Industry Context — Common BS Fingerprints in Security, Surveillance & Cybersecurity
STAR Labs SG
(https://starlabs.sg) 📸 Data Snapshot: May 24, 2026Analyze the raw signals below. How would a machine score this business’s credibility?
Here are the exact signals captured from up to six pages of the site — the same raw inputs the evaluation engine analyzed. They are grouped by signal type so you can weigh each the way the machine does.
🏗️ Semantic Structure — heading hierarchy & page identity (Info Density · Commodity Fingerprint)
HOMEPAGE STAR Labs | Offensive Security, Engineered (https://starlabs.sg)
STAR Labs | Offensive Security, Engineered
STAR Labs SG is a Singapore-based offensive security research and services team. Vulnerability research. Red teaming. Pwn2Own champions.
NAV_HEADER_HEADING_REPEATED_BODY_FOOTER Services | STAR Labs (https://starlabs.sg/services/)
Services | STAR Labs
Offensive security services from STAR Labs: pentesting, red team, vulnerability research, code audits, and training.
NAV_HEADER_HEADING_REPEATED_BODY_FOOTER Advisories | STAR Labs (https://starlabs.sg/advisories/)
Advisories | STAR Labs
CVE advisories and vulnerability reports published by STAR Labs.
NAV_HEADER_HEADING_REPEATED_BODY_FOOTER Blog | STAR Labs (https://starlabs.sg/blog/)
Blog | STAR Labs
Technical write-ups, research deep-dives, and field notes from the STAR Labs team.
📝 The Narrative — clean text per page (Info Density · Semantic Coherence)
HOMEPAGE (https://starlabs.sg) STAR Labs | Offensive Security, Engineered
Singapore · Offensive Security Research [H1] We break software before attackers do. STAR Labs is a Singapore-based offensive security firm specializing in vulnerability research and advanced cybersecurity training. We identify critical weaknesses in widely used software, collaborate with vendors to remediate them, and equip defenders with the mindset and techniques of real-world attackers. Our expertise is demonstrated through success at Pwn2Own and a strong track record of responsible vulnerability disclosures to Microsoft, Google, and enterprise clients across Asia. Explore services Browse advisories 0+ CVEs published 0+ Pwn2Own entries 0+ Years operating 0+ Team members What we do [H2] Attacker-grade security, delivered. From product audits to red team engagements, our services are run by the same people who find bugs in browsers, kernels, and firmware. [H3] Penetration Testing Licensed pentesting in Singapore (CS/PTS/C-2022-0106). Web, mobile, network, cloud, and infrastructure assessments run by researchers who also find 0-days. Learn more → [H3] Red Teaming Adversary-emulation engagements that test whether your detection & response actually work when a capable attacker is inside. Learn more → [H3] Vulnerability Research Targeted research on your product, supply chain, or key third-party software. Reverse engineering, fuzzing, and manual review to surface pre-disclosure vulnerabilities. Learn more → [H3] Source Code Audits Manual code review by researchers who've found critical bugs in the Linux kernel, Chromium, Windows, and IoT firmware. Learn more → [H3] Training Hands-on offensive-security training for blue teams, developers, and researchers-in-training. Delivered by instructors with real exploit chains to their name. Learn more → [H3] Advisory & Consulting Strategic guidance for CISOs and product teams navigating secure-by-design, SDLC, and incident response. Learn more → Latest advisories [H2] CVEs published by STAR Labs. All advisories → Advisory Apr 28, 2026 [H3] (CVE-2026-41873) Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover A CRLF injection vulnerability in Apache Pony Mail's Lua implementation allows an unauthenticated attacker to smuggle arbitrary HTTP … Advisory Oct 14, 2025 [H3] (CVE-2025-55336) Windows Cloud Files Mini Filter Driver Information Disclosure CVE: CVE-2025-55336 Affected Versions: Windows 10 (21H2, 22H2, 1809), Windows 11 (22H2, 23H2, 24H2, 25H2), Windows Server 2019, 2022, 2022 … Advisory Sep 09, 2025 [H3] (CVE-2025-54098) Windows Hyper-V vhdmp.sys Arbitrary File Write Leading to Elevation of Privilege A missing OBJ_FORCE_ACCESS_CHECK flag in vhdmp.sys allows a low-privileged local attacker to write arbitrary data to any file on the system … Advisory Sep 05, 2025 [H3] (CVE-2025-39682) Linux Kernel net/tls Use-After-Free in tls_sw_recvmsg Leading to Privilege Escalation A use-after-free in tls_sw_recvmsg arises when a zero-length decrypted TLS record causes darg.skb (strp->anchor) to be queued into rx_list … Advisory Aug 12, 2025 [H3] (CVE-2025-50170) Windows Cloud Files Mini Filter Driver Elevation of Privilege CVE: CVE-2025-50170 Affected Versions: Windows 10 (1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), Windows Server 2019, 2022, 2025 … Advisory Jul 08, 2025 [H3] (CVE-2025-47985) Windows Event Tracing Insufficient Validation Leading to Elevation of Privilege Insufficient validation of the TRACE_ENABLE_FLAG_EXTENSION offset in Windows Event Tracing allows a local attacker to corrupt flag extension … From the lab [H2] Deep-dive research & write-ups. All posts → Research Apr 29, 2026 [H3] Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold TL;DR In April 2026, Adobe disclosed three critical security issues (CVE-2026-34621,CVE-2026-34622,CVE-2026-34626) affecting Acrobat DC, Acrobat Reader DC, and Acrobat 