César Cerrudo
Over 25 years finding security flaws before criminals do — in Microsoft and Oracle software, in social networks, and even in New York City's traffic lights. Today he devotes that experience to helping anyone defend themselves in the digital world.
From Paraná to the world map of information security
César Cerrudo was born in Paraná, Entre Ríos (Argentina), and became one of the Spanish-speaking security researchers most cited by the international press. Self-taught, he began researching software vulnerabilities in the late 1990s and has devoted his career to a single principle ever since: finding security problems before criminals do — and getting them fixed.
He is the founder and CEO of Argeniss Software, and currently works as a cybersecurity advisor for companies, institutions and governments. In 2026 he launched Mission 1 Million: getting one million people to learn how to defend themselves from digital threats through his free book and the educational resources that accompany it.
Over 25 years of security research
- Vulnerability research: identified hundreds of security problems in technologies from Microsoft, Oracle, Twitter, IBM and many other companies — flaws that affected millions of people and were fixed thanks to his reports.
- Technical leadership: served as CTO of IOActive Labs, the research division of the international security firm IOActive.
- Entrepreneurship: founder and CEO of Argeniss Software, a software development company.
- Advisory: cybersecurity consultant for companies, institutions and governments.
- Public education: author of the free book A Hacker's Security Guide and of the project's educational resources (academy, scam simulator, school kit).
Research that changed the conversation
New York City's traffic lights (2014). He demonstrated that some 200,000 traffic control sensors installed in cities such as New York, Washington D.C., San Francisco and London communicated without encryption and could be manipulated remotely. The research, covered by WIRED and The New York Times, brought him worldwide recognition and forced a rethink of urban infrastructure security.
Vulnerable smart cities. His pioneering work on smart city risks — from traffic systems to municipal services — was covered by The Wall Street Journal, the Financial Times and Bloomberg, and drove the collaborative Securing Smart Cities initiative.
Enterprise software vulnerabilities. Over two decades he reported critical flaws in products from Microsoft, Oracle and other vendors, contributing to the security of software used by millions of people and companies every day.
Speaker on the world's security stages
He has presented his research at the world's leading information security conferences, including Black Hat, DEF CON and RSA Conference in the United States, as well as at leading Spanish-speaking events such as Ekoparty (Buenos Aires) and 8.8 (Chile), where he was announced as a keynote speaker for the 2026 edition.
He has also given talks and training sessions at companies and institutions in several countries on digital threats, infrastructure security and protecting people.
Papers, whitepapers and technical articles
- "An Emerging US (and World) Threat: Cities Wide Open to Cyber Attacks" (IOActive, 2015) — the reference whitepaper on smart cities' exposure to cyberattacks, cited by Communications of the ACM and media worldwide.
- "Hacking US Traffic Control Systems" (DEF CON 22, 2014) — the research on the traffic control systems of New York and other cities, presented at DEF CON.
- "Token Kidnapping" y "Token Kidnapping's Revenge" (2008–2010) — a series of Windows privilege-escalation research pieces presented at Microsoft BlueHat, DEF CON 18 and Ekoparty, covered by specialized media such as Threatpost.
- Numerous security advisories and technical papers on vulnerabilities in SQL Server, Oracle, Windows and other enterprise software published throughout his career.
His work in the international press
- The New York TimesTraffic Hacking: Caution Light Is On
- TIME5 Easy Ways to Hacker-Proof Your Home
- WIREDHackers Can Mess With Traffic Lights
- Wall Street JournalHow Hackers Could Break Into the Smart City
- Financial TimesSmart cities coverage
- BloombergAtlanta's Ransomware Attack
- BBCVideo interview
- CNNVideo interview
- La TerceraThe Argentine who hacked NYC's traffic lights
- El ObservadorMission 1 Million
- ClarínA hacker's advice on AI-era scams
A Hacker's Security Guide
How to protect your data, your family and your business from digital threats (2026). Written for everyone, jargon-free, from the perspective of someone who spent 25 years thinking the way attackers think. With a foreword by Chema Alonso.
It covers everything from passwords, phones and scams to protecting children online and the new threats of artificial intelligence. It is distributed free in PDF and Epub, in English, Spanish and Portuguese, under a Creative Commons license (CC BY 4.0), as part of Mission 1 Million.
DOWNLOAD THE BOOK FREE →Writing for the public
- He was a member of the Forbes Technology Council, where he published articles on cybersecurity and technology for an executive audience.
- Columnist at Dark Reading, one of the leading information security outlets, where he published articles on smart cities, infrastructure and vulnerability management.
- Author of public-awareness articles on LinkedIn about threats to connected cities.
- Author of this site's digital security guides (in Spanish): what to do if your WhatsApp or Instagram gets hacked, how to spot phishing, scams, AI-cloned voices and deepfakes, among others.
- Creator of the content of the Digital Security Academy and of the project's free educational material: infographics and a kit for workshops in schools and companies.