Blog

Blog

Research Aug 18, 2025

[Updates] Summer Pwnables 🔥

[Updates] Summer Pwnables 2025 Major Announcement: ISD Sponsorship We are pleased to announce that Internal Security Department (ISD) is sponsoring Summer …

BySTAR Labs SG
Research Jul 16, 2025

My `Blind Date` with CVE-2025-29824

In April 2025, Microsoft patched a vulnerability that had become a key component in sophisticated ransomware attack chains. CVE-2025-29824, an use-after-free …

ByOng How Chong
Research Jul 10, 2025

Fooling the Sandbox: A Chrome-atic Escape

For my internship, I was tasked by my mentor Le Qi to analyze CVE-2024-30088, a double-fetch race condition bug in the Windows Kernel Image ntoskrnl.exe. A …

ByVincent Yeo
Research May 30, 2025

Gone in 5 Seconds: How WARN_ON Stole 10 Minutes

As part of my internship at STAR Labs, I was tasked to conduct N-day analysis of CVE-2023-6241. The original PoC can be found here, along with the accompanying …

ByTan Ze Jian
Research May 28, 2025

Badge & Lanyard Challenges @ OBO 2025

Introduction We are back with Round 2 of the Off-By-One conference — where bits meet breadboards and bugs are celebrated! 🐛⚡ If you are into hardware and IoT …

ByManzel Seet & Sarah Tan