BSides Tallinn 2025

When 1 + 1 = 11: The Hidden Math of Application Vulnerabilities
2025-09-25 , Stage 2

Manual penetration tests don’t always reveal critical vulnerabilities — but even minor issues, when linked together, can result in significant risks. In this session, Axinom and Neverhack share highlights from a recent engagement that brought such vulnerability chains to light. You’ll also discover how a single pentest can deliver value across multiple areas within a company, turning one investment into value several times over.

Giorgi is a Senior Penetration Tester at NEVERHACK Estonia specializing in web and mobile application security. He is experienced in uncovering complex vulnerabilities through manual testing and advanced logic flaw exploitation. Giorgi conducts ethical social engineering engagements to identify and improve human-related security weaknesses. He also brings a practical, business-aware approach to offensive security, helping teams turn findings into real improvements. On top of everything he is a creator of Security Summit CTF Challenge.