Hi folks! My name is Riyaz Walikar and I’m a seasoned security researcher, trainer, and offensive security expert with over 18 years of hands-on experience across industry verticals and technology stacks.
My work spans Web, API, Mobile, Thick Client, Windows and Linux systems, Internal and Internet-facing Infra, Wireless, Cloud, Containers, Kubernetes, and more recently, Agentic AI and MCP security.
Professionally, I’ve led penetration testing and security research teams at Microland, PwC, Citrix, Appsecco, and Kloudle. I now work independently as a full-time security researcher and consultant, while continuing to mentor, teach, and train at conferences and private programs. I have spoken and trained at several leading security and hacker conferences around the world, including Black Hat, DEF CON, OWASP AppSecUSA, nullcon, and c0c0n.
When I’m not breaking things or poking around systems, I enjoy stargazing, photography, travel, googling easy weight-loss solutions, and cracking terrible jokes in the hope of gaining more followers.
Professional Career
| Company | Time Period | Role | Responsibilities |
|---|---|---|---|
| Independent | May 2026 - Present | Security Researcher | Full-time vulnerability research, security mentorship, and consulting AI and Cloud first developer and security teams. Finding new and novel ways of exploiting AI, Agentic, MCP and Cloud native services, speaking at conferences and publishing tools and methodologies around this. Upcoming conferences include Blackhat, Defcon, VulnCon, c0c0n. AWS Community Builder (Security) for 3+ years now. |
| Kloudle | September 2021 - April 2026 | Co-Founder & Chief of R&D | Co-founded Kloudle, a cloud security automation platform. Led R&D - worked on the security scanning engine covering 350+ cloud security issues, building the detection rules framework across 6+ cloud providers. Kubernetes RBAC auditing, multi-cloud security research. |
| Appsecco | April 2016 - April 2026 | Principal Security Consultant and Chief Hacker | Led application security assessments, penetration tests, and security training for global clients. Led a strong team of pentesters and security testers, performed assessment on over a hundered apps across industry verticals and technologies including fintech, medtech, edtech, cloud and container orchestration products, security software, shipping and marine engineering and telecommunications. Worked closely with a lot of developer, engineering and security customer teams to mentor, aid and assist in evaluating and explaining risks versus product security testing issues uncovered. Created tools and pentesting methodologies for web, cloud, mobile, APIs, network penetration testing, MCP and AI Agentic systems. Authored several body of works, knowledgebases, methodologies, process documents, blogs, spoke at several conferences and sessions, published video content and delivered hands on training at several industry favorite conferences. Was also in charge of technical pre-sales, product discovery/scoping and customer management along with company wide compliances and admin. |
| Citrix R&D | December 2014 - February 2016 | Product Security Manager | Drove product security for Citrix’s product portfolio. Led security design reviews, threat modeling, and penetration testing. Conducted independent vulnerability research resulting in multiple CVEs and bug bounty findings at Facebook, Yahoo, Adobe, and Twitter. Worked as a liaison with the dev teams, management and the security teams to ensure communication clarity and release maintenance |
| PwC SDC | February 2012 - December 2014 | Sr. Software Engineer | Performed security assessments, vulnerability research, and penetration testing for PwC’s global clients - several of which were Fortune 500. Discovered several vulnerabilities in public software, assigned CVEs for them. Published research on SSRF/XSPA attacks - went on to speak at BlackHat Asia 2012 and OWASP AppSecUSA 2012. Built foundation for offensive security career through enterprise security exposure. |
| Microland | July 2007 - January 2012 | Solutions Architect - Professional Services | Built expertise in networking, systems administration, and IT infrastructure. Hands-on systems and network knowledge that became the foundation for understanding how to break and secure complex systems. Web Application Security Consulting for Fortune 500 customers. Several onsite engagements to test on-prem network infrastructure and apps. Created testing frameworks for teams and clients and built several internal security service processes for the organisation. |
Timeline of Talks/Research/Conferences
Important events, tool releases, vulnerability disclosures and public research, talks, presentation, training programs and conferences I have spoken at.
