Offensive security research & engineering.
I'm Mateusz Adamczyk — security researcher and engineer. I publish notes on vulnerability research, exploit development, and the systems I break for a living.
Latest research
Recent writeups

HTB · Cerberus — Three-Headed Privilege Escalation
Chaining an SSRF in a SAML responder with a misconfigured ADCS template for domain admin.

THM · Glyph — Reversing a Custom VM
Recovering the bytecode dispatcher of a hand-rolled stack VM and decrypting the flag with a 40-line Python lifter.
In the pipeline
- researchQ1 2026
Bypassing Kubernetes Admission Controllers via Mutating Race
A timing window between admission decision and object persistence that allows policy-violating workloads to land.
- ctfFeb 2026
HTB · Season VI Finale — full chain writeup
Domain takeover via abused MSA delegation and a forgotten Exchange transport rule.
- talkMar 2026
Talk · BSides Warsaw 2026
Engineering offensive tooling that survives EDR maturity curves — patterns and anti-patterns.
In the press & on stage
- Wired· Feature · ENWhy the next major breach will start in your build pipelineOct 2025
- Niebezpiecznik.pl· Interview · PLJak działają ataki PKCE downgrade — rozmowa z m4tSep 2025
- Gazeta Wyborcza· Feature · PLPolacy łamią systemy — i robią to dla naszego bezpieczeństwaJun 2025
- Darknet Diaries· Podcast · ENEp. 152 — The OAuth JobApr 2025
Recent posts
- linkedin · research
Krótki wątek o tym, dlaczego PKCE downgrade wciąż działa w 2025 — i co konkretnie należy sprawdzić w swoim IdP, zanim audytor sprawdzi za ciebie.
♥ 312💬 28open ↗ - linkedin · talk
Slajdy + notatki z mojej prelekcji na CONFidence: "When the Identity Provider Lies". Dla wszystkich, którzy nie zdążyli w sali.
♥ 198💬 14open ↗ - linkedin · industry
Niepopularna opinia: bug bounty nie zastępuje zespołu bezpieczeństwa. Tłumaczę dlaczego — i co programy bb naprawdę kupują firmom.
♥ 451💬 62open ↗ - linkedin · career
Otwieram kilka miejsc na mentoring dla osób wchodzących w offensive security. Co działa, czego unikać, jak budować portfolio bez CTF-burnout.
♥ 287💬 41open ↗
Books & papers
Field Manual: Modern Web Exploitation
A practitioner's guide to current-era web attack surface — request smuggling, prototype pollution, SSRF chains, and identity provider abuse.
PKCE Downgrade Attacks Against Public OAuth Clients
Formal analysis of method negotiation in widely deployed OAuth libraries and three CVE-class findings.
AD CS Revisited: Two Years After ESC1
What changed, what didn't, and why most environments are still vulnerable to certificate template abuse.
Work with me
Selective consulting, responsible disclosure, speaking.