Skip to main content
open to security & platform rolesnewnol@research-lab:~

$ whoami

Ngô Tấn Tài/ newnol

Security Researcher & Cloud Infrastructure Engineer

3 CVE IDs · API security · source-code review · responsible disclosure

Cloud infrastructure · Kubernetes · Terraform · Ansible

DevSecOps · CI/CD · observability · Linux hardening

AI infrastructure & intelligent automation systems

newnol — interactive shell
newnol@homelab:~
$whoami
newnol
$help
Available commands:
whoami - Display current user
ls - List directory contents
cd <dir> - Change directory
cat <file> - Display file contents
pwd - Print working directory
docker ps - List running containers (simulated)
ssh <host> - Connect to server (simulated)
skills - Show technical skills
projects - List projects
contact - Show contact information
clear - Clear terminal
help - Show this help message
Try: cat about.txt, ls projects/, skills
$
Tip: Use Tab for completion, ↑/↓ for history, type "help" for commands
Ngô Tấn Tài (Newnol) - Security Researcher and Cloud Infrastructure Engineer
Chapter 01 · security research

$ cat research/9router.md

A coordinated open-source security review that produced three CVE IDs across authentication, credential handling, and AI conversation privacy.

3
CVE IDs
2
Critical findings
9.3
Highest CNA CVSS v4
Public
Responsible disclosure
CVE-2026-59801
Critical · CNA 9.3

Unauthenticated provider-management API access

Provider-management routes accepted requests without authentication, allowing remote users to enumerate, create, modify, or delete provider connections.

affected
9Router <= 0.4.41
weakness
CWE-306
View NVD record
CVE-2026-62327
Critical · CNA 9.3

Plaintext AI provider API-key exposure

An unauthenticated usage endpoint returned complete provider API keys together with usage and billing metadata.

affected
9Router <= 0.4.41
weakness
CWE-306 · CWE-522
View NVD record
CVE-2026-62328
High · CNA 8.7

AI request-log and conversation-history disclosure

Unprotected usage routes exposed request metadata and complete AI conversation histories to unauthenticated users.

affected
9Router <= 0.4.41
weakness
CWE-359 · CWE-862
View NVD record

GHSA-vjc7-jrh9-9j86

Read the coordinated disclosure case

Review the timeline, methodology, root causes, CNA scoring, remediation guidance, public references, and responsible-research boundaries behind the three findings.

View Security Research
Chapter 02 · selected projects

$ ls -la projects/featured/

Four representative projects selected for evidence, technical depth, and alignment with security, platform, infrastructure, and private AI work.

9Router Security Research project visual
Completed

9Router Security Research

2026

A coordinated open-source security review resulting in three CVE IDs across API authentication, credential exposure, and AI conversation privacy.

Source Code Review
API Security
Next.js
Responsible Disclosure
CVE
YAS (Yet Another Shop) CI/CD project visual
In Progress

YAS (Yet Another Shop) CI/CD

2026

Advanced CI/CD pipeline and Kubernetes deployment for a Java Spring Boot microservices architecture.

Kubernetes
Jenkins
Java Spring Boot
Docker
Kafka
PostgreSQL
Keycloak
Homelab Infrastructure Automation project visual
In Progress

Homelab Infrastructure Automation

2026

Automated provisioning and configuration of Proxmox VMs using Terraform and Ansible with GitOps principles.

Terraform
Ansible
Proxmox VE
Docker
Prometheus
Grafana
Open WebUI Tools project visual
In Progress

Open WebUI Tools

2026

Task-specific Open WebUI tools for transcript extraction, diagram generation, and smarter LLM workflows.

Python
Open WebUI
Selenium
LLM Tools
Chapter 03 · capabilities

$ ls -la capabilities/

Security research grounded in practical infrastructure engineering: understand how systems fail, then build clearer boundaries, safer delivery, and more reliable operations.

Security Research

Source-code review, API authentication and authorization testing, vulnerability reproduction, and responsible disclosure.

API Security
Code Review
CVE
Technical Writing

Cloud & DevSecOps

Delivery pipelines, container platforms, hardening, observability, and reliable operations across cloud and self-hosted systems.

Kubernetes
Docker
GitHub Actions
Jenkins

Infrastructure

Reproducible infrastructure and networking built with declarative automation and measurable operational health.

Terraform
Ansible
Proxmox
Prometheus

AI Systems

Private AI infrastructure, model routing, task-specific tools, and small automation components with explicit security boundaries.

LiteLLM
Open WebUI
FastAPI
Python
3
Assigned CVE IDs
2
Critical findings
9.3
Highest CNA CVSS v4
4
Selected projects
contact.sh

$ ./contact.sh --intent=collaborate

Let's build and secure reliable systems

Open to security research, Product Security, DevSecOps, cloud infrastructure, platform engineering, and responsible technical collaboration.

Get In Touch