About Me

I am a Security Research Engineer with an offensive security background, working across vulnerability research, red teaming, AI security, identity security, application security, and security tooling. My professional experience spans enterprise banking security and cybersecurity consulting, conducting end-to-end security assessments across Web, API, Mobile, Network, and Identity environments, alongside red team operations focused on real-world attack scenarios, security-control bypasses, and adversary simulation.

I am particularly interested in research at the intersection of Security, AI, and Systems, including Identity & Access Security, AI/LLM and Agent Security, Mobile/iOS Security, and vulnerability discovery, with a genuine applied AI/ML research background beyond cybersecurity in computer vision, biometrics, medical AI, and deep learning systems. My long-term direction is to deepen into vulnerability research, AI systems security, reverse engineering, fuzzing, OS/kernel internals, and security-focused systems engineering.

Beyond security testing, I enjoy turning research into practical outputs: PoCs, tools, open-source projects, CVEs, academic publications, and conference presentations. I am the creator of Oblivion Token (presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs), an upcoming speaker for Black Hat India 2026 Briefings and Red x Blue Pill 2026, credited on 32 CVEs, and author of 3 IEEE publications spanning Android OAuth 2.0 security testing and applied AI/ML systems.

Open to global opportunities in Security Research, Offensive Security, AI Security, Vulnerability Research, and graduate research pathways.

LinkedInGitHubResearchGateCredlyTryHackMeHackTheBoxHack The Box LabsCredential.NetMedium

Experience

Offensive Security Engineer at KASIKORN Business-Technology Group

Offensive Security Engineer

KASIKORN Business-Technology GroupFull-timeNov 2024 - Present · 1 yr 10 mosBangkok, Thailand 🇹🇭 · Hybrid
  • Delivered 40+ penetration tests across annual assessments and major-change projects, and contributed as a core member of advanced Red Team engagements, translating findings into practical remediation actions.
  • Supported SSE security testing, including AI Prompt Gateway testing, guardrail validation, and Thai/English attack scenarios.
  • Owned 10+ major security assessment projects across 2025–2026, leading planning, testing oversight, reporting, stakeholder communication, and remediation follow-up.
Cybersecurity Consultant (Penetration tester) at ALPHASEC

Cybersecurity Consultant (Penetration tester)

ALPHASECFull-timeJun 2024 - Oct 2024 · 5 mosBangkok, Thailand 🇹🇭 · Hybrid
  • Conducted in-depth penetration testing of IT infrastructure, identifying vulnerabilities in operating systems, applications, configurations, and user behavior.
  • Specialized in web, mobile, and software vulnerability assessments following OWASP Top 10 and industry best practices.
  • Delivered detailed security reports with actionable remediation steps to strengthen clients’ overall security posture.
  • Worked cross-functionally with development and infrastructure teams to ensure timely remediation of security risks.
  • Successfully completed 16 security assessment projects during the engagement.
Cybersecurity Consultant (Penetration tester) at KPMG Thailand

Cybersecurity Consultant (Penetration tester)

KPMG ThailandInternshipJan 2024 - Apr 2024 · 4 mosBangkok, Thailand 🇹🇭 · Hybrid
  • Assisted in conducting penetration tests on software, mobile, and web applications using tools such as Kali Linux and Burp Suite.
  • Followed OWASP best practices to identify and document security vulnerabilities and simulate real-world cyberattacks.
  • Performed vulnerability assessments on KPMG’s internal network using Nessus and other scanning tools.
  • Contributed to the development of a secure internal website, incorporating security-by-design principles.
  • Completed 2 penetration testing projects and 1 vulnerability assessment project, improving communication of complex findings to stakeholders.

Talks & Contributions

ConferenceUpcoming (Accepted)
Policy per App, Trust per Family: Cross-Application Privilege Amplification in Microsoft 365
Black Hat India Briefings 2026

This briefing presents a systematic methodology for evaluating Microsoft 365 Conditional Access enforcement across applications and explores how cross-application trust relationships can create unintended privilege amplification.

Track 2 · 16:00 IST · Sheraton Grand – Brigade Gateway, Bengaluru, India30 Oct 2026
ConferenceUpcoming (Accepted)
Your Clients Think MFA Means Secure. Prove Them Wrong: Systematic M365 Conditional Access Bypass via Microsoft First-Party Apps
Red x Blue Pill 2026

Waris Damkham and Nuttakorn Tungpoonsup present a systematic methodology for mapping Microsoft 365 Conditional Access enforcement across users, resources, client applications, authentication flows, and Microsoft first-party app behavior.

