Yehia Ezzat
0xSemizzz
Computer Science student at The British University in Egypt with hands-on experience in penetration testing and vulnerability research, including publicly published CVEs. Interested in low-level systems, reverse engineering, compiler engineering, and security research.
01
Experience
Mimocodes
mimocodes.comJunior Offensive Security Engineer
ActiveFull-time
July 2026 to present. Egypt, hybrid.
- Conducted penetration testing across web applications, networks, and fintech systems for real-world clients, combining manual exploitation with automated testing and AI-assisted security workflows to identify, validate, and prioritise vulnerabilities.
- Documented reproducible attack paths, technical impact, and remediation guidance, and collaborated with engineering teams through the remediation process.
- Participated in security and development discussions, reviewing feature designs for potential attack paths and security weaknesses.
Offensive Security Intern
Internship
June 2026. Egypt, on-site.
02
Achievements
Published CVEs & Advisories
- CVE-2026-18649 — GStreamer RTP depayloader denial of service
- CVE-2026-92162 — Flatpak system helper path traversal to local root
Competitive Programming
- ECPC Finalist 2026
Model United Nations
- Best Delegate, Nile International Model United Nations (NIMUN), the largest MUN conference in Egypt
TryHackMe Top 3% Globally
03
Certifications
- Web Application Pentesting Certificate — TryHackMe
- Jr Penetration Tester — TryHackMe
- Google Cybersecurity Certificate — Coursera
- CompTIA Security+ (SY0-701) Complete Course & Exam — Udemy
04
Security Research
CVE-2026-18649: Unbounded Memory Growth
GStreamer RTP Depayloader
A remote, unauthenticated denial of service in GStreamer's H.264 and H.265 RTP depayloaders, where FU-A fragment reassembly had no size limit. Assigned CVE-2026-18649.
CVE-2026-92162: Flatpak System Helper Path Traversal
Flatpak DeployAppstream arch traversal
A path traversal in the Flatpak system helper where an unvalidated arch string in DeployAppstream lets an active local user make the root helper create directories at an arbitrary path, chaining into a local root file write. Assigned CVE-2026-92162 and GHSA-v2gw-v9h5-9q4x.
05
Software
Vonnis
Offline script triage, measured against real corpora
A script triage engine that reads a suspicious PowerShell or shell script and answers, in plain English, whether running it is a bad idea. 111 deterministic YAML detection rules, no API key and no network for the verdict, and a measurement harness that scores the rules against 2,526 real package maintainer scripts and 1,862 Atomic Red Team tests.
TrackMUN
Model UN conference management platform
A full-stack platform for running Model UN conferences end to end: delegate registration, council assignments, QR check-in, and a live press feed. Built with React, Hono on Cloudflare Workers, Turso, and Supabase Auth.
06
Leadership
All councils. 100+ delegates.
Owned the academic output of the whole conference, making sure every council's material was correct, presentable, and up to date.
- Reviewed and signed off presentations, activities, rules of procedure, and guidelines for every council.
- Oversaw the background papers, which ran past 30 pages per council.
- Taught and supervised the academic teams directly, covering presentation skills and background paper writing.
- Helped run certificate distribution to delegates.
- Ran the conference on TrackMUN, the platform I built for it, which served hundreds of requests and handled real delegate activity throughout the conference.
07
Skills
Security
- Vulnerability Research
- Penetration Testing
- Red Teaming
- Reverse Engineering
- Exploit Development
- Web Application Security
- Open Source Security
- Detection Engineering
- Malware Triage
- MITRE ATT&CK
- Memory Corruption
- Fuzzing
Systems
- Low-Level Systems
- Linux
- Assembly
- x86/x64
- LLVM
- Compiler Theory
Programming
- C
- C++
- C#
- Python
- PHP
- TypeScript
- SQL
08
Education
The British University in Egypt
Bachelor's degree, Computer Science
London South Bank University
Bachelor's degree, Computer Science
09
Interests
Areas I am currently exploring.
- Low-Level Systems
- Compiler Engineering
- Vulnerability Research
- Reverse Engineering
- Open Source Security
- Hypervisors
- Web Browsers
- Operating Systems
- Linux