Tyler Zars

Vulnerability Researcher & Reverse Engineer ยท tyler@zars.me

As a vulnerability researcher and reverse engineer, I specialize in discovering and analyzing security weaknesses in software and hardware systems. My work involves extensive reverse engineering across multiple architectures and the development of proof-of-concept exploits to demonstrate security issues.

I have experience with responsible vulnerability disclosure and have contributed to improving the security of various open-source projects. My research has resulted in CVE assignments and coordinated fixes with development teams and security organizations.

In addition to security research, I maintain expertise in system automation, broadcast engineering, and live event production, bringing a diverse technical background to complex security challenges.

Find me online

Public Security Research

Vulnerability research and responsible disclosure of security issues in open-source projects.

CVE-2025-54472: Denial of Service in Apache bRPC

CVE

Discovered an unauthenticated denial of service vulnerability in Apache bRPC that could allow attackers to crash the service using a crafted Redis message.

Apache bRPC DoS C++

One Byte Stack Overflow in NMAP

Fixed

Remotely triggerable one-byte stack buffer overflow in Nmap FTP parsers when scanning a malicious server.

Nmap Stack Overflow C

Arbitrary File Upload Vulnerability

Fixed

Discovered an arbitrary file upload vulnerability in simple-http-server that could allow attackers to upload malicious files. Coordinated with the maintainer for a security release.

HTTP Server File Upload Rust

Authenticated Remote Code Execution

Research

Research project demonstrating authenticated remote code execution vulnerabilities. Developed proof-of-concept and documentation for security awareness and testing purposes.

RCE IoT Firmware

ZDI-CAN-28221

Pending Release

Vulnerability research currently under responsible disclosure through Zero Day Initiative.

Details will be published upon vendor patch release
CVE Pending ZDI

ZDI-CAN-27329

Pending Release

Vulnerability research currently under responsible disclosure through Zero Day Initiative.

Details will be published upon vendor patch release
CVE Pending ZDI

ZDI-CAN-26889

Pending Release

Vulnerability research currently under responsible disclosure through Zero Day Initiative.

Details will be published upon vendor patch release
CVE Pending ZDI

Responsible Disclosure

All vulnerabilities were reported through proper channels and coordinated disclosure processes. I believe in working with maintainers and security teams to improve software security for everyone.

Featured Projects

Awesome VR/RE Writeups

A curated list of vulnerability research and reverse engineering writeups, resources, and learning materials for security researchers.

Security Research Reverse Engineering Educational

Space Heroes 2023 CTF Problems

Created challenges for a Capture the Flag competition covering web security, reverse engineering, forensics, and cryptography.

Security CTF Education

Typing Test Game

A typing test game implemented in x86 assembly language using the Irvine library.

Assembly x86 Games

Latency Test Docker for InfluxDB

A Docker container for running a latency test and reporting to InfluxDB and Grafana.

Docker Monitoring DevOps

InControl2 Configuration Downloader

A Python script for downloading configuration files from Peplink InControl2 devices.

Python Networking Automation

Scribd Notifier

Automated notification system for monitoring Scribd content and updates.

Python Automation API

FlightRadar24 API

Rust API wrapper for FlightRadar24 data access and flight tracking functionality.

Rust API Aviation

Experience

Vulnerability Researcher & Reverse Engineer

Cromulence LLC

Research software and hardware systems to identify security vulnerabilities. Conduct reverse engineering analysis and develop security assessments for various platforms and architectures.

  • Reverse engineering and vulnerability research across multiple architectures
  • Development of security analysis tools and methodologies
  • Documentation and reporting of research findings
  • Collaboration with team members on security assessments
2023 - Present

Broadcast Engineer & Software Developer

Ross Production Services

Working for two and a half years developing, testing, debugging, and managing multiple installation and upkeep scripts. Writing technical documentation for code projects and setup procedures for both internal and external recipients. Solving problems across a wide range of technical issues and assisting in managing cloud solutions for remote live video production.

  • Developed automated installation and maintenance scripts
  • Created comprehensive technical documentation
  • Managed cloud infrastructure for live video production
  • Provided technical support across diverse problem domains
2021 - 2023

Security Researcher & Developer

Contact me for my full resume.

2019 - Present

Skills

Programming & Development
  • Python Development & Automation
  • C Development
  • Rust Development
  • Bash Scripting
  • Version Control with Git
  • Cross-Platform Development
Security Research
  • Vulnerability Research & Responsible Disclosure
  • Static & Dynamic Code Analysis
  • Penetration Testing & Security Assessment
  • CVE Coordination & Documentation
System Administration
  • Linux & Unix-based Systems
  • macOS System Configuration
  • Windows 10 Administration
  • Device Imaging & Deployment
Broadcast Engineering
  • Live Event Production
  • eSports & Gaming Broadcasts
  • Audio Visual Setup & Management
  • Broadcasting Hardware & Software

Education

Florida Institute of Technology

Bachelor of Science - Computer Science

3.91 GPA

Relevant coursework: Cybersecurity, Assembly Language, Networking, Programming Language Concepts, Big Data, Systems Programming.

2019 - 2023

Eagle Scout

Boy Scouts of America
Vigil Honor - Order of the Arrow
2017

Get In Touch

Want to collaborate on a project or just say hello? Feel free to reach out through any of these platforms.

Blog

Check out my latest posts at tylzars.github.io

Visit Party Parrot memorial!