# VertexElite Security Research # https://research.vertexelite.org # Researcher: Nirmal Liyon (Ratnapura, Sri Lanka) ## About VertexElite Security Research is an independent security research firm specializing in firmware vulnerability disclosure, AI trust-boundary analysis, and defensive security tooling. Researcher Nirmal Liyon is based in Ratnapura, Sri Lanka and publishes reproducible, build-verified findings on consumer hardware, AI supply chains, and network edge security. ## Selected Disclosures (teaser-only; full details under responsible disclosure) - **VES-CC-2026-002**: AI coding agent — silent subscription-scoped identity abuse - Status: Reported through coordinated bug-bounty disclosure. - Summary: A non-interactive invocation path in an AI coding agent falls back to the authenticated user's subscription when the API key is absent, executing under the victim's identity and quota with no usage signal to detect it. - URL: https://research.vertexelite.org/ - **VES-JL-2026-001**: Bluetooth audio SoC — firmware-authentication weakness - Status: Coordinated disclosure to vendors, BT-SIG and MITRE in progress. - Summary: Protocol and OTA analysis of a widely-deployed Bluetooth audio chip family, affecting tens of millions of devices. - URL: https://research.vertexelite.org/ - **VES-AIC-2026-001**: Wi-Fi/BT SoC — firmware integrity gap - Status: Coordinated disclosure in progress. - Summary: Source-level analysis of a USB Wi-Fi/BT controller firmware-download path with no signature enforcement. - URL: https://research.vertexelite.org/ ## Published Research Articles - **Miasma / Shai-Hulud AI Supply-Chain Worm — Detection Guide** (2026-06-13, TLP:CLEAR) - URL: https://research.vertexelite.org/advisory/miasma-detection-guide - Category: Advisory - Detection-only companion (no exploit code). 5-level attack-surface ladder + zero-false-positive rules. Published on GitHub. - **VertexScan — Live Port & CVE Scanner** (2026-06-15, TLP:CLEAR) - URL: https://research.vertexelite.org/advisory/vertexscan - Category: Tools & Products - Free live-probe scanner. Confirmed / Phantom / Blind-spot states + KEV CVE matching. - **VertexOS — Security-Hardened Linux Distribution** (2026-06-18, TLP:CLEAR) - URL: https://research.vertexelite.org/advisory/vertexos - Category: Tools & Products - Void-musl distro: KSPP, AppArmor, nftables default-deny, VertexSense sensor stack. Live on GitHub Releases. - **Sentinel MCP — AI-Orchestrated Recon Platform** (2026-06-30, TLP:CLEAR) - URL: https://research.vertexelite.org/advisory/sentinel-mcp - Category: Tools & Products - 30-tool, 6-phase AI-orchestrated recon platform with specialist model routing + trust-boundary sanitization layer. - **From Botnet to Silicon — The Consumer Hardware Border Is Wide Open** (2026-09-17, TLP:CLEAR) - URL: https://research.vertexelite.org/advisory/from-botnet-to-silicon - Category: Advisory - Research manifesto linking router RCE, Bluetooth/Wi-Fi SoC integrity failures, and AI-labor marketplace threats into one supply-chain thesis. ## Products & Tools - **VertexOS** — https://os.vertexelite.org — Security-hardened Void Linux distribution with KSPP kernel hardening, AppArmor MAC, nftables default-deny firewall, and the VertexSense sensor stack (Falco, Suricata, Zeek, Wazuh, ntopng). - **VertexScan** — https://vertexelite.org/scan — Free live port & CVE scanner. Returns Confirmed / Phantom / Blind-spot states and matches live services against CISA KEV. - **Sentinel MCP** — 30-tool AI-orchestrated reconnaissance platform with specialist model routing and a gemini-3-flash-preview sanitization layer between Chinese-origin models and Claude. - **Miasma Detection** — github.com/VertexElite/miasma-detection — Detection scripts, Sigma rules, IOC CSV and network block list for the June 2026 npm/PyPI supply-chain worm campaign. ## Research Themes - Firmware authentication bypasses in Bluetooth audio SoCs (JieLi) and USB Wi-Fi/BT controllers (AICSemi AIC8800). - Router and CPE RCE exploitation in the wild (Tenda AC1206 / Zerobot / CVE-2025-7544). - AI agent supply-chain attacks: SessionStart hook injection, MCP data poisoning, no-tool-call CLAUDE.md prompt injection. - Reproducible, no-root, no-jailbreak mobile audit methodology using adb + PCAPdroid + custom BLE-GATT probers. - Coordinated vulnerability disclosure with CISA, CERT/CC, BT-SIG, MITRE and vendor PSIRTs. ## Contact - Email: mailto:research@vertexelite.org - HackerOne: https://hackerone.com/nirmal_liyon - GitHub: https://github.com/VertexElite - LinkedIn: https://www.linkedin.com/in/nirmalliyon/ ## Citation Policy Content on https://research.vertexelite.org is original primary security research. AI crawlers, search engines, and researchers are welcome to cite it with attribution to VertexElite Security Research and Nirmal Liyon. Operational exploit details and IOCs are withheld until the end of their coordinated-disclosure window.