Security Researcher & AI Red Teamer

Onurcan Genç

I find vulnerabilities in web applications and language models, then publish the findings so defenders can act on them. 8 CVEs disclosed, 14+ months of hands-on pentesting, OWASP GenAI contributor.

BlueDot Impact — Technical AI SafetyOWASP GenAI Red Team Lab ContributoreWPTXv3eWPTv2C-AI/MLPenC-AgAIPenCompTIA Security+

CVE Disclosures

CVE-2026-34156

NocoBase VM Sandbox Escape to RCE

CVSS 10.0

NocoBase v2.0.26

VM sandbox escape through console prototype chain in Workflow Script Node. Authenticated attacker achieves RCE as root inside Docker containers — database credential theft, arbitrary file access, reverse shell.

CVE-2026-9558

Mautic SSTI via Twig Themes to RCE

CVSS 9.9

Mautic 5.2.10

Server-side template injection through theme upload. Low-privilege Designer user with core:themes:create achieves remote code execution via unsandboxed Twig rendering.

CVE-2026-3251

Stored XSS

High

Stored cross-site scripting vulnerability. Reported through T.C. Siber Güvenlik Başkanlığı.

CVE-2025-60506

Stored XSS in Moodle PDF Annotator

High

Moodle PDF Annotator v1.5r9

Student-level attacker injects JavaScript via Public Comments. Payload fires when any user views the annotated PDF — session hijacking, credential theft.

CVE-2025-60511

IDOR in Moodle OpenAI Chat Block

Medium

Moodle OpenAI Chat Block 3.0.1

Authenticated student impersonates another user (admin, teacher) and sends OpenAI queries using their configuration. API misuse and admin-data exposure.

CVE-2025-60507

Reflected & Stored XSS via PDF Upload

High

Moodle GeniAI Plugin 2.3.6

Teacher uploads PDF with embedded JavaScript. The assistant outputs an unsanitized HTML link — payload executes for any user who clicks it.

CVE-2025-10228

Session Fixation

High

Session fixation vulnerability. Reported through USOM.

CVE-2025-57520

Stored XSS in Decap CMS

High

Decap CMS ≤ 3.8.3

Contributor/editor injects payloads into title, tags, description, and body fields. Fires when admin opens content preview — session hijacking, arbitrary JS execution.

Experience

Jul 2026 – Present

HUX AI

London, UK · Remote

AI Research Intern — LLM Guardrails Evaluation

  • LLM guardrail evaluation and adversarial testing
  • Prompt injection and jailbreak resistance assessment
  • AI safety evaluation workflow development

Nov 2025 – Feb 2026

Deloitte

Ankara · Remote

Cybersecurity Intern

  • Pentest report QA aligned with MITRE ATT&CK and CVSS
  • Severity scoring validation across deliverables
  • CTF competition — 1st place

Jan 2025 – Sep 2025

Bilishim Cyber Security

Ankara · Hybrid

Penetration Tester

  • Web, mobile, wireless, and LAN penetration testing
  • AI/ML red team engagements
  • Threat intelligence: dark web leak analysis
  • Mentored junior interns

Open Source & Research Contributions

OWASP GenAI Security Project

Multi-Technique Guardrail Bypass Evaluation

Five-stage evaluation sequence across four bypass technique families against a production chatbot. Demonstrates that patching individual bypasses fails — the same intent gets through via different surface transformations.

OWASP GenAI Security Project

Multi-Turn Safety Bypass & System Role Override

Six-stage attack chain: control token injection, role-label spoofing, role-switching disclosure, Crescendo escalation. Mapped to LLM01, LLM02, LLM05, LLM07. Responsibly disclosed via MITRE.

Independent Research

Mechanistic Interpretability — Refusal in Open-Weight Models

Characterizing how refusal is represented in the residual stream of Qwen 2.5. Using targeted interventions to identify which directions are causally responsible for refusal vs. compliance.

Certifications

eWPTXv3

INE

Dec 2025

eWPTv2

INE

Jun 2025

C-AI/MLPen

SecOps Group

2025

C-AgAIPen

SecOps Group

2025

CompTIA Security+

CompTIA

Aug 2024

CNSP

SecOps Group

Jun 2024

AWS Cloud Practitioner

AWS

Jul 2025

Technical AI Safety

BlueDot Impact

Jun 2026

Future of AI

BlueDot Impact

May 2026

Education

Bilkent University

B.ASc, Information Systems & Technologies

2020 – 2026 · 50% Scholarship

Best Intern AwardSocial Excellence Award

C, C++, Python, Java, PHP, Kotlin, C#/.NET, Oracle SQL/PL-SQL. GoF design patterns, RESTful microservices, algorithmic analysis, IS auditing.

Training Programs

  • Boğaziçi Cybersecurity Program (BUSIBER)
  • Türk Telekom Cybersecurity Camp
  • Deloitte CyberOps Bootcamp — CTF 1st Place