Umut Can Yurdayardım · Penetration Tester

Security is neverjust the job.

I’m a penetration tester and vulnerability researcher with a genuine passion for security. I assess systems, validate vulnerabilities, and report findings clearly so they can be understood and fixed.

01 · Certifications

Certifications along the way.

eJPT, eWPTX, and CEH mark different stages of my development in offensive security, supported by the hands-on work I continue to do.

01
eJPT

Junior Penetration Tester

Practical offensive-security foundation

02
eWPTX

Web Application Penetration Tester eXtreme

Advanced web exploitation and assessment

03
CEH

Certified Ethical Hacker

Broad attack-surface and security methodology

02 · Vulnerability research

Research, documented.

Two CVE records assigned through independent vulnerability research and responsible coordination with the affected vendors.

RESEARCH REF. 01RESPONSIBLE DISCLOSURE

CVE-2026-13432

VIEW RECORD

Published through the CVE Program following independent research and responsible disclosure.

RESEARCH REF. 02RESPONSIBLE DISCLOSURE

CVE-2026-10029

VIEW RECORD

Published through the CVE Program following independent research and responsible disclosure.

04 · Attack surface

What I work on.

My main focus is web application and API security, alongside practical experience in network and mobile penetration testing.

01CORE SPECIALTY

Web Applications

Deep manual assessment of authorization, authentication, business logic, injection paths, and client-server trust.

02CORE SPECIALTY

API Security

Object- and function-level authorization, token handling, workflow abuse, schema behavior, and data exposure.

03CORE PRACTICE

Network

Infrastructure discovery, service enumeration, segmentation review, and configuration testing.

04CORE PRACTICE

Mobile

Android application assessment across storage, transport, platform configuration, and backend interaction.

05 · Security contributions

A record of responsible disclosure.

Selected organizations whose security I’ve contributed to by identifying and responsibly reporting vulnerabilities.

Coolblue
Decathlon
OTTO
TOOM
AnyTask
Upwork
Enterprise Rent-A-Car
Kaspersky
R10.net

A selected view—not the full list.

06 · Contact

Let’s talk security.

For penetration testing, collaboration, or responsible disclosure, email is the best way to reach me. You can also find my work and updates through the channels below.