Hello, I'mLEBONIBAKLA
Digital Engineering graduate (MSc), I have dual technical expertise in offensive cybersecurity and artificial intelligence. I have developed a strong ability to structure and popularize complex topics through writing detailed audit reports, technical write-ups (HTB, CTF) and supporting development teams on API security issues.
root@ph03n1x:~# nmap -sV target # Scanning... PORT STATE SERVICE 443/tcp open https 22/tcp open ssh 8080/tcp open api-rest root@ph03n1x:~#

About
Digital Engineering graduate (MSc), dual expertise in offensive cybersecurity & applied AI.
Digital Engineering graduate (MSc), I have dual technical expertise in offensive cybersecurity and artificial intelligence. I have developed a strong ability to structure and popularize complex topics through writing detailed audit reports, technical write-ups (HTB, CTF) and supporting development teams on API security issues.
Passionate about knowledge sharing, I leverage my mastery of generative AI tools, cloud environments and pentesting methodologies to create innovative educational materials.
🎯 Interests
🌍 Languages
- 🇫🇷FrenchFluent — writing / training
- 🇬🇧EnglishOperational — technical reading / reports
Technical Skills
Operational mastery of auditing, development and AI tools — from pentesting to DevSecOps.
Cybersecurity & Audit
- Pentesting (Web, API, AD)85%
- ISO 27001 / NIST / GDPR80%
- Vulnerability analysis85%
- Digital Forensics75%
- Bug Bounty (YesWeHack)70%
- SOC monitoring70%
Artificial Intelligence
- Machine Learning fundamentals75%
- Generative AI (ChatGPT, Claude, Copilot)85%
- AI-applied security80%
- Automation & data analysis80%
Development & Scripting
- Python85%
- Bash80%
- JavaScript / Node.js75%
- Task automation85%
Tools & Environments
- Burp Suite85%
- Metasploit80%
- Docker80%
- Git / CI-CD80%
- Cloud Computing75%
- Linux / Sysadmin85%
Certifications
Official recognitions in security management, pentesting and AI.
ISO/IEC 27001:2022
SkillFront
Information security management standard
Certified Cybersecurity Technician (CCT)
EC-Council
Certified cybersecurity technician
ID: 308246
Ethical Hacking Essentials (EHE / NDE / DFE)
EC-Council
Fundamentals of ethical hacking, network defense and forensics
Artificial Intelligence in Everyday Life
Orange Digital Center • Coursera
Practical applications of generative AI
API Penetration Testing
APIsec University
Specialized API penetration testing
Linux & Python Scripting for DevOps
Coursera
Linux/Python scripting for DevOps pipelines
Experience & Achievements
International CTFs, HTB machine compromises, educational projects and field work.
TraceBash CTF 2026 — Top 18% (Solo)
International Competition
- ▸Solo participation (team TH3 PH03N1X) over 24 hours, more than 2,200 players.
- ▸Ranked 205th out of 1,382 teams (top 18%) with 1,200 points and 12 challenges solved.
- ▸Demonstrated strong analytical and problem-solving skills under time pressure.
Hack The Box Enterprise — Machine Compromise
HTB Meetup Yaoundé
- ▸Reactor machine: initial access via web, SQLite enumeration, credential reuse, privesc via Node.js Inspector service abuse (RCE).
- ▸Connected machine: SQLi exploitation (CVE-2025-57819) on FreePBX, RCE via Cron, incrond daemon abuse, DAHDI poisoning for permanent root access.
- ▸Writing and publishing detailed write-ups covering attack chains and remediations.
Design of Practical Modules on API Security
Educational & technical project
- ▸Conducted penetration tests on vulnerable environments (CRAPI, VAPI, DVGA) and wrote detailed reports.
- ▸Educational support for dev teams: presenting risks (BOLA, injections, IDOR), collaborative remediation workshops.
- ▸Development of best practice sheets for securing REST/GraphQL APIs.
Automation & Infrastructure (DevOps & Cloud)
Technical project
- ▸Design of secure CI/CD pipelines (Jenkins, GitHub Actions) integrating vulnerability scans (DevSecOps).
