offensive security research collective

We break it
before they do.

TEAM N1TRO hunts vulnerabilities across every attack surface, from the web to the kernel. We find them before anyone else can abuse them, hand them to the vendor under responsible disclosure, and hold the details until the patch ships.

01

About

// who we are

N1TRO is a security research team that digs into real vulnerabilities. Through bug bounty platforms and direct vendor channels we find flaws in services and software already in production, and report them with a proof of concept that reproduces exactly as written.

Not one-off reports that fire once and die — we build research that reproduces on any run. Every finding follows responsible disclosure, and no detail goes public before the patch.

From the application layer — web and mobile — down to the Windows and Linux kernel, desktop clients, and open source code audits. No surface is off limits.

CVEs authored5
Disclosed10+
Bounty earned$17.3K+
ATO chains1
02

AI-Driven Research

// hunting at machine scale

Hunting comes down to coverage, and one pair of hands only sweeps so much. N1TRO runs recon, code audit and variant analysis through an LLM-driven analysis pipeline, reaching surfaces a solo hunter would have walked past.

→ ai.01

AI Red Teaming

LLM and agent systems are the target themselves. Prompt injection, tool abuse, privilege boundary bypass. An AI product is still code, and code still breaks.

→ ai.02

$10,000+ with AI

Real bounties paid out of a hunting workflow with AI in the loop. Pin a pattern once — auth proxy shapes, operation_id replay — and you mine it again and again.

→ ai.03

Automated Audit

Whole binaries and source trees go through the LLM pipeline to surface CVE variants. Bolt on headless decompilation and the spots we used to guess at get swept automatically.

$ ai-hunt --target prod --scale ∞  [running]
03

Expertise

// attack surface
— application layer
srf.01

Web

IDOR · SSRF · auth bypass · command injection · cross-auth endpoint testing

srf.02

Mobile

Android / iOS · static & dynamic analysis · gRPC · API & deeplink abuse

srf.03

Desktop App

named pipe DACL · DLL hijack · IPC abuse · local privilege escalation

— systems
srf.04

Windows Kernel

driver fuzzing · IOCTL surface · token & ACL primitives · EoP

srf.05

Linux Kernel

syscall audit · container runtime (runc) · namespace & mount escapes

srf.06

Open Source

source code audit · CVE authorship · variant analysis · responsible disclosure

04

Findings

// selected disclosures
Bugcrowd
programs · multiple
Command injection, SSRF and more — cumulative bounty milestone
$16,000 · status: accepted
Google
VRP
Path Traversal
$1,337 · status: accepted
Kakao
KV-2026-230
Validated and accepted report
accepted
Kakao
KV-2026-278
Validated and accepted report
accepted
Naver
NBB-2026-0118
Validated and accepted report
accepted
FindTheGap
disclosure
Account Takeover (ATO)
resolved
more disclosures pending vendor patch — listed after public release
06

Articles

// research notes
chwrld 4 min read

Write-up format

The house format for research notes: every frontmatter field and what belongs in it, how to use code blocks, images and tables, and the redaction checklist that runs before anything is published.

chwrld 4 min read

Responsible disclosure policy

How TEAM N1TRO reports the vulnerabilities it finds and when it publishes them: the disclosure window, the exceptions, and what vendors and reporters can each expect from us.

05

Team

// the operators
chwrld
chwrld
security researcher / pentester
Web · Mobile · Cloud · Desktop Application.
Bug bounty research first — mostly white-box targets where the source is open.
CVE CVE-2026-25531CVE-2026-25530CVE-2026-2557CVE-2026-5117CVE-2026-54312
Hercent
Cyber Security Researcher
Web · Geo-OSINT.
Researches web application vulnerabilities and exploit chains. Digs into the root cause of bugs in live services and CTF environments, then builds proof of concept exploits that actually reproduce. Web security is the main focus, with the scope widening into systems and offensive security.
[ recruiting — next operator ]

Found something on our radar?

Collaboration, joint research and reports are always welcome.
If you want to join the team, we want to hear from you.