available for collaboration · Q1 2026

Offensive security research & engineering.

I'm Mateusz Adamczyk — security researcher and engineer. I publish notes on vulnerability research, exploit development, and the systems I break for a living.

m4t@research:~$
as seen in
WiredNiebezpiecznik.plDarknet DiariesThe RecordGazeta WyborczaPhrack
featured

Latest research

view all →
upcoming

In the pipeline

  • researchQ1 2026

    Bypassing Kubernetes Admission Controllers via Mutating Race

    A timing window between admission decision and object persistence that allows policy-violating workloads to land.

  • ctfFeb 2026

    HTB · Season VI Finale — full chain writeup

    Domain takeover via abused MSA delegation and a forgotten Exchange transport rule.

  • talkMar 2026

    Talk · BSides Warsaw 2026

    Engineering offensive tooling that survives EDR maturity curves — patterns and anti-patterns.

press

In the press & on stage

view all →
  • Wired· Feature · EN
    Why the next major breach will start in your build pipeline
    Oct 2025
  • Niebezpiecznik.pl· Interview · PL
    Jak działają ataki PKCE downgrade — rozmowa z m4t
    Sep 2025
  • Gazeta Wyborcza· Feature · PL
    Polacy łamią systemy — i robią to dla naszego bezpieczeństwa
    Jun 2025
  • Darknet Diaries· Podcast · EN
    Ep. 152 — The OAuth Job
    Apr 2025
publications

Books & papers

view all →
Book2024

Field Manual: Modern Web Exploitation

A practitioner's guide to current-era web attack surface — request smuggling, prototype pollution, SSRF chains, and identity provider abuse.

Paper2025

PKCE Downgrade Attacks Against Public OAuth Clients

Formal analysis of method negotiation in widely deployed OAuth libraries and three CVE-class findings.

Article2024

AD CS Revisited: Two Years After ESC1

What changed, what didn't, and why most environments are still vulnerable to certificate template abuse.

contact

Work with me

Selective consulting, responsible disclosure, speaking.

get in touch →