At just 21, HEXER is a rising star in cybersecurity, specializing in web hacking, malware analysis, and AI vulnerabilities. With a passion for identifying flaws before attackers do, he digs through source code and binaries the way a wizard reads an ancient text โ patient, precise, and never satisfied until every claim is proven at runtime. From memory corruption in C/C++ codebases to SSRF and injection chains in modern web stacks, HEXER treats each target as a puzzle worth solving properly, not quickly.
name: Kanishka De Silva
alias: HEXER | H3X4R
sigil: ๐ the cobra strikes where the code is weakest
role: Independent Security Researcher
focus: Memory safety bugs, SSRF, injection, runtime-verified 0-days
methodology:
- Clone target at exact commit
- Build with ASan / UBSan / libFuzzer harnesses
- Runtime-confirm before ever reporting
- CVSS >= 5 as the reporting bar
- Self-correct false positives, openly
currently: BSc (Hons) Ethical Hacking and Network Security [2nd Year Reading @2026]
building: HunterX โ a multi-agent autonomous pentesting framework| Target | Finding | ID |
|---|---|---|
| Blitz Panel (v1.17.0 โ fixed 1.18.1) | Open redirect โ /login next_url |
CVE-2025-60935 |
| Blitz Panel (fixed 2.5.3) | Path traversal / arbitrary file access โ restore functionality | Release 2.5.3 |
| FreeRDP | Integer overflow โ heap buffer overflow | CVE-2026-57156 |
| FreeRDP | OOB read in the Planar RLE decoder | CVE-2026-57159 |
| OpenSSH | PAMServiceName silently ignored | Commit c66bef0 |

