About

About Mars Cheng

Mars Cheng (@marscheng_) is the Senior Manager of the Cyber Threat & Product Defense Center at TXOne Networks Inc., responsible for coordinating product security incident response, threat detection operations, and advanced threat research. He also serves as Executive Director of the Association of Hackers in Taiwan, General Coordinator of HITCON CISO Summit 2026, and continues to foster collaboration across the cybersecurity community, enterprise, and government sectors.

His current primary roles include:

  • Senior Manager of the Cyber Threat & Product Defense Center at TXOne Networks Inc., leading PSIRT, advanced threat research, and threat operations
  • Executive Director of the Association of Hackers in Taiwan, supporting HITCON, international collaboration, and executive-level security dialogue
  • General Coordinator of HITCON CISO Summit 2026

What I Work On

  • building product defense capabilities that connect research to product and operational security
  • leading work across ICS, OT, CPS, AI security, malware analysis, threat intelligence, threat hunting, and emerging attacker tradecraft
  • strengthening product security incident response, regulatory readiness, and cross-functional execution
  • teaching and speaking on practical cybersecurity in international settings
  • connecting enterprise, community, and public-sector security efforts

Selected Highlights

  • leading TXOne Networks’ Cyber Threat & Product Defense Center across PSIRT, Advanced Threat Research, and Threat Operation
  • serving on the review boards for HITCON Conference, HITCON Training, and FIRST Conference 2026
  • acting as General Coordinator for HITCON CISO Summit 2023, 2024, 2025, and 2026
  • invited instructor at the NATO Cooperative Cyber Defence Centre of Excellence
  • cybersecurity auditor roles supporting the National Information and Communication Security Taskforce, Executive Yuan (NICST), and the Ministry of Economic Affairs
  • speaker at Black Hat USA, Black Hat Europe, Black Hat MEA, RSA Conference, DEF CON, CODE BLUE, FIRST, HITB, HITCON, Troopers, NOHAT, SecTor, S4, SINCON, ROOTCON, ICS Cyber Security Conference Asia and USA, CYBERSEC, CLOUDSEC, VXCON, and related venues

Speaking and Training

Mars has delivered more than 65 international conference talks and more than 30 cybersecurity training sessions. Representative teaching and speaking environments include:

  • NATO Cooperative Cyber Defence Centre of Excellence
  • Global Cybersecurity Camp 2026 and 2024
  • NICS Elite Practical Training Program
  • Taiwan ministries including National Defense, Economic Affairs, Education, and Finance
  • HITCON Training and multiple private-sector organizations

Education

  • Master of Library and Information Science, Fu Jen Catholic University, 2016-2017
  • Thesis: The Study of RFID Ownership Transfer and Delegate Protocol Based on Quadratic Residues
  • Bachelor of Library and Information Science, Fu Jen Catholic University, 2012-2016
  • Teaching assistant experience in Computer Introduction, Data Structure, Operating System, and Cloud Applications

Certifications and Foundation

  • BS10012 Lead Auditor
  • CCPA
  • One-Month Malware Analysis Training Certificate
  • Previously held CEH, ECSA, and Trend Micro certifications

Vulnerability Research and CVEs

Earlier in my career, I worked on penetration testing, vulnerability research, and coordinated disclosure across IoT and critical-environment products. To date, I have submitted more than ten CVE identifiers and published applied cryptography research in three SCI journal papers. Representative findings include:

  • CVE-2018-9149 for Zyxel, a physical security issue rated Critical 9.8
  • CVE-2018-9156, CVE-2018-9157, and CVE-2018-9158 for Axis, covering remote code execution and denial-of-service issues rated High 7.5
  • CVE-2018-11491 and CVE-2018-11492 for ASUS, involving insecure authentication and denial-of-service issues rated Critical 9.8 and High 7.5
  • CVE-2019-15067, CVE-2019-15068, and CVE-2019-15069 for Gigastone, involving authentication and access control issues rated Critical 9.8

Contact