/vcth4nh
Vũ Chí Thành
Vulnerability researcher building exploits and AI-assisted security tooling.
Profile
I investigate the assumptions around authentication, trust boundaries, and complex application behavior—then turn the findings into clear, reproducible security research. Experienced across web, mobile, IoT, exploit development, and LLM-assisted security workflows.
Experience
Cyber Security Specialist
VinSOC · Security Technology Research Department
- Built LLM-integrated offensive tooling for patch diffing, fuzz-harness generation, and exploit prototyping.
- Engineered custom exploits and infrastructure for red-team operations.
Cyber Security Researcher
Viettel Cyber Security · Offensive Security Service Center
- Researched pre-authentication vulnerabilities across web, mobile, and IoT products.
- Produced proofs of concept and coordinated responsible disclosure leading to vendor advisories and CVE records.
Cyber Security Mentor
Korea Internet & Security Agency · Part-time
- Led small-cohort exploitation labs, project guidance, and career mentoring.
Cyber Security Research Intern
Viettel Cyber Security · Part-time
- Trained across application security, systems security, red teaming, and exploit analysis.
Selected security research
GoAnywhere MFT authentication boundary
CVE-2024-0204 · CVE-2024-25156
Independently discovered and reported pre-authentication administrative access and a related path-traversal weakness. Fortra credits vcth4nh for CVE-2024-25156.
a-blog cms vulnerability chain
CVE-2025-36560 · CVE-2025-41429
Reported unauthenticated SSRF and improper log neutralization that could be chained into administrative session compromise; credited by JPCERT/CC.
authentik SAML identity mismatch
CVE-2026-57580 · GHSA-35v6-hv2g-6992 · independent research
Independently reported an XML-comment interpretation conflict in signed SAML NameIDs that could persistently bind an attacker's external identity to an existing account.
9Router unauthenticated RCE
GHSA-g6g7-pvmx-m74p · co-research with Ductinn
Reported missing authentication and operating-system command injection in the open-source project.
Selected projects
IdeSense
Creator · Kotlin, JetBrains Platform, MCP
MCP server exposing IDE indexing, navigation, diagnostics, and refactoring to coding agents.
decaf
Creator · Python, Java
Sources-first Java decompiler CLI with five-engine automatic fallback and nested archive support.