
Security Research · Cloud Infrastructure · DevSecOps
Ngô Tấn Tài (Newnol)
I investigate how real systems fail at their API and infrastructure boundaries, then apply those lessons to build safer cloud, platform, and AI environments.
Security Research
Reviewing open-source systems for broken authentication, authorization gaps, and sensitive-data exposure. Credited with three 9Router CVE IDs.
Cloud Infrastructure & DevSecOps
Building Kubernetes environments, CI/CD pipelines, infrastructure as code, observability, and hardened self-hosted platforms.
AI Systems Engineering
Building private AI infrastructure, LLM routing, task-specific tools, and automation systems with practical security boundaries.
Milestones & Experience
Open-source coordinated disclosure
Three CVEs assigned from 9Router security researchAchievement
Discovered and responsibly disclosed vulnerabilities affecting provider-management APIs, plaintext provider credentials, and AI conversation-history privacy. Assigned CVE-2026-59801, CVE-2026-62327, and CVE-2026-62328.
DevOps.vn
Top 2 – Dockerfile ContestAchievement
Recognized for designing a hardened Python container image with a reduced attack surface, automated security scanning, and reproducible builds.
University of Information Technology – UIT
Top 1 – Wanagame CTF with Team BlackpinkerAchievement
Solved forensics and system-security challenges, analyzed malicious payloads, and documented the technical approach after the event.
Self-directed engineering lab
Security & Infrastructure Homelab
Operating Proxmox infrastructure, automating provisioning, running observability stacks, and testing security controls in controlled environments.
University of Science – Ho Chi Minh City (HCMUS)
Bachelor of Information Technology (Network & Security)Education
Coursework and independent practice focused on computer systems, networking, infrastructure security, Linux, and automation.
Core Capabilities
Security Research
- Source Code Review
- API Authentication & Authorization Testing
- Sensitive Data Exposure Analysis
- Vulnerability Reproduction
- CVE & Responsible Disclosure Process
- Technical Security Writing
Cloud & DevOps
- Cloud Platforms (GCP, AWS)
- Container Orchestration (Docker, Kubernetes)
- CI/CD Pipelines (GitHub Actions, Jenkins)
- Linux Administration & Hardening
Infrastructure
- Infrastructure as Code (Terraform, Ansible)
- Virtualization (Proxmox VE, VMware)
- Networking (VPC, DNS, VPN, Firewalls)
- Monitoring & Observability (Prometheus, Grafana, ELK)
AI Systems
- LLM Orchestration & Routing
- Private AI Infrastructure
- FastAPI Backend Development
- Task-specific AI Tools & Automation