- August 10th - 11th - Defcon USA 2026 (Upcoming) [Conference][Training] - 2 Day hands on Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel
- June 13th - VulnCon 2026 [Conference][Talk] - The Confused Copilot: Exploring Capabilities and Privilege Boundaries in Amazon Q
- June 5th - Released Web Fetcher MCP [GitHub][Tool] - MCP to bypass robots.txt restrictions to fetch data for Claude Desktop type tools.
- May 23rd - AWS Community Builder (Security) Renewed for Year 3 [Community][Membership] - Membership renewed for 3rd year by AWS for security community contributions.
- April 7th - Research [Research][Technique] - Released v3 of a checklist for pentesting Model Context Protocol (MCP) servers via Appsecco
- March 27th - Rippling AI Security Event [Event][Talk] - Game of Groans - Fav Hacks and Terrible Bugs in AI Agents and MCP
- February 28th - null Dubai [Event][Talk] - AI Agents: Building and securing with AWS Bedrock Guardrails - [Slides]>
- February 19th - Seasides 2026 [Conference][Workshop] - Building and Hacking AI Agents and MCP Servers in the Real World - AWS Edition
- December 18th - Released Vulnerable MCP Servers Lab at Appsecco [GitHub][Tool] - Collection of deliberately vulnerable MCP servers along with instructions for exploitation labs.
- December 13th - BSides London [Conference][Workshop] - Hacking MCP Servers for Fun and Profit
- November 8th - null Bangalore [Event][Talk] - MCP Hacking for Fun and Profit
- October 31st - OWASP Bay Area [Event][Talk] - Pentesting MCP Servers - [Video]
- September 9th - Appsecco Masterclass [Event][Workshop] - Pentesting MCP Servers - [Slides], [Video]
- August 13th - Released MCP Client and Proxy with Akash at Appsecco [GitHub][Tool] - A universal MCP client with proxying feature to route MCP server traffic through Burp Suite for security testing.
- May 15th - AWS Community Builder (Security) Renewed for Year 2 [Community][Membership] - Membership renewed for 2nd year by AWS for security community contributions.
- February 20th - Seasides 2025 [Conference][Workshop] - AWS Hacking and Security - From Zero to Hero
- June 28th - BSides Bangalore [Conference][Workshop] - Kubernetes Hacking for Profit & Fun - [Slides]
- May 18th - AI Day Bangalore [Event][Talk] - Hacking AI Applications on Kubernetes Clusters - [Slides]
- April 24th - RiskProfiler Webinar [Event][Webinar] - Modern External Threats for Cloud and Managed Kubernetes - [Video]
- March 4th - AWS Community Builder (Security) Membership Accepted [Community][Membership] - Membership approved by AWS for security community contributions.
- December 15th - Appsecco Masterclass [Event][Workshop] - Hacking Kubernetes for Fun and Profit. - [Slides], [Video]
- September 25th - 27th - nullcon Goa Conference [Conference][Training] - Breaking and Pwning Apps and Servers on AWS and Google Cloud
- July 29th - Kloudle Masterclass [Event][Workshop] - Session 10 - AWS Hands-on Hacking - [Slides], [Video]
- July 22nd - Kloudle Masterclass [Event][Workshop] - Session 9 - AWS RDS Misconfigs - [Slides], [Video]
- July 15th - Kloudle Masterclass [Event][Workshop] - Session 8 - AWS Lambda Misconfigs - [Slides], [Video]
- July 8th - Kloudle Masterclass [Event][Workshop] - Session 7 - AWS EC2 Misconfigs - [Slides], [Video]
- July 1st - Kloudle Masterclass [Event][Workshop] - Session 6 - Letβs Hack Stuff! - [Slides], [Video]
- June 24th - Kloudle Masterclass [Event][Workshop] - Session 5 - AWS EC2's AMI Misconfigs - [Slides], [Video]
- June 17th - Kloudle Masterclass [Event][Workshop] - Session 4 - AWS EC2's EBS Misconfigs - [Slides], [Video]
