Pentester / red teamer for private and government organizations. Also, I’m a bug bounty hunter and an all-infosec enthusiast.

You can find me on Twitter, GitHub, Intigriti, YesWeHack, and via email at vict0ni at protonmail dot com.

Research

Talks and on the media

CVEs and Vulnerabilities

Blog

Roundcube CVE-2024-42008 and CVE-2024-42010 PoC

On the hunt for data leaks: Elastic(search²)

Oracle Database remote “stealth password brute-force”

Bypassing the IPinfo API