Security researcher with over a decade of experience in network&application&cloud security. Speaker at BlackHat, HITB, CanSecWest and TyphoonCon.

Joined February 2016
289 Photos and videos
Pinned Tweet
May 28
Amazing vibe! Really impressive experience !
🌪️ Now on stage @pyn3rd revealing the hidden attack surface ClickHouse
2
15
3,296
Jun 12
#CVE-2026-48907 Unauthenticated RCE in #Joomla Content Editor Extension
1
54
376
20,264
Jun 10
#CVE-2026-8054: #dotCMS Core SQL Injection Based on internet-wide exposure data in Shadon, many organizations appear to be running #dotCMS instances. Users are strongly encouraged to upgrade and patch affected systems immediately.
3
20
125
10,015
Jun 2
I know that for sure. However, even when a Content-Length header is present, inconsistencies in the Content-Type header can still create problems. Some WAFs, such as F5 BIG-IP, may treat such requests as protocol non-compliant and refuse to forward them to the upstream application. The concern is that with this type of “chaotic” request, forwarding it can introduce security risks regardless of whether the WAF chooses the first or the second interpretation. For example, if the WAF parses and validates the request as application/x-www-form-urlencoded while the upstream application interprets it as application/json, discrepancies in request processing may arise, potentially leading to security issues. The reverse scenario is equally problematic.
Replying to @pyn3rd
That's correct but it's missing the content length because the focus of the post was the duplicate headers. It's not meant to be used verbatim.
2
1
27
6,399
Jun 2
Regarding the ApacheMQ vulnerabilities we reported, one was dismissed as not a security issue because its root cause lies in Xstream, which now whitelists only java.lang.String for deserialization. This post strongly warns you about configuring systems in untrusted environments.
Replying to @pyn3rd
Apache ActiveMQ is having a rough month. Two more CVEs. ⚠️ CVE-2026-42253 - HTTP Response Header Injection via JMS Message Properties ⚠️ CVE-2026-42588 - RCE via Jolokia addNetworkConnector The Jolokia one is the scary one - default access policy permits exec operations on all ActiveMQ MBeans. Fix: upgrade to 5.19.7 or 6.2.6. VulnTracker.io
2
2
19
4,311
Jun 1
#CVE-2026-42253 Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties #CVE-2026-42588 Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector These two vulnerabilities we reported have been credited.
1
2
28
2,503
May 30
This kind of abnormal HTTP request is related to protocol compliance with the RFC specifications. For example, Akamai WAF even rejects POST requests that do not include a Content-Length header.
POST /api/update HTTP/1.1 Host: target.com Content-Type: application/x-www-form-urlencoded Content-Type: application/json {"test": true}
2
1
17
5,762
May 29
If you have any Log4Shell obfuscated variants for WAF bypass, please let me know — my detection approach can normalize and reconstruct all of them😆 x.com/pyn3rd/status/19994534…

Hey bug bounty hunters 👋Apache log4j is not dead. Before you skip Apache log4j targets in 2026 — read this : pingback.sh/article-log4j-20… We documented exactly where, how, and how to report it clean.Drop everything and read: #BugBounty #Log4Shell #BugBountyTips
1
6
64
10,127
pyn3rd retweeted
🌪️ Now on stage @pyn3rd revealing the hidden attack surface ClickHouse
2
3
14
10,031
May 27
Just arrived in Seoul for @typhooncon! Not only is this my first time attending the conference, but it’s also my first time in Korea. Really loving the vibe already! 🇰🇷
3
38
3,221
May 26
More than a year ago, I shared a sneaky type of backdoor that steals SSH passwords and exfiltrates them through DNS TXT records.Looks like my tweets have been on a #SupplyChain poisoner’s radar ever since. 😅 x.com/pyn3rd/status/18548791…
Security researchers have exposed a malicious Go module backdoor hidden inside the shopsprint/decimal package that executes code using stealthy DNS TXT records. #SupplyChainAttack #GoLang #CybersecurityNews #AppSec #Malware securityonline.info/maliciou…
1
2
12
4,094