Training Example: STAR Labs SG – Review the Data, Give Your Score & Compare to the Real AI Evaluation

Industry Context — Common BS Fingerprints in Security, Surveillance & Cybersecurity
Generic Claims: protecting your business, stay ahead of threats, world-class security, trusted by enterprises…
Red Flags: guaranteed prevention of all breaches, penetration testing without accreditation, security certifications for team without named individuals, no own-practice security certifications…
Semantic Drift Patterns: homepage claims enterprise SOC but services are basic antivirus resale, claims penetration testing expertise but no CREST or CHECK accreditation, homepage targets critical infrastructure but client list is SMB, claims 24/7 SOC but no staffing or operations evidence…
Proof Expectations: CREST, CHECK, or equivalent accreditation numbers, named team with security certifications (OSCP, CISSP, CEH), ISO 27001 certification for own operations, specific case studies with anonymized but detailed findings…

STAR Labs SG

(https://starlabs.sg) 📸 Data Snapshot: May 24, 2026

Analyze the raw signals below. How would a machine score this business’s credibility?

Here are the exact signals captured from up to six pages of the site — the same raw inputs the evaluation engine analyzed. They are grouped by signal type so you can weigh each the way the machine does.

🏗️ Semantic Structure — heading hierarchy & page identity (Info Density · Commodity Fingerprint)
HOMEPAGE STAR Labs | Offensive Security, Engineered (https://starlabs.sg)
Title

STAR Labs | Offensive Security, Engineered

Meta

STAR Labs SG is a Singapore-based offensive security research and services team. Vulnerability research. Red teaming. Pwn2Own champions.

H1 We break software before attackers do.
H2 Attacker-grade security, delivered.
H2 CVEs published by STAR Labs.
H2 Deep-dive research & write-ups.
H2 Vendors we've reported to.
H2 Competition-tested. Independently verified.
H2 Have a system you want broken before someone else does?
H3 Penetration Testing
H3 Red Teaming
H3 Vulnerability Research
H3 Source Code Audits
H3 Training
H3 Advisory & Consulting
H3 (CVE-2026-41873) Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover
H3 (CVE-2025-55336) Windows Cloud Files Mini Filter Driver Information Disclosure
H3 (CVE-2025-54098) Windows Hyper-V vhdmp.sys Arbitrary File Write Leading to Elevation of Privilege
H3 (CVE-2025-39682) Linux Kernel net/tls Use-After-Free in tls_sw_recvmsg Leading to Privilege Escalation
H3 (CVE-2025-50170) Windows Cloud Files Mini Filter Driver Elevation of Privilege
H3 (CVE-2025-47985) Windows Event Tracing Insufficient Validation Leading to Elevation of Privilege
H3 Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold
H3 CHECK Removed, Context Confused, Checkmate Achieved
H3 Pickling the Mailbox: A Deep Dive into CVE-2025-20393
H3 Pwn2Own Berlin 2026: 2nd Place
H3 Pwn2Own Ireland 2025
H3 Pwn2Own Berlin 2025: Master of Pwn
H5 Work
H5 Lab
H5 Contact
NAV_HEADER_HEADING_REPEATED_BODY_FOOTER Services | STAR Labs (https://starlabs.sg/services/)
Title

Services | STAR Labs

Meta

Offensive security services from STAR Labs: pentesting, red team, vulnerability research, code audits, and training.

H1 Security work, delivered by peoplewho find real bugs.
H2 Penetration Testing
H2 Red Team
H2 Vulnerability Research
H2 Source Code Audit
H2 Training
H2 Advisory & Consulting
H2 Tell us what you're protecting. We'll tell you how we'd break it.
H5 Work
H5 Lab
H5 Contact
NAV_HEADER_HEADING_REPEATED_BODY_FOOTER Advisories | STAR Labs (https://starlabs.sg/advisories/)
Title

Advisories | STAR Labs

Meta

CVE advisories and vulnerability reports published by STAR Labs.

H1 Security Advisories
H5 Work
H5 Lab
H5 Contact
NAV_HEADER_HEADING_REPEATED_BODY_FOOTER Blog | STAR Labs (https://starlabs.sg/blog/)
Title

Blog | STAR Labs

Meta

Technical write-ups, research deep-dives, and field notes from the STAR Labs team.

H1 Research & write-ups.
H3 Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold
H3 CHECK Removed, Context Confused, Checkmate Achieved
H3 Pickling the Mailbox: A Deep Dive into CVE-2025-20393
H3 8th Anniversary: Embrace the new but don't forget the old
H3 2025: WE BROKE THINGS, WE BUILT THINGS, WE BROKE EVEN MORE THINGS
H3 HEX ADVENT 2025: Crack the Advent, Conquer the Threat ?
H3 HEX ADVENT 2025: Rules & Information
H3 Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
H3 Summer Pwnables: lz1 Solution
H3 Summer Pwnables: Temporal Paradox Engine Solution
H3 Lost in Translation: Apache Vulnerabilities That Don't Count (Literally)
H3 Fuzzing a Printer: Pre-auth RCE in a Network IoT Device
H3 [Updates] Summer Pwnables ?
H3 Summer Pwnables: When the Heat Rises, So Do the C-Shells ?
H3 My `Blind Date` with CVE-2025-29824
H3 Fooling the Sandbox: A Chrome-atic Escape
H3 Solo: A Pixel 6 Pro Story (When one bug is all you need)
H3 Gone in 5 Seconds: How WARN_ON Stole 10 Minutes
H3 Badge & Lanyard Challenges @ OBO 2025
H3 Lessons From Pwn2Own Berlin 2025: Building a Hypervisor Escape
H3 Breaking Out of Restricted Mode: XSS to RCE in Visual Studio Code
H3 CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)
H3 STAR Labs Windows Exploitation Challenge 2025 Writeup
H3 Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)
H3 CVE-2024-26230: Windows Telephony Service – It's Got Some Call-ing Issues (Elevation of Privilege)
H3 Celebrating 7 Years of STAR Labs SG
H3 STAR Labs 2025 New Year Exploitation Challenge
H3 All I Want for Christmas is a CVE-2024-30085 Exploit
H3 Behind the Scenes: Understanding CVE-2022-24547
H3 #BadgeLife @ Off-By-One Conference 2024
H3 Send()-ing Myself Belated Christmas Gifts – GitHub.com's Environment Variables & GHES Shell
H3 Send()-ing Myself Belated Christmas Gifts: GitHub.com's Environment Variables & GHES Shell
H3 Route to Safety: Navigating Router Pitfalls
H3 Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)
H3 Analysis of NodeBB Account Takeover Vulnerability (CVE-2022-46164)
H3 [P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955)
H3 nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)
H3 Under The Hood – Disassembling of IKEA-Sonos Symfonisk Speaker Lamp
H3 A new method for container escape using file-based DirtyCred
H3 prctl anon_vma_name: An Amusing Linux Kernel Heap Spray
H3 Breaking the Code – Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability
H3 The Old, The New and The Bypass – One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022
H3 Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707)
H3 CS-Cart PDF Plugin Unauthenticated Command Injection
H3 Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer
H3 STAR LABS SG PTE. LTD. has been authorized by the CVE Program as a CVE Numbering Authority (CNA)
H3 Gotta KEP-tcha 'Em All – Bypassing Anti-Debugging methods in KEPServerEX
H3 Dissecting the Vulnerabilities – A Comprehensive Teardown of acmailer's N-Days
H3 Deconstructing and Exploiting CVE-2020-6418
H3 The Last Breath of Our Netgear RAX30 Bugs – A Tragic Tale before Pwn2Own Toronto 2022
H3 TheHole New World – how a small leak will sink a great browser (CVE-2021-38003)
H3 Multiple Vulnerabilities in Proxmox VE & Proxmox Mail Gateway
H3 Microsoft SharePoint Server Post-Authentication Server-Side Request Forgery vulnerability
H3 Apple CoreText – An Unexpected Journey to Learn about Failure
H3 Step-by-Step Walkthrough of CVE-2022-32792 – WebKit B3ReduceStrength Out-of-Bounds Write
H3 Exploiting WebKit JSPropertyNameEnumerator Out-of-Bounds Read (CVE-2021-1789)
H3 Gitlab Project Import RCE Analysis (CVE-2022-2185)
H3 io_uring – new code, new bugs, and a new exploit technique
H3 Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability
H3 New Wine in Old Bottle – Microsoft Sharepoint Post-Auth Deserialization RCE (CVE-2022-29108)
H3 The Cat Escaped from the Chrome Sandbox
H3 Diving into Open-source LMS Codebases
H3 Analysis of CVE-2021-1758 (CoreText Out-Of-Bounds Read)
H3 Identifying Bugs in Router Firmware at Scale with Taint Analysis
H3 Simple Vulnerability Regression Monitoring with V8Harvest
H3 You Talking To Me?
H3 Chrome 1-Day Hunting – Uncovering and Exploiting CVE-2020-15999
H3 Instrumenting Adobe Reader with Frida
H3 Analysis & Exploitation of a Recent TP-Link Archer A7 Vulnerability
H3 Pwn2Own 2020: Oracle VirtualBox Escape
H3 This Font is not Your Type
H3 ASUSWRT URL Processing Stack Buffer Overflow
H3 Oracle VirtualBox VHWA Use-After-Free Privilege Escalation Vulnerability
H3 TianFu Cup 2019: Adobe Reader Exploitation
H3 Adventures in Hypervisor: Oracle VirtualBox Research
H5 Work
H5 Lab
H5 Contact
📝 The Narrative — clean text per page (Info Density · Semantic Coherence)
HOMEPAGE (https://starlabs.sg) STAR Labs | Offensive Security, Engineered
Singapore · Offensive Security Research

