whoami
Hesham Mahmoud
Offensive Security Engineer
Hesham Mahmoud Aka 0xRyuzak1 — an offensive security engineer who breaks into things for a living: red team operations, penetration testing, and adversary simulation against hardened environments. My focus is the full attack chain — initial access, web application exploitation, AI security, Active Directory exploitation, EDR/AV evasion — and the custom C/C++ and Python tooling that makes it all work quietly.
Beyond engagements I hunt bugs and research where defenses fall short — credited in several CVEs and Oracle's Critical Patch Update. I contribute to open-source security tooling and write up technique and methodology so others learn the how, not just the what.
Certifications
Credential wallet ↗
Acknowledgments
CVE
High · Duplicate
CVE
Medium
CVE
Medium
CVE
Medium
CVE
High
Disclosure
Critical
CVE
Medium
CVE-2026-45401 — OpenWebUI
SSRF bypass via HTTP redirect following in web-fetch and image-load endpoints — advisory marked duplicate
CVE-2026-45397 — OpenWebUI
Unauthenticated RAG configuration disclosure via an unprotected endpoint
CVE-2024-34071 — Umbraco .NET CMS
Open redirect protection bypass
CVE-2024-34074 — ERPNext (Frappe)
Open redirect protection bypass
CVE-2024-29035 — Umbraco .NET CMS
Blind SSRF enabling internal port scanning and sensitive information leakage
1-Click Account Takeover — Oracle Content Management (CMS)
Misconfigured CORS leads to one-click account takeover · credited in Oracle CPU Jan 2024
CVE-2023-20179 — Cisco Catalyst SD-WAN Manager
Web UI HTML injection leading to denial of service
Bounty
Bug bounty hunter
Helped secure many domains through responsible disclosure
At a glance
45+
Machines pwned
06
CVEs
12
Writeups published
12
Certifications
01
Pro labs











