion for cybersecurity ignited when he was in Class 7. He began his journey by learning programming through free online resources, YouTube tutorials, e-books, and PDFs. By the time he reached Class 8, he had already immersed himself in the world of cybersecurity, participating in bug hunting and hackathons. Over the years, he explored various sectors in technology such as SEO, graphic design, and video editing, but ultimately, he realized that cybersecurity was his true calling. His significant breakthrough came on June 11, 2024, when he discovered a privacy-related bug in NASA’s systems. Describing the process behind his discovery, Shuvon said, “At first, I went through recent vulnerabilities reported by other security researchers and tried to reproduce them, but none of those attempts were successful. Then I tried combining several known vulnerabilities. Eventually, I used a technique called IDOR (Insecure Direct Object Reference) along with SSRF (Server-Side Request Forgery).” He further explained that by chaining these two techniques, he was able to uncover a bug that allowed unauthorized access to Earth data, which included sensitive personal information. With such access, a malicious actor could have carried out phishing attacks, sold private data, or exploited it for unethical purposes. Understanding the potential danger, Shuvon promptly reported the vulnerability to NASA, who took the matter seriously and patched the issue. This recognition from NASA stands as a testament to Shuvon's talent, dedication, and the impact a passionate young mind can have in the field of cybersecurity.
Latest
458 words · 153 secSmall Boat Crossings Hit 2026 High as 781 Arrive in a Day
Small boat crossings to the UK reached a 2026 daily high on Wednesday, with 781 people arriving aboard 10 vessels, according to Home Office figures. Despite the surge, 18,565 crossings have been recorded so far this yea…
Read more→