Security research & disclosure
Vulnerability discovery in third-party products — from SSRF and authz gaps to full privilege-escalation chains — published through coordinated disclosure.
Vienna, Austria · Working with teams worldwide
Security researcher and software developer. I find vulnerabilities others miss, publish them responsibly, and build the kind of web infrastructure that survives contact with the real world.
What I do
No checklists theater. Each of these is a discipline I've practiced for years — and can prove.
Vulnerability discovery in third-party products — from SSRF and authz gaps to full privilege-escalation chains — published through coordinated disclosure.
Web applications designed and built with security as a constraint from day one — threat-modeled, hardened, and maintainable by ordinary humans.
Analysis of obfuscated and protected code — bytecode-level investigation and source recovery — plus building static analysis (SAST) tooling that understands programs instead of guessing at patterns.
Running and hardening servers for real workloads — nginx, PHP-FPM, MySQL/MariaDB, mail, TLS — with backups that actually restore.
Ventures
Founder. Security tooling company in formation — static and dynamic analysis with signed, reproducible evidence, built for real audits. Publisher of the HKV advisory series.
Founder. European hosting and VPS provider — the infrastructure backbone behind this site and a number of long-running projects.
Founder. Full-service web development and security company in Vienna — dissolved by choice. Its best ideas live on in everything above.
Research
28 coordinated disclosures in 2026 alone, plus ongoing tracking of the ecosystems I depend on — including the MyBB September 2026 advisory batch.
Unauthenticated XML-RPC pingback combined with incomplete IP-range checks and a DNS TOCTOU gap — cloud metadata exposure on real deployments. HKV-ADV-2026-025.
Username disclosure plus unbounded XML-RPC multicall forms a low-noise password-guessing channel against privileged accounts. HKV-ADV-2026-026.
Fourteen coordinated advisories from the MyBB security team — authorization gaps across moderation surfaces and admin XSS. Tracked and summarized on my research page.
About
I've spent my career on both sides of the fence: building web platforms and hosting infrastructure, then turning around and attacking them — mine and other people's — to find out what actually breaks.
After years of running a company (Websec GesmbH, now dissolved), I work independently and put my findings where they belong: in public, responsibly, with enough detail for defenders to act.
Security reviews, research collaboration, or a project that needs to be built right.