Vienna, Austria · Working with teams worldwide

Hi, I'm Aria.
I break software so it holds.

Security researcher and software developer. I find vulnerabilities others miss, publish them responsibly, and build the kind of web infrastructure that survives contact with the real world.

28coordinated disclosures (2026)
14MyBB advisories — Sept 2026 batch
2active ventures founded
PHP/C/C++/Rust/TypeScript/JavaScript/Python/Ruby/Perl/C#/Java/

What I do

Four things, done properly

No checklists theater. Each of these is a discipline I've practiced for years — and can prove.

Security research & disclosure

Vulnerability discovery in third-party products — from SSRF and authz gaps to full privilege-escalation chains — published through coordinated disclosure.

WordPressMyBBPHP ecosystems

Secure web development

Web applications designed and built with security as a constraint from day one — threat-modeled, hardened, and maintainable by ordinary humans.

Threat modelingArchitectureHardening
PHP 8.xTypeScriptJavaScriptPythonCC++RustRubyPerlC#Java

Reverse engineering, deobfuscation & SAST

Analysis of obfuscated and protected code — bytecode-level investigation and source recovery — plus building static analysis (SAST) tooling that understands programs instead of guessing at patterns.

SAST developmentDeobfuscationPHP bytecodeC · C++ · Rust11 languages

Hosting & infrastructure

Running and hardening servers for real workloads — nginx, PHP-FPM, MySQL/MariaDB, mail, TLS — with backups that actually restore.

LinuxnginxMySQL

Ventures

Selected work

Haikhavan Security

Founder. Security tooling company in formation — static and dynamic analysis with signed, reproducible evidence, built for real audits. Publisher of the HKV advisory series.

Current

haikhavan.com ↗

VPSrv Premium Hosting

Founder. European hosting and VPS provider — the infrastructure backbone behind this site and a number of long-running projects.

Active

vpsrv.com ↗

Websec GesmbH

Founder. Full-service web development and security company in Vienna — dissolved by choice. Its best ideas live on in everything above.

Closed

Research

Advisories & publications

28 coordinated disclosures in 2026 alone, plus ongoing tracking of the ecosystems I depend on — including the MyBB September 2026 advisory batch.

HighWordPress

Cloud-account compromise via pingback SSRF & DNS rebinding

Unauthenticated XML-RPC pingback combined with incomplete IP-range checks and a DNS TOCTOU gap — cloud metadata exposure on real deployments. HKV-ADV-2026-025.

Read advisory ↗

HighWordPress

Unauthenticated admin takeover chain

Username disclosure plus unbounded XML-RPC multicall forms a low-noise password-guessing channel against privileged accounts. HKV-ADV-2026-026.

Read advisory ↗

LowMyBB

MyBB September 2026 batch

Fourteen coordinated advisories from the MyBB security team — authorization gaps across moderation surfaces and admin XSS. Tracked and summarized on my research page.

See the breakdown

All research & advisories

About

Vienna-based, evidence-driven

I've spent my career on both sides of the fence: building web platforms and hosting infrastructure, then turning around and attacking them — mine and other people's — to find out what actually breaks.

After years of running a company (Websec GesmbH, now dissolved), I work independently and put my findings where they belong: in public, responsibly, with enough detail for defenders to act.

More about me →

Have something worth breaking?

Security reviews, research collaboration, or a project that needs to be built right.

Start a conversation