xaccefyupdated september 2026
Khaserdene
Security Researcher & Developer
Cybersecurity student at MUST (expected 2028) learning vulnerability research, development, and systems design & engineering. Learning by doing: CTFs, writeups, and small open-source contributions, including two responsible disclosures fixed upstream.
Cybersecurity student · Ulaanbaatar, Mongolia · open to junior roles
FINDINGS
CVE-2026-33151
Socket.IO: memory exhaustion via unbounded binary attachments, found by fuzzing [high]
CVE-2026-33245
React Router: XSS in unstable RSC redirect handling via javascript: targets [high]
ACHIEVEMENTS
PROJECTS
pi-xpi
pentest tools for Pi Agent: casefile, web search, exploit lookup, code intel [author]
ratic
cleaner Claude Code fork for engineering and security [core maintainer]
casefile
bug bounty casefile: targets, notes, evidence in one place [author] [archived]
learnmax
full learning loop for coding agents: learn, quiz, spaced repetition [author]
sweep
lazy senior-dev mode for Pi: stdlib before custom code, one line before fifty [author]
archdot
Arch + Hyprland setup for daily security work [author]
WRITING
htb
HackTheBox writeups · seasons and fortress boxes
pwn
ROP Emporium solutions · every challenge, with short notes
ctf
CTFMN solutions · local CTF walkthroughs
STACK
security
binary exploitation · reversing · vuln research · disclosure · CTF
agents
agentic development · MCP servers · Pi extensions · RAG workflows
systems
architecture · system design · distributed systems (learning)
languages
Python · C · Bash · JavaScript · Go · Rust
tools
pwntools · pwndbg · GDB · Ghidra · Caido · MCP servers · Git
platforms
Linux · Docker · networking · cloud basics
ACTIVELY LEARNING
now
vulnerability research · software development · systems design & engineering · rust
CONTACT
email: xaccefy@gmail.com · github · x · hackratic · htb