Independent offensive security research across AI, applications, mobile, cloud and network — high-signal vulnerabilities, reproducible proof, and reports engineering can ship against by Monday.
dexter0us — an independent offensive security researcher and bug-bounty hunter who works the deep end of the target: language-model agents, core banking APIs, the surfaces most testers write off as too hard. Every engagement lands on a working exploit and a report that turns the fix into a foregone conclusion — never a reflected string or a maybe.
No scanner doing the thinking. No low-severity padding. Only the bugs that move real money, data, or trust — surfaced before an adversary charges for the lesson.
Every model wired to a tool or an API is a fresh pair of hands on the system — and most trust their input far too much. Engagements chase the whole chain: prompt injection that survives a summariser, agents talked into SSRF and command execution, guardrails walked straight past, and sandboxes that quietly hand over the keys to everything downstream.
The classics still take down the giants. Access control gets dismantled until one tenant reads another's data, server-side requests get bent into the internal network, and business logic gets pushed into states it was never meant to reach — then the same thread runs through iOS and Android, down to the secrets in local storage and the quiet API behind the app.
Breaches rarely start at the front door. Recon maps the entire perimeter — the staging box someone forgot, the wildcard cert, the token committed in the clear — and treats every acquisition, SaaS bolt-on, and build dependency as another way in. One goal: see the estate exactly as an attacker would, and get there first.
High- and Critical-severity findings, accepted and resolved on HackerOne — weighted for signal and impact, never padded with noise. The count is on the public record; the thinking behind the sharpest ones lives on the blog.
Sitting on a target that keeps you up at night? Open for security engagements, private bug-bounty invitations, and advisory work — reach out and let's scope it. PGP available on request.