Carlo Jae
Avila
Lead Offensive Security Engineer at Secuna. I break mobile apps for fun (still hunting for the profit part)
Android and iOS internals, malware analysis, forensics. Currently pushing into red teaming, OSINT, and offensive AI security research.
Security Research CVEs
AnkiDroid Open Source Team · AnkiDroid v2.17.6 · Feb 2025
Team Amaze · Amaze File Manager ≤ 3.8.5 · Feb 2024
hamza417 · Inure App Manager · Aug 2023
hamza417 · Inure App Manager · Aug 2023
hamza417 · Inure App Manager · Aug 2023
Team Amaze · Amaze File Utilities · WelcomeScreen.kt · Aug 2023
Certifications
mobile-heavy, all hands-on exams
CAAH
Certified Advanced Android Hacker
Advanced Android exploitation and vulnerability research, aimed at competition-grade targets.
verify ↗OMSE
Offensive Mobile Security Expert
iOS and Android security across userland and kernel, including vulnerability research.
verify ↗eMAPT
eLearnSecurity Mobile Application Penetration Tester
Android application penetration testing, assessed through a fully practical exam.
eWPTXv2
eLearnSecurity Web Application Penetration Tester eXtreme
Advanced web application exploitation and filter-bypass technique.
Work
Profiles
- Google Bug Hunters profile ↗
- HackerOne black_b3ard ↗
- Hack The Box profile ↗
- TryHackMe BLACKBEARD ↗
Projects
pwn_exhibit
Archive of CTF writeups and exploit dev notes — binary exploitation, Android reverse engineering, and malware analysis.