Skip to content

01 — Case Studies

Case Studies

7 selected cases - what was at stake, how it was approached, and what remained.

01

OT/ICS Security (IEC 62443)

LS ELECTRIC Automation Devices - Achilles Communication Certificate Level 2 Certification

Background
Prior review, testing, and remediation were required for LS ELECTRIC's PLC product line to obtain the international communication robustness certification (Achilles Communication Certificate Level 2). The demanding pass criteria required control functions to remain operational even under DoS, storm, and abnormal traffic conditions.
Approach
Performed communication robustness review across all Achilles Communication Certificate Level 2 test items for the PLC product line. Verified storm/fuzzing/abnormal packet resilience against the communication stack including XGT Protocol, and reproduced defects. Designed certification test scenarios and handled retests to verify that pass criteria were met.
Result
Achieved Achilles Communication Certificate Level 2 certification for the LS ELECTRIC PLC product line. Identified communication robustness defects -> reflected in product firmware remediation.

Role & period

LS ELECTRIC · 2024.07 — 2025.03 · Lead (overall certification review and testing)

02

Cyber Range & CTF Development

NATO CCDCOE Locked Shields 2025 - Korea-Canada Joint DFIR Blue Team

Background
Participated as a member of the Korea-Canada joint DFIR (Digital Forensics and Incident Response) Blue Team in Locked Shields, the world's largest international cyber defense exercise. It is a high-intensity exercise involving the analysis of intrusion artifacts and incident response reporting under a live-attack environment. (In 2026, participated in the Korea-Hungary joint Special System Blue Team.)
Approach
Performed incident forensic analysis and timeline reconstruction under live attack scenarios. Carried out DFIR CTF tasks - artifact analysis and malware triage. Operated an incident response reporting framework based on joint-team collaboration.
Result
Locked Shields 2025: #6 overall (of 17 teams) · DFIR #1. Locked Shields 2026: #9 overall (of 16 teams).

Role & period

NATO CCDCOE · 2025.01 — 2025.04 · DFIR Blue Team member (forensics and incident response)

03

Vulnerability Research (CVE/FVE)

llama.cpp LLM Inference Engine Vulnerability Research (3 CVEs)

Background
While LLM inference engines are being rapidly incorporated into internal and product infrastructure, the attack surface exposed in server mode had been only shallowly reviewed. I verified the possibility of remote unauthenticated attacks against the llama.cpp server's external-input handling paths (grammar conversion, model parser, ranking API).
Approach
Analyzed the uncontrolled recursion in json-schema-to-grammar's SchemaConverter::visit and _generate_union_rule - reproduced a DoS from exhaustion of the default 8MB thread stack at recursion depths above 7000 (CVE-2026-52130, CWE-674, CVSS 7.5). Scoped the affected path precisely - confirmed that only POST /completions is affected and that /v1/chat/completions is not, as it goes through the jinja engine, yielding a false-positive-free impact assessment. Induced a process abort when loading a malicious GGUF model via an assertion reachable in gguf_reader::read (CVE-2026-52131, CWE-617). Identified a DoS based on an integer overflow from a negative top_n on the /rerank endpoint and wrote a PoC (CVE-2026-52132, CWE-190).
Result
3 CVEs assigned for llama.cpp - CVE-2026-52130 / 52131 / 52132. Provided upstream with reproduction procedures distinguishing vulnerable from non-vulnerable paths, including 2 remote unauthenticated DoS issues (CVSS 7.5).

Role & period

ggml-org/llama.cpp (open source) · 2026.07 — 2026.08 · Lead for vulnerability analysis and reporting

04

IoT Vulnerability Research & Tooling

Development of an IoT/CCTV Incident Investigation Tool

Background
IoT devices such as CCTV lack standardized evidence-collection procedures and tools when an incident occurs. An automated investigation tool was needed to rapidly secure configuration files and logs inside the firmware.
Approach
Designed and implemented an automated incident-evidence collection tool for 40 domestic and overseas CCTV models. Developed modules for UART access, flash dumping, binwalk-based firmware extraction, and exhaustive collection of configuration files and logs. Performed collection of incident artifacts on 40 actual devices at a public institution's site.
Result
Developed an automated incident-evidence collection tool for 40 domestic and overseas CCTV models. Field validation at a public institution - collected and analyzed intrusion artifacts across 40 devices.

