PENETRATION TESTER · BUG BOUNTY HUNTER
Security
testing.
Research.
I’m Niccolò Parlanti, a penetration tester and bug bounty hunter. I offer freelance security testing for web applications and APIs.
Penetration testing
Vulnerability research
Triage & campaign management
01 / WORK WITH ME
Freelance
penetration testing.
I work with teams that need an independent security assessment of their web applications or APIs. We agree on the scope, access, and timing before testing starts.
Discuss a pentest- Application & API testing
- Manual testing of authentication, access controls, business logic, and the way components interact.
- Technical reporting
- Findings with reproducible evidence, an explanation of the impact, and practical remediation guidance.
- Findings walkthrough
- A discussion of the results with your team. Follow-up testing can be agreed as part of the scope.
02 / SELECTED RESEARCH
Findings & writeups.
Root causes, evidence, and lessons from testing real applications.
When an echo endpoint becomes a script runner
A missing Content-Type header, Go’s MIME detection, and the browser behavior behind CVE-2026-43644.
The moment JSON stops being data
Following a constructor name into dynamic code generation in TeleJSON.
THE BUG CODE
Rules applications learn the hard way.
A casebook of broken assumptions, code, and evidence.
03 / THE DAY JOB
Testing.
Research.
Triage.
My work at UNGUESS.
Alongside penetration testing and independent bug bounty research, I manage vulnerability triage and security testing campaigns for private organizations at UNGUESS.
I assess reported vulnerabilities, review the evidence, and help make the impact and next steps clear.
More about my workCONTACT
Need a
penetration test?
Email me Send me a brief description of your project and your preferred timeframe. We can discuss scope and availability.
parlanti.niccolo@gmail.com