HaiND's Blog
Security researcher // PTIT

Nguyen Dinh Hai

Nguyen Dinh Hai
ID // HaiND
11CTF achievements
22CVEs credited
3×Flare-On 11 · 12 · 13
147Posts written
…Total views
0x01

Whoami

I'm Hai. I mostly do reverse engineering and malware analysis, plus some digital forensics and web bug hunting. This blog is where I keep my notes.

Right now I'm a cybersecurity teaching assistant at PTIT (Posts and Telecommunications Institute of Technology). I help with security courses, some research, and training students for CTFs. Before that I was at BlueCyber for about three years, first as an intern doing RE and malware analysis, then full time on threat hunting and incident response.

In my free time I look for bugs in WordPress plugins and report them through Wordfence and Patchstack. I also play CTF with the PTIT team, usually reversing and forensics.

0x02

Experience

  • May 2026 · now
    Cybersecurity Teaching Assistant
    Posts and Telecommunications Institute of Technology

    Teaching support for security courses, academic research, and training students for security competitions.

  • 2024 · Apr 2026
    Threat Hunting & Malware Analysis
    BlueCyber Limited Company

    Hunting for advanced persistent threats, analysing malicious activity and samples, and running incident response investigations.

  • Feb 2023 · Feb 2024
    Intern, Reverse Engineering & Malware Analysis
    BlueCyber Limited Company

    Reverse engineering and malware analysis.

  • 2024 · 2025
    Challenge author
    PTIT Student Information Security Competition

    Wrote reverse engineering and forensics challenges, validated the solutions and deployed the infrastructure for the qualifying and final rounds.

0x03

Vuln research

I find bugs in WordPress plugins and report them through the Wordfence and Patchstack bug bounty programs. So far that's 22 CVEs (#244 all time on Wordfence). Top 5 by CVSS below, the full list is in the CVE archive, and the advisories are on my Wordfence researcher profile.

CVSSCVEAffectedType
10.0 CVE-2026-48836 Easy Invoice <= 2.1.19 Unauthenticated Remote Code Execution
9.3 CVE-2026-61950 TrueBooker Appointment Booking and Scheduler System <= 1.2.3 Unauthenticated SQL Injection
9.3 CVE-2026-57683 WP Fast Total Search <= 1.80.280 Unauthenticated SQL Injection
9.3 CVE-2026-49776 GPTranslate <= 2.32.6 Unauthenticated SQL Injection
8.8 CVE-2026-65542 Super Socializer <= 7.14.5 Missing Authorization
0x04

Honors

2026 Flare-On 13, Mandiant's reverse engineering challenge FINISHER
2025 Flare-On 12, Mandiant's reverse engineering challenge FINISHER
2024 Flare-On 11, Mandiant's reverse engineering challenge FINISHER
0x05

Start reading

0x06

Latest

$ ls -t posts/ | head -5