hi_im_d4rkn3ss Profile Banner
Thach Nguyen Hoang πŸ‡»πŸ‡³ Profile
Thach Nguyen Hoang πŸ‡»πŸ‡³

@hi_im_d4rkn3ss

Followers
3K
Following
3K
Media
1
Statuses
889

Security Researcher @starlabs_sg. Pwn2Own Mobile 2020, 2021, 2022, 2023. Pwn2Own Vancouver 2022, 2023, 2024, 2025.

Joined March 2019
Don't wanna be here? Send us removal request.
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
3 months
This year had two ESXi attempts, and I was lucky to go first. I was nervous, but unlike last year, everything went well. Huge thanks to the ZDI team for the setup support, and to my friends and colleagues for the moral boost πŸ™.
@thezdi
Trend Zero Day Initiative
3 months
Oh my! In a #Pwn2Own first, Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG was able to go from guest to host on #VMware ESXi. Amazing work. He's off to the disclosure room to provide the details. #P2OBerlin
Tweet media one
20
9
191
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
13 days
RT @opzero_en: 101 Chrome Exploitation β€” Part 0: Preface . We are starting a new series on modern browsers' architecture and their exploita….
0
70
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
1 month
RT @xvonfers: A toolkit to turn Chromium vulnerabilities into full-chain exploits. From BSidesLuxembourg 2025."Brow….
0
46
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
3 months
RT @scwuaptx: Thrilled to share our latest deep dive into Windows Kernel Streaming!.Just presented this research at @offensive_con. Check….
Tweet card summary image
devco.re
In-depth research into Windows Kernel Streaming vulnerabilities, revealing MDL misuse, buffer misalignment, and exploitation techniques used in CVE-2024-38238 and others.
0
82
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
3 months
0
12
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
4 months
RT @kind_k11rwhale: Part 2 of the Fuzzilli IR series explores Opcodes.swift, Operation.swift, Program.swift, and Variable.swift. With the g….
rpc.kr
A deep dive into the core IR components of Fuzzilli, focusing on Opcodes.swift, Operation.swift, Program.swift, Variable.swift. This post is the second in the series exploring the IR internal...
0
14
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
4 months
RT @kind_k11rwhale: A deep dive into the core IR components of Fuzzilli, focusing on Analyzer.swift, Blocks.swift, and Context.swift. This….
rpc.kr
A deep dive into the core IR components of Fuzzilli, focusing on Analyzer.swift, Blocks.swift, and Context.swift. This post kicks off a series exploring the internal structure of Fuzzilli's IR.
0
27
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
4 months
RT @xvonfers: [$20000](CVE-2024-12693)[382190919][maglev]Array OOB access in the maglev phi untaggingoptimization is now open with PoC: .ht….
0
10
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
6 months
RT @0x10n: The most elegant V8 Wasm Turboshaft typer exploit that I've reported. This primitive converts **any** Wasm type confusion in **a….
0
42
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
7 months
RT @starlabs_sg: Think you’ve got what it takes to pop shells and snag your ticket to. @REverseConf and @offbyoneconf ? 😏..
0
44
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
7 months
RT @starlabs_sg: πŸŽ„ All I Want for Christmas is a CVE-2024-30085 Exploit πŸŽ„.As always, we at @starlabs_sg are sharing what we learnt. This ti….
Tweet card summary image
starlabs.sg
TLDR CVE-2024-30085 is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini Filter Driver cldflt.sys. By crafting a custom reparse point, it is possible to trigger the...
0
49
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
8 months
RT @alexjplaskett: Pwning a Brother labelmaker, for fun and interop! by sdomi.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
21
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
8 months
RT @eternalsakura13: My first V8 sandbox bypass vulnerability has been fixed, and I will continue to discover more.
0
40
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
9 months
RT @POC_Crew: #POC2024.Nguyα»…n HoΓ ng ThαΊ‘ch(@hi_im_d4rkn3ss) - VMware Workstation: Escaping via a New Route - Virtual Bluetooth πŸ˜† https://t.c….
0
10
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
10 months
RT @DimitriFourny: My V8 vulnerability CVE-2019-5790 is now public (Heap buffer overflow in the V8 language parser)
0
79
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
10 months
RT @zerodaylinks: [Browser Exploitation] Insightful little analysis of v8 CVE-2024-7965: .PoC: .
Tweet card summary image
github.com
This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64. - bi-zone/CVE-2024-7965
0
32
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
10 months
RT @samwcyo: New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed a….
0
998
0
@hi_im_d4rkn3ss
Thach Nguyen Hoang πŸ‡»πŸ‡³
11 months
RT @Steph3nSims: Fuzzing from First Principles with Alisa Esage
0
61
0