M2HCZ // SECURITY RESEARCH + SOFTWARE ENGINEERING

Offensive security.
Secure engineering.

RESEARCHER / ENGINEER / LIVEOPS / CVE AUTHOR

I analyze software the way an attacker would and build it the way production demands. Vulnerability research, AppSec, secure backend engineering and large-scale systems — backed by reproducible evidence and more than a decade of implementation experience.

12+
Years of software engineering
02
Assigned CVE identifiers
1.5B+
Visits across shipped games
TRUSTED WALL · RESPONSIBLE DISCLOSURE

RESEARCH SUBMITTED TO OR ACKNOWLEDGED BY

Trust is earned
in real systems.

Public programs, responsible disclosure channels and validated security research.

01 / 10

External names identify the relevant program or affected ecosystem. They do not imply employment, endorsement, partnership or a commercial relationship.

INDEPENDENT SECURITY PRACTICE

A.S.I.A Security — Attack Surface Intelligence & Assurance

My independent practice for offensive security, AppSec, vulnerability research and security engineering. Presented separately from third-party acknowledgements.

Visit A.S.I.A ↗
01 — Profile

Engineering depth.
Adversarial perspective.

I am a senior software engineer and offensive security researcher working at the intersection of secure systems, application security and vulnerability research. My engineering background spans backend architecture, distributed systems, server-authoritative design, performance and abuse resistance.

That engineering experience directly informs my security work. I trace a flaw through architecture, code, authorization boundaries and operational behavior — then translate it into reproducible evidence, root cause and practical remediation.

Role
Senior Engineer · LiveOps · Offensive Security
Focus
AppSec · Research · Backend
Location
Brazil · Remote
Twitter / X
@inf0secc
Availability
Open to opportunities
02 — Capabilities

Security research,
backed by engineering.

01 / 03

Offensive Security & Research

Manual analysis, vulnerability research, controlled exploitation, reverse engineering and evidence-driven validation.

Vulnerability ResearchExploit DevelopmentReverse Engineering
02 / 03

Application & Product Security

Secure code review, threat modeling, authorization analysis, hardening and practical support for secure delivery.

Code ReviewThreat ModelingAuthorization
03 / 03

Secure Backend Engineering

Production-grade backend architecture, distributed systems, server-authoritative controls, performance and abuse resistance.

Distributed SystemsAnti-AbuseArchitecture
03 — Security Research

Public work.
Reproducible impact.

Selected disclosures with a clear distinction between assigned CVEs, accepted reports and independently published proof-of-concept research.

R-001
CVE-2026-54094

File Browser — Symlink Scope Bypass

Assigned CVEHigh · CVSS 7.5CWE-22 / CWE-59

A symlink-handling flaw allowed scoped users — and in some public-share scenarios unauthenticated recipients — to access files outside the enforced directory boundary.

R-002
CVE-2026-28740

Gitea — Git LFS Cross-Repository Authorization Bypass

Assigned CVEHigh · CVSS 7.1CWE-639 / CWE-863

An authorization flaw in Gitea's cross-repository Git LFS flow allowed a user with insufficient source-repository permissions to retrieve private LFS objects.

R-003
GH CLI

GitHub CLI — Symlink Path Traversal / Git Hook Injection

Accepted reportCWE-22 / CWE-59

A path-boundary issue in gh run download enabled writes outside the expected destination and could be used to plant an executable Git hook.

R-004
CVE-2025-6440

WooCommerce Designer Pro — Public PoC

Independent PoCCritical · CVSS 9.8CWE-434

Independent proof-of-concept research for an unauthenticated file-upload vulnerability leading to remote code execution.

D-01

Gemini CLI

Three reported vulnerabilities involving CI/CD and AI developer-tooling surfaces.

D-02

NASA VDP

Security research submitted through NASA's vulnerability disclosure process.

D-03

Tesla · xAI / X

Security issues reported through the appropriate program channels.

D-04

Automattic

Research involving Automattic and WordPress.com-related assets.

D-05

Discord · USP

Reports submitted through the corresponding disclosure channels.

D-06

Gov.br · Roblox

Additional authorized research and responsible reporting activity.

Disclosure note — External names indicate the relevant program or affected ecosystem; they do not imply employment, endorsement or commercial affiliation.
05 — Engineering

Built for
production.

More than a decade working with backend systems, production reliability, real-time networking, persistence, anti-abuse controls and live operations.

