Offensive security researcher & full-stack engineer. I break web, infrastructure and AI systems — and I build the tooling that scales it. Bug-bounty hunter on YesWeHack (53 reports) and Apple — credited in WebKit CVE-2026-28962. Every finding backed by a working PoC, never theoretical. Finishing a Cybersecurity Master's (work-study) in the south of France.
Method: source-driven auditing and invariant reasoning over blind fuzzing — "look where people don't look."
🐉 HYDRA — autonomous AI offensive-security engine · hydra.land
My flagship: a system that runs the offensive loop on its own and only reports what it can prove.
- Multi-model agent arena — chains recon → exploitation → validation against a live target.
- Exploit-proof gate — a finding is promoted to High/Critical only when a real exploit oracle fires and several agents reach consensus. No reflection-only "RCE", no false positives.
- Out-of-band collector — proves blind RCE / SSRF end-to-end.
- Cross-engagement memory — primes new hunts and de-duplicates against prior work.
Python · multi-LLM orchestration · Kali tooling · Docker · Traefik
- 🍎 Apple WebKit — CVE-2026-28962 · Safari 26.5, May 2026 — malicious web content → sensitive-information disclosure. Credited by name.
- 🎯 53 reports on YesWeHack · KYC-verified, alias
BaguettePwnM— across health, public-sector & fintech.
Classes: DOM-XSS · Open Redirect · IDOR · Broken Access Control · SSRF
⚠️ Responsible disclosure. Live-target findings are reported privately through the relevant program and are not published here. What you'll find in my public repos is CTF write-ups, lab PoCs against intentionally-vulnerable targets, my own tooling, and findings that have been publicly disclosed. No undisclosed exploit code, ever.
📰 Also building — claudenews.online
An independent AI-intelligence publication: 16 thematic dossiers (sovereign AI, AI agents, AI & cybersecurity, regulation, open-source models…). I live in the AI world I attack.
Offense · web exploitation (XSS / CSRF / SQLi / IDOR / access-control / open-redirect), PoC dev, recon Systems · Kali · BlackArch · Windows AD & Server · Docker · Nginx/Apache · TCP/IP · VPN · firewalls Code · Python · C# · Java · Swift · JS/TS (React, Next, Vue, Angular, Node) · PHP/Laravel Governance · ISO 27001 · GDPR (ANSSI) · IGI 1300
hydra— public face / teaser of the HYDRA engine (open-source the safe parts you choose)ctf-writeups— solved challenges, root-to-flag chainssecurity-research— lab PoCs, disclosed findings, methodology notesoffensive-tooling— small recon/exploitation utilities you wrote
hydra.land ·
LinkedIn ·
[email protected]
HÉRA SASU — independent security & AI R&D · references & PoCs on request
