Nadi Labs · Vulnerability DivisionSecurity Division · Nadicorp Ltd

Striking at the Root. Hardening the Foundation.

Nadi Labs is the dedicated systems, binary exploitation, and vulnerability research laboratory operating within Nadicorp Ltd, directed by founder and lead security researcher Yahya Toubali. We discover zero-day flaws in operating system kernels, browser JIT compilers, and low-level protocols.

Disclosed CVEs

0

Coordinated Disclosures

Operating Division

Nadi Labs

Under Nadicorp Ltd

Core Targets

Kernel / JIT

Linux · V8 · Protocols

Fuzzing Engine

CrashWise

Rust & LibAFL Engine

Technical Publications

Security Advisories & Exploitation Whitepapers

Peer-reviewed technical analyses, root-cause dissections, and full reproduction methodologies produced by Nadi Labs researchers.

Coordinated Vulnerability Disclosure in Progress

Research Advisories & Whitepapers Coming Soon

Nadi Labs researchers are currently coordinating vulnerability remediation with upstream maintainers. Full exploitation writeups, memory diagrams, root-cause dissections, and Proof of Concepts will be published here upon patch release.

Research Methodology

Systematic Discovery. Adversarial Rigor.

How Nadi Labs investigates the attack surfaces of modern operating systems, hypervisors, and compiler engines.

Kernel & Hypervisors

Deep inspection of Linux kernel subsystems (io_uring, eBPF, network stack, SLUB memory management), virtual machine escape primitives, and hardware privilege boundaries.

Browser Engines & JIT

Targeted exploitation of speculative compiler optimizations, Sea-of-Nodes IR representations, type confusion vulnerabilities, and WebAssembly execution sandboxes.

Autonomous Fuzzing

Leveraging CrashWise (pure Rust LibAFL engine) to instrument continuous in-process fuzzing campaigns, deterministic Tree-sitter AST mining, ASan crash triage, and automated 5-stage patch verification.

Responsible Disclosure

Coordinated Vulnerability Disclosure & PGP Key

Nadi Labs strictly adheres to a 90-day coordinated disclosure policy with software vendors. Read our policy guidelines or send encrypted security inquiries to our researchers.