Languages

PythonTypeScriptRustGoCC#Lua / LuauSQL

Infrastructure

LinuxDockerKubernetesTerraformCloudflarePostgreSQLRedis

Security

Burp SuitemitmproxyFridaGhidraSemgrepNmapWireshark

Specializations

Backend ArchitectureDistributed SystemsServer-Authoritative DesignAnti-CheatVulnerability ResearchReverse Engineering
06 — Shipped Systems

Engineering at
player scale.

Selected Roblox titles, studios and communities where backend architecture, persistence, networking, game integrity and live operations were central concerns.

Current studio · Live operations
Spong

Senior LiveOps Developer responsible for production updates, game maintenance, systems optimization and the continued evolution of live Roblox experiences.

Senior LiveOps DeveloperCurrent rolespong.pro ↗
Current studio · Production engineering
Wendigo Studios

Programmer contributing production gameplay and backend systems with server-authoritative design and maintainable implementation.

ProgrammerCurrent role
Current studio · Software development
Chabungus LLC

Developer contributing robust software and game systems for production projects and scalable technical delivery.

DeveloperCurrent rolechabungus.com ↗
Current studio · Software engineering
Lost Creative

Software Engineer working on backend and gameplay-facing systems built for stability, clean integration and long-term maintenance.

Software EngineerCurrent role
Previous studio · Senior engineering
BlockTurns

Former Senior Software Engineer contributing production game development, backend systems and technical delivery within a large Roblox publishing ecosystem.

Former Senior Software EngineerPrevious roleView community ↗
Verified Roblox studio
PlayBox!

Verified studio behind Animatronic Nights. I contribute backend, gameplay-supporting systems, persistent state, server-authoritative mechanics and live content delivery.

Backend & systems developer2026 — PresentView community ↗
07 — Video Showcase

Selected work.
In motion.

A visual selection of gameplay, systems and production work. Players load only when requested, keeping the portfolio fast and focused.

09 selected recordings
VIDEO 01 / 09

Development Showcase 01

YouTube ↗
VIDEO 02 / 09

Development Showcase 02

YouTube ↗
VIDEO 03 / 09

Development Showcase 03

YouTube ↗
VIDEO 04 / 09

Development Showcase 04

YouTube ↗
VIDEO 05 / 09

Development Showcase 05

YouTube ↗
VIDEO 06 / 09

Development Showcase 06

YouTube ↗
VIDEO 07 / 09

Development Showcase 07

YouTube ↗
VIDEO 08 / 09

Development Showcase 08

YouTube ↗
VIDEO 09 / 09

Development Showcase 09

YouTube ↗
08 — Experience

Production experience.
Live products, real scale.

Current and previous studio roles across LiveOps, backend engineering, gameplay systems and production software development.

CURRENT APPOINTMENTS
CURRENT // 01LIVEOPS
Spong

Senior LiveOps Developer

Maintaining and evolving live Roblox games through production updates, system improvements, performance work, abuse prevention and reliable content delivery.

Live game updatesBackend systemsProduction maintenance
CURRENT // 02ENGINEERING
Wendigo Studios

Programmer

Building production gameplay and backend systems with an emphasis on maintainability, server authority and reliable delivery.

Gameplay systemsBackendLuau
CURRENT // 03DEVELOPMENT
Chabungus LLC

Developer

Contributing software and game systems for production projects, with a focus on robust implementation and scalable architecture.

Software systemsArchitectureProduction
CURRENT // 04SOFTWARE
Lost Creative

Software Engineer

Engineering backend and gameplay-facing systems designed for clean integration, stability and long-term maintainability.

Backend engineeringSystemsScalability
FULL PROFESSIONAL PROFILELinkedIn
View LinkedIn
Independent practice
A.S.I.A

Security without
theater.

A.S.I.A Security — Attack Surface Intelligence & Assurance — is my independent practice for offensive security, AppSec, vulnerability research and security engineering. It translates research depth into scoped assessments, reproducible evidence and practical remediation.

Web & API PentestAppSecSecure Code ReviewThreat ModelingRemediation
Collaborative venture
wnk.sh

Built together,
clearly separated.

wnk.sh is a collaborative project developed with a partner. It is intentionally presented separately from my solo security research, A.S.I.A practice and engineering work.

09 — Contact

Serious systems.
Serious security.

Available for senior software engineering, offensive security, application security and focused research engagements.

CLIENT-SIDE DIAGNOSTICSSTATUS // ONLINE
viewport
loading
platform
loading
timezone
loading
language
loading
cores
loading
memory
loading
pixel ratio
loading
connection
loading