Product engineer · Application security researcher
I ship native, mobile, and web products — and I take apart other people's.
Two disciplines, one habit: read the system until it gives up its assumptions.
Building — native desktop in Rust, iOS and watchOS in Swift, cross-platform in Flutter, web in TypeScript. I own the whole line: interface, API, data model, deployment, and the App Store review that follows.
Breaking — authentication, authorization, business logic, API surface, and data exposure. Everything goes through responsible disclosure, and I hold details until the vendor ships a fix.
| Product | Platform | What it is |
|---|---|---|
| Zolt | macOS · Windows · Linux | GPU-rendered database client written in Rust on GPUI. 120 fps across Postgres, MySQL, SQLite, Redis, and MongoDB — no Electron. |
| Trade Buddy | Web · iOS | Trading journal with a visual PnL calendar, AI coaching, and decision-grade performance analytics. |
| Korva | Desktop | Offline Microsoft Publisher alternative that opens real .pub files and exports print-ready PDF. |
|
The Fixed in the June 2026 servicing release: SDK |
Fourteen more records across the WordPress ecosystem, sorted by CVSS base score.
| CVE | CVSS | Product | Class |
|---|---|---|---|
| CVE-2026-7458 | 🔴 9.8 Critical | User Verification | Authentication bypass |
| CVE-2026-57739 | 🔴 9.3 Critical | AcyMailing SMTP Newsletter | Blind SQL injection |
| CVE-2026-42747 | 🔴 9.3 Critical | Easy Form Builder | Blind SQL injection |
| CVE-2026-7465 | 🟠 8.8 High | Spectra Gutenberg Blocks | Remote code execution |
| CVE-2026-48874 | 🟠 8.5 High | GamiPress | SQL injection |
| CVE-2026-3453 | 🟠 8.1 High | ProfilePress | Subscription IDOR |
| CVE-2026-3629 | 🟠 8.1 High | Import and export users | Privilege escalation |
| CVE-2026-49112 | 🟠 7.5 High | Shared Files | Path traversal |
| CVE-2026-3454 | 🟡 6.5 Medium | GenerateBlocks | Sensitive data exposure |
| CVE-2026-48965 | 🟡 6.5 Medium | XCloner | Sensitive data exposure |
| CVE-2026-3722 | 🟡 6.4 Medium | Auto Image Attributes | Stored XSS |
| CVE-2026-3361 | 🟡 6.4 Medium | WP Store Locator | Stored XSS |
| CVE-2026-3369 | 🟡 5.4 Medium | Better Find and Replace | Stored XSS |
| CVE-2026-4664 | 🟡 5.3 Medium | Customer Reviews for WooCommerce | Authentication bypass |
Combined reach of the affected WordPress plugins is over 1.6 million active installs, with a single record — Spectra — covering 1M+ on its own.
| Target | Status |
|---|---|
| NoMachine | Private research, details withheld |
| Foxit PDF | Private research, details withheld |
| Additional vendors | In the disclosure queue |
Details go public when the vendor ships, not before.
Languages — Rust · Swift · Dart · TypeScript · Go · PHP · C# · Solidity
Native & mobile — GPUI · SwiftUI · watchOS · Flutter · Android
Web — Next.js · Nuxt · Svelte · Astro · Node.js · NestJS · Express
Data & infra — PostgreSQL · MongoDB · RabbitMQ · Google Pub/Sub · Docker · Nginx · Google Cloud · Cloudflare · Linux
korsund.com — full portfolio and disclosure archive
App Store · Google Play — published apps
Open to security research collaboration and product work. Reach me at supanat0245@gmail.com.
Counts current as of July 2026.






