Security engineer · London

Hello, I’m Moaaz.

I work on threat simulation at CME Group. My day-to-day work is full-scope red teaming: understanding how determined attackers move through hybrid environments, then helping defenders make those paths harder to use.

I’ve spent more than a decade in offensive security, including ethical-hacking work at PwC UK and time on the Synack Red Team. Most client work has to stay private. This site collects the part of my work that can be checked in public.

moaaz@moaaztaha.comLinkedInIdentity record

01

Public research

Five published CVEs, including a business-logic issue in SolarWinds Web Help Desk. The original advisories are linked below; they are better evidence than a list of claims on a résumé.

  1. 2021CVE-2021-32076SolarWinds Web Help Desk — access restriction bypassVendor credit
  2. 2021CVE-2021-34249Online Book Store 1.0 — SQL injectionAuthor record
  3. 2020CVE-2020-25905Mobile Shop System 1.0 — SQL injectionAuthor record
  4. 2020CVE-2020-25362Online Shopping Alphaware 1.0 — SQL injectionAuthor record
  5. 2020CVE-2020-24862Pharmacy Medical Store and Sale Point 1.0 — SQL injectionAuthor record

02

Background

2024—now
CME Group

Senior Cyber Security Engineer, Threat Simulation

2026
Stingrai

Senior Penetration Tester (freelance)

2022—24
PwC UK

Manager, Ethical Hacking

2020—22
Synack Red Team

Red Team Member

2022
EY

Senior Consultant, Cyber Security

Selected credentials

GCPN · OSEP · OSCP · OSWP · CREST CRT · CRTO · eWPTX

Certifications are listed under the full credential name “Moaaz Mohamed Ahmed Taha.” Direct badge links will be added as each issuer account is consolidated.

03

A note on identity

Older research and bounty records use several handles. They all refer to me: 0xStorm, 0xStorm0,Moaaz_Taha, MoaazTaha, and n0lsec.

The identity record brings those references together and provides a single contact address for professional verification.