
2nd Runner-up
Thailand Banking AI Red Team Challenge 2026
Thailand Banking Sector CERT (TB-CERT)

Security Research Engineer
Red Teaming • AI Security • Identity & AppSec
I am a Security Research Engineer with an offensive security background across vulnerability research, red teaming, AI security, identity security, application security, and security tooling. My experience spans enterprise banking security and cybersecurity consulting, including end-to-end assessments across Web, API, Mobile, Network, and Identity environments, as well as red team operations focused on real-world attack scenarios, security-control bypasses, and adversary simulation.
My research interests sit at the intersection of Security, AI, and Systems, particularly AI Systems & Agent Security, Identity & Authorization, Mobile/OS Security, Vulnerability Research, and Systems Security. I also remain interested in applied AI research, especially computer vision and deep learning systems. My long-term direction is to deepen into AI systems security, identity and authorization, reverse engineering, fuzzing, mobile/OS internals, and security-focused systems engineering.
I enjoy turning research into practical outputs: PoCs, tools, open-source projects, CVEs, academic publications, and conference talks. My applied AI/ML background includes computer vision and deep learning systems. I am the creator of Oblivion Token, presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs, a speaker at Red x Blue Pill 2026, and an upcoming speaker at Black Hat India 2026 Briefings. I have also presented academic research at IEEE QRS 2023 and IEEE InCIT 2022, and I am credited on 35 CVEs with 3 IEEE publications spanning Android OAuth 2.0 security and applied AI/ML systems.
Open to research collaborations, speaking opportunities, and graduate research pathways.


Key Responsibilities & Achievements


Key Responsibilities & Achievements


Key Responsibilities & Achievements

This briefing presents a systematic methodology for evaluating Microsoft 365 Conditional Access enforcement across applications and explores how cross-application trust relationships can create unintended privilege amplification.

Waris Damkham and Nuttakorn Tungpoonsup present a systematic methodology for mapping Microsoft 365 Conditional Access enforcement across users, resources, client applications, authentication flows, and Microsoft first-party app behavior.

Presented for DEF CON Singapore 2026 Demo Labs. Oblivion Token is an offensive research utility for practical, repeatable testing of Microsoft 365 Conditional Access (CA) edge cases. It systematizes token-centric workflows to help identify where device, network, or app-context assumptions can fail in real-world environments.

Presented at Black Hat Asia 2026 Arsenal. Oblivion Token is an offensive research utility for practical, repeatable testing of Microsoft 365 Conditional Access (CA) edge cases. It systematizes token-centric workflows to help identify where device, network, or app-context assumptions can fail in real-world environments.
TENCON 2024
2024IEEE Region 10 Conference 2024
QRS 2023
202323rd IEEE International Conference on Software Quality, Reliability, and Security
InCIT 2022
20226th International Conference on Information Technology

2nd Runner-up
Thailand Banking Sector CERT (TB-CERT)

Rising Award
KASIKORN Business-Technology Group (KBTG)
The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary popups and inject malicious JavaScript that executes when the popup is displayed, leading to Stored XSS.
The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or sanitization of the URL. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations.



Red Thailand Cyber Top Talent 2026Team Leaders
View CredentialAl Governance Week 2026
View CredentialHack The Box
View CredentialRed Team Leaders
View Credential
Senior project / thesis focused on classifying chicken diseases from fecal images through a LINE Official Account.
Joined the exhibition showcasing B.Sc. ICT International Program student internships. Proudly shared my experience from Ritsumeikan University among esteemed peers. An enriching platform for insights and networking.

University application portfolio and supporting academic showcase.
waris_m@portfolio:~$ ls -lh latest-resume.pdf
Waris_Resume_2026.pdf
Preview the document here or download the original PDF.
waris_m@portfolio:~$ whoami
Waris Damkham
Security Research Engineer
# CONTACT
# PROFILES
waris_m@portfolio:~$