For the complete documentation index, see llms.txt. This page is also available as Markdown.

Global Cybersecurity Camp VN 2026

Xin chào!

Hi everyone! I'm Ruhan Aidan, a recent cyber security graduate from Malaysia and I want to share with you guys the amazing experience I recently had. Over the course of 1 week from the 1st to the 6th of March I had the amazing privilege of attending the Global Cybersecurity Camp Vietnam 2026 as one of the four representatives for Malaysia.

Day 1

The first day which is the day of our arrival had only one event scheduled for the GCC representatives, an ice breaking party!

This was a great introductory session and a fun one for all participants, I myself had a great time talking to the other representatives of the other countries and getting to know how has their experience at Vietnam been so far. There was also a short introduction for each country where each staff and student representative would give a brief introduction about themselves. (SUPER STACKED YO)

Day 2

FIRST TRAINING SESSION! So the first training session was done by Mars Cheng and his topic was Introduction to IoT/ICS Security & Firmware Analysis Skills. So as you can tell by the title this training session was focused on IoT/ICS security, here Mars Cheng introduced us to a bunch of tools that are equipped for firmware analysis such as Ghidra, QEMU, Firmadyne, FACT, Firmwalker, and GDB. Some tools were tools that I had never used before so it was a great learning experience for me to understand and learn the proper usage of commands. This class was a really great introductory session to the start of the camp and I believe got all of us kicking ready for the next sessions to come. We also had a brief ethics session and introduction to the group assignment before the training session as well which introduced the Mobile App Security assignment.

Then later at night we had a little extra time before starting the group assignment to go out and explore Ho Chi Minh and have a quick dinner. A beautiful city that words cant describe so i'll let the picture do the talking. I also had a lovely time at dinner meeting some of the other student representatives from the other participating countries.

Day 3

For day 3 we started off with the Practical Binary Hardening with Control-flow Enforcement Technology (CET) class led by Michael and Kento Oki. This class was about how modern binaries can be protected from control-flow hijacking attacks using CET, this was also one of the classes I was less familiar with so there was a lot to learn. The session first explained some initial binary exploitation techniques such as ROP, JOP and COP as many modern exploits depended on them. Afterwards, the class introduced Intel CET focusing on two key features Shadow Stack and Indirect Branch Tracking. What I found interesting was learning how CET reflects the direction that modern system security is heading towards. It showed how much more advanced exploit techniques have become which has led to the evolution of defenses moving beyond traditional software protections.

After lunch we headed on to the next class, Hypervisors for Hackers: Security from the Hardware Up by Satoshi Tanda. This class looked at hypervisors from the perspective of a security researcher. What was taught was the history of virtualization starting from full emulation, then moving to trap-and-emulate and para-virtualization before covering hardware-assisted virtualization such as Intel VT-x. From here, the class explained how hypervisors work internally, including concepts like VMX root and non-root mode, VMCS, VM-entry and VM-exit. Seeing how a hypervisor could monitor sensitive actions like changes to CR4.SMEP made the idea much easier to understand and was a good example that helped me grasp the knowledge quicker. It was an interesting session because not only did it stay at the theory level, but the trainer showed how hypervisors can actually be used in real defensive scenarios.

Day 4

For day 4, it was a full day of training by Shenghao Ma on Super Hat’s Kernel Trick: Social Engineering the AV/EDR Kernel Protection. This was one of the more memorable class as for me it was something I had totally no knowledge about but it piqued my interest as I felt like it could be used and replicated for CTF challenges which I'm keen on making someday soon. I expected this class to mainly be about finding ways to turn off AV or EDR, however the session was much more broader than that. It explained how endpoint protection is built from several connected mechanisms, and how with this knowledge someone could start taking advantage of the gaps in between those mechanisms.

This class covered a lot of areas, including file scanning when malware is dropped onto disk, Windows privilege tokens, Protected Process Light (PPL), kernel-level anti-tamper features and snadbox behavior. What stood out to me was how the session kept showing how these protections are not isolated but they depend on assumptions about trust, privilege and process integrity. Once you understand these assumptions, you can start thinking about how they might be exploited.

Side note: At night I had this really good noodle dish that I have now forgotten what it was called.

Day 5

Unfortunately, I fell sick this morning of day 5 so I was unable to attend the initial session of JimmySu & John Jiang on Born in the Cloud, Breached on the On-Prem: Entra ID Attack Chains. But I do highly recommend you guys to check out one of the other Malaysian representatives blogs to learn more about this session such as Cheng Xun's.

Fortunately, I felt better enough to attend the next session hosted at the HQ of VNG Group which was on a topic I was very much interested about Hands On Cybersecurity AI Workshop: Build your own Automated Agentic AI Penetration Tester in N8N & Car Hacking by Kar Wei Loh whom I had actually previously competed in a CTF where she was the challenge author. This session was a lot more hands-on than the other sessions as Kar Wei guided all students step-by-step on how to use OpenCode and it's features to build your own AI agent for pentesting. For more context, the session used OpenCode as she felt like n8n was outdated which was fine but a little bit of a bummer for me as I had never dabbled in n8n before so I was curious to see what could be possible. Overall, the session was a great introduction to building AI Agents for complete beginners. During the industrial session, every sponsor had an opportunity to give a brief introduction to their company and I was very fortunate to meet the sponsors for Malaysia which are Cyberwise Inc., Stratos Security, SecIron and SherpaSec. I am very grateful and thankful to these sponsors as they made the participation of all Malaysian representatives and it's inspiring for me to see them support the growth of the Malaysian community.

Later that night, my group and I decided to burn the midnight oil and really grind out the last few hours we had before the group assignment submission. Here we collaborated and split the group between 3 and 2 people to handle task 1 and 2 respectively. I couldn't thank my groupmates enough as well for being so cooperative and just fun to work with. I will never forget day 1 where we shared with each other the songs from our home country to get to know and appreciate each other's cultures.

Day 6

Okay so final day! I actually woke up late because we had stayed up till 4 am working on the group assignment, fortunately I made it in time before the Groupwork Presentation + Closing Ceremony started. During this time, each group presented their work and achievements throughout the group assignment and it was very eye opening for me at least as I was able to learn new kinds of Android Application Exploits which I had never seen before as I mainly pentest Web Applications. Very happy and proud to say that my team managed to secure 2nd Place!! This was deserved and truly the fruits of our hardwork together and nothing more that I can say besides I'm very proud of us.

Final Acknowledgements

I would like to again personally thank the sponsors for Malaysia once again whom without this would not have been possible Cyberwise Inc., Stratos Security, SecIron and SherpaSec. Thank you so much for your support and belief in us 4 student representatives for GCC 2026.

A special and heartful thank you to the Malaysian Staff, Shiau Huei and Ryan (Wo De Homie) for managing the logistics and coordinating with the other GCC staff for making our experience a lot easier during the event. Lastly, a special thank you to Khoa from the Vietnamese organizing staff that was in-charge of the Malaysian representatives. Thank you so much Khoa for being kind and patient with us as you showed us around Vietnam and cared for our well-being!

Conclusion

This whole event is now a core memory for me that I will not forget, from experiencing Vietnam to meeting the other countries representatives this was an experience that is simply priceless and I only dreamt of a year ago. The highlights for me from this trip was trying Pho Le, that my groupmate Yi brought our entire group to try, working as a group with people of different cultures which was something new for me, learning from trainers from all around the world and last but not least the memories I was able to make with everyone! Truly I cannot put into words how grateful I am for the experience. Thank you everyone for making this camp and experience one of the best of my life <3.

Last updated