+ + + +

// red teamer · vulnerability researcher · hanoi

Breaking stuff, building fast open source

Red Teamer & Vulnerability Researcher - I break into systems, find what others miss, and build high-performance offensive-security tooling in Go and C++. Active at @kcsc-club, shipping open source from Hanoi, Vietnam.

TRY MY WORK ON YOUR MACHINE
# clone any of my open-source repos and build in seconds $ git clone https://github.com/hypnguyen1209/fasthttp-reverse-proxy
199 repos / 234 followers

// ascii.orb · click me

// what i build

Core Components

01

Backend Systems

High-performance services and APIs in Go and C++ - FastHTTP, WebSocket and REST, built for speed and concurrency.

02

Network Tooling

Reverse proxies, self-hosted VPNs and traffic routing - fasthttp-reverse-proxy, proxigo and ionscale-vpn.

03

Web Frameworks

Lightweight HTTP frameworks and web infrastructure - like ming - with a focus on minimal, readable code.

04

Security & CTF

Breaking stuff at @kcsc-club - CTF infrastructure, reverse engineering and hands-on security research.

// process

How I Work

+
STEP 01

Explore

Dig into the problem, read the source, and reverse-engineer how things actually work under the hood.

+
STEP 02

Build

Ship minimal, high-performance solutions in Go and C++ - measured, tested and documented.

+
STEP 03

Open Source

Release it, maintain it, and help others learn. Everything I can, out in the open.

// security research

CVE Discoveries

CRITICAL CVE-2026-66012 SiYuan Desktop Unauthenticated administrator takeover via MCP endpoint
CRITICAL CVE-2026-66395 SiYuan Desktop Reflected XSS to RCE via siyuan:// protocol deep link
CRITICAL CVE-2026-73644 OpenDJ Server SASL PLAIN authzid bypassing proxy ACI scope check
HIGH CVE-2026-47894 Spring Cloud Config Unauthenticated cross-tenant file read via wildcard substitution
HIGH CVE-2026-59291 Spring Cloud Stream Arbitrary file read and SSRF via JsonMessageConverter class loading
HIGH CVE-2026-62354 Apache NiFi Incorrect authorization for parameter context validation requests
HIGH CVE-2026-66396 SiYuan Desktop Stored XSS to RCE via title-img IAL attribute injection
HIGH CVE-2026-67587 Apache Airflow Arbitrary module import in scheduler via Task SDK Callback deserialization
HIGH CVE-2026-70666 Netflix Lemur SSRF via ACME client following server-controlled URLs
HIGH GHSA-pvcr-8mvp-w8qr Budibase Chat-link handoff identity confusion (same-tenant account-link CSRF)
MEDIUM CVE-2026-61793 nuxt-og-image Unauthenticated SSRF via fonts[].path parameter
MEDIUM CVE-2026-60093 Apache Camel Path traversal in Azure Storage Data Lake downloadToFile operation
MEDIUM CVE-2026-12834 huntr bounty Vulnerability disclosed via huntr bug bounty platform
// resume

Resume

Nguyen Van Hiep

Red Teamer & Vulnerability Researcher based in Hanoi, Vietnam. Specializing in penetration testing, red team operations and building high-performance offensive-security tooling in Go and C++. Active member of @kcsc-club with hands-on experience in CTF infrastructure, reverse engineering and security research. Download my full CV for detailed work experience, certifications, technical skills and contact information.

// featured

Selected Projects

offensive-claude - Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest (382★)

CVE-2026-62911 - POC pre-auth RCE on Exchange (181★)

codex-free - Local MCP bridge server that turns ChatGPT into a Codex-like coding agent (28★)

log4j2-rce - Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2 (37★)

codex-cyber-fixer - Clear the cyber flag Trusted Access refusal from a Codex session (29★)

dpi-bypass - A lightweight SOCKS5 proxy that selectively routes traffic to bypass DPI (9★)

all repositories
// stack

Skills & Tooling

Go C++ JavaScript Python Shell HTML/CSS FastHTTP WebSocket REST APIs Git Docker Linux VPN / Networking Reverse Proxy CTF / Security
// metrics

By The Numbers

382★
Stars on top project
6+
Languages
15+
Tools & technologies
100%
Open source
13+
CVEs published
∞
Things left to break
// ecosystem

Toolchain

GitHub

Open-source home - 184+ repositories, automated with GitHub Actions CI.

Go & C++

Primary languages for high-performance services, tooling and systems work.

Docker & Linux

Containerized builds and deploys on Linux servers.

Networking & VPN

Tailscale / ionscale, reverse proxies and traffic routing across networks.

AI Coding

Claude and Codex in the loop to design and ship faster.

// contact

Get In Touch

Open to opportunities & collaborations

Open source, infrastructure, or anything that breaks interestingly. The fastest way to reach me: