- Offensive security focused on penetration testing, adversary emulation and vulnerability research
- Red Team @ Sophos · Secureworks CTU™ Adversary Group
- Day job covers APT emulation, TLPT (Threat-Led Penetration Testing), and full-scope red team operations
- Vulnerability research spans the Linux kernel, libvirt and virtualization security, Apple platform internals, and the MCP / LLM tooling ecosystem
- Credited with 46 CVEs across major vendors and open-source projects including Red Hat, Apple, Linux kernel, Google, Docker, IBM, GitHub, HashiCorp, Model Context Protocol SDKs, Rapid7, and others
- Recognized by the Microsoft Security Response Center (MSRC) with a 2027 Special Mention, and by Google with Honorable Mentions for security research
- Active in native-code and systems security research, with fixes merged into upstream projects and coordinated disclosures across major vendors and open-source communities
- Security blogger publishing technical write-ups, PoCs, and research notes in English and 日本語
- Interested in web, AD and cloud pentesting, Azure red teaming, adversary emulation, vulnerability research, systems security, and coordinated disclosure
| Red Team / Adversary Emulation | Vulnerability Research | Cloud / Infra |
|---|---|---|
| Adversary Emulation (APT) TLPT / Threat-Led PT Active Directory PT Web / Network PT OSINT |
Source Code Review Memory Safety / Native Code Kernel / Virtualization Security Trust Boundary Analysis Coordinated Disclosure PoC Development |
Azure Red Team / Entra ID AWS Security Cloud Attack Paths Container / K8s MCP / API Security |
| CVE | Vendor / Project | Score | CVSS Basis | Severity |
|---|---|---|---|---|
| CVE-2026-53709 | IBM / ContextForge | 9.8 | v3.1 · GitHub Advisory | Critical |
| CVE-2026-14537 | Google / MCP Toolbox | 9.8 | v3.1 · NVD | Critical |
| CVE-2026-76092 | Docker MCP Gateway | 9.2 | v4.0 · GitHub / Docker | Critical |
| CVE-2026-11719 | Google / MCP Toolbox | 8.6 | v4.0 · Google CNA | High |
| CVE-2026-16328 | HashiCorp / Consul MCP Server | 8.6 | v3.1 · HashiCorp CNA | High |
| CVE-2026-16481 | Google / MCP Toolbox | 8.4 | v4.0 · Google CNA | High |
| CVE-2026-14541 | Google / MCP Toolbox | 8.0 | v4.0 · Google CNA | High |
| CVE-2026-14538 | Google / MCP Toolbox | 7.7 | v3.1 · NVD | High |
| CVE-2026-76094 | Docker MCP Gateway | 7.7 | v4.0 · GitHub / Docker | High |
| CVE-2026-53957 | Contentful MCP Server | 7.7 | v3.1 · GitHub Advisory | High |
| CVE-2026-14539 | Google / MCP Toolbox | 7.5 | v3.1 · NVD | High |
| CVE-2026-54358 | MISP Project | 7.5 | v4.0 · CIRCL CNA | High |
| CVE-2026-63128 | MCP Rust SDK | 7.5 | v3.1 · GitHub Advisory | High |
| CVE-2026-67432 | MCP Ruby SDK | 7.5 | v3.1 · GitHub CNA | High |
| CVE-2026-52869 | MCP Python SDK | 7.1 | v3.1 · GitHub Advisory | High |
| CVE-2026-63118 | MCP Ruby SDK | 6.9 | v4.0 · GitHub CNA | Medium |
| CVE-2026-76095 | Docker MCP Gateway | 6.8 | v4.0 · GitHub / Docker | Medium |
| CVE-2026-53708 | IBM / ContextForge | 6.6 | v3.1 · GitHub Advisory | Medium |
| CVE-2026-44968 | dbt Labs / dbt-mcp | 6.3 | v3.1 · GitHub CNA | Medium |
| CVE-2026-48529 | GitHub MCP Server | 6.0 | v3.1 · GitHub CNA | Medium |
| CVE-2026-67430 | MCP Ruby SDK | 5.3 | v3.1 · GitHub CNA | Medium |
| CVE-2026-54357 | MISP Project | 5.1 | v4.0 · CIRCL CNA | Medium |
| CVE-2026-6948 | Rapid7 / Velociraptor | 4.9 | v3.1 · Rapid7 CNA | Medium |
| CVE-2026-44970 | dbt Labs / dbt-mcp | 4.3 | v3.1 · NVD | Medium |
| CVE-2026-44969 | dbt Labs / dbt-mcp | 3.3 | v3.1 · NVD | Low |
| CVE-2026-76093 | Docker MCP Gateway | 2.3 | v4.0 · GitHub / Docker | Low |
For profile display, when multiple public CVSS v3.1 and v4.0 base scores exist for the same CVE, the higher published base score is used. The CVSS version and scoring source are shown explicitly above.
Product-specific downstream distribution scores are not substituted for an upstream project score unless they represent the relevant public CVE assessment.