2024. … AuthorShreyas Penkar (@streypaws) Read13 min Research Apr 01, 2026 [H3] CHECK Removed, Context Confused, Checkmate Achieved TL;DR In January 2026, the Chrome Releases blog announced several security fixes across different Chrome components. One entry caught our attention: CVE-2026-0899, an Out-of-Bounds … AuthorShreyas Penkar Read19 min Research Feb 05, 2026 [H3] Pickling the Mailbox: A Deep Dive into CVE-2025-20393 A single-byte integer overflow in Cisco's EUQ RPC protocol chains into Python pickle deserialization, achieving unauthenticated RCE with a single HTTP request against Cisco Secure … AuthorLi Jiantao and Shi Weiming Read12 min Responsibly disclosed to [H2] Vendors we've reported to. Every vulnerability we find goes through a structured disclosure process. Here are some of the vendors we've worked with. Microsoft 66 findings Adobe 19 findings Apple 26 findings Oracle 14 findings Chamilo 10 findings Google 8 findings ASUS 6 findings Calibre 4 findings Singtel 2 findings Linux Kernel 3 findings VMware 3 findings Cisco 1 finding Track record [H2] Competition-tested. Independently verified. All achievements → Pwn2Own May 2026 [H3] Pwn2Own Berlin 2026: 2nd Place Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software … Result2nd Place Pwn2Own Oct 2025 [H3] Pwn2Own Ireland 2025 Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software … ResultMultiple Successful Exploits Pwn2Own May 2025 [H3] Pwn2Own Berlin 2025: Master of Pwn Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software … ResultMaster of Pwn Work with us [H2] Have a system you want broken before someone else does? Drop us a line. We'll scope a pentest, red team, or code audit tailored to your stack. Contact STAR Labs
SUB-PAGE (https://starlabs.sg/services/) Services | STAR Labs
Services [H1] Security work, delivered by peoplewho find real bugs. Every engagement is led by researchers with real CVEs and competition wins to their name. We don't churn through checklists, and we don't ship reports that read like auto-generated scan output. 01 · Pentesting 02 · Red Team 03 · Vuln Research 04 · Code Audit 05 · Training 06 · Consulting 01 [H2] Penetration Testing Licensed, scoped, methodical, but run by researchers who find 0-days, not button-pushers. We're a CSA-licensed pentesting provider in Singapore (CS/PTS/C-2022-0106). Our testers are the same people who break Windows, Chrome, and enterprise appliances at Pwn2Own. They bring that lens to every engagement.Scope: web apps, mobile apps, APIs, network infrastructure, cloud (AWS/Azure/GCP), and device firmware. Deliverables: executive summary, technical findings with repro steps, CVSS scoring, remediation guidance, and a debrief with the engineering team. Is this right for you? When you need a credible third-party assessment for compliance, a customer audit, or simply to find what an attacker would. 02 [H2] Red Team Adversary emulation that tests whether your detection & response actually work. Red team engagements start from a realistic initial-access scenario (phishing, supply chain, stolen credentials, insider) and work toward specified crown-jewel objectives. We emulate threat-actor TTPs mapped to MITRE ATT&CK, and coordinate with your blue team for a purple-team debrief.Deliverables: attack narrative, detection gap analysis, timeline of observed vs. missed events, recommendations for SIEM/EDR tuning. Is this right for you? When your pentests keep coming back clean but you're not confident you'd catch a real operator. 03 [H2] Vulnerability Research Targeted 0-day research on your product, your supply chain, or your critical third-party stack. Reverse engineering, fuzzing, static analysis, and manual review to find pre-disclosure vulnerabilities in software you ship or depend on. Our researchers have responsibly disclosed critical findings to Microsoft, Google, Apple, VMware, and others.Engagements: product security reviews pre-launch, supply-chain due diligence, M&A technical assessment, threat-informed research on specific attack surfaces. Is this right for you? When finding a bug before it ships is worth more than finding it after. 04 [H2] Source Code Audit Manual review by people who've found critical bugs in the Linux kernel, browsers, and IoT firmware. Automated SAST catches a fraction of what matters. We combine tool-assisted triage with manual review of trust boundaries, auth flows, parsers, IPC, privileged components, and cryptography. We care about exploitability, not just pattern matches.Languages we regularly audit: C/C++, Rust, Go, Java, Kotlin, Swift, Objective-C, JavaScript/TypeScript, Python, PHP, Ruby. Is this right for you? Before a major release, after a critical CVE in a dependency, or as an input to your secure-SDLC program. 05 [H2] Training Hands-on offensive-security training taught by active researchers. Courses for defenders who want to think like attackers, developers who want to stop shipping bugs, and junior researchers who want to level up. Run on-site or remote, with real lab environments and CTF-style exercises.Tracks: web exploitation, Windows/Linux kernel internals, mobile app security, browser internals, firmware & IoT, AI system red teaming. Is this right for you? When your team needs to close a specific skill gap before an engagement, launch, or certification milestone. 06 [H2] Advisory & Consulting Strategic guidance for CISOs and product teams. For organizations that need offensive-security expertise on tap: not a single engagement, but an ongoing voice in architecture reviews, threat modeling, vendor risk, and incident response retrospectives.Outcomes: security architecture decisions that hold up, threat models that reflect real attackers, incident debriefs that produce actual change. Is this right for you? When you've outgrown ad-hoc pentest procurement but aren't ready for a full internal offensive team. Scope an engagement [H2] Tell us what you're protecting. We'll tell you how we'd break it. Most engagements start with a 30-minute scoping call. No sales funnel, no back-and-forth with people who won't be doing the work. You talk directly to the researchers. Email us
