Offensive security research
I find and report vulnerabilities before attackers do.
Independent security researcher working across firmware and IoT, mobile, and web applications. Static-first reverse engineering, custom tooling, and coordinated disclosure.
whoami → Andrii Timofeev · Kyiv · reverse engineer
latest → CVE-2026-77538 · Ubiquiti UniFi Connect · CVSS 8.2
What I work on
Research focus
01 Firmware & IoT
Reverse engineering embedded devices and network gear: extracting firmware, mapping attack surface, and finding memory-safety and access-control bugs in native services.
02 Mobile & Android
Application and platform security on Android: static and dynamic analysis of apps and native libraries, auth and logic flaws, and path-traversal classes at scale.
03 Web & application
Access control, injection, and business-logic vulnerabilities in web backends and APIs, reported through bug bounty and coordinated disclosure channels.
Featured advisory
Latest public disclosure
HIGH · CVSS 8.2→ Read the full writeup
Selected results
Track record
- CVE CVE-2026-77538 — improper access control in Ubiquiti UniFi Connect (CVSS 8.2). Reported via bug bounty; fixed and publicly disclosed by the vendor.
- Bug bounty Reported and rewarded findings through HackerOne and Bugcrowd, including Ubiquiti's program.
- Vendor Acknowledged report to Samsung Mobile Security.
- Open source 19 CVE IDs assigned by MITRE for Zip Slip path-traversal issues in open-source Android and Java projects.
About
Approach
I am an independent security researcher based in Kyiv. My work starts with static reverse engineering: pulling apart firmware images, native binaries, and mobile apps to understand how they actually behave, then confirming findings dynamically on real hardware where it matters.
I build my own tooling and automation around industry-standard reversing platforms to cover more surface faster. Everything I report goes through responsible, coordinated disclosure. Vendors and programs get the details and time to fix before anything becomes public.
Contact
Get in touch
Open to vulnerability research, reverse-engineering, and red-team contract work, and to coordinating disclosure on issues in scope.
Security contact & disclosure policy: /.well-known/security.txt