Jiacheng(Gavin) Zhong — DevOps Engineer
I am a security researcher (OSCP, BSCP) specializing in AI system security, autonomous LLM agent architectures, OAuth/SaaS exploitation, and large-scale vulnerability discovery. As a graduate researcher at the Johns Hopkins Security Lab under Dr. Yinzhi Cao, I have identified over 10 sandbox escape vulnerabilities in prominent LLM agent frameworks—including LlamaStack, Hugging Face, SmolAgents, and SecretFlow—as well as critical vulnerabilities in widely adopted LLM-integrated application platforms such as Gradio, Llama-Factory and AutoGPT. I have also discovered more than 300 Python class pollution vulnerabilities across open-source ecosystems, impacting major vendors including Google (Mesop) and Microsoft (Azure CLI). My research involves building CodeQL pipelines and LangGraph-based static analysis agents to automate end-to-end exploit path tracing, leading to multiple CVEs and a paper acceptance to the IEEE Symposium on Security and Privacy (S&P) 2026. During my internship at Obsidian Security, I led four offensive security research projects targeting OAuth and OpenID Connect flaws, including misimplementation, misconfiguration, misadoption, and misintegration. Across these projects, I uncovered 600+ critical vulnerabilities in widely used SaaS platforms spanning financial, HR, and CRM sectors, enabling account takeovers, personal/tenant-wide data breaches and authentication/2FA bypass. My work directly drove vendor remediation efforts and strengthened product-level identity threat detection. Earlier in my career, I developed over 800 IDS detection rules and identified 100+ critical vulnerabilities through web and mobile application security assessments across diverse industries in China. Notable achievements include a 2nd place finish at the Raymond James CTF 2024 and top-3 national rankings in multiple bug bounty programs.
Stackforce AI infers this person is a Cybersecurity Researcher specializing in AI and SaaS security.
Experience: 2 yrs 6 mos
Skills
- Security Research
- Web Security
- Pwn
- Reverse Engineering
- Network Security
- Security Operations
Career Highlights
- Identified over 10 sandbox escape vulnerabilities in LLM frameworks.
- Uncovered 600+ vulnerabilities in SaaS platforms during internship.
- Achieved 2nd place at Raymond James CTF 2024.
Work Experience
TikTok
Privacy Engineer - Red Team (7 mos)
Obsidian Security
Security Researcher (1 mo)
The Johns Hopkins University
Research Assistant (7 mos)
Course Assistant (4 mos)
Obsidian Security
Security Research Intern (3 mos)
Tophant Information Technology Co.
Cyber Security Researcher (7 mos)
DBAPPSecurity Co Ltd
Cyber Security Engineer (5 mos)
Education
Master of Science - MS at The Johns Hopkins University