Researchers

Kinryū Labs is a small team working across space systems and advanced threat intelligence. Reports are credited to their authors individually; this page is just a bit more about who's behind the work.

Photo of Davis Zheng

Davis Zheng

Founder & Principal Researcher

Davis founded Kinryū Labs in 2025 to bring two threads of his work together publicly: large-scale threat intelligence and space-systems security. By day he tracks platform-abuse actors across millions of domains at internet scale. He's also a Cyber Specialist and veteran of the Singapore Armed Forces Digital Intelligence Service, as well as a Cyber Security Agency (CSA) Cyber Olympian, having led a team within a national 24/7 Security Operations Centre handling nation-state-level incidents. He's presented related research at cybersecurity conferences like Black Hat, most recently co-presenting threat modelling for nanosatellite on-board computers at CYSAT Asia 2026 in Singapore. And yes, that is an owl on his shoulder.

Photo of Klara Kim

Klara Kim

Co-founder & Researcher

Klara is a Cybersecurity Consultant at Deloitte Anjin, working across IT General Controls (ITGC) and Governance, Risk, and Compliance (GRC) engagements including SOC 2 and Sarbanes-Oxley (SOX). Her research focuses on systems that interact with the physical world - from Internet of Things (IoT) devices and commercial robots to satellite systems - with a particular interest in threat modeling, embedded systems, and operational security risks.

She has contributed to and published research on Advanced Persistent Threat (APT) group profiling with the Institute of Electronics, Information and Communication Engineers (IEICE), and has presented research on robotics and satellite security at the Network and Distributed System Security Symposium (NDSS) and DefCamp. As a Best of the Best (BoB) alumna, she also served as editor-in-chief of the BoB security newsletter, leading security content planning and editorial work. Her long-term dream is to make it to Mars; until then, she is staying busy on Earth with cybersecurity, space-systems security, and emerging technology risk - quietly waiting for the call from SpaceX.

Photo of Donavan Cheah

Donavan Cheah

Co-founder & Researcher

Donavan has ten years of experience in cybersecurity consultancy, beginning his career as a penetration tester, and has since traversed multiple security domains including threat modeling, risk and maturity assessments, and cyber policy.

Donavan is an accomplished speaker, with prior talks at conferences in Europe and Asia including DefCamp (Romania), SECCON (Japan), DEFCON SG and SINCON (Singapore). He has also given threat modeling training at Forum of Incident Response and Security Teams (FIRST) Central Asia (Uzbekistan), SeaSides @ Goa (India) as well as Global Cybersecurity Camp. Donavan is a thought leader on several cybersecurity topics through his contributions to the Information Systems Audit and Control Association (ISACA) as a member of the ISACA Emerging Trends Working Group since 2025, as well as a writer on InfoSecurity Magazine.

Donavan sits on the advisory board of VULNCON since 2024, and currently co-organises OASec, an artificial intelligence security conference based in Singapore. He also co-leads the Threat Modeling Connect Singapore chapter to build a community of practice surrounding threat modeling in the Asia-Pacific region. More details at donavan.sg.

Photo of Yi Ting Shen

Yi Ting Shen

Co-founder & Researcher

Yi Ting is an Artificial Intelligence (AI) Security Researcher specializing in the security assessment of AI systems, vulnerability research, and the development of AI-driven security solutions. Her work focuses on identifying security weaknesses in emerging AI technologies, evaluating the resilience of AI applications, and leveraging AI to address complex cybersecurity challenges.

Since 2022, she has presented cybersecurity research at more than 20 international and regional conferences across multiple countries, including Black Hat SecTor, DEF CON Asia, ROOTCON, and BSides Tokyo. Her research spans offensive security, AI security, vulnerability discovery, and the practical application of artificial intelligence and machine learning (AI/ML) technologies in cybersecurity.

She actively conducts vulnerability assessments and security testing across a wide range of platforms, and has identified and responsibly disclosed security vulnerabilities affecting organisations including Google, Cloudflare, educational institutions, and numerous open-source projects.

Collaborators

Researchers and practitioners who have collaborated with Kinryū Labs on joint projects, talks, or published work.

Photo of Yoon Yik

Yoon Yik

Researcher & Collaborator

Incoming Master's student in Information Security Policy and Management at Carnegie Mellon University. He works across digital forensics and incident response, operational technology security, threat intelligence, and threat modelling. He co-founded and co-leads the Threat Modeling Connect Singapore Chapter, founded the Nanyang Technological University cybersecurity community and its Capture-the-Flag team NUT Flaggers, and serves as Crew at Division Zero. He has presented and run workshops at the Forum of Incident Response and Security Teams (FIRST), DEF CON Singapore, Black Hat Asia, and SINCON.

Talks & appearances

Davis Zheng presenting Cyber Threat Intelligence at NUS Friday Hacks

NUS Friday Hacks · Singapore · 14 March 2025

Cyber Threat Intelligence: Introduction and Deep Dive

An introductory session for NUS Hackers breaking down the fundamentals of cyber threat intelligence (CTI): how intelligence is gathered, analysed, and used to detect and mitigate cyber threats. The talk covered the key skills, tools, and strategies for navigating the CTI landscape - from beginner footing through to specialisation - including practical advice on breaking into a field typically reserved for intelligence analysts.

Presented by Davis Zheng.

Klara Kim and Donavan Cheah presenting at DefCamp 2025, Bucharest

DefCamp 2025 · Bucharest, Romania

Threat Assessment and Remediation Analysis for Nanosatellite On-Board Computers

Presented at one of Europe's largest cybersecurity conferences, held at the Palace of the Parliament in Bucharest. The talk covered a structured threat modelling approach for nanosatellite on-board computers, combining MITRE EMB3D's hardware-aware taxonomy with TARA's mission-critical risk assessment methodology. The session examined how pre-launch design oversights - exposed debug ports, legacy codebases, insecure communications - translate into exploitable attack surfaces post-launch, and made the case for defense-by-design as a non-optional baseline for space systems.

Presented by Klara Kim and Donavan Cheah.

Davis Zheng and co-presenter at CYSAT Asia 2026, Singapore

CYSAT Asia 2026 · Singapore

Securing Space: Threat Assessment and Remediation Analysis for Nanosatellite On-Board Computers

A custom threat model for CubeSat on-board computers, addressing the gap in existing cybersecurity frameworks that don't account for the operational realities of space systems: limited compute, long mission lifecycles, and constrained patching capabilities. Developed following consultations with satellite developers and operators in Singapore and internationally.

Presented by Davis Zheng and Donavan Cheah.