AppSec · AI security · Pentesting · DevSecOps

I build software, then I break it.

Mohamed Fadel Moumeni — application security engineer at Invygo, bug bounty hunter since 2020. I find what attackers would, write it up, and help ship the fix.

01 · About

Where building and breaking meet.

I’m a Software & Application Security Engineer at Invygo, a Dubai-based startup, where I focus on the security and scalability of our services. I started as a full-stack developer, and that’s what makes the security work land: I know where the shortcuts get taken because I’ve taken them. Outside the day job, I hunt bugs through bounty programs and publish what I find.

50+Vulnerabilities closed
6Published writeups
2020Hunting bugs since

02 · Practice

Six ways in. One job: close them.

Builds with

  • React
  • Next.js
  • Node.js
  • NestJS
  • TypeScript
  • RabbitMQ
  • SQL & NoSQL

03 · Research

Findings, written up.

  1. The Hidden Security Risk on Our Factory InfrastructureSCADAICS
  2. DevSecOps 101 — IntroductionDevSecOps
  3. Exploiting GraphQL Introspection to Leak Sensitive DataGraphQL
  4. From Django Debug Mode to Full SSRF-Driven Organization TakeoverSSRFDjango
  5. Dependency Confusion Attacks and Prevention: Full GuideSupply chain
  6. Your Smart TV Isn’t Smart.IoT
All writeups on the blog

04 · Experience

Three roles, one thread.

05 · Projects

Things I’ve shipped.

06 · Certifications

Paper trail.

4 issuers6 credentialsAll verifiable

FOXGRID Industrial

Practical Offensive Industrial Security Essentials

Offensive security for industrial control systems.

Verify credential

TheSecOpsGroup

Certified AppSec Practitioner

An exam testing knowledge of the core concepts of application security.

Verify credential

PentesterLab

Three badges, earned hands-on.

View profile
  • Recon badge

    A set of exercises for learning reconnaissance.

  • Unix badge

    Key Unix vulnerabilities: weak passwords, file-permission issues and more.

  • Blue badge

Have something worth breaking?

Pentests, application security reviews, or a vulnerability to report — my inbox is open.