otwarty na współpracę · Q1 2026

Research i inżynieria offensive security.

Jestem Mateusz Adamczyk — security researcher i engineer. Publikuję notatki z researchu podatności, exploit developmentu i systemów, które łamię zawodowo.

m4t@research:~$
pisali o mnie
WiredNiebezpiecznik.plDarknet DiariesThe RecordGazeta WyborczaPhrack
wyróżnione

Najnowszy research

zobacz wszystkie →
w planie

W pipeline

  • researchQ1 2026

    Bypassing Kubernetes Admission Controllers via Mutating Race

    A timing window between admission decision and object persistence that allows policy-violating workloads to land.

  • ctfFeb 2026

    HTB · Season VI Finale — full chain writeup

    Domain takeover via abused MSA delegation and a forgotten Exchange transport rule.

  • talkMar 2026

    Talk · BSides Warsaw 2026

    Engineering offensive tooling that survives EDR maturity curves — patterns and anti-patterns.

media

W mediach i na scenie

zobacz wszystkie →
  • Wired· Feature · EN
    Why the next major breach will start in your build pipeline
    paź 2025
  • Niebezpiecznik.pl· Interview · PL
    Jak działają ataki PKCE downgrade — rozmowa z m4t
    wrz 2025
  • Gazeta Wyborcza· Feature · PL
    Polacy łamią systemy — i robią to dla naszego bezpieczeństwa
    cze 2025
  • Darknet Diaries· Podcast · EN
    Ep. 152 — The OAuth Job
    kwi 2025
publikacje

Książki i papers

zobacz wszystkie →
Book2024

Field Manual: Modern Web Exploitation

A practitioner's guide to current-era web attack surface — request smuggling, prototype pollution, SSRF chains, and identity provider abuse.

Paper2025

PKCE Downgrade Attacks Against Public OAuth Clients

Formal analysis of method negotiation in widely deployed OAuth libraries and three CVE-class findings.

Article2024

AD CS Revisited: Two Years After ESC1

What changed, what didn't, and why most environments are still vulnerable to certificate template abuse.

kontakt

Współpraca

Selektywny consulting, responsible disclosure, wystąpienia.

skontaktuj się →