Security Research

Vulnerability Disclosures & Security Research

Explore CVEs, security advisories, bug bounty recognition, and conference research published by CyStack researchers through responsible disclosure.

All years
All types
All researchers
Newest first
Showing 10 of 10 research items
Title
Conference / Venue
Type
Researcher
Year
The Crucial Role of Secrets Management in Contemporary Product Security
In this talk, the speaker emphasizes the critical importance of secrets management in modern product security. As digital threats evolve, effective management of sensitive information is essential for both individuals and organizations to safeguard their assets and maintain trust.
secrets managementproduct securitycybersecurity
CYBERSEC 2024
2024
Talk
TrungNH
2024
Running a Bug Bounty Program: What Works, What Fails, and What No One Tells You
In this talk, the speaker Trung Nguyen explores the intricacies of running a successful bug bounty program. He discusses what strategies work, what common pitfalls to avoid, and shares insights that are often overlooked in the industry.
bug bountycybersecuritytalk
CYBERSEC 2025
2024
Talk
TrungNH
2024
Cybersecurity Strategies in Cross-Border Trade
This presentation covers the importance of cybersecurity strategies in cross-border trade, highlighting innovative solutions to address global trade challenges. It emphasizes the role of technology in enhancing security measures and fostering collaboration among customs authorities worldwide.
cybersecuritycross-bordertrade
World Customs Organization Tech Conference 2023
2023
Presentation
TrungNH
2023
From Passwords to Passwordless
In this talk, the speaker explores the evolution from traditional password-based authentication to passwordless solutions. The discussion highlights the benefits of adopting passwordless technologies and the impact they have on security and user experience.
passwordlessauthenticationsecurity
FIDO APAC 2023
2023
Talk
TrungNH
2023
Detecting DGA Botnet based on Malware Behavior Analysis
This paper presents a novel approach to detecting Domain Generation Algorithm (DGA) botnets through the analysis of malware behavior. By leveraging behavioral patterns, the proposed method enhances the identification and mitigation of DGA threats, contributing to improved cybersecurity measures.
dgabotnetmalware
S
SOICT 2022
2022
Paper
TrungNH
2022
Demigod: The Art of Emulating Kernel Rootkits
This talk explores the challenges and techniques involved in emulating kernel rootkits, which are among the most dangerous forms of malware due to their ability to operate at the highest privilege level in a system. The speaker will discuss the limitations of existing dynamic analysis tools and present innovative approaches to enhance the detection and analysis of these sophisticated threats.
kernelrootkitemulation
BlackHat USA 2020
2020
Talk
TuanDM
2020
Redback: Advanced Static Binary Injection
In this talk, the speaker explores the concept of advanced static binary injection, detailing the techniques and methodologies used to manipulate binary files. The presentation will cover the implications of these techniques on software security and the potential risks they pose to various systems.
binaryinjectionsecurity
BlackHat Asia 2020
2020
Talk
TuanDM
2020
Security in the age of cloud services
This presentation covers the challenges and solutions related to security in the age of cloud services. It discusses the evolving landscape of cybersecurity threats and the importance of adopting robust security measures to protect sensitive data in cloud environments.
cloudsecuritycybersecurity
V
Vietnam Web Summit 2019
2019
Presentation
TrungNH
2019
Static Binary Injection
In this talk, the speaker explores the technique of static binary injection, which allows for the insertion of external code into executable files to monitor or alter program behavior during runtime. This method can be exploited by attackers for persistent infections, while also serving as a valuable tool for security researchers to instrument executable files.
binaryinjectionsecurity
XCon 2019
2019
Talk
TuanDM
2019
Static Binary Instrumentation
This talk explores the concept of Static Binary Instrumentation, focusing on its applications in security research. The speaker will discuss various techniques and tools used to analyze binary code statically, highlighting their importance in identifying vulnerabilities and enhancing software security.
staticbinaryinstrumentation
T2 infosec conference 2019
2019
Talk
TuanDM
2019

Responsible vulnerability disclosure backed by evidence

CyStack researchers investigate security weaknesses, coordinate remediation with affected vendors, and publish verifiable references when disclosure is safe. This archive brings our public vulnerability records, private-program recognition, and technical research together in one place.

CVEs & security advisories

Review disclosed vulnerabilities with identifiers, affected vendors, severity, CVSS scores, publication dates, researchers, and primary references.

Bug bounty recognition

See organizations that recognized findings submitted by CyStack researchers while confidential report details remain protected.

Security talks & papers

Browse technical presentations, papers, and conference contributions produced from CyStack's hands-on security research.