About
I graduated from Bilkent University’s Computer Technology and Information Systems program in June 2026. Before that, I spent roughly 14 months at a cybersecurity and AI security firm, running penetration tests on web applications, mobile apps, APIs, and AI/ML systems.
Since July 2026 I’ve been interning at HUX AI Research, where I’m building an LLM Guardrails Evaluation Toolkit, a testing framework that measures how LLM safety layers handle adversarial inputs. Alongside the internship, I do independent vulnerability research and AI red-teaming. I’m an approved researcher in Anthropic’s Constitutional Vulnerability Program (CVP).
In the security community I go by Baldwin IV.
Selected Findings
- NocoBase VM sandbox escape — CVSS 10.0. A critical vulnerability allowing full server compromise through the formula/scripting engine.
- Mautic SSTI-to-RCE chain — CVSS 9.9. Server-side template injection in the marketing automation platform, escalating to remote code execution.
- Ghost CMS SSRF — Server-side request forgery in the Ghost publishing platform.
- Moodle & Decap CMS — Multiple vulnerabilities in the learning management system and the headless CMS.
AI Red-Teaming
I’ve submitted case studies to MITRE ATLAS covering a Crescendo-style jailbreak technique and a prompt-injection trilogy. My open-source work includes direction_explorer, a mechanistic interpretability tool built on refusal-ablation and multi-direction SOM techniques that surfaced cross-lingual leakage patterns in safety-tuned models.
I also built PromptShot (repositioned as a guardrail-fingerprinting recon layer), NucAIScan, and LeakCTL—adversarial testing tools for LLM guardrails.
Certifications
- eWPTXv3 (Web Application Penetration Testing eXtreme)
- eWPT (Web Application Penetration Testing)
- CompTIA Security+
- C-AI/MLPen (AI/ML Penetration Testing)
- C-AgAIPen (Agentic AI Penetration Testing)
Research Areas
AI Security
LLM guardrail evaluation, jailbreak methodologies, OWASP GenAI Top 10 mapping, mechanistic interpretability.
Vulnerability Research
Web framework audits, CVE disclosure, CVSS 4.0 scoring, root-cause analysis and detection guidance.
Mobile Security
End-to-end APK red-team pipelines, binary-to-PoC workflows, Android application analysis.
Automation
AI agent architectures, scheduled task orchestration, multi-model coordination systems.
Contact
- Email:
- [email protected]
- GitHub:
- @onurcangnc
- LinkedIn:
- onurcangenc
Responsible Disclosure Policy
If you believe you have found a security vulnerability in any of my projects, I appreciate your help in disclosing it responsibly.
Please report findings to [email protected] or open a security advisory on the relevant GitHub repository. I aim to acknowledge receipt within 48 hours and provide an initial assessment within 7 days.
Please refrain from public disclosure until a fix has been released or 90 days have passed since the initial report, whichever comes first.