Nguyen Dinh Hai
haind@ptit:~$ whoami Nguyen Dinh Hai (HaiND) haind@ptit:~$ cat role.txt Cybersecurity Teaching Assistant @ PTIT haind@ptit:~$ cat focus.txt reverse engineering · malware analysis threat hunting · vulnerability research haind@ptit:~$ ./play --ctf --team PTIT [+] M*CTF 2025 ............. champion [+] CSCV 2025 .............. 2nd prize [+] Flare-On 11 12 13 ...... finisher x3 [+] Digital Dragons 2025 ... consolation [+] HackTheon Sejong 2025 .. top 10 [+] ASEAN 2024 ............. 3rd prize [+] ASEAN 2023 ............. consolation [+] PTIT CTF 2023 .......... 2nd prize [+] PTIT CTF 2022 .......... consolation haind@ptit:~$
Whoami
I'm Hai. I mostly do reverse engineering and malware analysis, plus some digital forensics and web bug hunting. This blog is where I keep my notes.
Right now I'm a cybersecurity teaching assistant at PTIT (Posts and Telecommunications Institute of Technology). I help with security courses, some research, and training students for CTFs. Before that I was at BlueCyber for about three years, first as an intern doing RE and malware analysis, then full time on threat hunting and incident response.
In my free time I look for bugs in WordPress plugins and report them through Wordfence and Patchstack. I also play CTF with the PTIT team, usually reversing and forensics.
Experience
- May 2026 · nowCybersecurity Teaching AssistantPosts and Telecommunications Institute of Technology
Teaching support for security courses, academic research, and training students for security competitions.
- 2024 · Apr 2026Threat Hunting & Malware AnalysisBlueCyber Limited Company
Hunting for advanced persistent threats, analysing malicious activity and samples, and running incident response investigations.
- Feb 2023 · Feb 2024Intern, Reverse Engineering & Malware AnalysisBlueCyber Limited Company
Reverse engineering and malware analysis.
- 2024 · 2025Challenge authorPTIT Student Information Security Competition
Wrote reverse engineering and forensics challenges, validated the solutions and deployed the infrastructure for the qualifying and final rounds.
Vuln research
I find bugs in WordPress plugins and report them through the Wordfence and Patchstack bug bounty programs. So far that's 22 CVEs (#244 all time on Wordfence). Top 5 by CVSS below, the full list is in the CVE archive, and the advisories are on my Wordfence researcher profile.
Honors
Start reading
$ cd technique-reverse/Technique ReverseMy RE series: assembly, file formats, languages, unpacking, anti-debug, Frida. $ cd malware-analysis/Malware analysisWrite-ups on malware samples and a threat hunting lab. $ cat ctf-journey.logCTF journeyPosts about the CTFs I've played. $ ls -la archives/ArchivesEvery post, by date.