About

Kinryū Labs is a research group working in two areas that overlap more every year: space-systems security and cyber threat intelligence. We find vulnerabilities, run honeypot networks, and track threat actors, coordinating disclosure with the organisations affected and publishing what we find once it's done and cleared for release.

What we do

Our work spans three areas that increasingly overlap.

  • Space-systems security We find and responsibly disclose vulnerabilities in space-systems infrastructure.
  • Honeypot networks We run honeypot networks to collect and analyse real adversary behaviour.
  • Threat intelligence We track the actors, tooling, and campaigns behind significant threats.

Whatever we can responsibly publish ends up here as a writeup.

What we publish, and what we don't

  • What we publish Technical, sourced writeups for researchers, vendors, and conference peers: findings on infrastructure, tooling, vulnerabilities, and the groups behind them, with enough detail to be useful and nothing that shouldn't be public.
  • What we don't publish Anything under embargo, anything that would put a disclosure at risk, and anything with client data, credentials, or unredacted proof-of-concept material. Not as drafts, not in private branches. If we can't publish it responsibly, we don't.

Contact

Email [email protected]

What to write to us about

  • Coordinated disclosure You're a vendor or organisation we've contacted about a finding, or a researcher coordinating with us.
  • Corrections You've spotted an error, an outdated detail, or something that needs a follow-up in a published writeup.
  • Collaboration You're working on something adjacent in space systems or threat intelligence and think there's overlap worth exploring.
  • Tips You've come across something relevant to what we cover and think it's worth a look.

Reporting a vulnerability?

To help us triage quickly, your first message can include:

  • The affected product, vendor, and version(s)
  • A short description of the issue and its likely impact
  • Reproduction steps or a proof of concept (redacted, if it's sensitive)
  • Your preferred disclosure timeline, and whether you'd like public credit

We follow a coordinated-disclosure approach: we won't publish anything about an issue until it's been addressed, or a reasonable timeline has passed without a response. See what we don't publish above, and the disclosure policy in the FAQ below.

Before you send anything sensitive

Plain email isn't a secure channel. Please don't send embargoed details, unredacted proof-of-concept material, credentials, or anything else that needs to stay confidential in the initial message - reach out first and we'll figure out a safer way to handle specifics.

Encrypted contact

For sensitive disclosures, you can encrypt your message to our PGP key:

PGP fingerprint 2CFD 8B35 6E98 D2DF 10D6 880F 3DB3 A396 39F9 8F45

Download the public key

Response times

Kinryū Labs is a small group publishing on an irregular cadence, so replies won't always be fast - but we do read everything that comes in. If something is time-sensitive (a disclosure deadline, an embargo date), say so up front and we'll prioritise accordingly.

Frequently asked

What's your disclosure policy?

We work to coordinated disclosure. When we report a finding, the terms we propose are 90 days from the date we notify you, or until the issue is fixed, whichever comes first. If you'd like to go public sooner and the fix is in place, we'll agree to as little as 30 days. We treat 180 days as the outer limit before we'd consider publishing regardless. A vendor going quiet doesn't trigger automatic publication - disclosing into silence tends to cause more harm than a fix, so we weigh each case on its own.

How do you make first contact about a finding?

Our first message says three things only: what the issue is, its class, and its likely impact. We don't include exploitation detail or a proof of concept unless you reply and ask for it. We verify we're reaching the right people before sharing anything further. Alongside the operator or data controller, we'll usually notify the relevant national CERT or CSIRT, and - where there's a clear data-protection nexus - the appropriate authority. We don't tell you who else you should report to.

What does your research actually involve?

Scoping, and nothing past it. We do read-only enumeration and bounded sampling to confirm and describe an exposure. We don't exfiltrate, modify, or retain data, and we stay well clear of anything that reads as active, unauthorised penetration testing. Enumerating an exposure to document it is fair game; probing it for exploitability beyond that isn't. Where an organisation publishes a vulnerability disclosure policy, we follow it - that's the clearest signal of a channel that's safe to use.

What goes into a published report, and what stays out?

Our reports are factual and proportionate. We redact personal data, refer to field names rather than their values, and use exact counts rather than round numbers. We mark findings under the Traffic Light Protocol to control how they're shared, and some are sensitive enough that we don't publish them at all. If we can't put something out responsibly, it stays off the site.

Do you take on paid engagements?

Yes. We also publish independent public research on our own schedule, and that's what this site is for - the writeups here are ours to make, driven by what we find rather than by a client brief.

Can I stay anonymous when reporting something?

Yes. Tell us how you'd like to be credited - by name, by handle, or not at all - and we'll go with that. A throwaway address works fine for first contact if you'd rather not use your everyday inbox.

How long until I hear back?

We read everything, but replies aren't always quick - see "Response times" above. Flagging anything time-sensitive up front helps us prioritise it.

Do you take on research collaborations?

Often, yes - particularly where it overlaps with space-systems security or threat intelligence. Send a short outline of what you have in mind and we'll take it from there.