IEVGEN BONDARENKO
PRODUCT SECURITY RESEARCH | INDUSTRIAL & AI INFRASTRUCTURE | SECURITY & COMPLIANCE ENGINEERING
PROFILE
Product security researcher working across AI infrastructure, open-source software, robotics, IoT, and industrial systems. Focused on source-led vulnerability research, reproducible validation, root-cause analysis, coordinated disclosure, and remediation verification.
Published and coordinated research includes CVE/GHSA findings in MLflow, Eclipse Ankaios, vLLM, and LMDeploy, plus rewarded Google Cloud VRP research. Current industrial and IoT research includes multi-vendor vulnerability work coordinated through vendor security teams and CISA VINCE.
SELECTED SECURITY RESEARCH
MLflow — CVE-2026-64849 / GHSA-7gwp-5pfp-969j
Credited finder of a Critical unauthenticated SSRF affecting webhook delivery through redirect and DNS-rebinding weaknesses. Reproduced the trust-boundary failure and validated remediation.
Eclipse Ankaios — CVE-2026-84173 / GHSA-rp6v-x3q5-cp2g
Reporter of an authorization flaw allowing scoped workloads to access or modify cluster state outside their intended subtree. Validated the maintainer fix and fixed release.
vLLM / LMDeploy
Reporter for CVE-2026-73560 and CVE-2026-46517, covering multimodal SSRF/local-file boundary bypass and unsafe remote-code trust during model initialization.
Google Cloud VRP
Identified SSRF, Google API-key disclosure, and response forgery through a provider endpoint override in Google Genkit. Report triaged and rewarded by Google Cloud VRP.
Industrial / IoT Research
Active multi-vendor research across device-management software, firmware, network services, certificate validation, protocols, and device-to-cloud trust boundaries. Findings are moving through coordinated vendor and CISA VINCE disclosure processes.
Open-Source Security Engineering
20+ merged upstream security and hardening changes across gVisor, Kubernetes, vLLM, Microsoft Sentinel, Swift Package Manager, OSV-Scanner, Tink, and Google Bumble.
EXPERIENCE
Independent Security Researcher
California, Remote|2026–Present
Source-led vulnerability research across AI infrastructure, open-source software, robotics, IoT, and industrial systems. Build reproducible test environments, validate impact, coordinate disclosure, review patches, and retest remediation.
Security & Compliance Consultant
California, Remote|2025–Present
Security and compliance assessments across cloud, identity, endpoint, application, and infrastructure environments. Work includes SOC 2, ISO 27001, HIPAA, NIST-aligned controls, technical remediation, and audit readiness.
Computer Security Manager
Technohome Inc. | Roseville, CA|2022–2025
Managed Windows/Linux security, hardening, patching, access reviews, network segmentation, pfSense controls, event investigation, and incident-response procedures.
Earlier Career: Business Ownership & Operations Leadership
Founded and operated a U.S. logistics business coordinating several dozen trucks and approximately 50 outsourced personnel.
CORE CAPABILITIES
- Vulnerability Research
- secure code review, source-to-sink tracing, reverse engineering, firmware/protocol analysis, threat modeling, SAST/DAST/SCA, PoC validation, fuzzing, CWE/CVSS, coordinated disclosure, remediation verification
- Product & Infrastructure Security
- AI model serving, distributed systems, robotics, IoT, embedded and industrial systems, Kubernetes, containers, authorization, SSRF, TLS/certificate validation, parsers, protocols, supply-chain trust
- Detection & Security Engineering
- Microsoft Sentinel, Defender XDR, KQL, Sigma, MITRE ATT&CK, Security Onion, Suricata, Zeek, Wazuh, Detection-as-Code
- Tools
- Python, Go, C++ analysis, Bash, PowerShell, Linux, Docker, GitHub Actions, Semgrep, Joern, CodeQL
CERTIFICATIONS & EDUCATION
- CompTIA Security+ ce
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Sierra College, IT & Cybersecurity, 2025–Present
- National Metallurgical Academy of Ukraine, B.S. Engineering