Saturday, 08 August 2026
I’m Daniele Linguaglossa, better known as dzonerzy - an offensive security researcher and developer.
I spend my time taking systems apart until they confess: source audit, root cause, working exploit, write-up. Kernels, userspace daemons, Windows internals, embedded devices, and lately machine learning models - if it parses untrusted input, it’s in scope. Some of that work ends up on this blog; the rest ends up in coordinated disclosure.
Here is a list of the projects that I made in my spare time, some of them are still in development, but I’m looking forward to finish them all.
Collections of articles grouped under one hat.
Below you can find a list of my articles, I’m writing about offensive security and programming, and also about my projects.
PhantomLayout
- Ghost Layouts, Real SYSTEM – How a poisoned
keyboard-layout descriptor in the shared window-station IME cache became
a handle-less cross-process injection primitive (no OpenProcess, no
WriteProcessMemory, no remote threads, no hooks), and how a message-free
foreground-layout chain rode it from a medium-integrity user to SYSTEM
inside consent.exe, before the UAC prompt was even answered
#windows #ime #injection
#privesc
HeartAttACK: An
SCTP HEARTBEAT ACK Control-Queue Use-After-Free – How a
parked SCTP heartbeat reply kept a raw pointer to a transport that
ASCONF had already freed, and how I rode that 14-year-old lifetime bug
to a deterministic, race-free local root on the Ubuntu 7.0.0-28-generic
kernel - whole-slab cross-cache recycling, a verification-tag overlap
oracle, and a rewritten f_mode in struct file. No ROP, no shellcode,
KASLR untouched #kernel #linux
#sctp #uaf #privesc
Neural
Backdoors - When Your AI Has a Secret Agenda – A weekend
journey into neural network security, poisoned datasets, and why
detecting backdoors is harder than you think #ai
#neural-networks #backdoors
#iot #router #rce
#botnetBelow you can find a list of my CVEs.
Questions I get asked a lot. The short version of most answers: dzonerzy@gmail.com.
Q: How can I contact you?
A: Email me at dzonerzy@gmail.com. Research, bugs, collaboration, responsible disclosure, or just to talk shop - all welcome.
Q: What do you do for a living?
A: Offensive security research. Who signs the paycheck stays off the record - opsec is a lifestyle.
Q: Where are the PoCs?
A: Exploit code gets published once coordinated disclosure runs its course, not before. If something I wrote about affects you, the remediation section of the post is the place to start.
Q: Can I republish or translate your articles?
A: Ask first, link back, and we’ll most likely be fine.