$ whoami
Ngô Tấn Tài/ newnol
Security Researcher & Cloud Infrastructure Engineer
➜3 CVE IDs · API security · source-code review · responsible disclosure
➜Cloud infrastructure · Kubernetes · Terraform · Ansible
➜DevSecOps · CI/CD · observability · Linux hardening
➜AI infrastructure & intelligent automation systems

$ cat research/9router.md
A coordinated open-source security review that produced three CVE IDs across authentication, credential handling, and AI conversation privacy.
Unauthenticated provider-management API access
Provider-management routes accepted requests without authentication, allowing remote users to enumerate, create, modify, or delete provider connections.
- affected
- 9Router <= 0.4.41
- weakness
- CWE-306
Plaintext AI provider API-key exposure
An unauthenticated usage endpoint returned complete provider API keys together with usage and billing metadata.
- affected
- 9Router <= 0.4.41
- weakness
- CWE-306 · CWE-522
AI request-log and conversation-history disclosure
Unprotected usage routes exposed request metadata and complete AI conversation histories to unauthenticated users.
- affected
- 9Router <= 0.4.41
- weakness
- CWE-359 · CWE-862
GHSA-vjc7-jrh9-9j86
Read the coordinated disclosure case
Review the timeline, methodology, root causes, CNA scoring, remediation guidance, public references, and responsible-research boundaries behind the three findings.
$ ls -la projects/featured/
Four representative projects selected for evidence, technical depth, and alignment with security, platform, infrastructure, and private AI work.

YAS (Yet Another Shop) CI/CD
Advanced CI/CD pipeline and Kubernetes deployment for a Java Spring Boot microservices architecture.
Homelab Infrastructure Automation
Automated provisioning and configuration of Proxmox VMs using Terraform and Ansible with GitOps principles.
Open WebUI Tools
Task-specific Open WebUI tools for transcript extraction, diagram generation, and smarter LLM workflows.
$ ls -la capabilities/
Security research grounded in practical infrastructure engineering: understand how systems fail, then build clearer boundaries, safer delivery, and more reliable operations.
Security Research
Source-code review, API authentication and authorization testing, vulnerability reproduction, and responsible disclosure.
Cloud & DevSecOps
Delivery pipelines, container platforms, hardening, observability, and reliable operations across cloud and self-hosted systems.
Infrastructure
Reproducible infrastructure and networking built with declarative automation and measurable operational health.
AI Systems
Private AI infrastructure, model routing, task-specific tools, and small automation components with explicit security boundaries.
$ cat competitions.log
Hành trình chinh phục các thử thách CTF, Hackathon và các cuộc thi kỹ thuật.
$ ./contact.sh --intent=collaborate
Let's build and secure reliable systems
Open to security research, Product Security, DevSecOps, cloud infrastructure, platform engineering, and responsible technical collaboration.
Get In Touch