SUB-PAGE (https://starlabs.sg/advisories/) Advisories | STAR Labs
Vulnerability Research [H1] Security Advisories STAR Labs responsibly discloses every vulnerability we discover. The following table is our public record of coordinated disclosures, sorted newest first. 169 / 169 advisories Date ↕ CVE ↕ Title Author ↕ Apr 28, 2026 CVE-2026-41873 Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover Li Jiantao, Tevel Sho Oct 14, 2025 CVE-2025-55336 Windows Cloud Files Mini Filter Driver Information Disclosure Chen Le Qi Sep 09, 2025 CVE-2025-54098 Windows Hyper-V vhdmp.sys Arbitrary File Write Leading to Elevation of Privilege Chen Le Qi Sep 05, 2025 CVE-2025-39682 Linux Kernel net/tls Use-After-Free in tls_sw_recvmsg Leading to Privilege Escalation Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan Aug 12, 2025 CVE-2025-50170 Windows Cloud Files Mini Filter Driver Elevation of Privilege Chen Le Qi Jul 08, 2025 CVE-2025-47985 Windows Event Tracing Insufficient Validation Leading to Elevation of Privilege Chen Le Qi Jul 08, 2025 CVE-2025-49660 Windows Event Tracing Reference Count Overflow Leading to Use-After-Free and Elevation of Privilege Chen Le Qi Jun 04, 2025 CVE-2025-23095 Samsung Exynos NPU Driver Double Free Leading to Privilege Escalation Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan ZhenPeng Jun 02, 2025 CVE-2025-23099 Samsung Exynos NPU Driver Out-of-Bounds Write Leading to Privilege Escalation Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan ZhenPeng Jun 01, 2025 CVE-2025-23096 Samsung Exynos NPU Driver Double Free in IMB Memory Buffer Leading to Privilege Escalation Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng Jun 01, 2025 CVE-2025-23098 Samsung Exynos NPU Driver Use-After-Free in IMB Memory Buffer Leading to Privilege Escalation Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng, Ng Zhi Yang Jun 01, 2025 CVE-2025-23100 Samsung Exynos NPU Driver Null Pointer Dereference Leading to Denial of Service Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng Jun 01, 2025 CVE-2025-23103 Samsung Exynos NPU Driver Out-of-Bounds Write via Unbounded Loop Counter Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng Jun 01, 2025 CVE-2025-23107 Samsung Exynos NPU Driver Out-of-Bounds Write via Undersized User Buffer Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng May 16, 2025 CVE-2025-37890 Linux Kernel net_sched netem Double Enqueue Leading to Use-After-Free and Local Privilege Escalation Gerrard Tai May 02, 2025 CVE-2025-37797 Linux Kernel hfsc_change_class TOCTOU Leading to Use-After-Free and Local Privilege Escalation Gerrard Tai May 02, 2025 CVE-2025-37798 Linux Kernel fq_codel_dequeue qlen Mismatch Leading to Use-After-Free and Local Privilege Escalation Gerrard Tai Nov 12, 2024 CVE-2024-43626 Windows Telephony Service Heap Out-of-Bounds Read/Write Leading to Elevation of Privilege Chen Le Qi, Nguyễn Đăng Nguyễn Oct 01, 2024 CVE-2024-9370 Google Chrome V8 Maglev Escape Analysis Incorrect Optimization Bug Nguyễn Hoàng Thạch, Đỗ Minh Tuấn, Wu JinLin Jul 31, 2024 CVE-2024-6781 Calibre Arbitrary File Read Amos Ng Jul 31, 2024 CVE-2024-6782 Calibre Remote Code Execution Amos Ng Jul 31, 2024 CVE-2024-7008 Calibre Reflected Cross-Site Scripting (XSS) Devesh Logendran Jul 31, 2024 CVE-2024-7009 Calibre SQLite Injection Devesh Logendran Jul 22, 2024 CVE-2024-1837 Singtel RT5703W Unauthenticated Command Injection RCE via Login Vulnerability Daniel Lim Wee Soong Jul 22, 2024 CVE-2024-1838 Singtel RT5703W Authenticated Command Injection RCE via SetLoginPwd Vulnerability Daniel Lim Wee Soong Jul 01, 2024 CVE-2024-26923 Android AF_UNIX Garbage Collector Race Condition Leading to Use-After-Free Billy Jheng Bing Jhong, Pan ZhenPeng Jul 01, 2024 CVE-2024-34594 Samsung Galaxy Kernel Information Disclosure via Debug proc Entry Leading to KASLR Bypass Billy Jheng Bing-Jhong, Pan Zhenpeng May 16, 2024 CVE-2024-36972 Linux Kernel Race Condition in unix_gc on oob_skb Leading to Double Free Billy Jheng Bing Jhong May 13, 2024 CVE-2024-27828 Apple IOSurfaceRoot Reference Count Leak Leading to Kernel Panic and Code Execution Pan Zhenpeng Jan 22, 2024 CVE-2024-27791 Apple PMP Firmware Out-of-Bounds Write via ApplePMPv2 writeDashboard Pan Zhenpeng Nov 28, 2023 CVE-2023-3368 Chamilo LMS Unauthenticated Command Injection Ngo Wei Lin Nov 28, 2023 CVE-2023-3533 Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write Ngo Wei Lin Nov 28, 2023 CVE-2023-3545 Chamilo LMS Htaccess File Upload Security Bypass Ngo Wei Lin Nov 28, 2023 CVE-2023-4220 Chamilo LMS Unauthenticated Big Upload File Remote Code Execution