The Operator’s Perspective
Jacob Krut
Security Engineer
A self-taught security engineer who started in bug bounty by turning a blind SSRF in Yahoo Mail into remote code execution. The same instinct later found a high-severity SSRF in ChatGPT.
- Bug bounty
- Application security
- AI security
- Cloud exposure

Introduction
Jacob Krut is a self-taught security engineer at Open Security. He started in bug bounty by escalating a blind SSRF in Yahoo Mail to remote code execution, a $15,000 finding he documented in Just Gopher It. He has responsibly disclosed more than 100 vulnerabilities to programs including AT&T, Goldman Sachs, DOD, and Yahoo, and holds over 1,000 reputation on HackerOne. In 2025 he disclosed a high-severity SSRF in ChatGPT Custom GPT Actions that reached Azure instance metadata, work covered by SecurityWeek, SC Media, and others.
“He wasn’t on a bug hunt. He was exploring how the feature worked. Curiosity turned into instinct, and instinct turned into discovery.”
Expertise
Where Jacob leads.
Bug bounty
Self-taught hunter who has responsibly disclosed more than 100 vulnerabilities to programs including AT&T, Goldman Sachs, DOD, and Yahoo.
Over 1,000 reputation on HackerOne
Application security
Looks for the validation gap that turns a convenience feature into server-side request forgery, then follows it to code execution or cloud metadata.
Yahoo Mail blind SSRF to RCE ($15,000, reported 2020)
Application testingAI security
Tests the seams where generative-AI products call the rest of the world. Actions, tools, and the cloud identities behind them.
Disclosed high-severity SSRF in ChatGPT Custom GPT Actions (2025)
Cloud exposure
Follows a finding to the identity and metadata services that make a web bug into an infrastructure problem. Azure IMDS, AWS metadata, localhost services.
Experience & background
How the authority was earned.
Jacob is self-taught. He came up through bug bounty, starting with the Yahoo Mail RCE, then kept chaining SSRF into cloud metadata and, later, AI product surfaces.
At Open Security he is on the assessment team. The same curiosity that produced those writeups is what clients hire when they want APIs and new product features tested like an adversary would.
Credentials
- Self-taught security engineer
- Security engineer, Open Security
- Over 1,000 reputation on HackerOne
- 100+ responsible disclosures (AT&T, Goldman Sachs, DOD, Yahoo, and others)
- Responsible disclosure via OpenAI / Bugcrowd (2025)
- Responsible disclosures
- 100+
- HackerOne reputation
- 1,000+
Responsible disclosures
HackerOne reputation
2025
ChatGPT Custom GPT Actions SSRF
OpenAI / Bugcrowd
High-severity SSRF that reached Azure instance metadata. Covered by SecurityWeek and SC Media.
2022
LarkSuite AWS metadata SSRF
Medium writeup
Bypassed SSRF protections with DNS rebinding and read AWS EC2 instance credentials.
2020
Yahoo Mail blind SSRF to RCE
Yahoo / The Paranoids
Escalated a logo-grabber SSRF through gopher and localhost Redis to a reverse shell. $15,000 bounty. Writeup published May 2021.
Featured media
Watch, listen, or read first.

Research
Just Gopher It: Escalating a Blind SSRF to RCE for $15k (Yahoo Mail)
The writeup that started his bug-bounty path. A Yahoo Mail logo-grabber became a blind SSRF, then a gopher-over-redirect bypass, then a Redis reverse shell on localhost. $15,000 from The Paranoids. Discovered in May 2020.
Medium · May 17, 2021
Read the writeup (opens in a new tab, Medium)Content library
Talks, writing, and teaching.
Research
Just Gopher It: Escalating a Blind SSRF to RCE for $15k (Yahoo Mail)
The writeup that started his bug-bounty path. Blind SSRF in Yahoo Mail, escalated to root RCE via gopher and Redis. $15,000 bounty.
Medium · May 17, 2021
Read the writeup on Medium (opens in a new tab)Research
Bypassing SSRF Protection to Exfiltrate AWS Metadata from LarkSuite
Full-read SSRF through a Confluence import path, then DNS rebinding to pull AWS EC2 instance credentials.
Medium · January 28, 2022
Read the writeup on Medium (opens in a new tab)Research
When GPTs Call Home: Exploiting SSRF in ChatGPT’s Custom Actions
Jacob’s own writeup of the Custom GPT Actions SSRF: HTTPS-to-IMDS redirect, a Metadata header injected as an API key, and a high-severity rating from OpenAI.
Medium · November 10, 2025
Read the writeup on Medium (opens in a new tab)Article
ChatGPT vulnerability exposed underlying cloud infrastructure
Independent coverage of the Custom GPT Actions SSRF and its path to Azure metadata.
SecurityWeek · November 2025
Read article on SecurityWeek (opens in a new tab)Article
How our engineer found a vulnerability in the ChatGPT API
Open Security’s account of the finding: curiosity, confirmation, and what it says about how the team tests.
Open Security · November 2025
Read articleArticle
ChatGPT cloud infrastructure threatened by newly patched bug
SC Media brief on the disclosure and OpenAI’s patch.
SC Media · November 2025
Read brief on SC Media (opens in a new tab)Related experts
Keep reading the practice.

Josh Christman
Chief Operating Officer
COO who runs security engineering and the applied AI behind Aludra. Tests stay scoped to business risk. Findings stay ones an engineer will stand behind.
View profile →
Bryce Zuccaro
Principal Security Engineer
Principal Security Engineer who plans engagements, mentors operators, and teaches the craft — SANS SEC460, Red Team Village, and the Las Vegas AI Security Forum.
View profile →
Matt Toussain
Founder & Chief Information Officer
Offensive security operator, SANS instructor, and the founder behind Sirius — turning real attack experience into the methodology and tools other operators use.
View profile →Want this kind of testing on your applications?
Jacob treats every new feature as an attack surface, then proves what is actually possible. That is the standard Open Security applies to client work.
