UndecimoDia

UndecimoDia

Penetration Tester, Application Security Engineer, Independent Security Researcher

Find it. Prove it. Explain it well enough that it gets fixed.

I'm a penetration tester and application security engineer specializing in web, API, and mobile security. My work centers on white-box audits, static source code review, and findings that map directly to business impact.

I also do independent reverse engineering research on native binaries and Android applications, using Ghidra, Binary Ninja, GDB, and dnSpy.

I do independent vulnerability research across web and API security, plus native and Android reverse engineering. Advisories go public here the moment they clear disclosure, nothing on this page is invented to fill space.

CVE ID Component Severity Status
PENDING RESEARCH IN PROGRESS

Long-form write-ups on reverse engineering, low-level exploitation, and web/API security land here as I finish each one, most recent first.

COMING SOON

Certifications

  • Burp Suite Certified Practitioner PortSwigger
    Issued May 2025 · Valid until May 2031 Verify ↗

Training

  • Jr. Penetration Tester TryHackMe
    Issued May 2024 · Credential ID THM-9ICHYBC1JU Verify ↗