We breakassumptions
Independent offensive
security practice
Romania, est. 2021
Manual penetration testing of web applications, APIs and the infrastructure behind them. No scanner output pasted into a template, no junior handoff.
Track record
Public and verifiableRanked #5 globally in 2024
Top 20 on the all-time leaderboard. Reporting since April 2020, across twelve Live Hacking Events and in-person security challenges.
1,300+ accepted reports, 500+ organizations
Triaged and accepted as valid by the programs they were reported to, through HackerOne, Bugcrowd, Intigriti and YesWeHack.
PortSwigger Top 10, 2021
Our research ranked sixth in the Top 10 Web Hacking Techniques of 2021, a list voted on by the security community.
HackerOne Hacker-Powered Security Report 2024
Featured as a security researcher specializing in financial services organizations. Read the excerpt.
AWS security
Cloud work centres on AWS, with six in-person live hacking events behind it.
NVIDIA Product Security
Recognised for contributions toward improving the security of NVIDIA products.
What programs say
Left on HackerOneyoustin has great communication and gracious professionalism. We are very happy to have them in our program!
A financial services program
Very nice report, in-depth knowledge and Prompt communication!
Exodus
We always have great interactions with them. Appreciate the quick replies.
An e-commerce platform
Impactful proof of concept code
An enterprise SaaS vendor
Research
All write-ups →Context-Aware Content Discovery with Chameleon
An open-source content discovery tool that fingerprints the technology stack of a target and automatically selects calibrated wordlists.
Cache Poisoning at Scale
Identifying and exploiting over 70 cache poisoning vulnerabilities across major bug bounty programs, including GitHub, GitLab, Shopify and HackerOne.
Bypassing 2FA using OpenID Misconfiguration
A two factor authentication bypass caused by an over-permissive AMR configuration in an OpenID identity provider, reported as High severity.
Est. December 2021
J23/7623/2021
Find out first.
Tell us what you built and what worries you. You get a scope, a fixed price and a start date.
iustin@youst.in →