↓ Skip to main content
Patrik Grobshäuser

Patrik Grobshäuser

Security researcher at Assetnote, a Searchlight Cyber company, finding pre-auth vulnerabilities in software that is deployed everywhere. Before that, bug bounty and triage at HackerOne and Shopify.

Where was Mythos when WordPress fell?

On marketing claims nobody checks, the 1,000 projects Anthropic never listed, and why an industry full of experts followed along.

Recent posts

View all

Google Cloud Console: dormant stored XSS

An XSS payload stored as a Google Cloud project name executed months later in the unfiltered project-deletion error message, earning a $5,000 VRP reward, plus the impact argument that got it past a self-XSS classification.

Selected research

All research

Projects

Research tooling

h1-brain

An MCP server that turns your HackerOne report history and public disclosures into a starting point for your next bug bounty hunt.

Vulnerability intelligence

RD Intelligence

A platform that brings together vulnerability disclosures, exploit activity, and threat context to help teams decide what to investigate first.

Security consulting

threatover

My security consulting practice, covering penetration testing, security advisory, bug bounty programmes, and vulnerability triage.

Browse by topic

All topics