Role & period

CoreSecurity (R&D) · 2022.08 — 2022.12 · Tool design and development

05

OT/ICS Security (IEC 62443)

LS ELECTRIC IEC 62443-4-2 Automated Assessment Tool Development

Background
During preparation for IEC 62443-4-2 certification of LS ELECTRIC's PLC product line, checking the component security requirements (CR) was mostly manual. Requirements that could be checked automatically over communication had to be tooled to reduce the cost of repeated assessments.
Approach
Selected IEC 62443-4-2 SL1 requirements amenable to communication-based automation and designed an assessment tool. Implemented assessment automation for the FR2 (Use Control), FR3 (System Integrity), FR4 (Data Confidentiality), and FR7 (Resource Availability) areas. Built a web-based UI for managing assessment targets and results and a result-storage pipeline.
Result
Developed an automated assessment tool for the communication-based IEC 62443-4-2 requirements of the LS ELECTRIC PLC product line (contribution 90%). Reduced assessment time compared to manual work.

Role & period

LS ELECTRIC · 2025.03 — 2025.11 · Lead for automation tool design and development

06

Cyber Range & CTF Development

APEX 2026 DFIR Green Team - FOR400 Problem Authoring

Background
Participated as part of the APEX 2026 DFIR Green Team and single-handedly authored a problem in the FOR400 (highest forensics difficulty) category. Designed a maritime-incident multi-flag scenario weaving together satellite communications (VSAT), AIS, and firmware reversing.
Approach
Designed a multi-flag forensic scenario weaving together a ship's satellite communication terminal command traffic (capture.pcap) and manipulation of the ECDIS navigation display. Constructed an intrusion timeline leading from CCSDS command interface probing -> AIS spoofing -> firmware tampering. Wrote the authoring deliverables including the ground truth report, scoring rubric, and incident report.
Result
Single-handedly authored the FOR400 highest-difficulty problem as part of the APEX 2026 DFIR Green Team (contribution 100%).

Role & period

APEX CTF 2026 · 2026.06 — 2026.09 · DFIR Green Team / FOR400 problem author

07

Cyber Range & CTF Development

Busan IT Industry Promotion Agency Cyber Attack-Defense Competition (HACKSIUM) Operations Contract

Background
Authored HACKSIUM qualifier and final-round problems and ran the competition. For the finals, designed a real-time defense scenario for a maritime-logistics group; for the qualifiers, authored all 16 Forensics, Crypto, Pwn, Rev, Web, and Misc problems using Busan place names as codenames.
Approach
Designed the final-round LiveFire blue-team defense scenario - 4 zones (satellite, ship, port, corporate IT) with a 6-hour (3-phase) real-time incident-response scoring framework. Authored all 16 qualifier problems - Busan place-name codenames, across all Forensics/Crypto/Pwn/Rev/Web/Misc categories. Supported operations of the qualifier and final rounds.
Result
Designed the HACKSIUM final-round LiveFire scenario, authored all 16 qualifier problems, and ran the competition (contribution 70%).

Role & period

Busan IT Industry Promotion Agency · 2026.06 — 2026.09 · Qualifier and final-round problem authoring and competition operations

Where this fits

Looking for someone who can run assessments like these?

02 — About

About Me

I'm Seungpyo Hong, a vulnerability researcher. I have found vulnerabilities across IoT, ICS, financial services and AI software.

These days I design and run my own LLM-driven pipeline to automate the search. I decide which targets and which parts of them to look at, and I report only the candidates I have reproduced myself and proven to have real impact. I want to go deeper into research on automating vulnerability analysis with LLMs.

Core Expertise

  • OT/ICS security (IEC 62443)
  • IoT & firmware analysis
  • Linux kernel vulnerability research
  • Web/app penetration testing
  • LLM inference-engine security
  • Medical device security (FDA)

Experience

2021.06 - Present

ICS Security Researcher (Associate Researcher) · CoreSecurity

OT/ICS security — performed IEC 62443-4-2 based threat modeling and penetration testing. Earned the Achilles Communication Certificate Level 2 for LS ELECTRIC automation devices and developed an automated assessment tool. IoT security — developed and validated smart-building IoT vulnerability-detection technology and built IoT/CCTV incident-investigation tools.