Ngo Wei Lin Nov 28, 2023 CVE-2023-4221 Chamilo LMS Learning Path PPT2LP OpenofficePresentation Command Injection Ngo Wei Lin Nov 28, 2023 CVE-2023-4222 Chamilo LMS Learning Path PPT2LP OpenofficeTextDocument Command Injection Ngo Wei Lin Nov 28, 2023 CVE-2023-4223 Chamilo LMS Document Ajax File Upload Functionality Remote Code Execution Ngo Wei Lin Nov 28, 2023 CVE-2023-4224 Chamilo LMS Dropbox Ajax File Upload Functionality Remote Code Execution Ngo Wei Lin Nov 28, 2023 CVE-2023-4225 Chamilo LMS Exercise Ajax File Upload Functionality Remote Code Execution Ngo Wei Lin Nov 28, 2023 CVE-2023-4226 Chamilo LMS Work Ajax File Upload Functionality Remote Code Execution Ngo Wei Lin Nov 01, 2023 CVE-2023-1713 Bitrix24 Remote Command Execution (RCE) via Insecure Temporary File Creation Lam Jun Rong & Li Jiantao Nov 01, 2023 CVE-2023-1714 Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction Lam Jun Rong & Li Jiantao Nov 01, 2023 CVE-2023-1715 (CVE-2023-1715 & CVE-2023-1716) Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page Lam Jun Rong & Li Jiantao Nov 01, 2023 CVE-2023-1717 Bitrix24 Cross-Site Scripting (XSS) via Client-side Prototype Pollution Lam Jun Rong & Li Jiantao Nov 01, 2023 CVE-2023-1718 Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access Lam Jun Rong & Li Jiantao Nov 01, 2023 CVE-2023-1719 Bitrix24 Insecure Global Variable Extraction Lam Jun Rong & Li Jiantao Nov 01, 2023 CVE-2023-1720 Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload Lam Jun Rong & Li Jiantao Oct 11, 2023 CVE-2023-4197 Dolibarr ERP CRM (<= 18.0.1) Improper Input Sanitization Authenticated RCE Poh Jia Hao Oct 11, 2023 CVE-2023-4198 Dolibarr ERP CRM (<= 17.0.3) Improper Access Control Poh Jia Hao Sep 29, 2023 CVE-2023-30591 NodeBB Pre-Authentication Denial-of-Service Ngo Wei Lin Sep 26, 2023 CVE-2023-41984 Apple AppleSPU Shared Memory Read/Write Mapping Leading to Kernel Panic and Code Execution Pan Zhenpeng Sep 18, 2023 CVE-2023-2315 Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 Poh Jia Hao Aug 28, 2023 CVE-2023-2016 Attendize <= 2.8.0 Authenticated TOCTOU Allows Multiple Refunds Per Order Poh Jia Hao Aug 22, 2023 CVE-2023-32523 Trend Micro Mobile Security (Enterprise) 9.8 SP5 (<= Critical Patch 3) Unauthenticated RCE Poh Jia Hao Aug 22, 2023 CVE-2023-32524 Trend Micro Mobile Security (Enterprise) 9.8 SP5 (<= Critical Patch 3) Unauthenticated RCE Poh Jia Hao Aug 22, 2023 CVE-2023-32529 Trend Micro Apex Central 2019 (<= Build 6016) Authenticated RCE Poh Jia Hao Aug 22, 2023 CVE-2023-32530 Trend Micro Apex Central 2019 (<= Build 6016) Authenticated RCE Poh Jia Hao Aug 22, 2023 CVE-2023-38624 Trend Micro Apex Central 2019 (<= Build 6394) Authenticated SSRF Poh Jia Hao Aug 22, 2023 CVE-2023-38625 Trend Micro Apex Central 2019 (<= Build 6394) Authenticated SSRF Poh Jia Hao Aug 19, 2023 CVE-2023-2110 Obsidian Local File Disclosure Li Jiantao Aug 19, 2023 CVE-2023-2316 Typora Local File Disclosure Li Jiantao Aug 19, 2023 CVE-2023-2317 Typora DOM-Based Cross-site Scripting leading to Remote Code Execution Li Jiantao Aug 19, 2023 CVE-2023-2318 MarkText DOM-Based Cross-site Scripting leading to Remote Code Execution Li Jiantao Aug 19, 2023 CVE-2023-2971 Typora Local File Disclosure (Patch Bypass) Li Jiantao Jul 14, 2023 CVE-2023-3513 RazerCentralService unsafe deserialization Escalation of Privilege Vulnerability Phan Thanh Duy Jul 14, 2023 CVE-2023-3514 RazerCentralSerivce unsafe NamedPipe permission Escalation of Privilege Vulnerability Phan Thanh Duy Apr 17, 2023 CVE-2023-2017 Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension Ngo Wei Lin Apr 12, 2023 CVE-2023-1872 Linux Kernel io_uring Missing Lock in io_file_get_fixed Leading to Use-After-Free and Local Privilege Escalation Billy Jheng Bing-Jhong Dec 13, 2022 CVE-2022-44667 Windows CDirectMusicPortDownload Integer Overflow Vulnerability Lê Hữu Quang Linh Dec 13, 2022 CVE-2022-44668 Windows DirectMusicPortDownload Double Free Vulnerability Lê Hữu Quang Linh Jul 13, 2022 CVE-2022-26438 Asus System Control Interface Backup Local Privilege Escalation (LPE) Schuyler Tay Jul 13, 2022 CVE-2022-26439 Asus System Control Interface Software Update Arbitrary File Deletion Schuyler Tay Mar 28, 2022 CVE-2021-4206 QEMU QXL Integer overflow leads to Heap Overflow Billy Jheng Bing Jhong Mar 28, 2022 CVE-2021-4207 QEMU QXL Integer overflow leads to Heap Overflow Billy Jheng Bing Jhong Mar 28, 2022 CVE-2022-0168 Linux Kernel smb2_ioctl_query_info NULL Pointer Dereference Billy Jheng Bing Jhong Mar 28, 2022 CVE-2022-0216 QEMU LSI SCSI Use After Free Muhammad Alifa Ramdhan Mar 14, 2022 CVE-2022-28730 Apache JSPWiki v2.11.1 - Reflected XSS in AjaxPreview.jsp Poh Jia Hao Mar 04, 2022 CVE-2022-26718 macOS smbfs Out-of-Bounds Read due to parse nic info Peter Nguyễn Vũ Hoàng Jan 11, 2022 CVE-2022-21877 Storage Spaces Controller Information Disclosure Vulnerability Lê Hữu Quang Linh Sep 13, 2021 CVE-2021-30844 macOS smbfs Out-of-Bounds Read Peter Nguyễn Vũ Hoàng Sep 13, 2021 CVE-2021-30845 macOS smbfs Out-of-Bounds Read Peter Nguyễn Vũ Hoàng Jun 18, 2021 CVE-2021-30868 macOS smbfs Race Condition leading to Use-After-Free Vulnerability Peter Nguyễn Vũ Hoàng Jun 10, 2021 CVE-20221-35400 Prolink PRC2402M mesh.cgi get_extender_page Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 10, 2021 CVE-20221-35401 Prolink PRC2402M login.cgi