STAR Labs
STAR Labs is a Singapore-based offensive security firm that delivers penetration testing, red teaming, vulnerability research, source code audits, training, and CISO advisory. It is staffed by Pwn2Own-winning researchers who have disclosed 150+ vulnerabilities to major vendors.
- Company typePrivate
- Founded2018
- HeadquartersSingapore, Singapore
- Headcount11–50
- GTM typeB2B
- OfferingServices
What STAR Labs does
STAR Labs SG Pte. Ltd. is a Singapore-based offensive security firm (founded 2018, 11–50 employees) that delivers attacker-grade cybersecurity services to enterprise clients, primarily software vendors and security teams across Asia. The company's core offerings are professional services rather than packaged software: licensed penetration testing (under Singapore licence CS/PTS/C-2022-0106), red teaming, targeted vulnerability research, source code audits, hands-on offensive security training, and CISO advisory/consulting. Engagements are scoped and quoted per project, with direct sales motion through [email protected] and inbound generated from public research output.
The firm is differentiated by the fact that the same researchers who deliver client work actively compete at Pwn2Own and publish zero-day vulnerabilities. STAR Labs won Master of Pwn at Pwn2Own Berlin 2025 and took 2nd Place at Berlin 2026, the first researcher to successfully exploit VMware ESXi in Pwn2Own history. Proprietary tooling includes KidFuzzerV2.0 (a grammar-aware coverage-guided fuzzing framework for Apple kernel/userspace), GPUAF (GPU attack-surface research against Qualcomm Android devices), and an LXD-group privilege escalation exploit. The team has responsibly disclosed over 150 findings to vendors including Microsoft (66), Apple (26), Adobe (19), Oracle (14), and Google (8), and has begun targeting AI/LLM infrastructure (LiteLLM, LM Studio, NVIDIA Megatron Bridge) — indicating a deliberate expansion of research surface into emerging technology stacks.
STAR Labs monetizes exclusively through professional services, with no software product, API, or platform. Revenue streams are pentesting/red teaming commissions, source code and vulnerability research retainers, training course delivery, and advisory consulting. The company is privately held with no disclosed institutional funding, appears founder/team-owned, and concentrates operations from a single Singapore headquarters while serving an enterprise client base that extends regionally across Asia and globally through vendor disclosure relationships.
STAR Labs firmographics
Firmographics- Name
- STAR Labs
- Legal name
- STAR Labs SG Pte. Ltd.
- Website
- https://starlabs.sg
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- STAR Labs is a Singapore-based offensive security firm that delivers penetration testing, red teaming, vulnerability research, source code audits, training, and CISO advisory. It is staffed by Pwn2Own-winning researchers who have disclosed 150+ vulnerabilities to major vendors.
- Ownership category
- akta.pro rank
STAR Labs industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Scientific and Technical Consulting Services (54169), Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
- akta.pro secondary industries
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK), Confidential Computing & Hardware-backed Protection (TEE/HSM) (HDADAFAJ)
Keywords
Where STAR Labs is headquartered
LocationHeadquarters
- HQ city
- Singapore
- HQ country
- Singapore
- HQ region
- Asia
Offices1 record
Markets served
STAR Labs business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Professional Security Services: STAR Labs generates revenue through commissioned offensive security engagements including penetration testing, red teaming, vulnerability research, and source code audits. Services are licensed and scoped per engagement. The company holds a pentesting license in Singapore (CS/PTS/C-2022-0106).
- Training: Hands-on offensive-security training delivered by researchers with real exploit chains, for blue teams, developers, and researchers-in-training. Revenue is generated through training course delivery.
- Advisory & Consulting: Strategic guidance for CISOs and product teams on secure-by-design, SDLC, and incident response, billed as consulting engagements.
Go-to-market motion2 records
Distribution channels1 record
Marketing channels6 records
STAR Labs product offering
Product offeringCore offering
STAR Labs is a Singapore-based offensive security firm that delivers professional cybersecurity services including licensed penetration testing, red teaming, vulnerability research, source code audits, hands-on offensive security training, and advisory/consulting engagements. Services are scoped and quoted per engagement and delivered by researchers who actively compete at Pwn2Own and have published 150+ vulnerability findings across Microsoft, Apple, Google, Adobe, Oracle, Linux Kernel, VMware, and Cisco. The company holds a Singapore pentesting license (CS/PTS/C-2022-0106) and operates from Singapore, serving enterprise software vendors and security teams.