This table highlights selected public CVEs. The total CVE count includes additional published findings not listed here.
| CVE | Vendor / Project | Component | Score | CVSS Basis | Severity / Class |
|---|---|---|---|---|---|
| CVE-2026-68326 | Linux Kernel | drivers/net/wireless/marvell/mwifiex/uap_event.c |
8.8 | v3.1 · kernel.org CNA | High · Slab out-of-bounds read |
| CVE-2026-63622 | Red Hat / libvirt | swtpm state handling |
7.8 | v3.1 · Red Hat | High · Sandbox boundary privilege escalation |
| CVE-2026-68402 | Linux Kernel | net/wireless/scan.c / cfg80211 |
7.1 | v3.1 · kernel.org CNA | High · Slab out-of-bounds read |
| CVE-2026-63623 | Red Hat / libvirt | Storage volume clone / convert | 5.5 | v3.1 · Red Hat | Medium · Guest disk information disclosure |
| CVE-2026-43806 | Apple | macOS mDNSResponder |
5.5 | v3.1 · CISA-ADP | Medium · Local denial of service |
| CVE-2026-64339 | Linux Kernel | drivers/usb/misc/usbio.c |
N/A | kernel.org CNA · NVD pending | Slab out-of-bounds read / kernel memory disclosure |
CVE-2026-64339 does not currently have a CVSS base score from the upstream kernel.org CNA or NVD. Downstream Linux distribution scores are therefore not used as the profile score.
- Google MCP Toolbox · Reported multiple vulnerabilities across Google MCP Toolbox, including CVE-2026-14537, a Critical 9.8 authorization failure, together with CVE-2026-11719, CVE-2026-14538, CVE-2026-14539, CVE-2026-14541, and CVE-2026-16481, covering authentication, authorization, isolation, and trust-boundary failures across MCP execution paths
- Linux kernel · Discovered and reported three kernel vulnerabilities, including CVE-2026-68326, CVE-2026-68402, and CVE-2026-64339, covering wireless and USB attack surfaces with fixes integrated into upstream development
- libvirt / Red Hat · Discovered CVE-2026-63622, a filesystem trust-boundary flaw allowing a compromised
swtpmservice context to influence host-side ownership changes, and CVE-2026-63623, a storage-volume permission window exposing guest disk contents during clone and convert operations - Docker MCP Gateway · Reported four vulnerabilities in Docker's MCP Gateway, including CVE-2026-76092, a Critical 9.2 authentication failure exposing proxied MCP tools without authentication, and CVE-2026-76094, a High 7.7 image signature-verification weakness
- Apple platform · Credited by Apple for CVE-2026-43806 in macOS
mDNSResponder - GitHub MCP Server · Reported CVE-2026-48529, an authorization and cross-user client isolation flaw in GitHub's official MCP Server
- MCP ecosystem · Cross-project security research spanning Google, Docker, IBM, HashiCorp, GitHub, Contentful, official Model Context Protocol SDKs, dbt Labs, MISP, and Rapid7, studying authentication, authorization, isolation, SSRF, filesystem, resource-lifecycle, and trust-boundary failures across LLM tooling
- Microsoft Security Response Center · Recognized as HE WEI in the MSRC 2027 Special Mentions
- Google Security · Received Honorable Mentions for vulnerability research and responsible disclosure
| Program | Recognition |
|---|---|
| Microsoft Security Response Center (MSRC) | HE WEI · 2027 Special Mention |
| Honorable Mentions | |
| Google / MCP Toolbox | CVE-2026-11719 · CVE-2026-14537 · CVE-2026-14538 · CVE-2026-14539 · CVE-2026-14541 · CVE-2026-16481 |
| Docker / MCP Gateway | CVE-2026-76092 · CVE-2026-76093 · CVE-2026-76094 · CVE-2026-76095 |
| Red Hat / libvirt | CVE-2026-63622 · CVE-2026-63623 |
| Linux Kernel | CVE-2026-68326 · CVE-2026-68402 · CVE-2026-64339 |
| Apple Security | CVE-2026-43806 |
| National CERT | IPA (情報処理推進機構), 7 acknowledgements |
| Responsible Disclosure | Rakuten · Mercari · BANDAI NAMCO · Sky · Neo4j · MISP Project and more |
🧵 Selected write-ups and PoCs are available on the blog
| Area | Topics |
|---|---|
| Research | Linux kernel • Virtualization and libvirt • MCP and LLM tooling security • Native-code trust boundaries |
| Red Team | APT emulation • TLPT • Active Directory • Azure / Entra ID • Cloud attack paths |
| Methodology | Source code review • Dynamic validation • Patch analysis • Reproducible PoCs |
| Tooling | Detection and exploitation PoCs • Security automation |
| Sharing | Conference talks and CFPs • Bilingual technical blogging • Coordinated disclosure |
| Next | OSED and OSCE3 • Continued systems and vulnerability research |







