Security engineer · London
Hello, I’m Moaaz.
I work on threat simulation at CME Group. My day-to-day work is full-scope red teaming: understanding how determined attackers move through hybrid environments, then helping defenders make those paths harder to use.
I’ve spent more than a decade in offensive security, including ethical-hacking work at PwC UK and time on the Synack Red Team. Most client work has to stay private. This site collects the part of my work that can be checked in public.
01
Public research
Five published CVEs, including a business-logic issue in SolarWinds Web Help Desk. The original advisories are linked below; they are better evidence than a list of claims on a résumé.
- 2021CVE-2021-32076SolarWinds Web Help Desk — access restriction bypassVendor credit
- 2021CVE-2021-34249Online Book Store 1.0 — SQL injectionAuthor record
- 2020CVE-2020-25905Mobile Shop System 1.0 — SQL injectionAuthor record
- 2020CVE-2020-25362Online Shopping Alphaware 1.0 — SQL injectionAuthor record
- 2020CVE-2020-24862Pharmacy Medical Store and Sale Point 1.0 — SQL injectionAuthor record
02
Background
Senior Cyber Security Engineer, Threat Simulation
Senior Penetration Tester (freelance)
Manager, Ethical Hacking
Red Team Member
Senior Consultant, Cyber Security
Selected credentials
GCPN · OSEP · OSCP · OSWP · CREST CRT · CRTO · eWPTX
Certifications are listed under the full credential name “Moaaz Mohamed Ahmed Taha.” Direct badge links will be added as each issuer account is consolidated.
03
A note on identity
Older research and bounty records use several handles. They all refer to me: 0xStorm, 0xStorm0,Moaaz_Taha, MoaazTaha, and n0lsec.
The identity record brings those references together and provides a single contact address for professional verification.