sys_login Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 10, 2021 CVE-20221-35403 Prolink PRC2402M touchlist_sync.cgi main Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 10, 2021 CVE-20221-35404 Prolink PRC2402M applogin.cgi sys_login1 Authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 10, 2021 CVE-20221-35406 Prolink PRC2402M login.cgi sys_login1 Authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 10, 2021 CVE-20221-35406 Prolink PRC2402M qos.cgi qos_settings Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 10, 2021 CVE-20221-35407 Prolink PRC2402M mesh.cgi get_upgrade_page Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 10, 2021 CVE-20221-35409 Prolink PRC2402M nightled.cgi SetNightLed Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 09, 2021 CVE-2021-30836 WebKit WebCore::AudioNode::disconnect null pointer reference Ta Dinh Sung Jun 09, 2021 CVE-20221-35402 Prolink PRC2402M live_api.cgi satellist_list Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong Jun 08, 2021 CVE-2021-35408 Prolink PRC2402M qos.cgi qos_sta_settings Un-authenticated Command Injection Vulnerability Daniel Lim Wee Soong May 28, 2021 CVE-2021-0956 Android NFC Out-Of-Bounds Write due to increase mNumTechList without bounds checking Nguyễn Hoàng Thạch May 20, 2021 CVE-2021-30745 Apple macOS QuartzCore Type Confusion Vulnerability Peter Nguyễn Vũ Hoàng Apr 14, 2021 CVE-2021-0204 Juniper Junos OS Local Privilege Escalation vulnerability in dexp Nguyễn Hoàng Thạch Apr 14, 2021 CVE-2021-0223 Juniper Junos OS Local Privilege Escalation vulnerability in telnetd Nguyễn Hoàng Thạch Apr 14, 2021 CVE-2021-0254 Junos OS overlayd service bss Buffer Overflow Nguyễn Hoàng Thạch Apr 14, 2021 CVE-2021-0255 Juniper Junos OS Local Privilege Escalation vulnerability in ethtraceroute Nguyễn Hoàng Thạch Apr 14, 2021 CVE-2021-0256 Juniper Junos OS Local Privilege Escalation vulnerability in mosquitto Nguyễn Hoàng Thạch Apr 06, 2021 CVE-2021-2321 Oracle VirtualBox E1000 BSS Out-Of-Bounds Read Muhammad Alifa Ramdhan Mar 23, 2021 CVE-2021-3409 QEMU Heap Overflow in SDHCI Component Muhammad Alifa Ramdhan Mar 22, 2021 CVE-2021-34978 NETGEAR R6260 setupwizard.cgi Buffer Overflow Unauthenticated Remote Code Execution Sherman Chann Zhi Shen & Nguyễn Hoàng Thạch Mar 22, 2021 CVE-2021-34979 NETGEAR R6260 mini_httpd Buffer Overflow Unauthenticated Remote Code Execution Sherman Chann Zhi Shen & Nguyễn Hoàng Thạch Mar 05, 2021 CVE-2021-0950 Android NFC android.hardware.nfc@1.2-service Writer mode Out-Of-Bounds Write leading to Information Disclosure Nguyễn Hoàng Thạch Feb 27, 2021 CVE-2021-33760 Windows Media Foundation Integer Overflow Vulnerability Phan Thanh Duy, Brandon Chong, Cao Yi Tian Feb 27, 2021 CVE-2021-34503 Windows Media Foundation Type Confusion Vulnerability Phan Thanh Duy Feb 10, 2021 CVE-2021-1758 macOS/iOS CoreText Out-Of-Bounds Read Peter Nguyễn Vũ Hoàng Feb 10, 2021 CVE-2021-1790 macOS/iOS CoreText libhvf O
SUB-PAGE (https://starlabs.sg/blog/) Blog | STAR Labs
From the lab [H1] Research & write-ups. Deep dives into vulnerability research, exploitation techniques, and security analysis from the STAR Labs team. Research Apr 29, 2026 [H3] Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold TL;DR In April 2026, Adobe disclosed three critical security issues (CVE-2026-34621,CVE-2026-34622,CVE-2026-34626) affecting Acrobat DC, Acrobat Reader DC, and … ByShreyas Penkar (@streypaws) Read13 min Research Apr 01, 2026 [H3] CHECK Removed, Context Confused, Checkmate Achieved TL;DR In January 2026, the Chrome Releases blog announced several security fixes across different Chrome components. One entry caught our attention: … ByShreyas Penkar Read19 min Research Feb 05, 2026 [H3] Pickling the Mailbox: A Deep Dive into CVE-2025-20393 A single-byte integer overflow in Cisco's EUQ RPC protocol chains into Python pickle deserialization, achieving unauthenticated RCE with a single HTTP request … ByLi Jiantao and Shi Weiming Read12 min Research Jan 08, 2026 [H3] 8th Anniversary: Embrace the new but don't forget the old Eight years ago today, I started STAR Labs by hiring several fresh grads with no working experiences. Today, I stand here with a different group of faces. Some … ByJacob Soo Read4 min Research Dec 27, 2025 [H3] 2025: WE BROKE THINGS, WE BUILT THINGS, WE BROKE EVEN MORE THINGS Most will talk about the success in their year-end posts. Great. Nobody talks about the failures. Nobody talks about what ACTUALLY happened. Well, we are going … BySTAR Labs SG Read5 min Research Nov 18, 2025 [H3] HEX ADVENT 2025: Crack the Advent, Conquer the Threat ? HEX ADVENT 2025: Crack the Advent, Conquer the Threat ? Last chance to register! Registration closing on 20 Dec 2025, 09:00 SGT! WELCOME TO HEX ADVENT 2025, … BySTAR Labs SG Read8 min Research Nov 10, 2025 [H3] HEX ADVENT 2025: Rules & Information Information This is a solo CTF event open to women residing in Singapore or Malaysia. To register and be eligible for the prizes: Register on CTFd, and select … BySTAR Labs SG Read2 min Research Nov 03, 2025 [H3] Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer The Target: Brother MFC-J1010DW Affected Models: Brother Printer MFC-J1010DW Vulnerable Firmware: Version <= 1.18 TL;DR: The Vulnerability Chain We … ByNguyên Đăng Nguyên & Manzel Seet & Amos Ng Read21 min Research Sep 15, 2025 [H3] Summer Pwnables: