$ whoami
Ngô Tấn Tài/ newnol
Security Researcher & Cloud Infrastructure Engineer
➜3 CVE IDs · API security · source-code review · responsible disclosure
➜Cloud infrastructure · Kubernetes · Terraform · Ansible
➜DevSecOps · CI/CD · observability · Linux hardening
➜AI infrastructure & intelligent automation systems

$ cat research/9router.md
A coordinated open-source security review that produced three CVE IDs across authentication, credential handling, and AI conversation privacy.
Unauthenticated provider-management API access
Provider-management routes accepted requests without authentication, allowing remote users to enumerate, create, modify, or delete provider connections.
- affected
- 9Router <= 0.4.41
- weakness
- CWE-306
Plaintext AI provider API-key exposure
An unauthenticated usage endpoint returned complete provider API keys together with usage and billing metadata.
- affected
- 9Router <= 0.4.41
- weakness
- CWE-306 · CWE-522
AI request-log and conversation-history disclosure
Unprotected usage routes exposed request metadata and complete AI conversation histories to unauthenticated users.
- affected
- 9Router <= 0.4.41
- weakness
- CWE-359 · CWE-862
GHSA-vjc7-jrh9-9j86
Read the coordinated disclosure case
Review the methodology, root causes, remediation guidance, public references, and responsible-research boundaries behind the three findings.
$ ls -la projects/
Selected work across security research, DevSecOps, infrastructure, AI systems, and practical product engineering.

YAS (Yet Another Shop) CI/CD
Advanced CI/CD pipeline and Kubernetes deployment for a Java Spring Boot microservices architecture.

Homelab Infrastructure Automation
100% automated provisioning and configuration of Proxmox VMs using Terraform and Ansible with GitOps principles.

Homelab Infra
Infrastructure-as-code experiments for homelab services, automation, and self-hosted platform work.

OpenClaw Terraform Review Assistant
A small CLI that reads Terraform plan JSON and turns it into a readable review with summary, risk flags, and pre-apply checks.
$ cat journey.log
Security research grounded in practical infrastructure: reviewing how systems fail, then building safer cloud, platform, and AI environments.
Three CVEs from 9Router Security Research
Reviewed authentication and authorization boundaries in an open-source AI routing dashboard and responsibly disclosed three vulnerabilities covering provider management, plaintext API keys, and conversation-history exposure.
Homelab Infrastructure Automation (IaC)
Developed a codified infrastructure pipeline to automate the provisioning, configuration, and observability of Proxmox resources.
Private AI Agent Infrastructure (LLMOps)
Architected a self-hosted AI stack with LiteLLM and Open WebUI, focusing on privacy, routing control, and resource efficiency.
Hybrid Cloud & DevSecOps Lab
Designed a hybrid architecture connecting physical clusters with public VPS infrastructure, automated delivery pipelines, monitoring, and security controls.
Cybersecurity & CTF
Built foundations in forensics, reverse engineering, web security, and system analysis, including a Top 1 result with Team Blackpinker at Wanagame CTF.
Computer Systems & Networking @ HCMUS
Studying computer systems networking with an emphasis on cloud-native infrastructure, security, Linux, and distributed systems.
$ ls -la capabilities/
Evidence-backed security skills supported by infrastructure engineering experience.
Security Research
Cloud & DevOps
Infrastructure
AI Systems
Live Infrastructure Status
Real-time observability of homelab and cloud services.
$ cat competitions.log
Hành trình chinh phục các thử thách CTF, Hackathon và các cuộc thi kỹ thuật.
$ ./contact.sh --intent=collaborate
Let’s build and secure reliable systems
Open to security research, DevSecOps, cloud infrastructure, platform engineering, and responsible technical collaboration.
Get In Touch




