About me
Builder turned breaker, still both.
I'm Aria Akhavan — a security researcher and software developer based in Vienna, Austria. I've founded and run companies, hosted real infrastructure for a decade, and published vulnerability research the responsible way.
The short version
My path into security ran through engineering: you can't properly break a system you don't understand, and you can't build one you've never attacked. That loop — build, attack, rebuild — has shaped everything from the hosting company I run to the advisories I publish.
Today my work concentrates on three areas: vulnerability research with coordinated disclosure (mostly PHP ecosystems — WordPress, MyBB, forum and hosting software), secure development for projects that need to get it right the first time, and reverse engineering of obfuscated code, down to bytecode level.
When I'm not doing that, I run VPSrv, a European hosting provider, and I'm building Haikhavan Security — tooling that makes security findings reproducible and auditable instead of anecdotal.
Track record
-
Founder, Haikhavan Security (in formation)
28 coordinated vulnerability disclosures published since September 2026; building static/dynamic analysis tooling with signed, reproducible evidence.
-
Founder, Websec GesmbH
Vienna-based web development and security company. Run end-to-end — development, hosting, security testing, server management — until deliberately wound down.
-
Founder, VPSrv Premium Hosting
European hosting and VPS provider. Production responsibility for nginx, PHP-FPM, MySQL/MariaDB, mail and TLS at scale.
-
SAE Institute
Audio/audio-engineering background — where the signal-processing mindset that later shaped my analysis tooling comes from.
How I work
Coordinated disclosure, always
Findings go to the vendor first, with reproduction steps and a fix window. Public publication happens after, with credit and care for affected users.
Evidence over assertion
An advisory without a reproduction path is a rumor. Everything I publish includes the chain, the preconditions and the impact boundary.
Defense is the point
Research is only useful if it makes software safer. Each advisory is written for the maintainer fixing it and the admin deciding whether it matters.
Focus areas
Languages: PHP, C, C++, Rust, TypeScript, JavaScript, Python, Ruby, Perl, C# and Java — plus English and German, spoken and written.
Think we should talk?
Research collaboration, security reviews, or a build that needs to be secure from day one.