lz1 Solution TL;DR ? We’re turning a simple compression library into a shell delivery service! This writeup exploits a buffer overflow in lz1/lz77 decompression by … ByZafir Rasyidi Taufik Read8 min Research Sep 15, 2025 [H3] Summer Pwnables: Temporal Paradox Engine Solution Last month, Jacob asked me to create a CTF challenge for the Summer Pwnables event. I went with a kernel pwnable since my goal was to teach students some more … ByMuhammad Alifa Ramdhan Read13 min Research Sep 11, 2025 [H3] Lost in Translation: Apache Vulnerabilities That Don't Count (Literally) During our security research in 2024, we discovered several vulnerabilities in Apache Foundation projects that seem to have gotten ’lost in … ByLi Jiantao Read9 min Research Sep 02, 2025 [H3] Fuzzing a Printer: Pre-auth RCE in a Network IoT Device Printers have three things going for them from an attacker’s perspective: they live on the corporate network, they trust far too much from far too many … ByPoh Jia Hao Read1 min fuzzingiotprinterrce Research Aug 18, 2025 [H3] [Updates] Summer Pwnables ? [Updates] Summer Pwnables 2025 Major Announcement: ISD Sponsorship We are pleased to announce that Internal Security Department (ISD) is sponsoring Summer … BySTAR Labs SG Read2 min Research Aug 12, 2025 [H3] Summer Pwnables: When the Heat Rises, So Do the C-Shells ? ?☀️ SUMMER PWNABLES 2025 ☀️? The hottest hacking challenge on this side of Southeast Asia! Think you can handle the heat? Time to prove your l33t skills are … BySTAR Labs SG Read3 min Research Jul 16, 2025 [H3] My `Blind Date` with CVE-2025-29824 In April 2025, Microsoft patched a vulnerability that had become a key component in sophisticated ransomware attack chains. CVE-2025-29824, an use-after-free … ByOng How Chong Read10 min Research Jul 10, 2025 [H3] Fooling the Sandbox: A Chrome-atic Escape For my internship, I was tasked by my mentor Le Qi to analyze CVE-2024-30088, a double-fetch race condition bug in the Windows Kernel Image ntoskrnl.exe. A … ByVincent Yeo Read11 min Research Jun 05, 2025 [H3] Solo: A Pixel 6 Pro Story (When one bug is all you need) During my internship I was tasked to analyze a Mali GPU exploit on Pixel 7/8 devices and adapt it to make it work on another device: the Pixel 6 Pro. While the … ByLin Ze Wei Read36 min Research May 30, 2025 [H3] Gone in 5 Seconds: How WARN_ON Stole 10 Minutes As part of my internship at STAR Labs, I was tasked to conduct N-day analysis of CVE-2023-6241. The original PoC can be found here, along with the accompanying … ByTan Ze Jian Read16 min Research May 28, 2025 [H3] Badge & Lanyard Challenges @ OBO 2025 Introduction We are back with Round 2 of the Off-By-One conference — where bits meet breadboards and bugs are celebrated! ?⚡ If you are into hardware and IoT … ByManzel Seet & Sarah Tan Read14 min Research May 20, 2025 [H3] Lessons From Pwn2Own Berlin 2025: Building a Hypervisor Escape At Pwn2Own Berlin 2025, STAR Labs took home Master of Pwn for a chain that escaped a major hypervisor from inside a guest VM. This is the short version of how … ByBilly Jheng Bing-Jhong Read2 min pwn2ownvirtualizationexploit-development Research May 14, 2025 [H3] Breaking Out of Restricted Mode: XSS to RCE in Visual Studio Code In April 2024, I discovered a high-severity vulnerability in Visual Studio Code (VS Code <= 1.89.1) that allows attackers to escalate a Cross-Site Scripting … ByDevesh Logendran Read7 min Research Mar 25, 2025 [H3] CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition) Introduction Many vulnerability writeups nowadays focus on the exploitation process when it comes to software bugs. The term “Exploit Developer” is … ByChen Le Qi Read21 min Research Mar 17, 2025 [H3] STAR Labs Windows Exploitation Challenge 2025 Writeup STAR Labs Windows Exploitation Challenge Writeup Over the past few months, the STAR Labs team has been hosting a Windows exploitation challenge. I was lucky … ByGuest Post by Võ Văn Tiến Dũng Read9 min Research Feb 02, 2025 [H3] Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793) Imagine downloading a game from a third-party app store. You grant it seemingly innocuous permissions, but hidden within the app is a malicious exploit that … ByNg Zhi Yang Read17 min Research Jan 24, 2025 [H3] CVE-2024-26230: Windows Telephony Service - It's Got Some Call-ing Issues (Elevation of Privilege) Executive Summary CVE-2024-26230 is a critical vulnerability found in the Windows Telephony Service (TapiSrv), which can lead to an elevation of privilege on … ByĐào Tuấn Linh Read11 min Research Jan 12, 2025 [H3] Celebrating 7 Years of STAR Labs SG ?? Cheers to 7 Amazing Years! ?? On 8th January 2018, STAR Labs SG Pte. Ltd. was born with a simple but bold idea: to do fun offensive research that protects … BySTAR Labs SG Read5 min Research Jan 01, 2025 [H3] STAR Labs 2025 New Year Exploitation Challenge Think you’ve got what it takes to pop shells and snag your ticket to… RE//verse and Off-By-One? ? ? Windows Exploitation Challenge ? Get SYSTEM … BySTAR Labs SG Read1 min Research Dec 24, 2024 [H3] All I Want for Christmas is a CVE-2024-30085 Exploit TLDR CVE-2024-30085 is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini Filter Driver cldflt.sys. By crafting a custom reparse … ByCherie-Anne Lee Read21 min Research Dec 24, 2024 [H3] Behind the Scenes: Understanding CVE-2022-24547 TL;dr