// independent security research

Ievgen Bondarenko

AI Infrastructure Security Researcher

I identify and validate vulnerabilities in AI model-serving, cloud, container, and open-source infrastructure.

scroll

01 / featured research

Security boundaries tested in code.

All research
01 / MLflowPublished | CVE-2026-64849 | CVSS 9.3

Unauthenticated full-read SSRF in webhook delivery

A Critical SSRF flaw let an unauthenticated caller cross the MLflow server network boundary through webhook redirects and DNS rebinding.

trust-boundary path

Unauthenticated input / Webhook delivery / Internal destination

Read case study
02 / Google GenkitGoogle Cloud VRP recognition

Provider endpoint trust-boundary failure

SSRF, API-key exposure, and response forgery were validated in an AI SDK integration that accepted a caller-influenced provider endpoint.

trust-boundary path

Request endpoint override / Authenticated provider client / Attacker-controlled origin

Read case study
03 / LMDeployPublished - CVE-2026-46517

Unsafe remote-code trust during model initialization

LMDeploy enabled Hugging Face remote code by default during model loading, removing the operator decision that peer inference systems expose as an explicit opt-in.

trust-boundary path

Model reference / Inference initialization / Python remote code

Read case study

02 / open source security

Selected upstream work.

View contributions
01 / 06upstream

Container isolation

gVisor

Isolation boundaries, networking, race conditions, checkpoint security, and protocol validation.

View evidence
02 / 06upstream

Model-serving media retrieval

vLLM

Security controls around multimodal media retrieval and shared connector policy.

View evidence
03 / 06upstream

Package extraction

Swift Package Manager

Archive extraction and symbolic-link boundary protection in package registries.

View evidence
04 / 06upstream

Cryptographic input validation

Tink

Strict JWK parsing and validation at a public cryptography-library boundary.

View evidence
05 / 06upstream

Protocol parsing

Google Bumble

Bluetooth protocol parsing and denial-of-service protections.

View evidence
06 / 06upstream

Detection engineering

Microsoft Sentinel

Detection content for suspicious network, identity, endpoint, and control-plane activity.

View evidence

03 / research method

Reproducible work, not a scanner result.

My research combines source-code analysis, data-flow tracing, controlled reproduction, exploit validation, impact analysis, and coordinated disclosure.

validation.sequence7 stages / deterministic
  1. 01

    Target and trust-boundary analysis

    trace
  2. 02

    Source review and data-flow tracing

    trace
  3. 03

    Reproducible test environment

    trace
  4. 04

    Proof-of-concept validation

    trace
  5. 05

    Impact and exploitability assessment

    trace
  6. 06

    Vendor coordination

    trace
  7. 07

    Remediation verification

    verified

04 / technical focus

Where trust crosses a system boundary.

01AI inference and model-serving systems02Agent and evaluation infrastructure03Cloud and container isolation04SSRF and untrusted resource retrieval05Parser and protocol security06Identity and trust boundaries07Source-code auditing08Reverse engineering

05 / background

Operations experience behind the research.

My security research is supported by hands-on experience in cloud security, detection engineering, incident response, enterprise infrastructure, and compliance-sensitive environments.

Read the background
now.txtlive

$ cat current_research

Currently researching trust boundaries and untrusted-input handling in AI-serving and evaluation infrastructure. Some findings are undergoing coordinated disclosure.

06 / security engagements

Security reviews built around evidence.

I review AI-serving systems, agent and evaluation infrastructure, and open-source components where untrusted input crosses a privileged boundary.

Discuss a Project
Typical deliverablesThreat modelVerified findingsReproduction evidenceRemediation guidanceRetest

07 / contact

Bring me the boundary that needs testing.

Open to AI infrastructure security roles, expert technical evaluation, open-source security engineering, and selective security research engagements.