Skip to content

SECURITY RESEARCHER // SWEDEN

I break things before they do.

live · andrei.sh

Work with me

Book a security engagement

Authorized audits and pentests for Rust and web codebases. Scoped, ethical, with a real report.

Book a call

Flagship project

Hugin Built

2.7 million lines of Rust, sixty-nine crates, one native binary. An enterprise-grade offensive stack.

A proxy, scanner, intruder, request-smuggling and race engine, an out-of-band detection server on eleven protocols, and a 169-tool AI layer that writes its own exploits — all mine, written from scratch in Rust, in one binary on your machine. No account, no telemetry. Community is free. Pro is a flat €7/month.

Hugin desktop app — the HTTP History view, intercepting and listing captured requests

2.7M LOC · one binary

OOB server on 11 protocols

169 AI-native MCP tools

Community free · Pro €7/mo

Findings

all findings →

Vulnerabilities I find and disclose responsibly — CVEs, advisories, bug-bounty work.

high CVE-2026-28840 CVSS 7.8 Apple

Local privilege escalation to root in macOS PackageKit

Impact An app could gain root privileges — full local compromise of the machine (read/modify any data, persist, disable protections).

Writing

all writing →

Writeups on the bugs above, and articles on tooling, Rust, and method.