Portfolio

Bui Le Anh Khoa

Offensive security · Application security · Vulnerability research

I investigate trust boundaries, source code, and memory-safety failures. My work includes three publicly credited CVE discoveries and a Critical CVSS 9.6 Incus chain demonstrated through root command execution.

Research
Three publicly credited original CVEs
Highest impact
Critical CVSS 9.6 · Root command execution
Experience
OPSWAT Cybersecurity Graduate Fellow · SWAT 2
Achievement
2nd Place, College Division · Advent of CTF 2025

Vulnerability research

Zero-day discoveries, responsible disclosure, and public reporter credit.

Research details

Exiv2

CVE-2026-68546

0-day research

Heap out-of-bounds write

C++ memory-safety flaw in RemoteIo processing of URL-based resources.

Moderate Read advisory

libheif

CVE-2026-84448

0-day research

Heap out-of-bounds read

Insufficient validation in inline-mask region handling, reproduced with AddressSanitizer.

Moderate Read advisory

Security Research

Malware detection & explainable triage

Graduation thesis

A security-analysis framework combining static analysis, reverse engineering, threat intelligence, and ML-assisted triage to support analysts.

Runtime-aware analysis for native, .NET, and PyInstaller artifacts; Python, Ghidra, SHAP, and Docker.

Explore the framework

PyMySQL SQL injection lab

CVE Reproduction & Technical Analysis

Reproduction of CVE-2024-36039, an object-key serialization flaw leading to SQL injection. A Docker lab, reproducible PoC, and technical analysis.

Reproduction and analysis of an existing CVE; not an original vulnerability discovery.

View the PoC & analysis

Experience & achievements

Cybersecurity Fellow · OPSWAT

June-August 2026 · SWAT 2

Hands-on vulnerability research and CVE reproduction in controlled labs, analyzing root causes, exploitation conditions, and security impact.

2nd Place, College Division

Advent of CTF 2025 · CyberStudents

Technical write-ups across reverse engineering, web security, digital forensics, pwn, and cryptography.

Read the challenge write-ups

Technical writing

All posts
CTF Writeups

Advent of CTF 2025

Mình tham gia cuộc thi này cuối năm 2025, một phần cũng bận và hơi lười nên đến bây giờ mới có thời gian viết lại writeup. Một số challenge mình viết bằ...

CTF Writeups

BuildGuidl CTF

“Bảo mật Smart Contract không chỉ dừng lại ở việc viết code đúng cú pháp (syntax), mà nằm ở việc thấu hiểu tường tận cách máy ảo Ethereum (EVM) vận hành...

CTF Writeups

amateursCTF 2025

Dưới đây là lời giải chi tiết cho các bài CTF mình đã clear thành công. Mỗi bài viết là một trải nghiệm và những kiến thức mới mà mình đã đúc kết được.

Areas of focus

Research & review
Vulnerability research · Secure code review · Memory-safety analysis · Technical reporting
Reverse engineering & analysis
Ghidra · IDA Pro · GDB · AddressSanitizer
Implementation & labs
C/C++ · Python · Bash · SQL · JavaScript · Docker · Linux

Get in touch

For conversations about offensive security, application security, and vulnerability research.

More about me