[H1]
We break software
before attackers do.
STAR Labs is a Singapore-based offensive security firm specializing in vulnerability research and advanced cybersecurity training. We identify critical weaknesses in widely used software, collaborate with vendors to remediate them, and equip defenders with the mindset and techniques of real-world attackers. Our expertise is demonstrated through success at Pwn2Own and a strong track record of responsible vulnerability disclosures to Microsoft, Google, and enterprise clients across Asia.

Explore services

Browse advisories

0+
CVEs published

0+
Pwn2Own entries

0+
Years operating

0+
Team members

What we do
[H2] Attacker-grade security, delivered.

From product audits to red team engagements, our services are run by the same people who find bugs in browsers, kernels, and firmware.

[H3] Penetration Testing
Licensed pentesting in Singapore (CS/PTS/C-2022-0106). Web, mobile, network, cloud, and infrastructure assessments run by researchers who also find 0-days.
Learn more →

[H3] Red Teaming
Adversary-emulation engagements that test whether your detection & response actually work when a capable attacker is inside.
Learn more →

[H3] Vulnerability Research
Targeted research on your product, supply chain, or key third-party software. Reverse engineering, fuzzing, and manual review to surface pre-disclosure vulnerabilities.
Learn more →

[H3] Source Code Audits
Manual code review by researchers who've found critical bugs in the Linux kernel, Chromium, Windows, and IoT firmware.
Learn more →

[H3] Training
Hands-on offensive-security training for blue teams, developers, and researchers-in-training. Delivered by instructors with real exploit chains to their name.
Learn more →

[H3] Advisory & Consulting
Strategic guidance for CISOs and product teams navigating secure-by-design, SDLC, and incident response.
Learn more →

Latest advisories
[H2] CVEs published by STAR Labs.

All advisories →

Advisory
Apr 28, 2026

[H3] (CVE-2026-41873) Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover
A CRLF injection vulnerability in Apache Pony Mail's Lua implementation allows an unauthenticated attacker to smuggle arbitrary HTTP …

Advisory
Oct 14, 2025

[H3] (CVE-2025-55336) Windows Cloud Files Mini Filter Driver Information Disclosure
CVE: CVE-2025-55336
Affected Versions: Windows 10 (21H2, 22H2, 1809), Windows 11 (22H2, 23H2, 24H2, 25H2), Windows Server 2019, 2022, 2022 …

Advisory
Sep 09, 2025

[H3] (CVE-2025-54098) Windows Hyper-V vhdmp.sys Arbitrary File Write Leading to Elevation of Privilege
A missing OBJ_FORCE_ACCESS_CHECK flag in vhdmp.sys allows a low-privileged local attacker to write arbitrary data to any file on the system …

Advisory
Sep 05, 2025

[H3] (CVE-2025-39682) Linux Kernel net/tls Use-After-Free in tls_sw_recvmsg Leading to Privilege Escalation
A use-after-free in tls_sw_recvmsg arises when a zero-length decrypted TLS record causes darg.skb (strp->anchor) to be queued into rx_list …

Advisory
Aug 12, 2025

[H3] (CVE-2025-50170) Windows Cloud Files Mini Filter Driver Elevation of Privilege
CVE: CVE-2025-50170
Affected Versions: Windows 10 (1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), Windows Server 2019, 2022, 2025 …

Advisory
Jul 08, 2025

[H3] (CVE-2025-47985) Windows Event Tracing Insufficient Validation Leading to Elevation of Privilege
Insufficient validation of the TRACE_ENABLE_FLAG_EXTENSION offset in Windows Event Tracing allows a local attacker to corrupt flag extension …

From the lab
[H2] Deep-dive research & write-ups.

All posts →

Research
Apr 29, 2026

[H3] Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold
TL;DR In April 2026, Adobe disclosed three critical security issues (CVE-2026-34621,CVE-2026-34622,CVE-2026-34626) affecting Acrobat DC, Acrobat Reader DC, and Acrobat 2024. …
AuthorShreyas Penkar (@streypaws)
Read13 min

Research
Apr 01, 2026

[H3] CHECK Removed, Context Confused, Checkmate Achieved
TL;DR In January 2026, the Chrome Releases blog announced several security fixes across different Chrome components. One entry caught our attention: CVE-2026-0899, an Out-of-Bounds …
AuthorShreyas Penkar
Read19 min

Research
Feb 05, 2026

[H3] Pickling the Mailbox: A Deep Dive into CVE-2025-20393
A single-byte integer overflow in Cisco's EUQ RPC protocol chains into Python pickle deserialization, achieving unauthenticated RCE with a single HTTP request against Cisco Secure …
AuthorLi Jiantao and Shi Weiming
Read12 min

Responsibly disclosed to
[H2] Vendors we've reported to.

