Working with developers, vendors and cybersecurity researchers from across 100+ countries to identify vulnerabilities in software or hardware, report them responsibly and build long-term relations with vendors.
Start Date: Oct 22, 2025
Status: Ongoing
Contributors: 5
The Cyber Diplomat Initiative (CDI) is designed to showcase how we can collaborate with security professionals and developers from over 100 countries. The name “Cyber Diplomat” reflects our mission, to engage with open-source software projects and vendors across these regions, fostering long-term partnerships aimed at enhancing global cybersecurity.
Through CDI, we focus on identifying, reporting, and mitigating vulnerabilities to safeguard digital assets (such as websites, applications, and infrastructure) and end-users from cyberattacks. Our ultimate goal is to protect lives on an international scale by strengthening the digital ecosystem worldwide.
All vulnerabilities reported under the Cyber Diplomat Initiative are classified with a severity score of 5.0 (Medium) or higher, based on the CVSS v3 calculator, ensuring accurate and standardized assessment of risks.
In addition, we leverage tools like BuiltWith to evaluate the real-world impact of these vulnerabilities on live digital assets, including websites, mobile applications, and other connected platforms to better understand their exposure and potential consequences.
Here is our progress so far:
| # | Country | CVE ID | Credit | 
|---|---|---|---|
| 1 | 🇨🇦 Canada | CVE-2025-25497 | Plumcake/ali | 
| 2 | 🇨🇳 China | CVE-2024-57604 | 0xHamy | 
| 3 | 🇩🇪 Germany | CVE-2025-47939 | 0xHamy | 
| 4 | 🇮🇳 India | CVE-2025-11280 | 0xHamy & KhanMarshai | 
| 5 | 🇷🇴 Romania | CVE-2025-11027 | KhanMarshai | 
| 6 | 🇺🇦 Ukraine | CVE-2025-32390 | Xoriath | 
| 7 | 🇬🇧 United Kingdom | CVE-2025-47781 | Xoriath | 
| 8 | 🇺🇸 United States of America | CVE-2025-29868 | 0xHamy & Daeda1us | 
| 9 | 🇻🇳 Vietnam | CVE-2025-8772 | 0xHamy | 
| 10 | 🇱🇻 Latvia | CVE-2025-10254 | 0xHamy & Daeda1us | 
| Name | Date Joined | 
|---|---|
| Hamed Kohi (0xHamy) | Oct 22, 2025 | 
| Alasdair Gorniak (plumcake) | Oct 22, 2025 | 
| Md. Taha Khan (KhanMarshai) | Oct 22, 2025 | 
| Alexandru Ionut Raducu (Xoriath) | Oct 22, 2025 | 
| Luke Smith (Daeda1us) | Oct 22, 2025 | 
Recorded 10 CVEs that were acquired as a result of responsibly disclosing vulnerabilities in software in 10 different countries such as Canada, Germany, Vietnam, Romania, India, Ukraine, United Kingdom, United States, Latvia and China.