Chaining Vulnerabilities in LLM APIs
A walkthrough of chaining multiple vulnerabilities found in LLM API endpoints — prompt injection, data exfiltration, and privilege escalation via model manipulation.
Hi, my name is Emmanuel.
I'm a Cybersecurity Specialist grinding Hack The Box, hunting threats, and building security tools. HTB Rank: Hacker.
Cybersecurity Enthusiast
📍 Philippines
A passionate cybersecurity professional diving deep into ethical hacking, threat analysis, and digital forensics. Currently grinding on Hack The Box, sharpening offensive and defensive skills one machine at a time.
My mission: protect, detect, and respond — turning vulnerabilities into lessons and threats into defenses.
Joined my first inter-school coding competition. Competing under pressure, solving algorithmic problems on the fly — this was the spark that ignited everything.
Competed in hackathons and a mobile app development competition. Built real apps under tight deadlines — learning to ship fast and collaborate under pressure.
Developed and defended a capstone research project. Applied technical skills in a real academic context, collaborating with BFP and institutions.
Built and launched real-world startup apps — TraysiTek and HatidGo. Designed, developed, and shipped products from scratch.
Joined Hack The Box, earned certs, and went deep into pentesting, web security, and DFIR. Still hacking. Always learning.
— Websites
Website for a therapy center with 23 branches across Luzon, offering behavioral therapy, speech & language, occupational therapy, and special education programs for children.
Official website for a Filipino burger franchise with 50+ locations across Luzon. Features the full menu, franchise info, and store locations across Nueva Ecija, Manila, and beyond.
— Mobile Apps
Tricycle booking and transport app connecting riders and drivers in Nueva Ecija. Built to modernize local transport with real-time tracking and cashless booking.
On-demand delivery and logistics app by Nueva Technologies. Connects users with couriers for fast, reliable package and food delivery across the region.
Home services marketplace app by Nueva Technologies. Lets users book trusted local service providers — plumbers, electricians, cleaners, and more — in just a few taps.
A walkthrough of chaining multiple vulnerabilities found in LLM API endpoints — prompt injection, data exfiltration, and privilege escalation via model manipulation.
Lab walkthrough demonstrating how excessive agency in LLM-integrated systems can be exploited to perform unauthorized actions beyond the intended scope.
A deep dive into tools and techniques used to track mobile devices — exploring the technical mechanics, ethical considerations, and defensive countermeasures.
My personal roadmap to building real cybersecurity skills — the 6 platforms I used to go from zero to Hacker rank on HTB and land my first certs.