Hi,
First mailing to Access Denied. This newsletter will cover my research releases, business launches, and upcoming events, with occasional unfiltered thoughts.
This list was consolidated from two sources: various opt-in subscriptions that I publicly shared over the years, and my business customers exported from merchant platforms. If you're here by accident - unsubscribe at the bottom.
In today's issue: keynote announcement, private launch of Zero Day Engineering Alpha Intelligence, Chrome exploit mitigations research preview.
My work is currently focused on Zero Day Engineering and exploit design: primarily R&D and theoretical modeling, then business systems (zerodayengineering.com).
As a side research, past five years I was looking at AI foundations and philosophy, complex NDS in practice of social systems, and formally studying theoretical physics - while building the ZDE brand & capability. Published a few things, which I intend to revisit and contextualize over following issues of this newsletter.
I am booked to keynote c0c0n 2026 cybersecurity conference in October, India.
c0c0n is a long-established industry event organized by Kerala police. Past editions hosted a strong lineup including government leaders, heads of banks, and founders of major technological projects. CFP and registrations are open at c0c0n.org.
I am opening early access to Zero Day Engineering Alpha Intelligence.
ZDE Alpha is a defense-oriented subscription product offering cybersecurity leaders direct access to curated threat landscape updates and expert judgement of a practicing exploit engineer.
As AI automates both security research and cybersecurity defense pipelines, it makes the landscape harder to navigate and less actionable for decision makers - not easier. It also accelerates hollow marketing, garbage and slop, among all the useful functions. Alpha solves it.
During the early access term, subscriptions are limited to 10 spots and include a 1:1 call with me. The call is intended primarily for me to ask the questions I need to improve the product.
Earlier this year I invested several weeks full-time hunting Chrome zero-days and writing exploits for VRP. I found a number of security issues across the renderer, network service, and browser process, wrote some exploits, built some tooling, and had a major disappointment with the VRP; a drama section for another issue.
I am not new to Chrome exploits. Yet I had many surprises that count as key findings of critical importance for offensive R&D.
Chrome security team moves fast on mitigating anything public and pre-empting bug classes. It also moves reasonably proactively to model threats and close them. The result is that most public knowledge - bug patterns, exploit techniques, system internals - is largely of archival interest.
Meanwhile, AI isn't great at closing the gap between obsolete published information (which is its primary knowledge base) and the actual, cutting-edge information required to find 0-days and bypass exploit mitigations. Most bugs that are marketed as "found autonomously" are known bug patterns from public knowledge, currently being eliminated aggressively by vendors with their own AI models.
Chrome exploit mitigations are harder than they look from published information, and much different in practice than what AI can tell if prompted or let loose to scout the codebase.
I am finalizing an article on the Chrome exploit mitigations I had to confront while writing the exploits. Scheduled for release Tuesday - check zerodayengineering.com/research or Twitter.
- Alisa
alisa.sh
30 May 2026