Vulnerabilities can often be found in places we don’t expect, and CVE-2022-24547 in CastSrv.exe is one of the examples. CVE-2022-24547 is a privilege … ByĐào Tuấn Linh Read5 min Research Jul 22, 2024 [H3] #BadgeLife @ Off-By-One Conference 2024 Introduction As promised, we are releasing the firmware and this post for the Off-By-One badge about one month after the event, allowing interested participants … ByManzel Joseph Seet Read13 min Research May 06, 2024 [H3] Send()-ing Myself Belated Christmas Gifts - GitHub.com's Environment Variables & GHES Shell Earlier this year, in mid-January, you might have come across this security announcement by GitHub. In this article, I will unveil the shocking story of how I … ByNgo Wei Lin Read15 min Research Apr 15, 2024 [H3] Send()-ing Myself Belated Christmas Gifts: GitHub.com's Environment Variables & GHES Shell Short version: while poking at GitHub Enterprise Server (GHES) for an unrelated reason the day after Christmas, I noticed an unvalidated Kernel#send() call in … ByNgo Wei Lin Read2 min githubrcerubyweb Research Mar 18, 2024 [H3] Route to Safety: Navigating Router Pitfalls Introduction Wi-Fi routers have always been an attractive target for attackers. When taken over, an attacker may gain access to a victim’s internal … ByDaniel Lim Wee Soong Read48 min Research Nov 24, 2023 [H3] Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969) Introduction The prevalence of memory corruption bugs persists, posing a persistent challenge for exploitation. This increased difficulty arises from … ByChen Le Qi Read24 min Research Sep 29, 2023 [H3] Analysis of NodeBB Account Takeover Vulnerability (CVE-2022-46164) Back in January 2023, I tasked one of our web security interns, River Koh (@oceankex), to perform n-day analysis of CVE-2022-46164 as part of his internship … ByNgo Wei Lin & River Koh Read14 min Research Sep 25, 2023 [H3] [P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955) Brief I may have achieved successful exploitation of a SharePoint target during Pwn2Own Vancouver 2023. While the live demonstration lasted only approximately … ByNguyễn Tiến Giang (Jang) Read18 min Research Sep 25, 2023 [H3] nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248) During my internship, I have been researching and trying to find bugs within the nftables subsystem. In this blog post, I will talk about a bug I have found, as … ByCherie-Anne Lee Read26 min Research Aug 01, 2023 [H3] Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp We are excited to embark on a series of teardowns to explore the inner workings of various devices. In this particular teardown, our focus will be on the … ByJoshua Tay Read11 min Research Jul 25, 2023 [H3] A new method for container escape using file-based DirtyCred Recently, I was trying out various exploitation techniques against a Linux kernel vulnerability, CVE-2022-3910. After successfully writing an exploit which made … ByChoo Yi Kai Read16 min Research Jul 25, 2023 [H3] prctl anon_vma_name: An Amusing Linux Kernel Heap Spray TLDR prctl PR_SET_VMA (PR_SET_VMA_ANON_NAME) can be used as a (possibly new!) heap spray method targeting the kmalloc-8 to kmalloc-96 caches. The sprayed … ByCherie-Anne Lee Read7 min Research Jun 19, 2023 [H3] Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability Background The discovery and analysis of vulnerabilities is a critical aspect of cybersecurity research. Today, we will dive into CVE-2023-1829, a vulnerability … ByVũ Thị Lan Read17 min Research Jun 14, 2023 [H3] The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022 TLDR; We began our work on Samsung immediately after the release of the Pwn2Own Toronto 2022 target list. In this article, we will dive into the details of an … ByNguyễn Tiến Giang (Jang) Read8 min Research Apr 28, 2023 [H3] Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707) Introduction While analyzing CVE-2022-41082, also known as ProxyNotShell, we discovered this vulnerability which we have detailed in this blog. However, for a … ByNguyễn Tiến Giang (Jang) Read6 min Research Mar 03, 2023 [H3] CS-Cart PDF Plugin Unauthenticated Command Injection Summary A command injection vulnerability exists in CS-Cart’s HTML to PDF converter (https://github.com/cscart/pdf) allowing unauthenticated attackers to … ByNgo Wei Lin Read4 min Research Feb 24, 2023 [H3] Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer Upon finding the vulnerability, our team member, Ngo Wei Lin (@Creastery), immediately reported it to the Microsoft Security Response Center (MSRC) on 19th … ByNgo Wei Lin Read5 min Research Feb 22, 2023 [H3] STAR LABS SG PTE. LTD. has been authorized by the CVE Program as a CVE Numbering Authority (CNA) STAR LABS SG PTE. LTD. (STAR Labs) announced today that it has become a CVE Numbering Authority (CNA) for the Common Vulnerabilities and Exposures (CVE®) … BySTAR Labs SG Pte. Ltd. Read2 min Research Feb 17, 2023 [H3] Gotta KEP-tcha 'Em All - Bypassing Anti-Debugging methods in KEPServerEX Background Lately, my focus has been on discovering any potential vulnerabilities in KEPServerEX. KEPServerEX is the industry’s leading connectivity … ByLê Hữu Quang Linh Read12 min Research Feb 16, 2023 [H3] Dissecting the Vulnerabilities - A Comprehensive Teardown of acmailer's N-Days Introduction In this post, one of our recent intern, Wang Hengyue (@w_hy_04) was given the task to analyse CVE-2021-20617 & CVE-2021-20618 in acmailer since … ByWang Hengyue Read12 min Research Dec 21, 2022 [H3] Deconstructing and Exploiting CVE-2020-6418 As part of my internship at STAR Labs, I conducted n-day analysis of CVE-2020-6418. This vulnerability lies in the V8 engine of Google Chrome, namely its … ByDaniel Toh Jing En Read15 min Research Dec 06, 2022 [H3] The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022 Background Some time ago, we were playing with some Netgear routers and we learned so much from this target. However, Netgear recently patched several … ByVu Thi Lan, Nguyễn Hoàng Thạ