Every vulnerability we find goes through a structured disclosure process. Here are some of the vendors we've worked with.

Microsoft
66 findings

Adobe
19 findings

Apple
26 findings

Oracle
14 findings

Chamilo
10 findings

Google
8 findings

ASUS
6 findings

Calibre
4 findings

Singtel
2 findings

Linux Kernel
3 findings

VMware
3 findings

Cisco
1 finding

Track record
[H2] Competition-tested. Independently verified.

All achievements →

Pwn2Own
May 2026

[H3] Pwn2Own Berlin 2026: 2nd Place
Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software …

Result2nd Place

Pwn2Own
Oct 2025

[H3] Pwn2Own Ireland 2025
Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software …

ResultMultiple Successful Exploits

Pwn2Own
May 2025

[H3] Pwn2Own Berlin 2025: Master of Pwn
Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software …

ResultMaster of Pwn

Work with us
[H2] Have a system you want broken before someone else does?
Drop us a line. We'll scope a pentest, red team, or code audit tailored to your stack.
Contact STAR Labs
6223 chars
SUB-PAGE (https://starlabs.sg/services/) Services | STAR Labs
Services
[H1]
Security work, delivered by peoplewho find real bugs.
Every engagement is led by researchers with real CVEs and competition wins to their name. We don't churn through checklists, and we don't ship reports that read like auto-generated scan output.

01 · Pentesting
02 · Red Team
03 · Vuln Research
04 · Code Audit
05 · Training
06 · Consulting

01
[H2] Penetration Testing

Licensed, scoped, methodical, but run by researchers who find 0-days, not button-pushers.
We're a CSA-licensed pentesting provider in Singapore (CS/PTS/C-2022-0106). Our testers are the same people who break Windows, Chrome, and enterprise appliances at Pwn2Own. They bring that lens to every engagement.Scope: web apps, mobile apps, APIs, network infrastructure, cloud (AWS/Azure/GCP), and device firmware. Deliverables: executive summary, technical findings with repro steps, CVSS scoring, remediation guidance, and a debrief with the engineering team.
Is this right for you?
When you need a credible third-party assessment for compliance, a customer audit, or simply to find what an attacker would.

02
[H2] Red Team

Adversary emulation that tests whether your detection & response actually work.
Red team engagements start from a realistic initial-access scenario (phishing, supply chain, stolen credentials, insider) and work toward specified crown-jewel objectives. We emulate threat-actor TTPs mapped to MITRE ATT&CK, and coordinate with your blue team for a purple-team debrief.Deliverables: attack narrative, detection gap analysis, timeline of observed vs. missed events, recommendations for SIEM/EDR tuning.
Is this right for you?
When your pentests keep coming back clean but you're not confident you'd catch a real operator.

03
[H2] Vulnerability Research

Targeted 0-day research on your product, your supply chain, or your critical third-party stack.
Reverse engineering, fuzzing, static analysis, and manual review to find pre-disclosure vulnerabilities in software you ship or depend on. Our researchers have responsibly disclosed critical findings to Microsoft, Google, Apple, VMware, and others.Engagements: product security reviews pre-launch, supply-chain due diligence, M&A technical assessment, threat-informed research on specific attack surfaces.
Is this right for you?
When finding a bug before it ships is worth more than finding it after.

04
[H2] Source Code Audit

Manual review by people who've found critical bugs in the Linux kernel, browsers, and IoT firmware.
Automated SAST catches a fraction of what matters. We combine tool-assisted triage with manual review of trust boundaries, auth flows, parsers, IPC, privileged components, and cryptography. We care about exploitability, not just pattern matches.Languages we regularly audit: C/C++, Rust, Go, Java, Kotlin, Swift, Objective-C, JavaScript/TypeScript, Python, PHP, Ruby.
Is this right for you?
Before a major release, after a critical CVE in a dependency, or as an input to your secure-SDLC program.

05
[H2] Training

Hands-on offensive-security training taught by active researchers.
Courses for defenders who want to think like attackers, developers who want to stop shipping bugs, and junior researchers who want to level up. Run on-site or remote, with real lab environments and CTF-style exercises.Tracks: web exploitation, Windows/Linux kernel internals, mobile app security, browser internals, firmware & IoT, AI system red teaming.
Is this right for you?
When your team needs to close a specific skill gap before an engagement, launch, or certification milestone.

06
[H2] Advisory & Consulting

Strategic guidance for CISOs and product teams.
For organizations that need offensive-security expertise on tap: not a single engagement, but an ongoing voice in architecture reviews, threat modeling, vendor risk, and incident response retrospectives.Outcomes: security architecture decisions that hold up, threat models that reflect real attackers, incident debriefs that produce actual change.
Is this right for you?
When you've outgrown ad-hoc pentest procurement but aren't ready for a full internal offensive team.

Scope an engagement
[H2] Tell us what you're protecting. We'll tell you how we'd break it.
Most engagements start with a 30-minute scoping call. No sales funnel, no back-and-forth with people who won't be doing the work. You talk directly to the researchers.
Email us
4487 chars
SUB-PAGE (https://starlabs.sg/advisories/) Advisories | STAR Labs
Vulnerability Research
[H1] Security Advisories

STAR Labs responsibly discloses every vulnerability we discover. The following table is our public record of coordinated disclosures, sorted newest first.

169 / 169 advisories

Date ↕

CVE ↕
Title
Author ↕

Apr 28, 2026

CVE-2026-41873

Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover
Li Jiantao, Tevel Sho

Oct 14, 2025

CVE-2025-55336

Windows Cloud Files Mini Filter Driver Information Disclosure
Chen Le Qi

Sep 09, 2025

CVE-2025-54098

Windows Hyper-V vhdmp.sys Arbitrary File Write Leading to Elevation of Privilege
Chen Le Qi

Sep 05, 2025

CVE-2025-39682

Linux Kernel net/tls Use-After-Free in tls_sw_recvmsg Leading to Privilege Escalation
Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan

Aug 12, 2025

CVE-2025-50170

Windows Cloud Files Mini Filter Driver Elevation of Privilege
Chen Le Qi

Jul 08, 2025

CVE-2025-47985

Windows Event Tracing Insufficient Validation Leading to Elevation of Privilege
Chen Le Qi

Jul 08, 2025

CVE-2025-49660

Windows Event Tracing Reference Count Overflow Leading to Use-After-Free and Elevation of Privilege
Chen Le Qi

Jun 04, 2025

CVE-2025-23095

Samsung Exynos NPU Driver Double Free Leading to Privilege Escalation
Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan ZhenPeng

