
Mateusz Adamczyk
aka m4t · m4teusz · offensive security researcher
I research offensive security and build the engineering scaffolding around it. My day-to-day moves between vulnerability discovery, exploit development, and the kind of platform work that lets a small team punch above its weight.
Over the last few years I've shipped CVE-class findings in identity providers, spoken at conferences in Europe and the US, and written a field manual on modern web exploitation. I split my time between long-form research, selective consulting, and mentoring engineers stepping into offensive work.
I write here to clarify my own thinking and to leave a trail for engineers solving the same problems. The bar I hold for posts is simple: they should be useful five years from now.
at a glance
- Based
- Warsaw, PL
- Languages
- Polish · English
- Open to
- Disclosure · consulting · speaking
- Responds
- Within 48h
focus
- Web & API
- Auth flows, request smuggling, server-side logic flaws.
- Binary & RE
- Userland exploitation, kernel 1-days, custom VMs.
- Cloud & K8s
- IAM design, container escapes, supply-chain reviews.
- Red team
- Tradecraft, AD attack paths, OPSEC-aware tooling.
stack
selected timeline
- 2025WOOT '25 paper · PKCE downgrade in public clients
- 2025Speaker · CONFidence — "When the Identity Provider Lies"
- 2024Released "Field Manual: Modern Web Exploitation"
- 2024Workshop lead · x33fcon — AD CS red teaming
- 2023Joined a red team practice — full-time engagements
- 2021First CVE-class disclosure · web identity layer
elsewhere
contact
For research collaboration, responsible disclosure, or selective consulting. PGP key available on request.