About the operator
Matt Moreschi
Founder of Inject and of Brackish Security. Offensive security practitioner across network, web, mobile, and embedded targets, with 13 published CVE records to show for it.
Why this matters when you hire a testing firm
Most penetration testing is sold by one group of people and performed by another. You meet a principal during the sales cycle, sign a statement of work, and then the engagement is delivered by whoever was available that sprint — frequently someone two years into the field running a commercial scanner and reformatting its output.
Inject exists to remove that gap. The person who scopes your engagement is the person who tests it and the person who writes the report. There is no bench, no handoff, and no template with your logo dropped onto the cover.
The certifications below matter less than what they represent. OSCP, OSWE, and OSEP are all practical exams — you compromise live systems under time pressure and document how, or you fail. OSWE in particular requires reading application source code, identifying a vulnerability chain, and writing working exploit code within 48 hours. That is the same work your web application assessment involves.
The CVE record is the part that cannot be studied for. Finding a vulnerability nobody has found before, in software with real users, and taking it through coordinated disclosure to a published identifier is a different exercise from confirming a known issue in your environment. Every entry in the list further down this page went through that process, and several of them affected products with substantial installed bases — a consumer garage door platform, a campus tutoring system, a widely used surveillance package.
Practical experience spans offensive security assessments and research support for large education systems, medical organizations, and government institutions, with an emphasis on real-world risk reduction rather than finding volume. The engagement is worth something when it changes what you fix, not when it produces the longest appendix.
Recognition
- 2023Department of Defense Vulnerability Disclosure Program Researcher of the Year
- Annual recognition for vulnerability research submitted through the Department of Defense vulnerability disclosure program.
- 2024State of California Top 25 Researcher
- Ranked among the top 25 researchers reporting vulnerabilities to the State of California disclosure program.
Certifications and education
- OSEPOffensive Security Experienced Penetration TesterOffSec
- Advanced evasion and lateral movement against defended Active Directory environments. The exam is a 48-hour hands-on compromise of a hardened network with endpoint protection in place.
- OSWEOffensive Security Web ExpertOffSec
- White-box web application exploitation. Requires reading application source, identifying the vulnerability chain, and writing working exploit code within a 48-hour exam window.
- OSCPOffensive Security Certified ProfessionalOffSec
- The baseline hands-on penetration testing certification, earned by compromising a live lab network under exam conditions rather than by answering multiple-choice questions.
- InsightVMRapid7 InsightVM Certified AdministratorRapid7
- Enterprise vulnerability management program design and operation — the defensive counterpart to offensive testing, and the reason our remediation guidance fits how your VM program actually works.
- CCNACisco Certified Network AssociateCisco
- Routing, switching, and network fundamentals. Segmentation testing and internal network assessment depend on understanding how the network was supposed to be built.
- Security+CompTIA Security+CompTIA
- DoD 8570 baseline certification for information assurance roles, frequently a contractual requirement for government and defense-adjacent engagements.
- BSBachelor of Science, ChemistryUniversity degree
- A laboratory science background, which is a better preparation for methodical vulnerability research than it sounds: hypothesis, controlled test, reproducible result, written up.
Published vulnerability research
13 CVE records published through the National Vulnerability Database, each found through original research and taken through coordinated disclosure with the vendor. Every identifier below links to its NVD entry.
- CVE-2025-46348Critical · 10.0
- CVE-2023-24080Critical · 9.8
- CVE-2022-35122Critical · 9.1
- CVE-2023-28627High · 8.3
- CVE-2021-35196High · 7.8
- CVE-2022-25568High · 7.5
- CVE-2022-43264High · 7.5
- CVE-2021-44255High · 7.2
- CVE-2025-46346Medium · 6.3
- CVE-2022-43263Medium · 6.1
- CVE-2025-46347Medium · 5.8
- CVE-2021-35959Medium · 5.4
- CVE-2023-24081Medium · 5.4
- CVE-2023-27109Unpublished
Other work
- Brackish Security
- Offensive security firm, founded and operated. Penetration testing and security research for education systems, healthcare organizations, and government institutions.
- templatesearch.io
- Search interface over more than 13,000 ProjectDiscovery Nuclei templates, filterable by CVE, severity, name, and description.
- techreport.io
- Consumer electronics reviews and teardowns, organized by category with structured scoring and search.
- brickreport.io
- Review publication with structured scoring, category browsing, and a large editorial library.
Work with the person who does the testing.
Scoping calls run about twenty minutes and end with a recommendation, including when the recommendation is a smaller engagement than you asked about.