Jun 02, 2025

CVE-2025-23099

Samsung Exynos NPU Driver Out-of-Bounds Write Leading to Privilege Escalation
Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan ZhenPeng

Jun 01, 2025

CVE-2025-23096

Samsung Exynos NPU Driver Double Free in IMB Memory Buffer Leading to Privilege Escalation
Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng

Jun 01, 2025

CVE-2025-23098

Samsung Exynos NPU Driver Use-After-Free in IMB Memory Buffer Leading to Privilege Escalation
Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng, Ng Zhi Yang

Jun 01, 2025

CVE-2025-23100

Samsung Exynos NPU Driver Null Pointer Dereference Leading to Denial of Service
Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng

Jun 01, 2025

CVE-2025-23103

Samsung Exynos NPU Driver Out-of-Bounds Write via Unbounded Loop Counter
Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng

Jun 01, 2025

CVE-2025-23107

Samsung Exynos NPU Driver Out-of-Bounds Write via Undersized User Buffer
Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng

May 16, 2025

CVE-2025-37890

Linux Kernel net_sched netem Double Enqueue Leading to Use-After-Free and Local Privilege Escalation
Gerrard Tai

May 02, 2025

CVE-2025-37797

Linux Kernel hfsc_change_class TOCTOU Leading to Use-After-Free and Local Privilege Escalation
Gerrard Tai

May 02, 2025

CVE-2025-37798

Linux Kernel fq_codel_dequeue qlen Mismatch Leading to Use-After-Free and Local Privilege Escalation
Gerrard Tai

Nov 12, 2024

CVE-2024-43626

Windows Telephony Service Heap Out-of-Bounds Read/Write Leading to Elevation of Privilege
Chen Le Qi, Nguyễn Đăng Nguyễn

Oct 01, 2024

CVE-2024-9370

Google Chrome V8 Maglev Escape Analysis Incorrect Optimization Bug
Nguyễn Hoàng Thạch, Đỗ Minh Tuấn, Wu JinLin

Jul 31, 2024

CVE-2024-6781

Calibre Arbitrary File Read
Amos Ng

Jul 31, 2024

CVE-2024-6782

Calibre Remote Code Execution
Amos Ng

Jul 31, 2024

CVE-2024-7008

Calibre Reflected Cross-Site Scripting (XSS)
Devesh Logendran

Jul 31, 2024

CVE-2024-7009

Calibre SQLite Injection
Devesh Logendran

Jul 22, 2024

CVE-2024-1837

Singtel RT5703W Unauthenticated Command Injection RCE via Login Vulnerability
Daniel Lim Wee Soong

Jul 22, 2024

CVE-2024-1838

Singtel RT5703W Authenticated Command Injection RCE via SetLoginPwd Vulnerability
Daniel Lim Wee Soong

Jul 01, 2024

CVE-2024-26923

Android AF_UNIX Garbage Collector Race Condition Leading to Use-After-Free
Billy Jheng Bing Jhong, Pan ZhenPeng

Jul 01, 2024

CVE-2024-34594

Samsung Galaxy Kernel Information Disclosure via Debug proc Entry Leading to KASLR Bypass
Billy Jheng Bing-Jhong, Pan Zhenpeng

May 16, 2024

CVE-2024-36972

Linux Kernel Race Condition in unix_gc on oob_skb Leading to Double Free
Billy Jheng Bing Jhong

May 13, 2024

CVE-2024-27828

Apple IOSurfaceRoot Reference Count Leak Leading to Kernel Panic and Code Execution
Pan Zhenpeng

Jan 22, 2024

CVE-2024-27791

Apple PMP Firmware Out-of-Bounds Write via ApplePMPv2 writeDashboard
Pan Zhenpeng

Nov 28, 2023

CVE-2023-3368

Chamilo LMS Unauthenticated Command Injection
Ngo Wei Lin

Nov 28, 2023

CVE-2023-3533

Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write
Ngo Wei Lin

Nov 28, 2023

CVE-2023-3545

Chamilo LMS Htaccess File Upload Security Bypass
Ngo Wei Lin

Nov 28, 2023

CVE-2023-4220

Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
Ngo Wei Lin

Nov 28, 2023

CVE-2023-4221

Chamilo LMS Learning Path PPT2LP OpenofficePresentation Command Injection
Ngo Wei Lin

Nov 28, 2023

CVE-2023-4222

Chamilo LMS Learning Path PPT2LP OpenofficeTextDocument Command Injection
Ngo Wei Lin

Nov 28, 2023

CVE-2023-4223

Chamilo LMS Document Ajax File Upload Functionality Remote Code Execution
Ngo Wei Lin

Nov 28, 2023

CVE-2023-4224

Chamilo LMS Dropbox Ajax File Upload Functionality Remote Code Execution
Ngo Wei Lin

Nov 28, 2023

CVE-2023-4225

Chamilo LMS Exercise Ajax File Upload Functionality Remote Code Execution
Ngo Wei Lin

Nov 28, 2023

CVE-2023-4226

Chamilo LMS Work Ajax File Upload Functionality Remote Code Execution
Ngo Wei Lin

Nov 01, 2023

CVE-2023-1713

Bitrix24 Remote Command Execution (RCE) via Insecure Temporary File Creation
Lam Jun Rong & Li Jiantao

Nov 01, 2023

CVE-2023-1714

Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction
Lam Jun Rong & Li Jiantao

Nov 01, 2023

CVE-2023-1715

(CVE-2023-1715 & CVE-2023-1716) Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page
Lam Jun Rong & Li Jiantao

Nov 01, 2023

CVE-2023-1717

Bitrix24 Cross-Site Scripting (XSS) via Client-side Prototype Pollution
Lam Jun Rong & Li Jiantao

Nov 01, 2023

CVE-2023-1718

Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access
Lam Jun Rong & Li Jiantao

Nov 01, 2023

CVE-2023-1719

Bitrix24 Insecure Global Variable Extraction
Lam Jun Rong & Li Jiantao

Nov 01, 2023

CVE-2023-1720

Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload
Lam Jun Rong & Li Jiantao

Oct 11, 2023

CVE-2023-4197

Dolibarr ERP CRM (<= 18.0.1) Improper Input Sanitization Authenticated RCE
Poh Jia Hao

Oct 11, 2023

CVE-2023-4198

Dolibarr ERP CRM (<= 17.0.3) Improper Access Control
Poh Jia Hao

Sep 29, 2023

CVE-2023-30591

NodeBB Pre-Authentication Denial-of-Service
Ngo Wei Lin

Sep 26, 2023

CVE-2023-41984

Apple AppleSPU Shared Memory Read/Write Mapping Leading to Kernel Panic and Code Execution
Pan Zhenpeng

Sep 18, 2023

CVE-2023-2315

Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2
Poh Jia Hao

Aug 28, 2023

CVE-2023-2016

Attendize <= 2.8.0 Authenticated TOCTOU Allows Multiple Refunds Per Order
Poh Jia Hao

