Runic Labs

exploit research & dev

What We Do

We research and exploit vulnerabilities in:

Recent Research

[2026-05] The QNAP Pattern

Target: QNAP QTS 5.x + bundled plugins (Notes Station 3, QmailAgent, QVPN, et al.)

Read across QTS's web layer and three first-party plugins. Looked at how authentication, IPC, plugin sandboxing, and container boundaries actually compose in practice, versus how QNAP's docs describe them.

Read post โ†’

View all research โ†’

Tools & Frameworks

sigil ยท modular framework for security research (coming soon)

View all tools โ†’

Engagement Model

We accept engagements for:

We do not offer:

Contact

Email: research@runiclabs.io