I’m Anas Hamidi — an Application Security Researcher and Penetration Tester based in Germany, focused on web and API security.

I’ve responsibly disclosed 50+ vulnerabilities to companies like Canva, Pexels,Axis Communications,Loveholidays,Inshur, GlanceCX and Lichess through HackerOne and Bugcrowd — including a critical bug at Canva. On this blog I share hands-on write-ups, tooling notes, and curated news from the offensive security world — practical notes from real testing, not theory.

I also mentor students in offensive security with Rushd , and research alongside the team at HAK-MZ.

Open to Opportunities

I’m currently open to roles in Penetration Testing, Application Security, or Security Engineering (within Germany). For the full picture, check out my CV.

Reach out via LinkedIn, Telegram, or contact@anashamidi.com.