a hacker at heart, a builder by practice, and a mentor by purpose. As co-founder of PRODAFT, I’ve spent the last two decades in vulnerability research and security product engineering.
Latests Blog Posts
-
Part 2/6 | Breaking the Postgres Superuser Guardrails: Attacking Security-Hardening Extensions |Systemic Risks in the Managed PostgreSQL Industry
It’s been a month since I published the first part of this research, and interest from the Postgres community has…
-
Part 1/6 | Systemic Risks in the Managed PostgreSQL Industry: Extension Risks Are Real! Exploiting PostGis Memory Corruption Bug at NeonDB, SupaBase and Many More
Back in April, I was talking with our system and software engineering teams at PRODAFT about the possibilities of using…
-
The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance
It was May 2024, and our internal security team was evaluating the LogPoint SIEM/SOAR platform to replace our existing platform,…
Disclosed Vulnerabilities
I’ve been in the vulnerability research field since 2004. Over the years, I’ve discovered and responsibly disclosed more than 300 vulnerabilities across a wide range of products and vendors. At this point, it’s almost impossible to keep track of all the CVE numbers I’ve accumulated — but I keep a personal index here.
Latest disclosed CVEs:
PostgreSQL Core
CVE-2026-14678 | BITVECP Out of Bound Read
memory corruption
TimescaleDB
CVE-2026-70634 | Out-of-Bounds Read Information Disclosure via Reverse Iterator
Memory Corruption
TimescaleDB
CVE-2026-70633 | Out-of-Bounds Read DoS via Gorilla Compression Reverse Iterator
DoS
TimescaleDB
CVE-2026-70635 | Out-of-Bounds Read DoS via Bulk Dictionary Decompression
DoS
DuckDB
CVE-2026-58139 | Security Policy Bypass via load_aws_credentials Procedure
authorization bypass
Experience

PRODAFT
◌
Chief Technology Officer
Jan 2021 – Present
◌
VP, Threat Intelligence Products & Engineering
Jan 2018 – Jan 2021 · 3 yrs
◌
Head of Offensive Security
Jan 2016 – Jan 2018 · 2 yrs
◌
Principal Security Engineer & Platform Architect (Threat Intelligence)
Jan 2013 – Jan 2015 · 2 yrs
◌
Lead Vulnerability Researcher & Security Software Engineer
Jan 2012 – Jan 2015 · 3 yrs
◌
Co-Founder of PRODAFT
Jan 2012 – Present

SONY
◌
Senior Vulnerability Researcher
Jan 2015 – Jan 2016

Private Security Consultant
◌
Linux and System Security Consultant
Jan 2010 – Jan 2012 · 3 yrs

Independent Vulnerability Researcher
◌
Discovered more than 300 vulnerabilities across a wide range of products and vendors.
Jan 2008 – Present
Talks
- TEDx | The Risk Brought by the Digital World: Cyber Attacks
- TEDx | You Pressed Enter, Now You Can Sleep
- Github | Best way to RCE: Command Injection
- DEFCON AppSec Village | A Heaven for Hackers: Breaking Web Security
- NahamCon | A Heaven for Hackers: Breaking Web Security Virtual Appliance
- Hacktivity Breaking Log & SIEM Products



