Skip to main content
open to security & platform rolesnewnol@research-lab:~

$ whoami

Ngô Tấn Tài/ newnol

Security Researcher & Cloud Infrastructure Engineer

3 CVE IDs · API security · source-code review · responsible disclosure

Cloud infrastructure · Kubernetes · Terraform · Ansible

DevSecOps · CI/CD · observability · Linux hardening

AI infrastructure & intelligent automation systems

newnol — interactive shell
newnol@homelab:~
$whoami
newnol
$help
Available commands:
whoami - Display current user
ls - List directory contents
cd <dir> - Change directory
cat <file> - Display file contents
pwd - Print working directory
docker ps - List running containers (simulated)
ssh <host> - Connect to server (simulated)
skills - Show technical skills
projects - List projects
contact - Show contact information
clear - Clear terminal
help - Show this help message
Try: cat about.txt, ls projects/, skills
$
Tip: Use Tab for completion, ↑/↓ for history, type "help" for commands
Ngô Tấn Tài (Newnol) - Security Researcher and Cloud Infrastructure Engineer
Chapter 01 · security research

$ cat research/9router.md

A coordinated open-source security review that produced three CVE IDs across authentication, credential handling, and AI conversation privacy.

3
CVE IDs
2
Critical findings
9.3
Highest CVSS v4
Public
Responsible disclosure
CVE-2026-59801
Critical · 9.3

Unauthenticated provider-management API access

Provider-management routes accepted requests without authentication, allowing remote users to enumerate, create, modify, or delete provider connections.

affected
9Router <= 0.4.41
weakness
CWE-306
View NVD record
CVE-2026-62327
Critical · 9.3

Plaintext AI provider API-key exposure

An unauthenticated usage endpoint returned complete provider API keys together with usage and billing metadata.

affected
9Router <= 0.4.41
weakness
CWE-306 · CWE-522
View NVD record
CVE-2026-62328
High · 8.7

AI request-log and conversation-history disclosure

Unprotected usage routes exposed request metadata and complete AI conversation histories to unauthenticated users.

affected
9Router <= 0.4.41
weakness
CWE-359 · CWE-862
View NVD record

GHSA-vjc7-jrh9-9j86

Read the coordinated disclosure case

Review the methodology, root causes, remediation guidance, public references, and responsible-research boundaries behind the three findings.

View Security Research
Chapter 02 · projects

$ ls -la projects/

Selected work across security research, DevSecOps, infrastructure, AI systems, and practical product engineering.

9Router Security Research project screenshot
Security Research

9Router Security Research

A coordinated open-source security review resulting in three CVE IDs across API authentication, credential exposure, and AI conversation privacy.

Source Code Review
API Security
Next.js
Responsible Disclosure
CVE
YAS (Yet Another Shop) CI/CD project screenshot
DevOps

YAS (Yet Another Shop) CI/CD

Advanced CI/CD pipeline and Kubernetes deployment for a Java Spring Boot microservices architecture.

Kubernetes
Jenkins
Java Spring Boot
Docker
Kafka
PostgreSQL
Keycloak
Homelab Infrastructure Automation project screenshot
Infrastructure

Homelab Infrastructure Automation

100% automated provisioning and configuration of Proxmox VMs using Terraform and Ansible with GitOps principles.

Terraform
Ansible
Proxmox VE
Docker
Prometheus
HealthSense-IoT project screenshot
IoT

HealthSense-IoT

Smart health monitoring system with ESP32, real-time dashboard, and AI-assisted health insights.

ESP32
Next.js
Python
FastAPI
TypeScript
Open WebUI Tools project screenshot
AI Systems

Open WebUI Tools

A set of custom Open WebUI tools for transcript extraction, diagram generation, and smarter tool workflows.

Python
Open WebUI
Selenium
LLM Tools
Homelab Infra project screenshot
Infrastructure

Homelab Infra

Infrastructure-as-code experiments for homelab services, automation, and self-hosted platform work.

Terraform
HCL
Infrastructure as Code
Homelab
OpenClaw Terraform Review Assistant project screenshot
DevOps

OpenClaw Terraform Review Assistant

A small CLI that reads Terraform plan JSON and turns it into a readable review with summary, risk flags, and pre-apply checks.

Python
Terraform
CLI
DevOps
Chapter 03 · journey

$ cat journey.log

Security research grounded in practical infrastructure: reviewing how systems fail, then building safer cloud, platform, and AI environments.

2026

Three CVEs from 9Router Security Research

Reviewed authentication and authorization boundaries in an open-source AI routing dashboard and responsibly disclosed three vulnerabilities covering provider management, plaintext API keys, and conversation-history exposure.

CVE-2026-59801
CVE-2026-62327
CVE-2026-62328
2025-Present

Homelab Infrastructure Automation (IaC)

Developed a codified infrastructure pipeline to automate the provisioning, configuration, and observability of Proxmox resources.

Terraform
Ansible
Proxmox
GitOps
2025-Present

Private AI Agent Infrastructure (LLMOps)

Architected a self-hosted AI stack with LiteLLM and Open WebUI, focusing on privacy, routing control, and resource efficiency.

Docker Compose
LiteLLM
Open WebUI
LLMOps
2023-Present

Hybrid Cloud & DevSecOps Lab

Designed a hybrid architecture connecting physical clusters with public VPS infrastructure, automated delivery pipelines, monitoring, and security controls.

Kubernetes
Jenkins
CrowdSec
Monitoring
2022-Present

Cybersecurity & CTF

Built foundations in forensics, reverse engineering, web security, and system analysis, including a Top 1 result with Team Blackpinker at Wanagame CTF.

Forensics
Reverse Engineering
Web Security
CTF
2023-Present

Computer Systems & Networking @ HCMUS

Studying computer systems networking with an emphasis on cloud-native infrastructure, security, Linux, and distributed systems.

Networks
Python
Go
Cloud Native

$ ls -la capabilities/

Evidence-backed security skills supported by infrastructure engineering experience.

Security Research

Source Code Review
API Authentication
Authorization Testing
Vulnerability Reproduction
Responsible Disclosure
Technical Security Writing

Cloud & DevOps

GCP
AWS
Docker
Kubernetes
GitHub Actions
Jenkins

Infrastructure

Proxmox
Terraform
Ansible
Linux
Networking
Observability

AI Systems

LLM Orchestration
LiteLLM
Open WebUI
FastAPI
Python
Go
3
Assigned CVE IDs
2
Critical findings
9.3
Highest CVSS v4
1
Coordinated case

Live Infrastructure Status

Real-time observability of homelab and cloud services.

Open Full Page
contact.sh

$ ./contact.sh --intent=collaborate

Let’s build and secure reliable systems

Open to security research, DevSecOps, cloud infrastructure, platform engineering, and responsible technical collaboration.

Get In Touch