Metin Yunus Kandemir

Metin Yunus Kandemir

Metin Yunus Kandemir is a vulnerability researcher on the Synack Red Team. His work focuses on Active Directory attack paths, NTLM relay, and identity based exploitation, and he has been credited with multiple CVEs, including CVE-2024-38200, an NTLMv2 hash disclosure vulnerability in Microsoft Office accepted by the Microsoft Security Response Center, along with privilege escalation and hash disclosure findings in ManageEngine ADManager Plus (CVE-2024-24409) and ADSelfService Plus (CVE-2022-29457). Metin Yunus is a longtime member of the Synack Red Team, where he was inducted into the Synack Acropolis program in 2025.