Vitaly Simonovich
Vulnerability Research · Threat Intelligence · AI Security

VITALYSIMONOVICH

Security Researcher
0+

Years Experience

0

CVEs Discovered

0

Public Speaking

0+

Press Mentions

BREAKING
TO DEFEND

Senior security researcher working across vulnerability research, threat intelligence, and AI security. I break systems the way real attackers do, from core internet infrastructure like DNS and glibc to browsers, web platforms, and LLMs, and turn those findings into practical defenses, threat reports, and education so organizations can stay ahead of attackers.

Core Expertise

Vulnerability Research
Threat Intelligence
LLM & GenAI Security
Jailbreaks & Prompt Injection
Application Security
Data Security
Offensive Security & CTFs
Security Education & Public Speaking

HIGHLIGHTS

01
01Conference TalkNEW

DEF CON 34 Main Track

C(2)YA: Inside the Adversary's Inbox — six months of LLM-assisted research against five C2 frameworks (Havoc, Mythic, Sliver, Covenant, AdaptixC2) yielding 251 findings, 85 exploitable straight from the internet, and 28 takedown chains.

Details

RECOGNITION & CVE DISCOVERIES

24 CVEs/10 High·11 Medium·3 Low/8 Awards
CVE Discoveries
~/research/advisories
24 entries

Server-side request forgery in the multimodal media fetching functions of NVIDIA TensorRT-LLM for Linux, where a network-accessible attacker can steer the inference server into issuing attacker-controlled requests, leading to information disclosure and denial of service. Affects TensorRT-LLM through v1.3.0 rc16.

View advisory
Awards & Recognition

Security Research Acknowledgement

2026

Apple

Recognized in Apple's security advisories for WebKit and WebKit Storage research, alongside credited WebKit vulnerabilities.

Product Security Acknowledgement

2026

NVIDIA

Credited on NVIDIA's Product Security Acknowledgements page for reporting two vulnerabilities in TensorRT-LLM.

Security Vulnerability Credit

2026

WordPress

Credited for reporting an AJAX query-attachments authorization bypass, fixed in WordPress 6.9.2.

Security Vulnerability Credit

2026

ISC (BIND9)

Credited for reporting a NULL pointer dereference crash in BIND9's QP-trie cache, fixed in BIND 9.21.19.

Security Advisory Credit

2026

Jenkins

Credited for independent discovery of a link following vulnerability in Jenkins, reported through the Jenkins Bug Bounty Program sponsored by the European Commission.

Security Researcher Hall of Fame

2026

MongoDB

Recognized for responsibly disclosing a security vulnerability in MongoDB products.

AI Safety - Immersive world jailbreak

2025

Microsoft

Awarded for discovering the 'Immersive world' jailbreak in Microsoft's copilot.

AI Security - Edge browser prompt injection

2025

Microsoft

Indirect prompt injection vulnerability found in Microsoft's edge browser.

PRESS

65 mentions·54 outlets·2019–2026·29 featured
202621 articles
202535 articles
20221 articles
20198 articles

RESEARCH21

2026-06-16researchCato Networks Blog

Cato CTRL Threat Research: Operation Poisson - Analyzing a Cybercriminal's Entire Operation

Post-incident analysis of Operation Poisson, a 33-day campaign by a junior French-speaking threat actor against four individuals and a French automotive business. Captured command-by-command after the operator left SSH keys and a playbook in an open bucket, it shows how free-tier Havoc C2, a Python keylogger, and Tailscale plus OpenSSH built persistence that survived the C2 going offline.

threat intelligenceHavoc C2Tailscalecredential theftincident response
Read Article

SPEAKING12

conference

C(2)YA: Inside the Adversary's Inbox

DEF CON 34
August 8, 2026Las Vegas, NV, USA

Six months of LLM-assisted research against five C2 frameworks — Havoc, Mythic, Sliver, Covenant and AdaptixC2 — surfacing 251 design flaws and vulnerabilities, 85 of them exploitable from the internet with no prior access, plus 28 takedown chains and crypto failures that decrypt all C2 traffic from a single recovered key.

No recording available
C(2)YA: Inside the Adversary's Inbox at DEF CON 34

MY BLOG12

BreachLogicCVE-2025-15281Use-After-FreeglibcMemory CorruptionVulnerability Research

glibc wordexp() Memory Initialization Flaw - CVE-2025-15281

A 26-year-old Use-After-Free vulnerability in glibc's wordexp() function when using WRDE_REUSE and WRDE_APPEND flags together, affecting versions 2.0 through 2.42.

Get in touch
Lectures, interviews, or collaborations?

Always open to discussing new opportunities, interesting projects, or just chatting about security and AI.

Remote, available worldwide
Vitaly Simonovich | Security Researcher