Hello world,

Welcome to my professional space. My name is Simon, a security researcher and penetration tester at Vumetric CyberSecurity. My focuses are Mobile App Security (iOS/Android) and Web Applications. I’m also a big fan of macOS.

The process of finding vulnerabilities inspires me to keep learning, share what I know, and solve tough challenges to help make the internet a safer place.

If you’re interested in collaborating or just want to chat about cybersecurity, feel free to reach out.

Happy hacking :)

Research
  • CVE-2025-55076 – Unauthenticated XPC Message Handling Leading to Local Privilege Escalation in Plugin Alliance InstallationHelper
  • CVE-2025-62686 – DYLD Library Injection via Missing Hardened Runtime in Plugin Alliance InstallationHelper
  • CVE-2025-65841 – Weak Credential Storage in Aquarius Desktop Allowing Password Cracking & Account Takeover
  • CVE-2025-65842 – Unauthenticated XPC Access & Faulty Authorization Logic Enabling RCE in Aquarius HelperTool
  • CVE-2025-65843 – Symlink Dereference in Aquarius Desktop Support Archive Generation Leading to Arbitrary File Disclosure
  • CVE-2024-3251 - Time-Based Blind SQL Injection in CLMS v1.0
Personal Projects/Tools
  • Lazy Payloads - Copy common payloads to clipboard directly from browser.
  • Deeeeper - Tools to find Activities and Deep Links in APK - Written in Go
  • FireCracker - Find Firebase instance in APK and exploit if Read/Write is possible - Written in Go
  • iOSDumper - Dump key information from .ipa and search for applinks - Written in Go
  • HeaderGrabber - Analyzes HTTP requests in real-time, highlighting headers, cookies, and POST data - Written in Go
  • MalCheck - Take list of Windows API calls and flag dangerous calls - Written in Go
Education & Certifications
CTF
  • Hack The Box - Synacktiv Fortress
  • Hack The Box - Dante Pro Lab
  • Praetorian Tech Challenges - Crypto
  • Praetorian Tech Challenges - Mastermind
  • Halborn CTF - Solana Farm CTF
  • NahamCon CTF 2021
  • MetaCFT 2022
Contact

Please don’t hesitate to contact me securely using my PGP key.

-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEYa0XahYJKwYBBAHaRw8BAQdAaLmubE7B0Xb3IgEZ5FtilzWZBzX5u2Qt
JM+gtjynH3TNJWFsbWlnaHR5c2VjQHBtLm1lIDxhbG1pZ2h0eXNlY0BwbS5t
ZT7CjwQQFgoAIAUCYa0XagYLCQcIAwIEFQgKAgQWAgEAAhkBAhsDAh4BACEJ
EIF23/0vurUzFiEELbeo/KRxTeoC53DtgXbf/S+6tTMMZQEA39gvDPtT2VZE
nQUEAw/sDldV8tLDwWzSobL8FTfa8WIBANTG7L6K67Obxxo5ImzY4rsiUAwQ
898bOCkk4gACHG4PzjgEYa0XahIKKwYBBAGXVQEFAQEHQNjcRNElR49N6UkY
iCehsz7c2iQ5PqXo5Kz4NDFDJdFKAwEIB8J4BBgWCAAJBQJhrRdqAhsMACEJ
EIF23/0vurUzFiEELbeo/KRxTeoC53DtgXbf/S+6tTO1igEAj8D0czHf68JL
qfkSR7/XLlnuTQJXCC8I+D99M/mvzu0A/ROqJx7KrufO8aooQlphpRU9sCXa
5YmbIfPGaWYdGmkP
=ZBYL
-----END PGP PUBLIC KEY BLOCK-----
Digital Ocean

I run my recon on a Digital Ocean droplet. If you’re interested in a $200 credit, feel free to use my referral link:

DigitalOcean Referral Badge