Product overview
STAR Labs is a Singapore-based offensive security firm that offers a portfolio of professional security services rather than a software product. The core offerings include Penetration Testing (licensed in Singapore under CS/PTS/C-2022-0106), Red Teaming, Vulnerability Research, Source Code Audits, Training, and Advisory & Consulting services. These services are delivered by the same researchers who discover 0-day vulnerabilities and compete in Pwn2Own competitions, ensuring that clients receive expert-level security testing and guidance.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing
Quantifiable outcome
- Over 150 vulnerability findings disclosed to major vendors including Microsoft (66), Apple (26), Adobe (19), Oracle (14), Google (8), and others
- +2 more outcomes
Companies that use STAR Labs
Customer profileNamed customers9 records
Segments3 records
Ideal customer profiles3 records
STAR Labs technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
STAR Labs partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core.
- MicrosoftcoreSTAR Labs has a structured responsible disclosure relationship with Microsoft, having reported 66 vulnerability findings across Microsoft products. The company also collaborated with Microsoft's security team as part of the Pwn2Own ecosystem facilitated by Trend Micro's Zero Day Initiative.
- Applecore26 vulnerability findings disclosed to Apple through responsible disclosure, including research on iOS, macOS, kernel, and fuzzing. STAR Labs researchers have presented Apple-related research at Offensivecon 2023.
- Googlecore8 vulnerability findings disclosed to Google. Research on Android and Pixel devices has been presented at CODE BLUE 2025 and HITCON 2025.
- Adobecore19 vulnerability findings disclosed to Adobe, including research on Adobe Acrobat and Reader vulnerabilities (CVE-2026-34621, CVE-2026-34622, CVE-2026-34626) analyzed and published by STAR Labs in April 2026.
- Oraclecore14 vulnerability findings disclosed to Oracle through responsible disclosure.
- VMware (Broadcom)coreVMware vulnerabilities found and disclosed; successfully exploited VMware ESXi at Pwn2Own Berlin 2025 (first in Pwn2Own history) and Pwn2Own Berlin 2026 (cross-tenant code execution). Also VirtualBox exploited at Berlin 2025.
- CiscocoreCVE-2026-20147 (Cisco ISE authenticated command injection RCE, CVSS 9.1) discovered independently and disclosed to Cisco PSIRT in May 2026. Additional vulnerability findings in Cisco products.
- Linux Kernelcore3 Linux kernel vulnerability findings disclosed, including CVE-2025-39682 (net/tls use-after-free privilege escalation, CVSS 7.1) reported to the Linux kernel security team in August 2025.
- Apache Software FoundationcoreCVE-2026-41873 (Apache Pony Mail CRLF injection and SSRF leading to full account takeover, CVSS 9.1) discovered and disclosed to Apache Security Team, with initial report sent July 2024 and public disclosure April 2026.
- Trend Micro Zero Day Initiative (ZDI)coreSTAR Labs participates in Pwn2Own competitions organized by Trend Micro's Zero Day Initiative, competing in Berlin 2025, Ireland 2025, and Berlin 2026. ZDI operates the contest through which STAR Labs' research is validated and publicized.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
STAR Labs competitors and assessment
Company assessmentDirect peers
- Trail of Bits:
- NCC Group: UK-listed offensive security and software resilience firm offering penetration testing, red teaming, and vulnerability research. NCC Group's NCC Group Domain Services and nccgroup.com research teams are a direct, larger-scale competitor to STAR Labs' pentesting and zero-day research practice.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks7 records
Key highlights7 records
Customer concentration
STAR Labs social profiles
Digital presenceSTAR Labs financial estimates
Financial estimateRevenue estimate
Valuation estimate
STAR Labs leadership team
Management profileNumber of profiles
Profiles10 records
STAR Labs funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
STAR Labs M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about STAR Labs
What does STAR Labs do?
STAR Labs is a Singapore-based offensive security firm that delivers professional cybersecurity services including licensed penetration testing, red teaming, vulnerability research, source code audits, hands-on offensive security training, and advisory/consulting engagements. Services are scoped and quoted per engagement and delivered by researchers who actively compete at Pwn2Own and have published 150+ vulnerability findings across Microsoft, Apple, Google, Adobe, Oracle, Linux Kernel, VMware, and Cisco. The company holds a Singapore pentesting license (CS/PTS/C-2022-0106) and operates from Singapore, serving enterprise software vendors and security teams.
Is STAR Labs a public or private company?
STAR Labs is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was STAR Labs founded?
STAR Labs was founded in 2018. It employs 11 to 50 people.
Where is STAR Labs based?
STAR Labs is headquartered in Singapore, Singapore, in the Asia region.
How does STAR Labs make money?
Three revenue lines are on record. Professional Security Services are the primary driver. The others are training and advisory & Consulting.
Who are STAR Labs's main competitors?
Direct peers on record are Trail of Bits and NCC Group.
Does STAR Labs have an API?
No public API is recorded for STAR Labs.
What industry is STAR Labs in?
STAR Labs's product category is Cybersecurity Services. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking, with a secondary code of HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms. Its NAICS code is 54169 and its SIC code is 8734.