- June 10th - Kloudle Masterclass [Event][Workshop] - Session 3 - AWS S3 Misconfigs - [Slides], [Video]
- June 3rd - Kloudle Masterclass [Event][Workshop] - Session 2 - AWS IAM Misconfigs - [Slides], [Video]
- May 27th - Kloudle Masterclass [Event][Workshop] - Session 1 - AWS Security Intro and the Hacker Mindset - [Slides], [Video]
- March 16th - null Dubai [Event][Talk] - Raining shells in AWS by chaining vulnerabilities - [Slides], [Video]
- February 16th - Kloudle Webinar [Event][Webinar] - From Success to Nightmare - The story of a cloud misconfig that destroyed a business - [Video]
- January 19th - E2E Networks Webinar [Event][Webinar] - Hacking and Securing Kubernetes clusters - [Video]
- December 8th - Kloudle Research [Research][Technique][Tool] - Cross Account IAM enumeration via Lambda Resource Policies in AWS Cloud - [GitHub]
- September 6th - 8th - nullcon Goa Conference [Conference][Training] - Breaking and Pwning Apps and Servers on AWS and Google Cloud β Post Pandemic Edition
- March 9th - Kloudle Research [Research][Technique] - AWS RDS does not force clients to connect using a secure transport layer
- February 23rd - Kloudle Research [Research][Technique] - Exploiting the 8KB Bypass in Google Cloud Platform WAF - with Karan Saini's assistance
- February 2nd - Kloudle Research [Research][Technique] - Bypassing the AWS WAF Protection with an 8KB POST Body
- September 14th - fwd:cloudsec 2021 [Conference][Talk] - An Attacker's Approach to Pentesting IBM Cloud - [Slides], [Video]
- August 21st - null Community Webinar [Event][Webinar] - Riyaz and Omair in a Webinar going down nostalgia lane in the null security community - [Video]
- May 4th - Kloudle Webinar [Event][Webinar] - IAM Bad: Privilege Escalation using Misconfigured Policies in AWS IAM - [Slides]
- April 27th - DeveloperWeek Conference [Conference][Talk] - Who else is in your pod? An Attacker's Approach to Container and Kubernetes Security - [Slides]
- March 18th - KubeSec Online Conference [Conference][Talk] - Who else is in your pod? An Attacker's Approach to Container and Kubernetes Security - [Slides]
- December 20th - Kloudle Research [Research][Technique] - A Technical Analysis of the AWS CloudShell service
- August 13th - 16th - nullcon Online Conference [Conference][Training] - Attack and Defence in AWS: Chaining vulnerabilities to go beyond the OWASP Top 10
- June 27th - Research [Research][Technique] - Using SQL Injection to perform SSRF/XSPA attacks
- June 25th - Hasgeek Fragments Online Event [Event][Talk] - Plug the vulnerabilities! - AMA on Mobile Apps Security - [Slides], [Video]
- April 9th - Research [Research][Technique] - Open sourced "Breaking and Pwning Apps and Servers on AWS and Azure" training courseware and labs with Akash via Appsecco
- March 3rd - 5th - nullcon Goa Conference [Conference][Training] - Breaking and Owning Applications and Servers on AWS and Azure
- January 18th - null Bangalore [Event][Talk] - API Security Testing - [Slides]
- August 12th - OWASP Bay Area [Event][Talk] - Raining shells in AWS by chaining vulnerabilities - [Slides]
- July 5th - Hasgeek JSFoo [Event][Talk] - Captain Marvellous JavaScript - [Slides], [Video]
- June 20th - 22nd nullcon Bangalore Conference [Conference][Training] - Xtreme Web Hacking
- May 18th - Research [Research][Technique] - Sangoma SBC 2.3.23-119-GA Authentication Bypass (via Appsecco) - CVE-2019-12148 via Appsecco
- May 18th - Research [Research][Technique] - Sangoma SBC 2.3.23-119-GA Unauthenticated User Creation (via Appsecco) - CVE-2019-12147 via Appsecco
- April 27th - null Bangalore [Event][Talk] - Injection attacks in apps with NoSQL backends - [Slides]