Red x Blue Pill 2026 · Thailand12 Sep 2026
Demo LabsPresented
Oblivion Token: M365 Conditional Access Policy Bypass OST (Offensive Tooling)
DEF CON Singapore 2026 Demo Labs

Presented for DEF CON Singapore 2026 Demo Labs. Oblivion Token is an offensive research utility for practical, repeatable testing of Microsoft 365 Conditional Access (CA) edge cases. It systematizes token-centric workflows to help identify where device, network, or app-context assumptions can fail in real-world environments.

Marina Bay Sands, SingaporeApr 28-30, 2026

Publications

TENCON 2024

2024

Practical Mobile Based Services for Identification of Chicken Diseases From Fecal Images

IEEE Region 10 Conference 2024

QRS 2023

2023

Detecting Vulnerable OAuth 2.0 Implementations in Android Applications

23rd IEEE International Conference on Software Quality, Reliability, and Security

InCIT 2022

2022

Automated COVID-19 Screening Framework Using Deep CNN With Chest X-Ray Medical Images

6th International Conference on Information Technology

Awards

2nd Runner-up

Thailand Banking AI Red Team Challenge 2026

Thailand Banking Sector CERT (TB-CERT)

LinkedIn Post

Rising Award

KBTG Star Awards 2025

KASIKORN Business-Technology Group (KBTG)

LinkedIn Post

Security Vulnerabilities (CVEs)

Total 32Critical 4High 11Medium 16Low 1Latest Aug 12, 2026
Medium
CVE-2026-0294
Prisma Access Agent: Local Privilege Escalation

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

Aug 12, 2026
Low
CVE-2026-0292
Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Aug 12, 2026
High
CVE-2026-18881
TableOn

The TableOn plugin for WordPress is vulnerable to blind SQL Injection via the 'comment_count' filter parameter in all versions up to, and including, 1.0.5.1 due to insufficient escaping on user-supplied input and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to extract sensitive information from the database.

Aug 4, 2026

Projects

Credentials & Recognition

Blue Team / DetectionJuly 08, 2026

Hack The Box Certified Defensive Security Analyst

Hack The Box

View Credential
AI SecurityJun 30, 2026

Certified Artificial Intelligence Security & Risk (CAISR)

Red Team Leaders

View Credential
Blue Team / DetectionJun 2026

Incident Responder Training Completion

Group‑IB

View Credential
Mobile / WirelessJun 2026

iOS Application Exploitation Challenges (4/11 Labs Completed)

8kSec

View Credential
Offensive SecurityJun 2026

ARM Exploitation Challenges (2/10 Labs Completed)

8kSec

View Credential
AwardsMay 2026

KBTG Star Award 2025: Rising Star Award

KASIKORNBANK

View Credential

Capabilities & Tools

Offensive Security & Red Teaming

Hands-on assessment, adversary simulation, exploitation, and vulnerability validation.

Penetration Testing · Red Teaming · Web Exploitation · Network Exploitation · Privilege Escalation · Burp Suite · Kali Linux

Application, API & Mobile Security

Security review and testing across web, API, mobile, OAuth, and Android attack surfaces.

Application Security · API Security · Mobile Security · Android Security · OAuth 2.0 · OIDC · OWASP Top 10

Identity, Cloud & M365 Security

Identity-centered cloud security research, policy testing, and Microsoft 365 attack paths.

Microsoft Entra ID · Microsoft 365 · Conditional Access · Microsoft Graph API · Azure · AWS · Cloud Security

AI, LLM & Machine Learning

AI security readiness, LLM threat modeling, and applied machine-learning research experience.

AI Security · LLM Security · AI Red Teaming · Prompt Injection · MCP Security · OWASP LLM Top 10 · TensorFlow

Security Automation & Engineering

Automation and engineering used to scale testing, reporting, triage, and repeatable workflows.

Python · JavaScript · Bash · Power Automate · Power Apps · GitHub Actions · Selenium

Reporting, Research & Communication

Turning technical findings into clear executive, engineering, academic, and public-facing output.

Executive Reporting · Technical Reporting · Vulnerability Triage · CVE Research · Risk Communication · Security Briefing · Public Speaking

Education

Mahidol University

Bachelor of Science (Information and Communication Technology)International Program2020 - 2024Thailand 🇹🇭
ICT Internship Poster Exhibition 2023 at ICT MahidolSep 2023

Joined the exhibition showcasing B.Sc. ICT International Program student internships. Proudly shared my experience from Ritsumeikan University among esteemed peers. An enriching platform for insights and networking.

Bangkok Christian College

GPAX 3.48Smart Computer2008 - 2020Thailand 🇹🇭
Portfolio

University application portfolio and supporting academic showcase.

Competitions

Blog

My Resume

resume.pdf - waaris_m@portfolioOpen PDF

waris_m@portfolio:~$ ls -lh latest-resume.pdf

Waris_Resume_2026.pdf

Latest version · PDF document

Preview the document here or download the original PDF.

Download PDF