Hello friend!

My name is João Marono, but I’m also known as r0n0. Besides working as SOC Eng, I like to delve into anything related to cybersecurity. From Android Hacking to Web security. You can find me in the next ctf playing with the team pwn_of_b4c4lh4u or just by testing the security of your favorite app, who knows.

Vulnerabilities Found

  • Telecom company in Portugal: Bypassing a captcha to get valid phone numbers for the platform.(#Bug Bounty)
  • Apache Superset: CVE-2025-27696 - Vulnerability in import function allows for a low privileged user to get ownership of resources.(#Open Source Project) Soon post coming!

Event Wins

  • CTF Bsides Lisbon 2024(team pwn_of_b4c4lh4u)

Certificates

Hackthebox Profile