Back to Insights
Cybersecurity · NASA·28 ABR 2026·6 min read·NASA · Vulnerability Disclosure Policy

NASA Sent Me a Letter. This Is What Real Security Looks Like.

On April 28, 2026, I received formal recognition from NASA — signed by Kelvin Taylor, Senior Agency Information Security Officer — for identifying and responsibly reporting a vulnerability in systems of the American space agency.

NASA Sent Me a Letter. This Is What Real Security Looks Like.
Official recognition · NASA VDP · 04/28/2026

Letter signed by Kelvin Taylor, Senior Agency Information Security Officer (SAISO), NASA Office of Chief Information Officer (OCIO). Mary W. Jackson NASA Headquarters, Washington, DC 20546-0001.

Official NASA letter — recognition of Victor Fornitani (l1ghtn1ng) for responsible vulnerability discovery and reporting. Signed by Kelvin Taylor, SAISO, NASA OCIO. April 28, 2026.
Original letter. Mary W. Jackson NASA Headquarters, Washington, DC — 04/28/2026.

Most cybersecurity certifications are a piece of paper. An exam, a fee, a printed certificate. This is not. On April 28, 2026, I received formal correspondence from the National Aeronautics and Space Administration — signed by Kelvin Taylor, Senior Agency Information Security Officer (SAISO) at NASA OCIO — recognizing my work as an independent security researcher.

Your reporting has facilitated NASA's awareness of otherwise unknown vulnerabilities and helped us protect the integrity and availability of NASA information.

— Kelvin Taylor — Senior Agency Information Security Officer, NASA OCIO

What Happened

Operating under the handle l1ghtn1ng, I identified a vulnerability in NASA systems and followed the correct protocol: responsible reporting through the agency's Vulnerability Disclosure Policy (VDP). No exploitation. No premature public disclosure. The playbook of what a serious security researcher does.

The result: NASA formally acknowledged the discovery, fixed the vulnerability, and sent an official letter of appreciation. Not a digital badge. Not a website "hall of fame." Official U.S. government letterhead with a handwritten signature.

Why This Matters

Real cybersecurity is not about having the right certificate on the wall. It's about finding what others didn't, in systems others assumed were secure. NASA operates critical infrastructure — satellites, communications systems, mission data — with security standards that very few organizations in the world ever need to meet.

  • Vulnerability identification in U.S. federal government infrastructure
  • Responsible reporting following VDP — the most rigorous standard of coordinated disclosure
  • Formal recognition by the SAISO, NASA's highest information security officer
  • Zero exploitation, zero data exposure — researcher ethics, not attacker mindset

What This Says About Who Builds IronBit

IronBit — CSX Tech's cybersecurity vertical — is not run by someone who learned about security from online courses. It's run by someone who found vulnerabilities in systems NASA assumed were secure. There's a difference. A massive difference.

My security trajectory has passed through international commerce systems, high-criticality financial platforms, and U.S. government infrastructure. Each context with its own attack vectors, its own exposure surfaces. The common denominator: find it before the adversary does.

Real security — what separates research from compliance

01

What is the NASA Vulnerability Disclosure Policy (VDP)?

Clique para ver a resposta
01

A formal NASA program to receive vulnerability reports from independent researchers. It follows the most rigorous coordinated disclosure standards — the researcher reports privately, NASA fixes it, and both protect the ecosystem.

02

What's the difference between bug bounty and VDP?

Clique para ver a resposta
02

Bug bounty pays for vulnerabilities. VDP is about ethical duty — reporting even without financial reward, because the integrity of the infrastructure matters more than the check. NASA operates a VDP, not a bounty.

03

Why are government systems the hardest to compromise?

Clique para ver a resposta
03

Because they operate with multiple layers of defense, continuous monitoring, and teams dedicated exclusively to security. Finding a vulnerability there requires a technical level that most professionals never reach.

04

What does "l1ghtn1ng" mean as a researcher handle?

Clique para ver a resposta
04

It's the identifier under which Victor Fornitani operates as an independent security researcher — separate from his executive roles, but directly informing the technical depth he brings to IronBit and every ecosystem he architects.

The letter you can't earn with a certificate

Mary W. Jackson NASA Headquarters, Washington, DC. Kelvin Taylor, SAISO. April 28, 2026. This isn't on any standard résumé — because most people never had a reason for it to be.

We are all in this together as a security community and your participation and expertise is commended.

— NASA · Vulnerability Disclosure Policy — Official Letter, 04/28/2026
Victor Fornitani

Victor Fornitani

CPTO · CSX Tech