# Vitaly Simonovich - Security Researcher > Security researcher at Cato Networks specializing in vulnerability research, threat intelligence, and AI security, with CVEs across core internet infrastructure, browsers, and web platforms. ## About Vitaly Simonovich is a security researcher at Cato Networks' CTRL (Cyber Threats Research Lab). His work focuses on: - Vulnerability Discovery (CVE) - Threat Intelligence and Analysis - AI and LLM Security Research - Malware Analysis - IoT Security - Browser Security ## Key Research ### HashJack Attack HashJack is an AI-powered browser attack that exploits Chrome's Lens search functionality to perform remote prompt injection, potentially hijacking AI assistants and extracting sensitive data. ### LLM Threat Landscape Research on how Large Language Models are transforming the cybersecurity threat landscape, from AI-powered assistants to potential adversarial tools. ### IoT Botnets Research on IoT botnets targeting home devices, examining infection vectors, command and control infrastructure, and threats to consumer networks. ## CVEs Discovered - **CVE-2026-42004** (Low): PowerDNS DNSdist EDNS options smuggling - **CVE-2026-42390** (Medium): PowerDNS Recursor ZONEMD validation bypass - **CVE-2026-48936** (Low): Node.js permission model network bypass via Unix domain socket - **CVE-2026-55827** (High): RemoteFX heap buffer overflow in FreeRDP - **CVE-2026-55564** (Medium): Glyph cache out-of-bounds read in FreeRDP - **CVE-2025-64496** (High): Code Injection in Open WebUI via SSE - **CVE-2025-52670** (High): Authorization Bypass (IDOR) in Revive Adserver - **CVE-2025-52668** (High): Stored XSS in Revive Adserver ## Speaking Engagements ### Upcoming - **RSA Conference 2026** (March 23, 2026, San Francisco) - "The Anatomy of Criminal Failure: Analyzing OpSec Flaws in Major Takedowns" ### Past Talks - **BSidesTLV AI Hacking Village** (December 2025) - "The Dark Side Of LLMs" - **APAC Partner Summit Bangkok** (September 2025) - "The Dark Mirror of LLMs" - **HackAPrompt Webinar** (July 2025) - "The Black Mirror of LLMs: How AI Powers the Adversary" - **Qubit 2025 Prague** (May 2025) - "From Assistants to Adversaries: The LLM Threat Landscape" - **Cato Networks Porsche Event Stuttgart** (November 2024) - "Skyfall - Threats in the Cloud" - **Botconf 2022** (April 2022) - "Warning! Botnet Is In Your House..." ## Important Pages - `/` - Homepage with expertise overview and highlights - `/#research` - Security research and publications - `/#speaking` - Conference talks and presentations - `/#press` - Media coverage and press mentions - `/blog/*` - Technical blog posts and articles ## Expertise Areas 1. **AI/LLM Security** - Prompt injection, model vulnerabilities, AI-powered attacks 2. **Threat Intelligence** - Threat actor analysis, campaign tracking 3. **Vulnerability Research** - CVE discovery, responsible disclosure 4. **Malware Analysis** - Reverse engineering, botnet research 5. **Browser Security** - Extension security, web-based attacks ## Employer **Cato Networks** - The SASE Leader - Role: Security Researcher, CTRL (Cyber Threats Research Lab) - Focus: Threat intelligence, vulnerability research, AI security ## Contact - Website: https://vitalysim.com - LinkedIn: https://www.linkedin.com/in/vitaly-simonovich - GitHub: https://github.com/vitalysim