Mert Sunar
Cyber Security Specialist
Cyber security specialist focused on engineering resilient defense, penetration testing, DevSecOps, and securing modern AI-powered systems.
High-Assurance Security & Autonomous Defense
Mert Sunar
CYBER SECURITY SPECIALIST
Engineering resilient enterprise architectures, leading adversary simulations (OWASP Top 10 & API pentests), and designing automated firewalls against AI Prompt Injection and agent hijacking attacks.
TÜBİTAK • ASELSAN • ROKETSAN
Practical field experience with TEMPEST emission standards, high-reliability embedded hardware, and unclassified encrypted communication protocols.
Flagship Security Engineering Projects
AI Cyber Security Agent
Autonomous AI security agent performing automated vulnerability discovery, OWASP assessment, and risk modeling across enterprise web and network environments.
3D Cyber Risk Map & Threat Visualizer
Three-dimensional topological risk visualization of enterprise infrastructure, microservices, API endpoints, and live attack vectors.
Autonomous Pentest Agent
Autonomous offensive security agent performing reconnaissance, service fingerprinting, vulnerability verification, and risk prioritization.
Hands-On Security Lab Write-Ups
Zero Trust eBPF Kernel Observability & Hardening Lab
Detect evasive rootkits, in-memory execution, and unauthorized kernel syscalls using real-time eBPF runtime observability.
Modern REST API Broken Object Level Authorization (BOLA/IDOR) Analysis
Identify authorization flaws and IDOR vulnerabilities in financial API endpoints and implement zero-trust attribute-based access control (ABAC).
CVEs & Disclosures
AI Agent Tool-Call Hijacking Vulnerability Advisory
Comprehensive analysis of parameter manipulation and unauthorized state changes in autonomous LLM agent tool-call execution pipelines.
OAuth2 State Desynchronization & Login CSRF Advisory
Analysis of session hijacking vectors stemming from mishandled OAuth2 PKCE state parameters in single-page applications.
Technical Articles & Insights
Mitigating Prompt Injection Risks in Enterprise LLM Deployments
Deep-dive into Direct and Indirect Prompt Injection mechanics, token boundary bypasses, and enterprise defense-in-depth patterns.
How Artificial Intelligence is Reshaping Cyber Security
The asymmetric evolution of offensive and defensive AI capabilities, autonomous security agents, and the emerging architecture of cyber defense.
OWASP Top 10 for Modern Web Application Architecture
Practical exploitation vectors and hardened defense patterns for OWASP Top 10 in modern microservices and API ecosystems.
Let's Build Resilient Systems
Available for high-impact cyber security engineering leadership, specialized penetration testing, AI security architecture review, and defense systems advisory.