Runic Labs

Vulnerability research.
Exploit development.

We find and exploit vulnerabilities in embedded systems, userland, network services, and enterprise software.

01 / capabilities

What we investigate

01

Embedded systems

Firmware, platform services, trust boundaries, and container escape paths.

02

Userland

Linux and Windows binaries, attack surfaces, and exploit chains.

03

Network services

Protocols, exposed parsers, authentication, and service boundaries.

04

Enterprise software

Large products with complex integrations and implicit trust.

02 / field notes

Current research

All research
2026-05 Research

The QNAP Pattern

Target / QNAP QTS 5.x + bundled plugins (Notes Station 3, QmailAgent, QVPN, et al.)

Read across QTS's web layer and three first-party plugins. Looked at how authentication, IPC, plugin sandboxing, and container boundaries actually compose in practice, versus how QNAP's docs describe them.

Read the field report

03 / training

Training

Self-guided modules covering how to work through difficult targets.

View training

V8 Vulnerability Research Training

V8, Chrome's JavaScript engine

In development

04 / engagements

Engagements

Research inquiry or target

Contact Runic Labs

research@runiclabs.io