Karim Rustom

Karim Rustom is the Offensive Security Lead at Escape, an ethical hacker and OSCP-certified security professional specializing in web app and API security. His work sits at the intersection of hands-on OffSec, vulnerability research, and AI.

Karim Rustom

Karim Rustom — Last Publications

Two Critical Vulnerabilities, One AI Pentester: How Cascade Found an Unauthenticated RCE and Walked Around the WAF
AI pentesting

Two Critical Vulnerabilities, One AI Pentester: How Cascade Found an Unauthenticated RCE and Walked Around the WAF

TL;DR We pointed Cascade, Escape's AI pentesting solution, at a single Spring + JSP customer portal. It came back with two findings that are typically difficult for traditional Dynamic Application Security Testing (DAST) scanners to detect: * Unauthenticated RCE via SpEL injection. A ref request parameter was dropped, unsanitized,

  • Karim Rustom