Open to Opportunities · EU · Remote

Mohamed MEDDAH

Cloud Security Engineer & Infrastructure Specialist

Final-year Cybersecurity Engineering student Bac+5 · EQF Level 7 with hands-on experience in cloud security architecture, adversary simulation, and web application penetration testing. Active bug bounty researcher with confirmed critical findings on production targets.

Expertise

Featured Projects

Bug Bounty Research Write-ups →

Critical · CVSS 9.1
Unauthenticated account creation → Django DEBUG cloud credential leak → BOLA/IDOR full PII exfiltration (CWE-200, CWE-284)
High · OAuth ATO
redirect_uri bypass on GitLab SSO — 1-click account takeover via authorization code grant misconfiguration
High · SSRF
Host Header auth bypass on a global ad platform; reached live Kubernetes microservice returning production data (CWE-918)
Medium · Info Disclosure
Exposed Swagger UI, Spring Boot Actuator, internal IP leakage on enterprise IoT/B2B SaaS
Medium · Credential Exposure
Unauthenticated AI API keys & search credentials on global e-commerce infrastructure (CWE-548)

Certifications View All & Verify →

Latest Write-ups All Posts →