- April 13th - null Bangalore [Event][Workshop] - null Puliya - Hands on with AWS
- February 28th - Book Published [Book] - Hands-On Application Penetration Testing with Burp Suite
- February 26th - 28th - nullcon Goa Conference [Conference][Training] - Breaking and Owning Applications and Servers on AWS and Azure
- October 13th - null Bangalore [Event][Talk] - An introduction to DefectDojo (OWASP Project) - [Slides]
- August 18th - null Bangalore [Event][Talk] - XML External Entity (XXE) Injection Attacks - [Slides]
- June 20th - 22nd June - nullcon Bangalore Conference [Conference][Training] - Xtreme Web Hacking
- June 9th - null Bangalore [Event][Workshop] - null Humla - Post Exploitation with Powersploit (Getting started)
- April 7th - null Bangalore [Event][Workshop] - null Humla - Post Exploitation with PowerShell Empire (Getting started)
- March 10th - null Bangalore [Event][Talk] - Second Order SQL Injection - [GitHub]
- February 27th - 1st March - nullcon Goa Conference [Conference][Training] - Breaking and Owning Applications and Servers in AWS
- January 20th - null Bangalore [Event][Talk] - Pentesting AWS Lambda Functions - [Slides]
- December 22nd - null Bangalore [Event][Talk] - Windows Privilege Escalation Techniques
- November 19th - null Bhopal [Event][Talk] - An Introduction to SysInternal - [Slides]
- October 14th - null Bangalore [Event][Talk] - Executing Windows Malware through WSL (Bashware) - [Slides]
- September 15th - JSFoo [Conference][Talk] - Safety Not Guaranteed - [Slides], [Video]
- July 14th - 15th - nullcon Hyderabad Conference [Conference][Training] - Xtreme Web Hacking
- June 24th - null Bangalore [Event][Workshop] - null Humla - Windows Privilege Escalation Techniques
- May 20th - null Bangalore [Event][Talk] - Wannacry - [Slides]
- May 18th - Research [Research][Technique] - A Windows UAC Bypass using Device Manager
- April 22nd - null Bangalore [Event][Talk] - Impacket Tools
- April 15th - null Bangalore [Event][Workshop] - null Humla - Solving Web CTF challenges
- March 18th - null Bangalore [Event][Talk] - Apache Struts RCE - CVE-2017-5638 - [Slides]
- March 11th - null Bangalore [Event][Workshop] - null Humla - Understanding and Exploiting SQL Injection flaws in Web Apps
- February 28th - 2nd March - nullcon Goa Conference [Conference][Training] - Cloud Security For Devs & Ops
- December 22nd - Research [Research][Tool] - Open sourced WinManipulate via Appsecco - A tool to manipulate Windows window objects like buttons, menu bars, text boxes, child windows, useful for Thick Client Pentesting
- December 17th - null Bangalore [Event][Talk] - An Introduction to SysInternal - [Slides]
- December 16th - null Dubai [Event][Talk] - An Introduction to SysInternal - [Slides]
- October 13th - 15th - nullcon Bangalore Conference [Conference][Training] - Xtreme Web Hacking
- June 11th - null Bangalore [Event][Talk] - Windows Privilege Escalation Techniques - [Slides]
- May 14th - null Bangalore [Event][Workshop] - null Puliya - Working with Virtual box for hands on sessions
- October 13th - 15th - nullcon Goa Conference [Conference][Training] - Xtreme Web Hacking
- August 20th - c0c0n [Conference][Talk] - Esoteric XSS Payloads - [Slides]
- August 20th - c0c0n [Conference][Training] - Xtreme Web Hacking Express
- August 4th - Def Con 24 Las Vegas [Conference][Workshop] - Ninja level Infrastructure Monitoring : Defensive approach to Security Monitoring & Automation
- January 16th - null Bangalore [Event][Workshop] - null Puliya - SysInternals Utilities
- October 31st - null Bangalore [Event][Workshop] - null Humla - Exploiting Windows Environments