Aug 22, 2023

CVE-2023-32523

Trend Micro Mobile Security (Enterprise) 9.8 SP5 (<= Critical Patch 3) Unauthenticated RCE
Poh Jia Hao

Aug 22, 2023

CVE-2023-32524

Trend Micro Mobile Security (Enterprise) 9.8 SP5 (<= Critical Patch 3) Unauthenticated RCE
Poh Jia Hao

Aug 22, 2023

CVE-2023-32529

Trend Micro Apex Central 2019 (<= Build 6016) Authenticated RCE
Poh Jia Hao

Aug 22, 2023

CVE-2023-32530

Trend Micro Apex Central 2019 (<= Build 6016) Authenticated RCE
Poh Jia Hao

Aug 22, 2023

CVE-2023-38624

Trend Micro Apex Central 2019 (<= Build 6394) Authenticated SSRF
Poh Jia Hao

Aug 22, 2023

CVE-2023-38625

Trend Micro Apex Central 2019 (<= Build 6394) Authenticated SSRF
Poh Jia Hao

Aug 19, 2023

CVE-2023-2110

Obsidian Local File Disclosure
Li Jiantao

Aug 19, 2023

CVE-2023-2316

Typora Local File Disclosure
Li Jiantao

Aug 19, 2023

CVE-2023-2317

Typora DOM-Based Cross-site Scripting leading to Remote Code Execution
Li Jiantao

Aug 19, 2023

CVE-2023-2318

MarkText DOM-Based Cross-site Scripting leading to Remote Code Execution
Li Jiantao

Aug 19, 2023

CVE-2023-2971

Typora Local File Disclosure (Patch Bypass)
Li Jiantao

Jul 14, 2023

CVE-2023-3513

RazerCentralService unsafe deserialization Escalation of Privilege Vulnerability
Phan Thanh Duy

Jul 14, 2023

CVE-2023-3514

RazerCentralSerivce unsafe NamedPipe permission Escalation of Privilege Vulnerability
Phan Thanh Duy

Apr 17, 2023

CVE-2023-2017

Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension
Ngo Wei Lin

Apr 12, 2023

CVE-2023-1872

Linux Kernel io_uring Missing Lock in io_file_get_fixed Leading to Use-After-Free and Local Privilege Escalation
Billy Jheng Bing-Jhong

Dec 13, 2022

CVE-2022-44667

Windows CDirectMusicPortDownload Integer Overflow Vulnerability
Lê Hữu Quang Linh

Dec 13, 2022

CVE-2022-44668

Windows DirectMusicPortDownload Double Free Vulnerability
Lê Hữu Quang Linh

Jul 13, 2022

CVE-2022-26438

Asus System Control Interface Backup Local Privilege Escalation (LPE)
Schuyler Tay

Jul 13, 2022

CVE-2022-26439

Asus System Control Interface Software Update Arbitrary File Deletion
Schuyler Tay

Mar 28, 2022

CVE-2021-4206

QEMU QXL Integer overflow leads to Heap Overflow
Billy Jheng Bing Jhong

Mar 28, 2022

CVE-2021-4207

QEMU QXL Integer overflow leads to Heap Overflow
Billy Jheng Bing Jhong

Mar 28, 2022

CVE-2022-0168

Linux Kernel smb2_ioctl_query_info NULL Pointer Dereference
Billy Jheng Bing Jhong

Mar 28, 2022

CVE-2022-0216

QEMU LSI SCSI Use After Free
Muhammad Alifa Ramdhan

Mar 14, 2022

CVE-2022-28730

Apache JSPWiki v2.11.1 - Reflected XSS in AjaxPreview.jsp
Poh Jia Hao

Mar 04, 2022

CVE-2022-26718

macOS smbfs Out-of-Bounds Read due to parse nic info
Peter Nguyễn Vũ Hoàng

Jan 11, 2022

CVE-2022-21877

Storage Spaces Controller Information Disclosure Vulnerability
Lê Hữu Quang Linh

Sep 13, 2021

CVE-2021-30844

macOS smbfs Out-of-Bounds Read
Peter Nguyễn Vũ Hoàng

Sep 13, 2021

CVE-2021-30845

macOS smbfs Out-of-Bounds Read
Peter Nguyễn Vũ Hoàng

Jun 18, 2021

CVE-2021-30868

macOS smbfs Race Condition leading to Use-After-Free Vulnerability
Peter Nguyễn Vũ Hoàng

Jun 10, 2021

CVE-20221-35400

Prolink PRC2402M mesh.cgi get_extender_page Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 10, 2021

CVE-20221-35401

Prolink PRC2402M login.cgi sys_login Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 10, 2021

CVE-20221-35403

Prolink PRC2402M touchlist_sync.cgi main Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 10, 2021

CVE-20221-35404

Prolink PRC2402M applogin.cgi sys_login1 Authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 10, 2021

CVE-20221-35406

Prolink PRC2402M login.cgi sys_login1 Authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 10, 2021

CVE-20221-35406

Prolink PRC2402M qos.cgi qos_settings Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 10, 2021

CVE-20221-35407

Prolink PRC2402M mesh.cgi get_upgrade_page Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 10, 2021

CVE-20221-35409

Prolink PRC2402M nightled.cgi SetNightLed Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 09, 2021

CVE-2021-30836

WebKit WebCore::AudioNode::disconnect null pointer reference
Ta Dinh Sung

Jun 09, 2021

CVE-20221-35402

Prolink PRC2402M live_api.cgi satellist_list Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

Jun 08, 2021

CVE-2021-35408

Prolink PRC2402M qos.cgi qos_sta_settings Un-authenticated Command Injection Vulnerability
Daniel Lim Wee Soong

May 28, 2021

CVE-2021-0956

Android NFC Out-Of-Bounds Write due to increase mNumTechList without bounds checking
Nguyễn Hoàng Thạch

May 20, 2021

CVE-2021-30745

Apple macOS QuartzCore Type Confusion Vulnerability
Peter Nguyễn Vũ Hoàng

Apr 14, 2021

CVE-2021-0204

Juniper Junos OS Local Privilege Escalation vulnerability in dexp
Nguyễn Hoàng Thạch

Apr 14, 2021

CVE-2021-0223

Juniper Junos OS Local Privilege Escalation vulnerability in telnetd
Nguyễn Hoàng Thạch

Apr 14, 2021

CVE-2021-0254

Junos OS overlayd service bss Buffer Overflow
Nguyễn Hoàng Thạch

Apr 14, 2021

CVE-2021-0255

Juniper Junos OS Local Privilege Escalation vulnerability in ethtraceroute
Nguyễn Hoàng Thạch

Apr 14, 2021

CVE-2021-0256

Juniper Junos OS Local Privilege Escalation vulnerability in mosquitto
Nguyễn Hoàng Thạch

