Vulnerability Research · Industrial & IoT Security · Detection Engineering · AI Infrastructure
I work across the boundary between how systems fail and how defenders detect that failure.
On the research side, I audit source code, firmware, update paths, network services, and trust boundaries across AI infrastructure, robotics, IoT, industrial systems, containers, and cloud integrations. That work has led to published CVEs, a CISA Industrial Control Systems advisory, Google VRP recognition, coordinated disclosures, and upstream security fixes.
On the defensive side, I build controls that are tested end to end rather than treated as configuration: detection logic, controlled triggering, incident generation, investigation evidence, false-positive measurement, and deployment as code.
More recently, those two sides have started to converge in my work: security tooling and detection systems that combine source-level analysis, operational telemetry, reproducible engineering, and ML where it improves the security workflow.
Open-source ML network-flow detector that turns unlabeled CICFlowMeter-compatible traffic into deterministic analyst-facing security incidents.
The v0.1 release includes a frozen temporally validated model, causal feature pipeline, deterministic incident aggregation, versioned incident-v1 output, Python CLI, Docker distribution, real-model end-to-end regression, and public CI.
The project is intentionally explicit about its limits: usable as a research/evaluation product, but not presented as production-ready.
- CISA ICSA-26-272-01 — Lantronix G520 Series Cellular Gateway — reported CVE-2026-84409 and CVE-2026-91191. CISA credits me as the researcher and documents potential arbitrary code execution under the affected update and package-handling conditions. Lantronix addressed the issues in firmware 2.6.0.7R6.
- Current research also covers embedded devices, robotics, industrial software, firmware and update trust, device-management surfaces, and network-facing components.
- GHSA-7gwp-5pfp-969j / CVE-2026-64849 — MLflow, Critical: unauthenticated full-read SSRF through redirect and DNS-rebinding weaknesses in webhook delivery.
- CVE-2026-84173 — Eclipse Ankaios: authorization bypass in workload control rules allowing access outside an authorized cluster-state subtree.
- GHSA-4hhp-h66f-j5j7 / CVE-2026-73560 — vLLM: SSRF and local-file access through a model-specific multimodal path that bypassed hardened media retrieval controls.
- GHSA-9xq9-36w5-q796 / CVE-2026-46517 —
lmdeploy: unsafe remote-code loading behavior in an AI model inference server, resolved through coordinated disclosure. - Google Cloud VRP recognition — SSRF, API-key disclosure, and response forgery through a per-request
baseUrloverride affecting Gemini and Vertex AI client paths. - llm-serving-security — security reference for the LLM serving stack, covering vulnerability classes and hardening across vLLM, Triton, lmdeploy, SGLang, BentoML, Ollama, and TGI.
azure-sentinel-detection-engineering
Detection-as-Code on Microsoft Sentinel and Defender: KQL detections mapped to MITRE ATT&CK, controlled triggers, incident generation, investigation evidence, false-positive measurement, and PR-gated deployment through GitHub Actions and OIDC.
Merged security and hardening work across projects including:
- Google gVisor
- Kubernetes
- Firecrawl
- Azure Sentinel
- Swift Package Manager
- OSV-Scanner
- Tink
The work spans container hardening, validation boundaries, race conditions, crash handling, sandbox behavior, shared-memory security, SSRF defenses, and protocol/API behavior.
Coordinated disclosure experience includes CISA Industrial Control Systems Vulnerability Management and Coordination, GitHub Security Advisories, Google VRP, Microsoft MSRC, Eclipse Foundation security channels, vendor PSIRTs, and CERT/CC VINCE.
Hands-on work spans cloud, endpoint, identity, and network telemetry:
- Microsoft Sentinel, Defender XDR, Defender for Endpoint, Entra ID
- KQL, Sigma, MITRE ATT&CK
- Security Onion, Suricata, Zeek, Wazuh
- Elastic / Kibana
- pfSense
- Windows Server / Active Directory
- Python and PowerShell
I have also worked through live red-team / blue-team engagements involving segmented WAN/DMZ/LAN environments, IDS/IPS, firewall policy, honeypots, incident response, and maintaining service availability under sustained attack.
- Vulnerability research: source-level and protocol-level analysis across AI infrastructure, robotics, IoT, embedded devices, industrial systems, cloud integrations, and security-sensitive open source.
- Industrial & IoT security: firmware and update trust, device-management surfaces, network services, protocol parsing, certificate validation, and component-to-component trust boundaries.
- Detection engineering: tested detections, Detection-as-Code, SIEM/XDR engineering, and operational signal quality.
- AI infrastructure security: model-serving systems, inference infrastructure, isolation boundaries, and attack surfaces created around AI workloads.
- Security tooling: reproducible systems that connect detection, program analysis, automation, and ML without hiding the evidence behind the result.
Research
Detection & cloud
Platforms
Open to remote roles and selected technical work in vulnerability research, industrial and IoT security, security engineering, detection engineering, and AI infrastructure security.
Website: ibondarenko.com
LinkedIn: ievgen-bondarenko-b13098241
Email: hi@ibondarenko.com





