@pyn3rd

I’m pyn3rd.

Melbourne, Victoria
Joined February 2016
#WAF Bypassing #AWS #CloudFront & #ALB WAF: Exploring the attack surface of a dual-layer web protection architecture. The first layer: a malicious XSS payload was blocked by CloudFront’s global WAF. By altering the XSS event-handler tag, I was able to bypass the first layer. The second layer: the request was then blocked by the regional WAF associated with the ALB. By exploiting normalization differences, I was able to bypass the second layer as well. The result: the XSS payload reached the origin and ultimately executed in the browser.
2
3
54
4,815
In the Tomcat August security bulletin, 6 CVEs were independently discovered and reported by our team (@4ra1n_x and unam4). Official severity ratings: 2 Important and 4 Low. If HackerOne’s Internet Bug Bounty hadn’t been suspended, we probably could’ve earned at least a few thousand bucks in bounties.
2
2
25
3,293
Apparently, I’m not done hunting JDBC vulnerabilities in IBM products. It started with my first report years ago. Found another one this year, bringing the total to 4 vulnerabilities reported to IBM, together with @4ra1n_x and unam4. The rabbit hole goes deeper.🐰 Make JDBC Attacks Great Again!🔥 ibm.com/support/pages/node/7… ibm.com/support/pages/node/7…
4
2
41
4,041
The author of the Fastjson project sent me a commemorative T-shirt as a token of appreciation for my vulnerability report.
3
61
4,743
Teamed up with my AI assistant and discovered a new Command Injection vulnerability in MariaDB. Another CVE added to the collection. Let’s go!🚀🚀🚀
1
44
2,966
Yet another real-world JDBC attack case. Back in my Black Hat talk, I pointed out that in cloud environments, attacks can originate from a tenant and reach the control plane, or even enable lateral movement across tenants—especially when container or VM isolation is not properly enforced. At the time, very few people seemed to understand what I meant, and most dismissed the risk. It’s interesting to see these scenarios continue to emerge in the real world.
This quoted post is unavailable.
44
6,322
#CVE-2026-28496: SSTI in #FOSSBilling Twig templates may escalate to SQLi or even RCE when FILE privileges are enabled.
2
22
174
12,709
AI-assisted discovery of a new MySQL vulnerability. Another CVE credit added to the list🚀🚀🚀@4ra1n_x
1
30
3,108
AI replacing Security Researchers?
28%It’s inevitable
35%Not a chance
38%Too early to tell
40 votes • Final results
1
4
3,012
#CVE-2026-53435: #Jenkins Unsafe XStream Deserialization Leads to Arbitrary File Read (low-privileged authenticated user)
7
49
1
328
19,130
#CVE-2026-48907 Unauthenticated RCE in #Joomla Content Editor Extension
3
61
1
385
23,467