Security Research · Web · Mobile · AI

Finding and documenting how systems break.

I'm Liliane Zukerman, a security researcher with a background in offensive security and malware analysis. I work on the vulnerabilities that matter in web applications, mobile platforms, and AI-based systems, and I write up what I find.

Read the research →
01 / research

Writeups & vulnerability analysis

Reproducible analysis of real vulnerabilities: root cause, proof of concept, and practical guidance for detection and mitigation. Focused on web, mobile, and AI systems.

CVE-2026-88028 / CVE-2026-88027: Query-Operator Injection in Laravel MongoDB Relation Identifiers
Root cause analysis and proof of concept for unauthorized document disclosure via query-operator injection in mongodb/laravel-mongodb < 5.11.0. CVSS 7.1 HIGH · CWE-943.
02 / about

About

I'm passionate about technology and security. Over close to two decades in the field, I've moved from infrastructure and network administration into penetration testing, offensive security, and malware analysis and reverse engineering.

Today my focus is research across web, mobile, and AI systems. My academic background started in physics and moved into computer science. I'm fluent in English and Portuguese, and I speak basic Hebrew.

Certifications

Education

03 / contact

Get in touch

Open to security research collaboration, consulting, and conversations about interesting vulnerabilities. The best way to reach me: