David Osipov
david-osipov.vision
David Osipov
@david-osipov.vision
AI & B2B SaaS Product Leader. Building secure enterprise software. Cybersecurity researcher, OpenStreetMap mapper & Wikipedian.
I've analyzed a critical design flaw in Cloudflare's Universal SSL: it actively nullifies IETF standard RFC 8657.

By overriding user-defined accounturi parameters with permissive CAA records, Cloudflare re-opens the exact vulnerability exploited in the 2023 jabber.ru MitM attack. 🧵
January 6, 2026 at 6:07 PM
I've tested your new model #GPT5 - it does a great job at uncovering vulnerabilities and patching them - good job, guys, from #openai
August 8, 2025 at 10:13 AM