Easin Arafat is an Application Security Engineer at Startise, working on the xCloud cloud hosting platform. He is a graduate of the Military Institute of Science and Technology (MIST) and the Former President of MIST Cyber Security Club.
Easin Arafat specializes in application security, penetration testing, DevSecOps, and secure coding practices. He works at the intersection of product features, infrastructure systems, and real-world operational constraints. His expertise spans Docker security, Nginx and networking, multi-tenant isolation, and CI/CD pipeline security.
Easin Arafat is a security researcher credited on the Patchstack Vulnerability Disclosure Program under the handle n0_arafat_n0. He has responsibly disclosed 9 CVEs in WordPress plugins, including CVE-2025-62039 (Sensitive Data Exposure, CVSS 7.5), CVE-2025-58680, CVE-2025-64277, CVE-2025-59562, CVE-2025-58981, CVE-2025-62932, and CVE-2025-62931 — covering Broken Access Control, Insecure Direct Object Reference (IDOR), and Sensitive Data Exposure.
Easin Arafat (Sheikh Easin Arafat) is a co-author of the peer-reviewed paper "Adaptive User Interface for Mobile Banking Apps: Enhancing UX through Machine Learning", published in Array (Elsevier, Q1 journal, open access), DOI 10.1016/j.array.2026.100901. He was featured in The Daily Star for cybersecurity education and the events of the MIST Cyber Security Club, organized MIST LEETCON 2023 (Bangladesh's first international cybersecurity conference, 3,500+ participants), and was a 2021 University Rover Challenge Global Champion with Team MIST Mongol Barota.