VASCO0X4
Penetration Tester · Security Researcher
Find it before they do.Web & API · LLM & Chatbot Security · Source-code Review
About.
I am a penetration tester and security researcher. For the past year I have worked as a pentester at a leading European security firm, running engagements across web applications, APIs and modern cloud and low-code stacks.
My research focuses on finding and responsibly disclosing real vulnerabilities — work that has led to several published CVEs in widely-used software, including a critical unauthenticated RCE. I also explore the security of LLMs and AI assistants, from prompt injection to agent abuse.
Current Focus:
- - Web & API penetration testing
- - LLM & chatbot security (prompt injection, data leakage, agent abuse)
- - Source-code & low-code review — the origin of my CVEs
- - Exploit development and responsible disclosure
Security Research.
Published vulnerabilities (CVE)
5 advisories · peak CVSS 10.0 · responsibly disclosed
Unauthenticated RCEAuthentication bypass in AuthenticationFilter leading to unauthenticated remote code execution.
Remote Code ExecutionRemote code execution via newline injection in the environment variable endpoint.
Path TraversalAuthenticated path traversal in the CSV import image field allows deletion of arbitrary server files.
Session HijackingInsecure HTTP transport permits session hijacking.
SSRFSSRF via the SMTP test endpoint enabling internal port scanning.
Expertise.
What I do
Web & API Pentesting
Black-box and authenticated testing of web apps and APIs.
LLM & Chatbot Security
Prompt injection, data leakage and agent abuse.
Source-code & Low-code Review
Code audits — the origin of my CVEs.
Projects.
What I build — open-source on GitHub
AIDA
Turn any LLM into an autonomous pentester. You define the scope, the agent does the work, you review the findings.
AI integrated into the Linux terminal.
Shellcode loader that bypasses most AV.
A library of shellcode loaders.
Process hollowing injector for Windows.
Alternative Myph loader for Havoc C2.
Cobalt Strike beacon notifier via Telegram.
In development — Neptun C2, a custom Rust C2 framework.
View all on GitHubCertifications.
Credentials & training
Blog.
Notes on web, API and LLM security — more coming soon.
Direct Syscalls: Bypassing EDR
SoonComing soon
Prompt Injection in Production RAG Applications
SoonComing soon
Contact.
Get in touch
Interested in collaborating on cybersecurity projects or need expertise in penetration testing and network security? Feel free to reach out.