2020.06 - 2021.06

Web/App Pentester (Staff) · A3 Security

Performed penetration testing of financial and public electronic-finance infrastructure. Targets included Cham Savings Bank, Acuon Capital, KOFIA, SBI Savings Bank, Hyundai Motor (HKMC), and Nonghyup RPA. Performed security reviews of non-standard systems. Targets included the KT GiGA Genie AI speaker, IoT thermal-detection equipment, and DB Insurance's claim-call system.

Education

2012.02 - 2020.02

Kongju National University, Dept. of Computer Engineering (2012.02 — 2020.02) · Kongju National University

Computer Engineering

2009.03 - 2012.02

Cheonan Commercial High School, Information Processing (2009.03 — 2012.02) · Cheonan Commercial High School

Information Processing

Download career statement (PDF)

Technologies & Tools

C/C++PythonTypeScriptShellIDA ProGhidraBurp SuiteFridaWiresharkAchilles Test Platform

03 — Research

Security Research

Current focus areas - OT/ICS security (IEC 62443), IoT and firmware, and Linux kernel and LLM inference-engine vulnerability research.

01

OT/ICS Security (IEC 62443)

2023.03 - 2025.11

4 projects

  • LS ELECTRIC Automation Devices - Achilles Communication Certificate Level 2 Certification
  • LS ELECTRIC Automation Devices - Threat Modeling Consulting
  • LS ELECTRIC IEC 62443-4-2 Automated Assessment Tool Development
  • Smart Ship Infrastructure Vulnerability Analysis/Validation Tool and Security Technology Development
Achilles Test PlatformXGT ProtocolPLCWiresharkPythonSTRIDEDREADDFD
02

Cyber Range & CTF Development

2021.05 - 2026.09

10 projects

  • NATO CCDCOE Locked Shields 2025 - Korea-Canada Joint DFIR Blue Team
  • C2021 Event (ELECCON Competition Operations)
  • Enhancement of a Hands-On Cybersecurity Training System
  • KEPCO Hands-On Cybersecurity Training System Reinforcement (ELECCON)
DFIRVolatilityWiresharkSysmonYARAOT/ICSSCADACTF
03

Vulnerability Research (CVE/FVE)

2026.07 - 2026.08

2 projects

  • llama.cpp LLM Inference Engine Vulnerability Research (3 CVEs)
  • Data Platform Unauthenticated IDOR Vulnerability Report (FVE)
C/C++llama.cppGGUFFuzzingCVSS 3.1PoCWebAPI Security
04

IoT Vulnerability Research & Tooling

2020.10 - 2022.12

5 projects

  • Development of an IoT/CCTV Incident Investigation Tool
  • KT GiGA Genie AI Speaker Device Penetration Testing
  • Development and Validation of IoT Device Vulnerability Detection Technology in Smart Buildings (Year 1)
  • Development and Validation of IoT Device Vulnerability Detection Technology in Smart Buildings (Year 2)
PythonC/C++UARTbinwalkFirmware DumpLinuxBluetoothAPK
05

Financial & Public Web/App Pentesting

2020.06 - 2021.06

1 project

  • Penetration Testing of Financial and Public Electronic Financial Infrastructure (12 sites)
Burp SuiteOWASP Top 10Web/App PentestSource Code Review
All research areas2 more, from Medical Device Security (FDA/eSTAR) to Security Consulting & CertificationView the full archive

04 — Findings

Selected Findings

The evidence index behind the case studies and the restored disclosure archive. Every entry links to a public artifact (a CVE record, advisory, or merged fix) or, for masked platform disclosures, to my own write-up.

Disclosure archive

24 CVEs + 4 masked platform disclosures (FVE)

9 memory-corruption, 2 out-of-bounds read, 5 injection/command-execution, 4 authentication/access-control, and 8 logic/denial-of-service findings.

