About
Andrei Dodu
Security researcher & systems engineer · Sweden
I'm a security researcher and systems engineer in Sweden. I find and disclose vulnerabilities in web applications, and I build Hugin — an intercepting proxy and vulnerability scanner in a single Rust binary, local-first and built to leave no trace.
Most of my work lives at the intersection of two things: breaking web apps, and building the tooling to break them faster. Bug-bounty research keeps the methodology sharp; building Hugin keeps me honest about what tooling actually helps. The two feed each other.
For something concrete: I reported CVE-2026-28840, a local privilege-escalation flaw in macOS PackageKit that let an unprivileged app gain root (CVSS 7.8). Apple fixed it in macOS Tahoe 26.4.
On the engineering side I work primarily in Rust — for tooling and systems it's where I think software is heading, and it's what I build my own tools in. React is the exception, not the rule: I reach for it on a product like Redofy, not on my tooling. I care about fast, correct software — this site runs on a strict performance budget for the same reason.
Ethics & authorization
All offensive work I do is authorized and ethical: testing within agreed scope, responsible disclosure, and bug-bounty work inside program rules. No grey areas. It's the right way to work, and it's the only way enterprises should buy security testing.