- August 21st - c0c0n [Conference][Talk] - A Pentester's Methodology to Discover, Automate and Exploit Windows Privilege Escalation flaws - [Slides]
- August 19th - c0c0n [Conference][Training] - Xtreme Web Hacking Express
- July 25th - null Bangalore [Event][Talk] - Content security Policy - [Slides]
- February 28th - null Bangalore [Event][Workshop] - null Humla - Detecting & Exploiting SQL Injection in Restful Webservices
- February 4th - 5th - nullcon Bangalore [Conference][Training] - Xtreme Web Hacking
- October 18th - null Bangalore [Event][Talk] - Windows Post Exploitation techniques
- February 22nd - null Bangalore [Event][Talk] - The fall of a domain - [Slides]
- February 13th - nullcon Goa [Conference][Training] - Xtreme Web Hacking
- September 28th - c0c0n [Conference][Talk] - SSRF / XSPA - Real World Attacks and Mitigations - [Slides]
- May 11 - Research [Research][Technique] - XSPA / SSRF bug with Facebookβs Developer Web Application - [GitHub]
- February 27th - nullcon Goa [Conference][Training] - Xtreme Web Hacking
- December 6th - BlackHat Abu Dhabi [Conference][Talk] - Poking Servers with Facebook (and other Web Applications) - [Slides]
- December 6th - Web Hacking Top 10 Techniques Listing - Cross Site Port Attack (XSPA) recognized as one of the top 10 web hacking techniques of 2012
- November 7th - Cross Site Port Attacks (XSPA) - Pioneering 3-part research series published on blogPart 1, Part 2, Part 3
- October 25th - OWASP AppSecUSA [Conference][Talk] - Poking Servers with Facebook (and other Web Applications) - [Slides], [Video]
- October 13th - null Bangalore [Event][Talk] - Cross Site Port Attacks - [Slides]
- September 26th - nullcon Delhi [Conference][Talk] - Poking Servers with Facebook (and other Web Applications) - [Slides]
- September 24th - Research [Research][Technique] - XSPA / SSRF Vulnerability with the Yahoo! Developer Network - [Video]
- September 24th - Research [Research][Technique] - XSPA / SSRF Vulnerability with the Adobe Omniture Web Application - [Video]
- August 11th - null Bangalore [Event][Talk] - Web AppSec Basics - CSRF with Mutillidae
- June 30th - null Chennai [Event][Talk] - Deep(er) Penetration: Reaching the Internal Network using Exposed Web Applications - [Slides]
- May 16th - Research [Research][Technique] - Twitter Wipe Addressbook CSRF Vulnerability
- February 15th - nullcon Goa [Conference][Training] - Xtreme Web Hacking
- December 10th - null Bangalore [Event][Talk] - C0C0N CTF walkthrough - [Slides]
- October 8th - c0c0n [Conference][Talk] - Deep(er) Penetration: Reaching the Internal Network using Exposed Web Applications - [Slides]
- August 20th - null Bangalore [Event][Talk] - Cracking CTFs
- March 12th - null Bangalore [Event][Talk] - Hacking the null CTF Battle Underground
- February 28th - Research [Research][Technique] - Apache Archiva Multiple XSS & CSRF Vulnerabilities - CVE-ID-2011-1077, CVE-2011-1026
- February 12th - null Bangalore [Event][Talk] - Vulnerabilities in Openfire
- August 21st - null Bangalore [Event][Talk] - WEP Cracking Demo
- June 10th - null Bangalore [Event][Talk] - Joomla vulnerabilities - [Slides]
- May 13th - Research [Research][Technique] - Multiple Joomla! XSS Vulnerabilities - CVE-2010-1649
- July 22nd - Research [Research][Technique] - The Case of the Intelligent Spambot - Malware Research shared with Mark Russinovich (Microsoft/Sysinternals)
- July 7th - Research [Research][Technique] - The Case of the Persistent Executable - Malware Research shared with Mark Russinovich (Microsoft/Sysinternals)
- January - December - Built internal tools and delivered sessions at Microland for various teams.
