Independent security research · Offensive engineering
I find the assumptions software shouldn’t make.
Michael Holmquist is a security researcher focused on finding consequential flaws in web applications, AI/ML systems, ICS, and mission-critical platforms.
09Published CVEs
101Disclosures
100%Responsible disclosure
Scroll to examine findings ↓
01
Vulnerability research
Published findings only. Technical details are shared after coordinated disclosure.
02
Highlighted Projects
Tools and experiments built to make security research faster, deeper, and more repeatable.
03
Research philosophy
Break thoughtfully. Report responsibly.
I approach vulnerability research as engineering: form a hypothesis, trace the trust boundary, prove impact, and leave maintainers with enough evidence to fix the root cause.
My current work explores agent-assisted source review, variant analysis, and attack-path-driven prioritization.