Apr 06, 2021

CVE-2021-2321

Oracle VirtualBox E1000 BSS Out-Of-Bounds Read
Muhammad Alifa Ramdhan

Mar 23, 2021

CVE-2021-3409

QEMU Heap Overflow in SDHCI Component
Muhammad Alifa Ramdhan

Mar 22, 2021

CVE-2021-34978

NETGEAR R6260 setupwizard.cgi Buffer Overflow Unauthenticated Remote Code Execution
Sherman Chann Zhi Shen & Nguyễn Hoàng Thạch

Mar 22, 2021

CVE-2021-34979

NETGEAR R6260 mini_httpd Buffer Overflow Unauthenticated Remote Code Execution
Sherman Chann Zhi Shen & Nguyễn Hoàng Thạch

Mar 05, 2021

CVE-2021-0950

Android NFC android.hardware.nfc@1.2-service Writer mode Out-Of-Bounds Write leading to Information Disclosure
Nguyễn Hoàng Thạch

Feb 27, 2021

CVE-2021-33760

Windows Media Foundation Integer Overflow Vulnerability
Phan Thanh Duy, Brandon Chong, Cao Yi Tian

Feb 27, 2021

CVE-2021-34503

Windows Media Foundation Type Confusion Vulnerability
Phan Thanh Duy

Feb 10, 2021

CVE-2021-1758

macOS/iOS CoreText Out-Of-Bounds Read
Peter Nguyễn Vũ Hoàng

Feb 10, 2021

CVE-2021-1790

macOS/iOS CoreText libhvf O
15000 chars
SUB-PAGE (https://starlabs.sg/blog/) Blog | STAR Labs
From the lab
[H1] Research & write-ups.

Deep dives into vulnerability research, exploitation techniques, and security analysis from the STAR Labs team.

Research
Apr 29, 2026

[H3] Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold

TL;DR In April 2026, Adobe disclosed three critical security issues (CVE-2026-34621,CVE-2026-34622,CVE-2026-34626) affecting Acrobat DC, Acrobat Reader DC, and …

ByShreyas Penkar (@streypaws)
Read13 min

Research
Apr 01, 2026

[H3] CHECK Removed, Context Confused, Checkmate Achieved

TL;DR In January 2026, the Chrome Releases blog announced several security fixes across different Chrome components. One entry caught our attention: …

ByShreyas Penkar
Read19 min

Research
Feb 05, 2026

[H3] Pickling the Mailbox: A Deep Dive into CVE-2025-20393

A single-byte integer overflow in Cisco's EUQ RPC protocol chains into Python pickle deserialization, achieving unauthenticated RCE with a single HTTP request …

ByLi Jiantao and Shi Weiming
Read12 min

Research
Jan 08, 2026

[H3] 8th Anniversary: Embrace the new but don't forget the old

Eight years ago today, I started STAR Labs by hiring several fresh grads with no working experiences.
Today, I stand here with a different group of faces. Some …

ByJacob Soo
Read4 min

Research
Dec 27, 2025

[H3] 2025: WE BROKE THINGS, WE BUILT THINGS, WE BROKE EVEN MORE THINGS

Most will talk about the success in their year-end posts. Great. Nobody talks about the failures. Nobody talks about what ACTUALLY happened.
Well, we are going …

BySTAR Labs SG
Read5 min

Research
Nov 18, 2025

[H3] HEX ADVENT 2025: Crack the Advent, Conquer the Threat ?

HEX ADVENT 2025: Crack the Advent, Conquer the Threat ? Last chance to register! Registration closing on 20 Dec 2025, 09:00 SGT!
WELCOME TO HEX ADVENT 2025, …

BySTAR Labs SG
Read8 min

Research
Nov 10, 2025

[H3] HEX ADVENT 2025: Rules & Information

Information This is a solo CTF event open to women residing in Singapore or Malaysia.
To register and be eligible for the prizes:
Register on CTFd, and select …

BySTAR Labs SG
Read2 min

Research
Nov 03, 2025

[H3] Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

The Target: Brother MFC-J1010DW Affected Models: Brother Printer MFC-J1010DW Vulnerable Firmware: Version <= 1.18 TL;DR: The Vulnerability Chain We …

ByNguyên Đăng Nguyên & Manzel Seet & Amos Ng
Read21 min

Research
Sep 15, 2025

[H3] Summer Pwnables: lz1 Solution

TL;DR ? We’re turning a simple compression library into a shell delivery service! This writeup exploits a buffer overflow in lz1/lz77 decompression by …

ByZafir Rasyidi Taufik
Read8 min

Research
Sep 15, 2025

[H3] Summer Pwnables: Temporal Paradox Engine Solution

Last month, Jacob asked me to create a CTF challenge for the Summer Pwnables event. I went with a kernel pwnable since my goal was to teach students some more …

ByMuhammad Alifa Ramdhan
Read13 min

Research
Sep 11, 2025

[H3] Lost in Translation: Apache Vulnerabilities That Don't Count (Literally)

During our security research in 2024, we discovered several vulnerabilities in Apache Foundation projects that seem to have gotten ’lost in …

ByLi Jiantao
Read9 min

Research
Sep 02, 2025

[H3] Fuzzing a Printer: Pre-auth RCE in a Network IoT Device

Printers have three things going for them from an attacker’s perspective: they live on the corporate network, they trust far too much from far too many …

ByPoh Jia Hao
Read1 min
fuzzingiotprinterrce

Research
Aug 18, 2025

[H3] [Updates] Summer Pwnables ?

[Updates] Summer Pwnables 2025 Major Announcement: ISD Sponsorship We are pleased to announce that Internal Security Department (ISD) is sponsoring Summer …

BySTAR Labs SG
Read2 min

Research
Aug 12, 2025

[H3] Summer Pwnables: When the Heat Rises, So Do the C-Shells ?

?☀️ SUMMER PWNABLES 2025 ☀️? The hottest hacking challenge on this side of Southeast Asia! Think you can handle the heat? Time to prove your l33t skills are …

BySTAR Labs SG
Read3 min

Research
Jul 16, 2025

[H3] My `Blind Date` with CVE-2025-29824

In April 2025, Microsoft patched a vulnerability that had become a key component in sophisticated ransomware attack chains. CVE-2025-29824, an use-after-free …

ByOng How Chong
Read10 min

Research
Jul 10, 2025

[H3] Fooling the Sandbox: A Chrome-atic Escape

For my internship, I was tasked by my mentor Le Qi to analyze CVE-2024-30088, a double-fetch race condition bug in the Windows Kernel Image ntoskrnl.exe. A …

ByVincent Yeo
Read11 min

Research
Jun 05, 2025

[H3] Solo: A Pixel 6 Pro Story (When one bug is all you need)

During my internship I was tasked to analyze a Mali GPU exploit on Pixel 7/8 devices and adapt it to make it work on another device: the Pixel 6 Pro.
While the …

ByLin Ze Wei
Read36 min

Research
May 30, 2025

[H3] Gone in 5 Seconds: How WARN_ON Stole 10 Minutes

As part of my internship at STAR Labs, I was tasked to conduct N-day analysis of CVE-2023-6241. The original PoC can be found here, along with the accompanying …

