Oleg Lazari

vulnerability research / reverse engineering / exploit dev

I break software and figure out why it broke: writing fuzzers, triaging crashes, building exploits. Mostly userland memory corruption, kernel stuff, and mobile targets right now.

I co-lead the RITSEC Vulnerability Research Interest Group, where I mentor ~7 students on modern mitigations (PAC, MTE) and how to beat them. We're currently trying to fuzz XNU, which is going about as well as you'd expect.

BS Cybersecurity at RIT. Class of 2027. Glen Burnie, MD.

70 72 6f 62 65 2e 20 62 72 65 61 6b 2e 20 70 72  |probe. break. pr|
6f 76 65 2e 0a 00 00 00 00 00 00 00 00 00 00 00  |ove..............|
vulnerabilities
CVE-2026-30409

Out-of-bounds read in bitmap serialization

Integer underflow in bitmap serialization -> OOB read. Structure-aware LibFuzzer harnesses at 90%+ code coverage. Coordinated disclosure.

DjVuLibre

Heap buffer overflow & use-after-free chain

Both RCE-class. Resource-constrained coverage-guided fuzzing. 90-day coordinated disclosure.

Linux / ksmbd

In-kernel SMB server memory-safety bugs

Heap over-reads and UAF writes. Custom syzkaller definitions + agentic source analysis.

research
V8

Chrome / V8 n-day exploit chains

Three published writeups + fully reliable PoC chains: CVE-2023-4068 (WASM/JS null type confusion), CVE-2025-5419 (ITW StoreStoreElimination), CVE-2025-5959 (Wasm type canonicalization + MurmurHash64A birthday attack). Type confusion -> sandbox escape -> code exec. Reversed TurboFan/Maglev pipelines, GC behavior, JSPI stack switching.

FuzzillAI

Distributed, adaptive fuzzing framework

10+ node distributed fuzzer, PostgreSQL-backed corpus sync. Thompson Sampling for mutator selection: ~35% faster coverage growth vs static weights. Coverage plateau detection with ML-based corpus generation. Turned up undocumented V8 JIT optimization flaws.

PythonC/C++FuzzilliPostgreSQLLibFuzzer
RE tooling

Headless Ghidra pipeline

Automated RE pipeline on headless Ghidra with LLaMA-based function signature recovery. Ran it on 4 ICS firmware images (Cisco IOS, Digi Transport, Phoenix Contact), cut manual analysis 70%.

eBPF

Kernel stealth/persistence tooling

eBPF-based process hiding via bpf_probe_read hook interception and syscall table manipulation. Built to study stealth/persistence techniques and inform defensive detection.

CTF design

Challenge design

Designed 5 challenges across 4 categories. Grounded in current papers (ePrint 2025/376, Tree Borrows PLDI 2025, Bourefis et al. MobiSec 2024): chained CSIDH-512 oracle attacks, Kipnis-Shamir UOV key recovery, Intel TSX anti-debugging RE, SDR/FHSS protocol RE, deterministic Rust+C CFI bypass.

tools
current / upcoming
Custom KoTH protocol

Details TBD ;)

VRIG XNU fuzzer

Also secret.

CTF Architect

Expect custom challenges :3

writing