whoami
I'm Kamdin Bembry, undergrad at Rochester Institute of Technology. I do VR and SecEng.
About Me
I'm interested in understanding core systems functionality and leveraging that for exploitation. My research focuses on:
- Compiler Security: LLVM codegen, optimization mechanisms, and MCA
- Browser Exploitation: V8 JS engine research and exploitation
- Kernel & OS Security: Custom operating systems and fuzzing
- Microarchitecture: Cache optimization and branch predictors
Education
- Rochester Institute of Technology (Graduating: Dec 2027)
- B.S., Individualized Study: Security Engineering and Research
- Korea University (Aug 2026 - Dec 2026)
- Study Abroad: College of Informatics
Work Experience
- Browser Security Researcher @ Dataflow Security (May 2026 – Present)
- Security Researcher @ Zellic (Jan 2026 – Present)
- Red Teamer @ Gray Swan (Jan 2026 – Present)
- Penetration Tester @ Coalfire (May 2025 – Aug 2025)
Research & Projects
- VRIG Lead (Aug 2024 – Present)
- Co-lead student security research group specializing in low-level exploitation, vulnerability analysis, and reverse engineering
- Led projects on custom OS development, custom allocator development, heap exploitation, and JavaScript browser engine research
- Zialloc: High-Performance Memory Allocator (Jan 2026 – Mar 2026)
- Engineered a production-inspired C++ memory allocator using segregated size classes, bitmap allocation, virtual-memory-backed heap organization, deferred-free rings, and thread-local caches, informed by the design tradeoffs of PartitionAlloc, mimalloc, libmalloc, and TCMalloc.
- V8 Quarterly Quiz (Feb 2025 – June 2025)
- Completed pwn.college V8 Quarterly Quiz (Username: ziarashid)
- Explored V8 compiler architecture, TurboFan's sea of nodes, feedback vectors, and V8 sandbox internals
- Compiler & Browser Research (Nov 2024 – Present)
- Implemented custom programming language with LLVM backend; studied LLVM IR creation and optimization mechanisms
- Experimented with Google's V8 JavaScript engine for exploitation research
- Kernel and OS for Fuzzing & Vulnerability Research (Aug 2024 – Dec 2024)
- Built minimalistic operating system and custom kernel for fuzz testing with LibAFL's QEMU mode
- Focused on hypervisor security and guest-to-host escape detection
CTF Competitions
Member of Squid Proxy Lovers and SDCL
| Competition | Team | Rank |
|---|---|---|
| DEF CON Quals 2026 | SuperDiceCodeLovers | 1st Place |
| CSAW Finals 2025 | Squid Proxy Lovers | 1st Place |
| DEF CON Finals 2025 | SuperDiceCode | 3rd Place |
| Google CTF 2025 | Squid Proxy Lovers | 3rd Place |
| Plaid CTF 2025 | Squid Proxy Lovers | 2nd Place |
Skills
- Languages & Architectures: C++, Golang, LLVM IR, Python, JavaScript, Swift, x86_64, MIPS, ARM
- Tools: LLVM-mca, Z3, CodeQL, AFL++, pwntools, Flamegraph, IDA, Burp Suite, pwndbg
- Security Research: Vulnerability research, penetration testing, reverse engineering, fuzzing
- Compiler Security: LLVM optimizations, instruction selection, Machine Code Analysis
- Browser Exploitation: V8 engine internals, sandbox bypass techniques, JavaScript exploitation
Personal Interests
In my free time I enjoy learning japanese & korean, backpacking the world, snowboarding, grappling, hacky sacking, archery, spirited driving, and reading novels.
Contact & Links
- Email: kamdinomaribembry@gmail.com
- GitHub: https://github.com/Zia-Rashid
- Twitter: @Zia__Rashid
- LinkedIn: linkedin.com/in/kamdin-bembry
- Resume: Download Resume (PDF)
This website showcases my research, projects, and experiences. Feel free to contact me on discord @ziarashid.