- July 16th - Joined Microland - Systems Engineer - First job - Diving deeper into appsec, networking, systems administration, and security fundamentals
- January 29th - 3rd Year of Engineering - Authored First Book [Book] - A Beginner's Approach to Windows
Books
Awards & Recognition
- π Web Hacking Top 10 Techniques (2012) β “Cross Site Port Attack (XSPA)” recognized as one of the top 10 new web hacking techniques of 2012 by the security community.
- π€ Conference Speaker β Presented at BlackHat Abu Dhabi (2012), OWASP AppSecUSA (2012), c0c0n (2011, 2013, 2015, 2016), JSFoo (2017, 2018, 2019), nullcon Delhi/Goa/Bangalore/Hyderabad (2012β2023), fwd:cloudsec (2021), BSides Bangalore (2024), Seasides (2025, 2026), BSides London (2025), VulnCon (2026), OWASP Bay Area (2019, 2025), DeveloperWeek Europe (2021), KubeSec Online (2021), Rippling AI Security Event (2026).
- π Defcon USA Trainer β Trainer at Def Con 24 (2016) and Def Con USA (2026, upcoming).
- π Conference Trainer β Delivered multi-day training programs at nullcon Goa (2012β2023), nullcon Bangalore (2016, 2018, 2019), nullcon Hyderabad (2017), c0c0n (2015, 2016), and Seasides (2025, 2026). Training topics: Xtreme Web Hacking, Cloud Security for Devs & Ops, Breaking and Pwning Apps and Servers on AWS/Azure/GCP, Ninja Level Infrastructure Monitoring.
- π BSides Bangalore CFP Review Board β Served on the Call for Papers review committee.
- π₯ null Community β Active contributor since 2010. Delivered 40+ talks, workshops, and hands-on training sessions across null Bangalore, null Bhopal, null Chennai, and null Dubai chapters. Topics covered: web application security, Windows privilege escalation, AWS/cloud security, SQL injection, XXE, DevSecOps, Sysinternals, and CTF training.
- βοΈ AWS Community Builder (Security) β 3+ year recognition by AWS for security community contributions (2023βPresent).
- π Published Author β “Hands-On Application Penetration Testing with Burp Suite” (Packt Pub, 2019, co-author) and “A Beginner’s Approach to Windows” (Scribd, 2007).
Key Vulnerabilities & CVEs
- CVE-2010-1649 β Multiple Joomla! XSS Vulnerabilities (2010)
- CVE-2011-1077 β Apache Archiva Multiple XSS Vulnerabilities (2011)
- CVE-2011-1026 β Apache Archiva Multiple CSRF Vulnerabilities (2011)
- CVE-2019-12148 β Sangoma SBC 2.3.23-119-GA Authentication Bypass (2019)
- CVE-2019-12147 β Sangoma SBC 2.3.23-119-GA Unauthenticated User Creation (2019)
- Twitter Wipe Addressbook CSRF β Reported to Twitter Security (2012)
- Adobe Omniture SSRF/XSPA β Reported to Adobe Security (2013)
- Facebook Developer App SSRF/XSPA β Bug bounty finding (2013)
- Yahoo! Developer Network SSRF/XSPA β Reported to Yahoo! Security (2013)
Areas of Expertise
- Web Application Security - XSS, CSRF, SSRF, SQL Injection, XXE, RCE exploitation chains
- Cloud Security - AWS exploitation, IAM/RBAC abuse, serverless security, Kubernetes security
- Windows Security - UAC bypass, privilege escalation, malware analysis, WSL attack surface
- Open Source Tools - Python, Go, shell scripting - offensive security automation
- Training & Mentoring - SQL injection workshops, AWS security training, conference speaking, community building
Certifications
| Certification | Status | Notes |
|---|---|---|
| OSCP - Offensive Security Certified Professional | β Active | Offensive Security |
| CEH - Certified Ethical Hacker | β Active | EC-Council |
| CKA - Certified Kubernetes Administrator | β³ Expired | CNCF - previously held |
| CKAD - Certified Kubernetes Application Developer | β³ Expired | CNCF - previously held |
| AWS Community Builder (Security) | β Active | 3+ years - AWS community program |
This page is a living document β last updated June 2026. If you spot gaps or want to add details, reach out on Twitter or LinkedIn.