Product engineer · Application security researcher
I ship native, mobile, and web products — and I take apart other people's.
Two disciplines, one habit: read the system until it gives up its assumptions.
Building — native desktop in Rust, iOS and watchOS in Swift, cross-platform in Flutter, web in TypeScript. I own the whole line: interface, API, data model, deployment, and the App Store review that follows.
Breaking — authentication, authorization, business logic, API surface, and data exposure. Everything goes through responsible disclosure, and I hold details until the vendor ships a fix.
| Product | Platform | What it is |
|---|---|---|
| Zolt | macOS · Windows · Linux | GPU-rendered database client written in Rust on GPUI. 120 fps across Postgres, MySQL, SQLite, Redis, and MongoDB — no Electron. |
| Trade Buddy | Web · iOS | Trading journal with a visual PnL calendar, AI coaching, and decision-grade performance analytics. |
| Korva | Desktop | Offline Microsoft Publisher alternative that opens real .pub files and exports print-ready PDF. |
|
The Fixed in the June 2026 servicing release: SDK |
|
A heap-based buffer overflow in the WPF .NET Desktop Runtime. At the native-to-managed boundary, a marshaling path fails to validate a buffer length before writing past its bounds — an out-of-bounds write on the native heap. A local attacker who gets a user to run crafted content can corrupt heap memory and execute arbitrary instructions at higher privilege. Fixed in Microsoft's August 2026 Patch Tuesday servicing release (August 11, 2026). Apply the current .NET Desktop Runtime and Visual Studio updates. |
Fourteen more records across the WordPress ecosystem, sorted by CVSS base score.
| CVE | CVSS | Product | Class |
|---|---|---|---|
| CVE-2026-7458 | 🔴 9.8 Critical | User Verification | Authentication bypass |
| CVE-2026-57739 | 🔴 9.3 Critical | AcyMailing SMTP Newsletter | Blind SQL injection |
| CVE-2026-42747 | 🔴 9.3 Critical | Easy Form Builder | Blind SQL injection |
| CVE-2026-7465 | 🟠 8.8 High | Spectra Gutenberg Blocks | Remote code execution |
| CVE-2026-48874 | 🟠 8.5 High | GamiPress | SQL injection |
| CVE-2026-3453 | 🟠 8.1 High | ProfilePress | Subscription IDOR |
| CVE-2026-3629 | 🟠 8.1 High | Import and export users | Privilege escalation |
| CVE-2026-49112 | 🟠 7.5 High | Shared Files | Path traversal |
| CVE-2026-3454 | 🟡 6.5 Medium | GenerateBlocks | Sensitive data exposure |
| CVE-2026-48965 | 🟡 6.5 Medium | XCloner | Sensitive data exposure |
| CVE-2026-3722 | 🟡 6.4 Medium | Auto Image Attributes | Stored XSS |
| CVE-2026-3361 | 🟡 6.4 Medium | WP Store Locator | Stored XSS |
| CVE-2026-3369 | 🟡 5.4 Medium | Better Find and Replace | Stored XSS |
| CVE-2026-4664 | 🟡 5.3 Medium | Customer Reviews for WooCommerce | Authentication bypass |
Combined reach of the affected WordPress plugins is over 1.6 million active installs, with a single record — Spectra — covering 1M+ on its own.
| Target | Status |
|---|---|
| NoMachine | Private research, details withheld |
| Foxit PDF | Private research, details withheld |
| Additional vendors | In the disclosure queue |
Details go public when the vendor ships, not before.
Languages — Rust · Swift · Dart · TypeScript · Go · PHP · C# · Solidity
Native & mobile — GPUI · SwiftUI · watchOS · Flutter · Android
Web — Next.js · Nuxt · Svelte · Astro · Node.js · NestJS · Express
Data & infra — PostgreSQL · MongoDB · RabbitMQ · Google Pub/Sub · Docker · Nginx · Google Cloud · Cloudflare · Linux
korsund.com — full portfolio and disclosure archive
App Store · Google Play — published apps
Open to security research collaboration and product work. Reach me at supanat0245@gmail.com.
Counts current as of August 2026.






