I'm Diego Palacios (DiegoAltF4), a security researcher based in Madrid, Spain, focused on low-level vulnerability research and exploit development, with a particular obsession: hypervisors.

By day I work as a Cyber Risk & Security Engineer at WTW; by night, I try to escape virtual machines.

A snapshot of my profile is below.
Feel free to reach out at diegoaltf4 [at] protonmail [dot] com.

Experience

  • Cyber Risk & Security Engineer · WTW, FINEX Western Europe Nov 2024 – current
  • Vulnerability Research Intern (N-day) · Exodus Intelligence Aug 2024 – Oct 2024
  • Security Researcher · Confidential (NDA) Jun 2023 – Apr 2024
  • Security Cloud Trainee · Ericsson R&D Nov 2022 – May 2023

Education

  • MSc Cybersecurity & Privacy · Universitat Oberta de Catalunya · 2024-2025 Final grade: 9.13 out of 10
  • BSc Cybersecurity Engineering · Universidad Rey Juan Carlos · 2020-2024 Top graduate across all degrees at the School of Computer Engineering (ETSII), with the school's highest GPA (9.25 out of 10) 23 Honors distinctions · Bachelor's Degree Extraordinary Award Thesis: "A Methodological Proposal for Hypervisor Exploitation: A Practical Approach" (10 out of 10), co-authored with my colleague David Billhardt

The lists below are a selection of highlights, not an exhaustive record.

CVEs & exploits

  • CVE-2026-47047 VirtualBox arbitrary host file write via a malicious OVA, leading to host code execution (High severity)
  • CVE-2026-35275 VirtualBox VM escape abusing the Shared Folders feature (High severity)
  • CVE-2026-35247 VirtualBox guest-to-host infoleak, enabling an ASLR bypass (Medium severity)
  • CVE-2024-24178 to CVE-2024-24184 Unauthenticated RCE, DoS and auth-bypass chain in an IoT device family, found with the IoTAK0S research team
  • CVE-2023-22098 (N-day) Published exploit and in-depth analysis for a VirtualBox VM escape abusing an out-of-bounds write in the virtio-net device, featured in the Exploits.club Newsletter.
  • CVE-2023-4911 (N-day) Published exploit for Looney Tunables, a local privilege escalation via GLIBC tunables

Competitions

Talks

  • Speaker at Mundo Hacker 2024 Talk on hypervisor exploitation, from virtualization theory and VirtualBox internals to an N-day VirtualBox escape (CVE-2021-2119), given with my colleague David Billhardt
  • Speaker at HackOn 2024 Workshop "Practical Fuzzing: Crashing Programs for Fun and Profit", given with my colleague Daniel Monzón