ByTan Ze Jian
Read16 min

Research
May 28, 2025

[H3] Badge & Lanyard Challenges @ OBO 2025

Introduction We are back with Round 2 of the Off-By-One conference — where bits meet breadboards and bugs are celebrated! ?⚡
If you are into hardware and IoT …

ByManzel Seet & Sarah Tan
Read14 min

Research
May 20, 2025

[H3] Lessons From Pwn2Own Berlin 2025: Building a Hypervisor Escape

At Pwn2Own Berlin 2025, STAR Labs took home Master of Pwn for a chain that escaped a major hypervisor from inside a guest VM. This is the short version of how …

ByBilly Jheng Bing-Jhong
Read2 min
pwn2ownvirtualizationexploit-development

Research
May 14, 2025

[H3] Breaking Out of Restricted Mode: XSS to RCE in Visual Studio Code

In April 2024, I discovered a high-severity vulnerability in Visual Studio Code (VS Code <= 1.89.1) that allows attackers to escalate a Cross-Site Scripting …

ByDevesh Logendran
Read7 min

Research
Mar 25, 2025

[H3] CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)

Introduction Many vulnerability writeups nowadays focus on the exploitation process when it comes to software bugs. The term “Exploit Developer” is …

ByChen Le Qi
Read21 min

Research
Mar 17, 2025

[H3] STAR Labs Windows Exploitation Challenge 2025 Writeup

STAR Labs Windows Exploitation Challenge Writeup Over the past few months, the STAR Labs team has been hosting a Windows exploitation challenge. I was lucky …

ByGuest Post by Võ Văn Tiến Dũng
Read9 min

Research
Feb 02, 2025

[H3] Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)

Imagine downloading a game from a third-party app store. You grant it seemingly innocuous permissions, but hidden within the app is a malicious exploit that …

ByNg Zhi Yang
Read17 min

Research
Jan 24, 2025

[H3] CVE-2024-26230: Windows Telephony Service - It's Got Some Call-ing Issues (Elevation of Privilege)

Executive Summary CVE-2024-26230 is a critical vulnerability found in the Windows Telephony Service (TapiSrv), which can lead to an elevation of privilege on …

ByĐào Tuấn Linh
Read11 min

Research
Jan 12, 2025

[H3] Celebrating 7 Years of STAR Labs SG

?? Cheers to 7 Amazing Years! ??
On 8th January 2018, STAR Labs SG Pte. Ltd. was born with a simple but bold idea: to do fun offensive research that protects …

BySTAR Labs SG
Read5 min

Research
Jan 01, 2025

[H3] STAR Labs 2025 New Year Exploitation Challenge

Think you’ve got what it takes to pop shells and snag your ticket to… RE//verse and Off-By-One? ?
? Windows Exploitation Challenge ? Get SYSTEM …

BySTAR Labs SG
Read1 min

Research
Dec 24, 2024

[H3] All I Want for Christmas is a CVE-2024-30085 Exploit

TLDR CVE-2024-30085 is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini Filter Driver cldflt.sys. By crafting a custom reparse …

ByCherie-Anne Lee
Read21 min

Research
Dec 24, 2024

[H3] Behind the Scenes: Understanding CVE-2022-24547

TL;dr Vulnerabilities can often be found in places we don’t expect, and CVE-2022-24547 in CastSrv.exe is one of the examples. CVE-2022-24547 is a privilege …

ByĐào Tuấn Linh
Read5 min

Research
Jul 22, 2024

[H3] #BadgeLife @ Off-By-One Conference 2024

Introduction As promised, we are releasing the firmware and this post for the Off-By-One badge about one month after the event, allowing interested participants …

ByManzel Joseph Seet
Read13 min

Research
May 06, 2024

[H3] Send()-ing Myself Belated Christmas Gifts - GitHub.com's Environment Variables & GHES Shell

Earlier this year, in mid-January, you might have come across this security announcement by GitHub.
In this article, I will unveil the shocking story of how I …

ByNgo Wei Lin
Read15 min

Research
Apr 15, 2024

[H3] Send()-ing Myself Belated Christmas Gifts: GitHub.com's Environment Variables & GHES Shell

Short version: while poking at GitHub Enterprise Server (GHES) for an unrelated reason the day after Christmas, I noticed an unvalidated Kernel#send() call in …

ByNgo Wei Lin
Read2 min
githubrcerubyweb

Research
Mar 18, 2024

[H3] Route to Safety: Navigating Router Pitfalls

Introduction Wi-Fi routers have always been an attractive target for attackers. When taken over, an attacker may gain access to a victim’s internal …

ByDaniel Lim Wee Soong
Read48 min

Research
Nov 24, 2023

[H3] Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)

Introduction The prevalence of memory corruption bugs persists, posing a persistent challenge for exploitation. This increased difficulty arises from …

ByChen Le Qi
Read24 min

Research
Sep 29, 2023

[H3] Analysis of NodeBB Account Takeover Vulnerability (CVE-2022-46164)

Back in January 2023, I tasked one of our web security interns, River Koh (@oceankex), to perform n-day analysis of CVE-2022-46164 as part of his internship …

ByNgo Wei Lin & River Koh
Read14 min

Research
Sep 25, 2023

[H3] [P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955)

Brief I may have achieved successful exploitation of a SharePoint target during Pwn2Own Vancouver 2023. While the live demonstration lasted only approximately …

ByNguyễn Tiến Giang (Jang)
Read18 min

Research
Sep 25, 2023

[H3] nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)

During my internship, I have been researching and trying to find bugs within the nftables subsystem. In this blog post, I will talk about a bug I have found, as …

ByCherie-Anne Lee
Read26 min

Research
Aug 01, 2023

[H3] Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp

We are excited to embark on a series of teardowns to explore the inner workings of various devices. In this particular teardown, our focus will be on the …

ByJoshua Tay
Read11 min

Research
Jul 25, 2023

[H3] A new method for container escape using file-based DirtyCred

Recently, I was trying out various exploitation techniques against a Linux kernel vulnerability, CVE-2022-3910. After successfully writing an exploit which made …

ByChoo Yi Kai
Read16 min

Research
Jul 25, 2023

[H3] prctl anon_vma_name: An Amusing Linux Kernel Heap Spray

TLDR prctl PR_SET_VMA (PR_SET_VMA_ANON_NAME) can be used as a (possibly new!) heap spray method targeting the kmalloc-8 to kmalloc-96 caches. The sprayed …

ByCherie-Anne Lee
Read7 min

Research
Jun 19, 2023

[H3] Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability

Background The discovery and analysis of vulnerabilities is a critical aspect of cybersecurity research. Today, we will dive into CVE-2023-1829, a vulnerability …

ByVũ Thị Lan
Read17 min

Research
Jun 14, 2023

[H3] The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022

TLDR; We began our work on Samsung immediately after the release of the Pwn2Own Toronto 2022 target list.
In this article, we will dive into the details of an …

ByNguyễn Tiến Giang (Jang)
Read8 min

Research
Apr 28, 2023

[H3] Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707)

