~/ whoami
Rishi — @rxerium

about rishi

Vulnerability researcher and threat intelligence specialist based in London, UK. Senior Security Researcher at KYND, volunteer at The Shadowserver Foundation, and part of the executive leadership of the UK OSINT community.

500+ nuclei templates
15+ conference talks
7 gov & cert citations
1m+ research impressions

profile

Rishi is a vulnerability researcher and threat intelligence specialist whose work has had global impact, recognised by government and law enforcement including the UK's National Cyber Security Centre (NCSC), CERT Polska, Cal-CSIC and more. A multi-time speaker at DEF CON and BSides, he has briefed UK Parliament and Government on emerging cyber threats and the evolving risks facing critical infrastructure.

He works across vulnerability research, threat intelligence, OSINT and attack surface management — finding and closing security gaps before attackers can reach them. Equally comfortable operating at the technical coalface and communicating risk at board level, he is also a committed open source contributor, giving back to the security community through personal projects, published tooling, and the open sharing of original research.

experience

The Shadowserver FoundationSecurity Researcher — Volunteer
Jan 2026 — Present
  • Develops detection signatures and internet-wide scans feeding daily CSIRT reports
  • Enriches threat intelligence informing government response
  • Supplies exposure data to CSIRTs and law enforcement
UK OSINTExecutive Leadership
Mar 2025 — Present
  • Strengthening sovereign UK intelligence capability
  • Produces high-quality OSINT educational content
  • Organises and hosts OSINT events across the UK
KYNDSenior Security Researcher
Feb 2022 — Present
  • Leads enterprise vulnerability research
  • Architected an internet-wide platform scanning millions of assets
  • Authors advisories translating CVE, CVSS and EPSS data into business risk
  • Mapped 100+ AI/ML products to build emerging-technology exposure coverage
  • Provides expert commentary to media on emerging CVEs and trends
  • Mentors junior researchers and sets detection-engineering standards
ECCFirst Line Support Engineer
Jan 2020 — Aug 2021
  • Delivered network and endpoint support within SLA across 500 customers
  • Led Windows 10 migration and MFA rollout to 2000 endpoints
  • Maintained EPP/MDR, Active Directory and O365 / Google Workspace

affiliations

ProjectDiscovery Pioneer
Oct 2024 — Present
  • Authored 500+ Nuclei detection templates used worldwide
  • Shapes PD Cloud through beta testing and product guidance
  • Authors technical blog content for ProjectDiscovery
OWASP Member
Feb 2025 — Present
  • Contributes to Amass, OWASP's attack surface framework
  • Contributes to Nettacker, an automated recon framework
  • Supported the OWASP Amass workshop at DEF CON 33

recognition

Government & CERT Recognition
2024 — Present
  • NCSC (UK) recognised detection script for CVE-2025-10035
  • CERT Polska adopted detection scripts into their tooling (CVE-2025-49113, CVE-2025-68461)
  • Cal-CSIC cited detection for CVE-2025-10035 in an official cyber advisory
  • NIST / NVD featured detection script on the official CVE-2023-40000 advisory
  • INCIBE (Spain) referenced detection script for CVE-2023-40000
  • CIRCL (Luxembourg) referenced vulnerability research
  • Government of Vietnam cited detection work in national advisories
Industry Citations
2024 — Present
  • Research cited by SonicWall, Qualys, Censys, ReSecurity, Coalition, Intruder, Black Kite, Feedly, PT Security, DarkWebInformer and others
  • Featured by GBHackers, CyberPress and lebigdata.fr
  • Research posts amassing 1M+ impressions on X over the past year
BSides Las Vegas
Aug 2025
  • Won the ProsVJoes capture-the-flag competition

research

Jan 2026 Dec 2025 Jun 2025 Apr 2025 Mar 2024

speaking

Multi-time speaker at DEF CON (Red Team Village, Recon Village, Social Engineering Village), the BSides circuit across Europe and the US, OWASP London, and GrrCON — plus a policy briefing at UK Parliament on vulnerability research and software supply chain security.

qualifications

  • BSc (Hons) Cyber Security Technical Professional — in progress
  • Anthropic Academy — Mar 2026
  • Communication, Leadership & Management — Aug 2025
  • C&G Level 4 Cyber Security Analyst — Mar 2024
  • BCS Level 3 Infrastructure Technician — Aug 2021

skills

domains
vulnerability research threat intelligence detection engineering osint attack surface management supply chain security
tooling & techniques
nuclei amass shodan dns osint certificate transparency shadowserver fingerprinting go cve / cvss / epss analysis

Want the full CV?

Open to security collaborations, speaking engagements, and media commentary.

request cv