Available for international opportunities
Onurcan Genç · Ankara, Turkey

Offensive Security
& AI Red Team
Researcher

Application security engineer and AI red team researcher specializing in adversarial LLM attacks, web application security, and vulnerability discovery. 6 published CVEs via MITRE & USOM. eWPTXv3 certified. Former Deloitte CyberOps.

eWPTXv3 eWPT Security+ C-AI/MLPen 6 CVEs 90+ Articles Top 2% TryHackMe
onurcan@kali: ~
onurcan@kali:~$ cat profile.json
──────────────────────────
"name": "Onurcan Genç"
"role": "Offensive Sec / AI Red Teamer"
"exp": "Deloitte · Bilishim Cybersecurity & AI"
"certs": ["eWPTXv3","eWPT","Sec+","C-AI/MLPen"]
"cves": 6, // MITRE + USOM
"focus": ["LLM jailbreak","prompt injection",
"web appsec","CVE research"]
"open": true // international roles
──────────────────────────
Type help to explore...
onurcan@kali:~$
6
CVEs Published
16mo
Pentest Field Exp
90+
Medium Articles
1st
Deloitte CTF
4+
Certifications
01

Published Vulnerabilities

CVE-2025-10878 CVSS 10.0 · Critical
SQL Authentication Bypass in Fikir Odaları AdminPando v1.0.1
CWE-89SQL InjectionAuth Bypass
MITRE · Feb 2026
CVE-2025-57520 HIGH
Stored XSS in Decap CMS ≤ 3.8.3 — payload executes in admin preview
CWE-79Stored XSSPrivilege Escalation
MITRE · Sep 2025
CVE-2025-60506 HIGH
Stored XSS in Moodle PDF Annotator Plugin v1.5 r9
CWE-79MoodleSession Hijack
MITRE · Oct 2025
CVE-2025-60507 HIGH
Reflected & Stored XSS + Prompt Injection in Moodle GeniAI Plugin 2.3.6
CWE-79Prompt InjectionLLM
MITRE · Oct 2025
CVE-2025-60511 MEDIUM
IDOR in Moodle OpenAI Chat Block v3.0.1 — student impersonates admin
CWE-639IDORPrivilege Escalation
MITRE · Oct 2025
CVE-2025-10228 CVSS 8.8 · High
Session Fixation in Agentis < v4.44 — session hijacking via CWE-384
CWE-384Session Fixation
USOM · Oct 2025
02

Selected GitHub Work

PromptShot v1.0 AI Security

Multi-phase adversarial attack pipeline for red-teaming LLMs. Multi-agent jailbreak generation, system-prompt poisoning, and persona hijacking.

PythonLLM Red TeamJailbreak
github ↗
NucAIScan Offensive

AI-assisted DAST pipeline. Subfinder, Subzy, FFUF heuristic fuzzing, Nuclei with GPT-4 template selection and automated HTML reporting.

PythonNucleiFFUFOpenAI
github ↗
LeakCTL Offensive

Threat intelligence platform for credential leak monitoring. Telegram-integrated with Elasticsearch backend for automated leak ingestion and search.

PythonElasticsearchTelegramCTI
github ↗
ArchiveWraith Offensive

Stealth Wayback Machine recon with smart URL filtering. Extracts high-value endpoints from historical snapshots.

PythonOSINTWayback
github ↗
web_app_ai_scanner Offensive

Full AI-assisted web scanner: Subfinder, Httpx, FFUF, Katana, WhatWeb, Wappalyzer, Wayback, Subzy, Nuclei. Full report generation.

PythonReconDAST
github ↗
ai-text-humanizer AI/ML

AI-generated text optimizer using BERT MLM + Q-Learning + 4-detector ensemble. Reduces AI detection scores while preserving semantic quality.

PythonBERTQ-Learning
github ↗
Moodle Student Tracker AI/ML

Telegram-integrated RAG chatbot tracking Moodle materials, lectures, grades, and attendances in real-time.

PythonRAGTelegram
github ↗
CVE-2025-10878 PoC CVE PoC

SQL Injection auth bypass PoC for AdminPando v1.0.1. CVSS 10.0 Critical — full unauthenticated admin access.

SQLiCVSS 10.0Auth Bypass
github ↗
CVE-2025-57520 PoC CVE PoC

Stored XSS in Decap CMS admin preview panel. Contributor-to-admin session hijacking PoC.

XSSDecap CMSStored
github ↗
web_app_recon_ci-cd Offensive

Recon-as-Code: fully automated passive reconnaissance via GitHub Actions CI/CD pipeline.

PythonGitHub ActionsCI/CD
github ↗
SmartHomeSystem Dev

Smart home automation implementing 6 GoF design patterns (Singleton, Abstract Factory, Observer, Mediator, Composite, Proxy) in Java.

JavaGoF PatternsOOP
github ↗
StoX Market Dev

Android cryptocurrency trading app with real-time price tracking, buy/sell functionality, and portfolio management.