Introduction While analyzing CVE-2022-41082, also known as ProxyNotShell, we discovered this vulnerability which we have detailed in this blog. However, for a …

ByNguyễn Tiến Giang (Jang)
Read6 min

Research
Mar 03, 2023

[H3] CS-Cart PDF Plugin Unauthenticated Command Injection

Summary A command injection vulnerability exists in CS-Cart’s HTML to PDF converter (https://github.com/cscart/pdf) allowing unauthenticated attackers to …

ByNgo Wei Lin
Read4 min

Research
Feb 24, 2023

[H3] Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer

Upon finding the vulnerability, our team member, Ngo Wei Lin (@Creastery), immediately reported it to the Microsoft Security Response Center (MSRC) on 19th …

ByNgo Wei Lin
Read5 min

Research
Feb 22, 2023

[H3] STAR LABS SG PTE. LTD. has been authorized by the CVE Program as a CVE Numbering Authority (CNA)

STAR LABS SG PTE. LTD. (STAR Labs) announced today that it has become a CVE Numbering Authority (CNA) for the Common Vulnerabilities and Exposures (CVE®) …

BySTAR Labs SG Pte. Ltd.
Read2 min

Research
Feb 17, 2023

[H3] Gotta KEP-tcha 'Em All - Bypassing Anti-Debugging methods in KEPServerEX

Background Lately, my focus has been on discovering any potential vulnerabilities in KEPServerEX. KEPServerEX is the industry’s leading connectivity …

ByLê Hữu Quang Linh
Read12 min

Research
Feb 16, 2023

[H3] Dissecting the Vulnerabilities - A Comprehensive Teardown of acmailer's N-Days

Introduction In this post, one of our recent intern, Wang Hengyue (@w_hy_04) was given the task to analyse CVE-2021-20617 & CVE-2021-20618 in acmailer since …

ByWang Hengyue
Read12 min

Research
Dec 21, 2022

[H3] Deconstructing and Exploiting CVE-2020-6418

As part of my internship at STAR Labs, I conducted n-day analysis of CVE-2020-6418. This vulnerability lies in the V8 engine of Google Chrome, namely its …

ByDaniel Toh Jing En
Read15 min

Research
Dec 06, 2022

[H3] The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022

Background Some time ago, we were playing with some Netgear routers and we learned so much from this target.
However, Netgear recently patched several …

ByVu Thi Lan, Nguyễn Hoàng Thạ
15000 chars
🛡️ Trust Signals — reviews, proof links, trust-theatre flag (Trust & Proof)
17Review mentions (all pages)
0External proof links (all pages)
PageReviewsProof links
/ (home) 3 0
/services/ 5 0
/advisories/ 2 0
/blog/ 7 0
🔗 Identity & Technical Layer — schema JSON-LD: identity chains, entity gaps (Identity & Authority)
Homepage — no schema detected (entity gap)
/services/ — no schema detected (entity gap)
/advisories/ — no schema detected (entity gap)
/blog/ — no schema detected (entity gap)

Your Diagnosis

Before revealing the machine’s verdict, predict the BS score for each signal. Higher = more BS (more fluff, less verifiable substance). Drag each slider, then submit to compare your judgment against the engine.

Information Density 0 / 30
Read the Narrative & headings: do hard facts (prices, dates, numbers) outweigh fluff power-words?
Semantic Coherence 0 / 20
Compare the homepage promise against the sub-page reality. Do they hold the same line?
Trust & Proof 0 / 20
Weigh review mentions against actual external proof links. Claims without verification = theatre.
Commodity Fingerprint 0 / 15
Check headings & narrative against the industry clichés in the setup above.
Identity & Authority 0 / 15
Inspect the schema: is there real Organization/Person identity with sameAs links, or gaps?
Your predicted BS score 0 / 100
💡 Stuck? Reveal the heuristic lens — how the deterministic page-auditor reads each signal (no AI, pure pattern rules)

These are the structural rules a local, deterministic auditor applies — the same lens you can use to judge each signal. They describe what to look for, not this company’s result.

Information Density

Classify each sentence as substantive or hollow. Grounding markers — numbers, currencies, dates, technical units, named entities — outweigh marketing adjectives. When fluff sits right next to hard evidence, the fluff is forgiven.

Semantic Alignment

Pull the main entities out of the H1, then check whether they actually recur through the body. A page that announces one thing and then talks about another drifts. Headings with no real sentences underneath read as pseudo-substance.

Trust & Proof

Count trust words (review, testimonial, rating, verified) against real outbound proof links (Google, Trustpilot, Clutch, G2, Yelp). Lots of trust language with zero verification links is trust theatre. Unlinked logo galleries count against it.

Commodity Fingerprint

Look at how much sentence length varies. Natural writing varies its rhythm; templated or mass-produced copy is statistically uniform. Very low variation reads as commodity content — unless unique named entities break the pattern.

Identity & Authority

Inspect the JSON-LD. Is there an Organization or Person schema, and does it carry sameAs links to real external profiles (LinkedIn, socials)? Missing schema or no identity declaration signals an anonymous entity.

Want to apply this lens yourself? The free BS Indicator Chrome extension runs these heuristic checks live on any page. Bear in mind it is a single-page, deterministic tool — it relies only on pattern rules for the page in front of it and does not perform the cross-page semantic correlation this audit uses, so its readout is a starting lens, not the full verdict.

B
BS Level
Security, Surveillance & Cybersecurity
36.5 Avg BS

Based on 370 businesses audited.

BS Detector

Security, Surveillance & Cybersecurity BS: STAR Labs SG (starlabs.sg)

https://starlabs.sg 📍 Industry: Security, Surveillance & Cybersecurity
15 BS / 100

This site is a masterclass in anti-BS security marketing. It bypasses industry cliches by overwhelming the user with forensic evidence of actual technical accomplishments and public competition wins.

Info Density Power-words vs. Substance ratio.
3
10% BS
Semantic Coherence Homepage promise vs. Sub-page reality.
0
0% BS
Trust & Proof Verifiable evidence vs. Trust Theatre.
8
40% BS
Commodity Fingerprint Detection of industry clichés/templates.
1
7% BS
Identity & Authority Expert verifiability & Schema depth.
3
20% BS

To achieve a near-zero BS score, implement structured Organization and Person schema to programmatically verify the named researchers. Resolve the trust theatre discrepancy by linking the review counts to specific third-party validation sources. Remove the minor power-word ‘Attacker-grade’ from the H2 to ensure 100% of headings are purely technical.

The website is a perfect fit for the Offensive Security and Cybersecurity category. The content is saturated with specific technical deliverables like vulnerability research, red teaming, and exploit development, which are substantiated by a massive public record of CVEs and competition results.

“The score of 15 is driven almost entirely by mechanical metadata gaps (missing schema and trust theatre flags) rather than substantive fluff. In terms of actual content, the site contains less than 3% generic marketing language.”

Verified Analysis Date: May 24, 2026 © 1EuroSEO Independent Evaluator — Non-Sponsored Result
Brand AI Reputation