Offensive security practitioner based in Egypt, with hands-on experience across web · mobile · network domains. Reported valid vulnerabilities to organizations including Visa · Indeed · Atlassian · Adobe, with multiple coordinated disclosures and published CVEs. Ranked among the top researchers in Egypt on HackerOne. Active in CTFs, open-source security tooling, and public vulnerability research.
BSc Computers & Data Science — Faculty of Computer & Data Science, Alexandria University.
CVE-2026-5562 — Unauthenticated Remote Code Execution in kafka-ui
CVE-2026-4045 — LDAP Injection User Enumeration in ProjectSend
CVE-2026-4044 — Path Traversal via Arbitrary File Deletion in ProjectSend
CVE-2026-23852 — Stored XSS to RCE via Dynamic Icons in SiYuan
CVE-2025-1553 — Stored XSS in Scale Project Management
|
|
|
|
|
|
|
|
|
|
- No Guardrails
- CAT CTF 25 — All Web Challenges Writeups
- HTB University CTF 2025 — All Web Challenges Walkthrough
- Breaking Boundaries: From Limited Stored XSS to Open Redirect & CSRF Referrer Bypass
- Critical $$$$ Bounty from PII Disclosure — Broken Access Control
Full archive at 0xnayel.com.
MonMon — AI-powered monitoring tool for bug bounty hunters. Tracks changes across subdomains, HTTP endpoints, command output, and scope pages. Alerts via Telegram, Discord, and webhooks.
For engagements, collaboration, or responsible disclosure — reach out via the contact form at 0xnayel.com.