- ▸Infrastructure deployment via Infrastructure as Code (Terraform) on Cloud — hybrid environments.
Backend Developer & Security (Internship)
PRAS System — IoT Startup • Sangmélima, Cameroon
- ▸Participated in backend services development and REST API security audit.
- ▸Internal training of developers on secure coding best practices.
Engineering Degree in Digital Engineering (MSc)
Inter-State University Congo-Cameroon (ESIGN) • Sangmélima, Cameroon
- ▸Training combining development, networks, cybersecurity, AI and data science, shaping Engineer-Entrepreneurs: experts capable of creating intelligent digital products, securing infrastructures and building the companies that carry them.
GitHub Projects
Public repositories — applications, automation scripts and security demonstrations. Counters updated live via the GitHub API.
Food-App
Complete food delivery web application built with React JS, Node.js, Express, MongoDB and Stripe. Menu browsing, cart management, order tracking.
devops-pipelines
CI/CD pipelines and DevOps automation — continuous integration and delivery chains with integrated security scans.
BLOG-API
Complete backend API for blog management — authentication, CRUD, persistence, built with Python.
Water-Pipe-Leak-Detection-System
IoT system for early detection of water leaks in domestic and industrial pipelines to prevent losses and material damage.
FastAPI-Todo-Secure
Hardened Todo API built with FastAPI — authentication, validation, security best practices.
Freecodecamp-Data-Analysis-with-Python
Data analysis projects completed as part of the freeCodeCamp Data Analysis with Python track.
chatappreel
Real-time chat application — JavaScript/Node.js frontend and backend with WebSocket management.
YouTube Videos
Demos, cybersecurity & AI explainers — hands-on experience in video. The featured video covers the same topic as the Medium article now in the blog.
Pourquoi votre pentest annuel n'a RIEN VU sur votre IA — Démonstration LIVE
ZEROLUME · SALLE DE GUERRE · PILIER 4 · ZÉRO TERMINAL — Same topic as the Medium article
Même sujet que l'article Medium : pourquoi votre pentest annuel est aveugle à votre IA — démonstrations LIVE d'injection → exfiltration et de RAG empoisonné, chiffres Cobalt 2026, EU AI Act et checklist.
🎬 In this video
10 chapters · same outline as the article
- ▸DEMO 01: injection → CRM exfiltration (14 tools, 0 alert)
- ▸DEMO 02: poisoned RAG — 3 docs / 12,847 enough
- ▸Cobalt 2026 stats: 32% vs 12% & 3× more risks
- ▸EU AI Act Art. 9/15/43 + 7-point provider checklist
Write-ups & Articles
Feedback on CTFs, HTB machines and security best practices. — incl. ZEROLUME article with ORIGINAL PDF indexed.
Why Your Annual Pentest Missed Your AI Completely
Your report is green. All boxes are ticked. Yet it tested none of your AI vulnerabilities. Why traditional pentests are blind to AI — LIVE demos, Cobalt 2026 stats, EU AI Act and a 7-point checklist.
TraceBash CTF 2026 — Story of a Solo Top 18%
24 hours of competition, 12 challenges solved, 1200 points and a top 18% worldwide. Feedback on my solo participation in TraceBash CTF 2026 under the pseudonym TH3 PH03N1X.
HTB Connected — SQLi on FreePBX to Root Access (CVE-2025-57819)
Write-up of the Connected machine from Hack The Box. Exploiting a SQL injection (CVE-2025-57819) on FreePBX, command execution via Cron, abusing the incrond daemon and DAHDI poisoning for definitive root access.
Contact me
Open to opportunities in cybersecurity, pentesting, training and open-source collaboration.
An idea to secure?
For an audit, DevSecOps support, a pentest mission or an offensive security project, I respond quickly and professionally.
- ✉️
Email
lebonilionel@gmail.com
- 📞
Phone
+237 658 704 191
- 📍
Location
Yaoundé, Cameroun
Contact form
Fill in these fields and I will get back to you quickly.
visitor@ph03n1x:~$ contact --hire # ➜ Available for your security projects 🔥 visitor@ph03n1x:~$