SECURITY RESEARCHER // SWEDEN
I break things before they do.
Work with me
Book a security engagement
Authorized audits and pentests for Rust and web codebases. Scoped, ethical, with a real report.
Book a callFlagship project
2.7 million lines of Rust, sixty-nine crates, one native binary. An enterprise-grade offensive stack.
A proxy, scanner, intruder, request-smuggling and race engine, an out-of-band detection server on eleven protocols, and a 169-tool AI layer that writes its own exploits — all mine, written from scratch in Rust, in one binary on your machine. No account, no telemetry. Community is free. Pro is a flat €7/month.
2.7M LOC · one binary
OOB server on 11 protocols
169 AI-native MCP tools
Community free · Pro €7/mo
Findings
all findings →Vulnerabilities I find and disclose responsibly — CVEs, advisories, bug-bounty work.
Local privilege escalation to root in macOS PackageKit
Impact An app could gain root privileges — full local compromise of the machine (read/modify any data, persist, disable protections).
Writing
all writing →Writeups on the bugs above, and articles on tooling, Rust, and method.
Enterprise-grade, from scratch
2.7 million lines of Rust, sixty-nine crates, one binary, an OOB server we own, and an AI that writes its own exploits. Almost a year of building Hugin to a bar that is not easily achievable.
This is the endgame for Anthropic
Anthropic has been covertly watermarking your Claude Code system prompt based on your timezone and proxy settings. I verified it in my own binary, version 2.1.190. Here is exactly what the code does.
Open source is the exit
The US government can switch off a frontier model overnight. China is giving away models that are just as good. The closed-AI giants are in deeper trouble than they admit — and funding them is a bad bet.
JavaScript is the past
JavaScript won the browser, but the next edge in security tooling belongs closer to the machine: native binaries, memory-safe systems code, and tools that can keep up with the protocols.