Explore the full ledger
Pending2026-09-07

CVE-UNASSIGNED-MDEV-40571

MariaDB .frm parsing OOB read leads to vtable hijacking RCE

Database
CVE2026-08-12

CVE-2026-52130

llama.cpp json-schema-to-grammar uncontrolled recursion

LLM
CVE2026-08-12

CVE-2026-52131

llama.cpp gguf_reader::read reachable assertion

LLM
CVE2026-08-12

CVE-2026-52132

llama.cpp /rerank negative top_n denial of service

LLM
FVE2026-08-10

FVE-2026-8617-75112

Masked web disclosure from Findthegap bug bounty platform

Web
FVE2026-06-11

FVE-2026-8617-74526

Masked web disclosure from Findthegap bug bounty platform

Web
FVE2026-06-07

FVE-2026-8617-74507

Masked web disclosure from Findthegap bug bounty platform

Web
FVE2026-06-07

FVE-2026-8617-74513

Masked web disclosure from Findthegap bug bounty platform

Web
CVE2024-05-06

CVE-2024-33788

Linksys E5600 command injection

IoT
CVE2024-05-03

CVE-2024-33789

Linksys E5600 command injection

IoT
CVE2024-05-03

CVE-2024-33791

netis-systems MEX605 cross-site scripting

IoT
CVE2024-05-03

CVE-2024-33792

netis-systems MEX605 OS command execution

IoT
CVE2024-05-03

CVE-2024-33793

netis-systems MEX605 OS command execution

IoT
CVE2019-12-31

CVE-2019-19927

Linux kernel ttm slab out-of-bounds read

Kernel
CVE2019-12-17

CVE-2019-19813

Linux kernel btrfs use-after-free

Kernel
CVE2019-12-17

CVE-2019-19814

Linux kernel f2fs slab out-of-bounds write

Kernel
CVE2019-12-17

CVE-2019-19815

Linux kernel f2fs NULL pointer dereference

Kernel
CVE2019-12-17

CVE-2019-19816

Linux kernel btrfs slab out-of-bounds write

Kernel
CVE2019-12-08

CVE-2019-19447

Linux kernel ext4 use-after-free

Kernel
CVE2019-12-08

CVE-2019-19448

Linux kernel btrfs use-after-free

Kernel
CVE2019-12-08

CVE-2019-19449

Linux kernel f2fs slab out-of-bounds read

Kernel
CVE2019-11-29

CVE-2019-19377

Linux kernel btrfs use-after-free

Kernel
CVE2019-11-29

CVE-2019-19378

Linux kernel btrfs slab out-of-bounds write

Kernel
CVE2019-11-28

CVE-2019-19318

Linux kernel btrfs use-after-free

Kernel
CVE2019-11-27

CVE-2019-19319

Linux kernel ext4 slab out-of-bounds write

Kernel
CVE2019-11-21

CVE-2019-19036

Linux kernel btrfs root node NULL pointer dereference

Kernel
CVE2019-11-21

CVE-2019-19037

Linux kernel ext4 NULL pointer dereference

Kernel
CVE2019-11-21

CVE-2019-19039

Linux kernel btrfs information disclosure

Kernel
CVE2019-11-14

CVE-2019-18885

Linux kernel btrfs NULL pointer dereference

Kernel

Bug-bounty submissions and client-security reports are disclosed privately by default; this is the subset with public artifacts. More on GitHub.

05 — Exercises

Cyber defence exercises

International and national cyber defence exercises, as a blue-team operator and a green-team challenge developer.

Locked Shields 2026

Korea-Hungary joint team

#9 overall (of 16 teams)

Special System Blue Team

APEX 2026

Green TeamDFIR challenge development

Locked Shields 2025

Korea-Canada joint team

#6 overall (of 17 teams) · DFIR #1

DFIR Blue Team

APEX 2025

Green TeamDFIR challenge development

KEPCO ELECCON 2021-2024

OperationsChallenge development

08 — Work with me

Choose the shortest path

I'm an Associate Researcher on the ICS Security Research Team at CoreSecurity. I'm glad to hear from hiring teams working on hard security problems.

For hiring teams

Evaluate role fit quickly

A concise recruiter brief with current focus areas, selected evidence, experience, working model, and links to the CV and professional profiles.

Open recruiter brief
newbiepwner@kakao.comNo formality needed for a first, non-confidential note.