Singapore · Offensive Security Research

We break software
before attackers do.

STAR Labs is a Singapore-based offensive security firm specializing in vulnerability research and advanced cybersecurity training. We identify critical weaknesses in widely used software, collaborate with vendors to remediate them, and equip defenders with the mindset and techniques of real-world attackers. Our expertise is demonstrated through success at Pwn2Own and a strong track record of responsible vulnerability disclosures to Microsoft, Google, and enterprise clients across Asia.

0+
CVEs published
0+
Pwn2Own entries
0+
Years operating
0+
Team members
Latest advisories

CVEs published by STAR Labs.

All advisories →
From the lab

Deep-dive research & write-ups.

All posts →
Research Apr 01, 2026

CHECK Removed, Context Confused, Checkmate Achieved

TL;DR In January 2026, the Chrome Releases blog announced several security fixes across different Chrome components. One entry caught our attention: CVE-2026-0899, an Out-of-Bounds …

AuthorShreyas Penkar Read19 min
Research Feb 05, 2026

Pickling the Mailbox: A Deep Dive into CVE-2025-20393

A single-byte integer overflow in Cisco's EUQ RPC protocol chains into Python pickle deserialization, achieving unauthenticated RCE with a single HTTP request against Cisco Secure …

AuthorLi Jiantao & Read12 min
Research Jan 08, 2026

8th Anniversary: Embrace the new but don't forget the old

Eight years ago today, I started STAR Labs by hiring several fresh grads with no working experiences. Today, I stand here with a different group of faces. Some of you were there …

AuthorJacob Soo Read4 min
Responsibly disclosed to

Vendors we've reported to.

Every vulnerability we find goes through a structured disclosure process. Here are some of the vendors we've worked with.

Microsoft
66 findings
Adobe
19 findings
Apple
26 findings
Oracle
14 findings
Chamilo
10 findings
Google
8 findings
ASUS
6 findings
Calibre
4 findings
Singtel
2 findings
Linux Kernel
3 findings
VMware
3 findings
Cisco
1 finding
Track record

Competition-tested. Independently verified.

All achievements →
Pwn2Own Oct 2025

Pwn2Own Ireland 2025

Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software …

ResultMultiple Successful Exploits
Pwn2Own May 2025

Pwn2Own Berlin 2025: Master of Pwn

Pwn2Own is a computer hacking contest held annually by Trend Micro’s Zero Day Initiative - ZDI. Contestants are challenged to exploit widely used software …

ResultMaster of Pwn
SpiriCyber Oct 2024

SpiriCyber 2024

SpiriCyber is a Capture the Flag (CTF) competition held in Singapore, focused on offensive security and vulnerability research challenges. At SpiriCyber 2024, …

ResultCo-organiser
Work with us

Have a system you want broken before someone else does?

Drop us a line. We'll scope a pentest, red team, or code audit tailored to your stack.

Contact STAR Labs