About

I graduated from Bilkent University’s Computer Technology and Information Systems program in June 2026. Before that, I spent roughly 14 months at a cybersecurity and AI security firm, running penetration tests on web applications, mobile apps, APIs, and AI/ML systems.

Since July 2026 I’ve been interning at HUX AI Research, where I’m building an LLM Guardrails Evaluation Toolkit, a testing framework that measures how LLM safety layers handle adversarial inputs. Alongside the internship, I do independent vulnerability research and AI red-teaming. I’m an approved researcher in Anthropic’s Constitutional Vulnerability Program (CVP).

In the security community I go by Baldwin IV.

Selected Findings

  • NocoBase VM sandbox escape — CVSS 10.0. A critical vulnerability allowing full server compromise through the formula/scripting engine.
  • Mautic SSTI-to-RCE chain — CVSS 9.9. Server-side template injection in the marketing automation platform, escalating to remote code execution.
  • Ghost CMS SSRF — Server-side request forgery in the Ghost publishing platform.
  • Moodle & Decap CMS — Multiple vulnerabilities in the learning management system and the headless CMS.

AI Red-Teaming

I’ve submitted case studies to MITRE ATLAS covering a Crescendo-style jailbreak technique and a prompt-injection trilogy. My open-source work includes direction_explorer, a mechanistic interpretability tool built on refusal-ablation and multi-direction SOM techniques that surfaced cross-lingual leakage patterns in safety-tuned models.

I also built PromptShot (repositioned as a guardrail-fingerprinting recon layer), NucAIScan, and LeakCTL—adversarial testing tools for LLM guardrails.

Certifications

  • eWPTXv3 (Web Application Penetration Testing eXtreme)
  • eWPT (Web Application Penetration Testing)
  • CompTIA Security+
  • C-AI/MLPen (AI/ML Penetration Testing)
  • C-AgAIPen (Agentic AI Penetration Testing)

Research Areas

  • AI Security

    LLM guardrail evaluation, jailbreak methodologies, OWASP GenAI Top 10 mapping, mechanistic interpretability.

  • Vulnerability Research

    Web framework audits, CVE disclosure, CVSS 4.0 scoring, root-cause analysis and detection guidance.

  • Mobile Security

    End-to-end APK red-team pipelines, binary-to-PoC workflows, Android application analysis.

  • Automation

    AI agent architectures, scheduled task orchestration, multi-model coordination systems.

Contact

LinkedIn:
onurcangenc

Responsible Disclosure Policy

If you believe you have found a security vulnerability in any of my projects, I appreciate your help in disclosing it responsibly.

Please report findings to [email protected] or open a security advisory on the relevant GitHub repository. I aim to acknowledge receipt within 48 hours and provide an initial assessment within 7 days.

Please refrain from public disclosure until a fix has been released or 90 days have passed since the initial report, whichever comes first.