Kyllian
Van Goidsenhoven

Cybersecurity graduate to-be · Offensive pentesting · Blue team

Passionate about offensive-defensive cybersecurity, machine learning applied to security, and CTFs. Bachelor's student at HELMo Liège (2026).

Latest writeups

All writeups →
Hack The Box Medium

DevHub

From anonymous RCE on an MCP server all the way to root: leaked Jupyter tokens, code execution over WebSocket and a hidden tool that dumps root's SSH key.

MCPJupyterWebSocketRCECVE-2026-23744