Skip to content
Andrei Dodu — security researcher

About

Andrei Dodu

Security researcher & systems engineer · Sweden

I'm a security researcher and systems engineer in Sweden. I find and disclose vulnerabilities in web applications, and I build Hugin — an intercepting proxy and vulnerability scanner in a single Rust binary, local-first and built to leave no trace.

Most of my work lives at the intersection of two things: breaking web apps, and building the tooling to break them faster. Bug-bounty research keeps the methodology sharp; building Hugin keeps me honest about what tooling actually helps. The two feed each other.

For something concrete: I reported CVE-2026-28840, a local privilege-escalation flaw in macOS PackageKit that let an unprivileged app gain root (CVSS 7.8). Apple fixed it in macOS Tahoe 26.4.

On the engineering side I work primarily in Rust — for tooling and systems it's where I think software is heading, and it's what I build my own tools in. React is the exception, not the rule: I reach for it on a product like Redofy, not on my tooling. I care about fast, correct software — this site runs on a strict performance budget for the same reason.

Ethics & authorization

All offensive work I do is authorized and ethical: testing within agreed scope, responsible disclosure, and bug-bounty work inside program rules. No grey areas. It's the right way to work, and it's the only way enterprises should buy security testing.

Toolkit

#rust#web-exploitation#vulnerability-research#http-request-smuggling#race-conditions#bug-bounty-methodology#react-typescript#systems-engineering