🛡️ Trust Signals — reviews, proof links, trust-theatre flag (Trust & Proof)
| Page | Reviews | Proof links |
|---|---|---|
| / (home) | 3 | 0 |
| /services/ | 5 | 0 |
| /advisories/ | 2 | 0 |
| /blog/ | 7 | 0 |
🔗 Identity & Technical Layer — schema JSON-LD: identity chains, entity gaps (Identity & Authority)
Your Diagnosis
Before revealing the machine’s verdict, predict the BS score for each signal. Higher = more BS (more fluff, less verifiable substance). Drag each slider, then submit to compare your judgment against the engine.
Stuck? Reveal the heuristic lens — how the deterministic page-auditor reads each signal (no AI, pure pattern rules)
These are the structural rules a local, deterministic auditor applies — the same lens you can use to judge each signal. They describe what to look for, not this company’s result.
Classify each sentence as substantive or hollow. Grounding markers — numbers, currencies, dates, technical units, named entities — outweigh marketing adjectives. When fluff sits right next to hard evidence, the fluff is forgiven.
Pull the main entities out of the H1, then check whether they actually recur through the body. A page that announces one thing and then talks about another drifts. Headings with no real sentences underneath read as pseudo-substance.
Count trust words (review, testimonial, rating, verified) against real outbound proof links (Google, Trustpilot, Clutch, G2, Yelp). Lots of trust language with zero verification links is trust theatre. Unlinked logo galleries count against it.
Look at how much sentence length varies. Natural writing varies its rhythm; templated or mass-produced copy is statistically uniform. Very low variation reads as commodity content — unless unique named entities break the pattern.
Inspect the JSON-LD. Is there an Organization or Person schema, and does it carry sameAs links to real external profiles (LinkedIn, socials)? Missing schema or no identity declaration signals an anonymous entity.
Want to apply this lens yourself? The free BS Indicator Chrome extension runs these heuristic checks live on any page. Bear in mind it is a single-page, deterministic tool — it relies only on pattern rules for the page in front of it and does not perform the cross-page semantic correlation this audit uses, so its readout is a starting lens, not the full verdict.
Based on 370 businesses audited.
Security, Surveillance & Cybersecurity BS: STAR Labs SG (starlabs.sg)
This site is a masterclass in anti-BS security marketing. It bypasses industry cliches by overwhelming the user with forensic evidence of actual technical accomplishments and public competition wins.
To achieve a near-zero BS score, implement structured Organization and Person schema to programmatically verify the named researchers. Resolve the trust theatre discrepancy by linking the review counts to specific third-party validation sources. Remove the minor power-word ‘Attacker-grade’ from the H2 to ensure 100% of headings are purely technical.
The website is a perfect fit for the Offensive Security and Cybersecurity category. The content is saturated with specific technical deliverables like vulnerability research, red teaming, and exploit development, which are substantiated by a massive public record of CVEs and competition results.
“The score of 15 is driven almost entirely by mechanical metadata gaps (missing schema and trust theatre flags) rather than substantive fluff. In terms of actual content, the site contains less than 3% generic marketing language.”
This training module utilizes a snapshot of public data from STAR Labs SG, captured on May 24, 2026, to demonstrate how machine logic evaluates different types of business narratives.
Purpose: This data is presented under “Fair Use” / “Educational Exception” for the purpose of forensic semantic analysis, allowing users to compare human intuition against machine-generated evaluations.
Notice to STAR Labs SG: This analysis is part of a non-adversarial audit conducted by 1 Euro SEO. The results provided by 1EuroSEO are intended as professional feedback to help improve any website’s machine-readability and authority signals. The 1EuroSEO BS Detection Tool is a free tool, and anyone can test any company to see how their content is interpreted by AI models.
Any company can use the insights for free and improve its voice by comparing it to industry clichés or competitors. When a company has updated its content, it can always submit a new audit request, which will be reflected in a new current score.
To all users: You are encouraged to visit the live site at https://starlabs.sg to view the most current version of its content and learn from the source what this company is about and what it offers.