KotlinAndroidAPI
github ↗
View all repos on GitHub ↗
03

Work History

DELOITTE
Nov 2025 – Feb 2026
Ankara · Remote

Cybersecurity Intern, CyberOps

Technical review and QA of penetration testing reports. Validated vulnerability findings, impact analysis, and remediation guidance. Alignment with MITRE ATT&CK and CVSS. Refined report structure for international non-Turkish engagements.

MITRE ATT&CKCVSSPentest ReportsQA
Bilishim Cybersecurity & Artificial Intelligence
May 2025 – Sep 2025
Ankara · Hybrid

Penetration Tester

Web, mobile, wireless, and LAN penetration tests against real-world targets. AI/ML red team engagements. Cyber threat intelligence including dark web credential leak validation. Mentored junior interns. Built offensive security tooling.

Web AppSecMobileAI/ML Red TeamLANCTIBurp Suite
Bilishim Cybersecurity & Artificial Intelligence
Jan 2025 – May 2025
Ankara · Hybrid

Penetration Tester, Long-Term Intern

Application security assessments against real-world instances. LAN security tests. Cyber threat intelligence and dark web leak investigations. Wireless penetration testing. Mentored interns. Prepared for eWPT and OSCP.

Web AppSecLANWirelessCTIeWPT Prep
Bilishim Cybersecurity & Artificial Intelligence
Jun 2024 – Jul 2024
Ankara · Remote

Penetration Tester, Summer Intern

Application security assessments via Burp Suite and PortSwigger. Custom automation scripts. HackTheBox CTF analysis on Windows machines. Published writeups on Medium. Prepared for CompTIA Security+.

Burp SuitePythonHackTheBoxSecurity+
VULNERDAY
Feb 2024 – May 2024
Istanbul · Remote

Envoy Team Member

Tested and validated CTF machine vulnerabilities. Published writeups ensuring correct exploit trigger paths per machine design.

CTFWriteupsVuln Validation
04

CTF & Competitions

2024
Deloitte CyberOps CTF
Tied 1st place in final. Improved from 19th in technical interview stage.
1st Place
2024
Hackmasters 2024
Organized and designed web application challenges.
Organizer
2024
STM CTF'24
National CTF competition.
Participant
2024
Siber Yıldız 2024
Active participation with EgeSiber CTF Team, associated with VulnerDay.
Team Member
Ongoing
TryHackMe
4+ years active. Completed offensive path.
Top 2%
05

Licenses & Credentials

INE / INESECURITY
eWPTXv3 — Web App Pentest eXtreme
Dec 2025 · Exp Dec 2028 · ID: 169289107
INE / INESECURITY
eWPT — Web Application Penetration Tester
Jun 2025 · Exp Jun 2028 · ID: 149492314
COMPTIA
Security+ ce (SY0-701)
Aug 2024 · Exp Aug 2027 · ID: LWS20RJZGM14Q63L
THESECOPSGROUP
Certified AppSec Practitioner (CAP)
Mar 2025
THESECOPSGROUP
Certified Network Security Practitioner (CNSP)
Jun 2024 · ID: 8798877
AMAZON WEB SERVICES
AWS Cloud Quest: Cloud Practitioner
Jul 2025
CISCO
CCNAv7: Switching, Routing & Wireless Essentials
Jun 2024
DELOITTE / BUSIBER / TÜRK TELEKOM
CyberOps Bootcamp · Boğaziçi Cybersecurity · TT Camp
Sep 2024 · Aug 2023
06

Latest from the Blog

Loading...
Fetching latest posts
View all posts ↗
07

Background & Tools

Senior Information Systems & Technologies student at Bilkent University (graduating June 2026). Background in C, C++, Python, Java, Kotlin, PHP, Oracle SQL/PLSQL, GoF 23 design patterns, and Linux systems.

Over 16 months of hands-on penetration testing at Bilishim Cybersecurity & Artificial Intelligence and Deloitte CyberOps — web, mobile, wireless, LAN, and AI/ML red team engagements on real-world targets.

Specializing in adversarial LLM security: building red team frameworks (PromptShot), developing threat intelligence platforms (LeakCTL), and publishing CVE research through MITRE and USOM.

90+ technical articles on Medium. First place, Deloitte CTF. Top 2% TryHackMe. IELTS 6.5 Academic. Actively targeting international roles in AI security and offensive research.

Turkish — Native English — C1 · IELTS 6.5
EDUCATION
Bilkent University
B.ASc. Information Systems & Technologies
2020 – 2026 · Ankara, Turkey · Senior
Offensive
Burp SuiteMetasploitFFUFNucleiNmapSQLmapHydraNikto
AI / LLM
Prompt InjectionJailbreakMITRE ATLASLangChainOpenAI APIFAISS
Recon
SubfinderHttpxSubzyKatanaWaybackWhatWebShodan
Languages
PythonJavaKotlinC / C++PHPSQLBash
Dev / Infra
DockerGitHub ActionsFlaskRailwayElasticsearchTelegram Bot
Frameworks
GoF 23 PatternsMITRE ATT&CKCVSS v3.1OWASP Top 10PTES
08

Get in Touch

Open to international roles in AI security research, offensive security, and red team consulting. Feel free to reach out.

Send an Email