About
I'm Diego Palacios (DiegoAltF4), a security researcher based in Madrid, Spain, focused on low-level vulnerability research and exploit development, with a particular obsession: hypervisors.
By day I work as a Cyber Risk & Security Engineer at WTW; by night, I try to escape virtual machines.
A snapshot of my profile is below.
Feel free to reach out at diegoaltf4 [at] protonmail [dot] com.
ACCESS
Diego Palacios
Security Researcher
LOCATION outside the VM
Experience
- Cyber Risk & Security Engineer · WTW, FINEX Western Europe
- Vulnerability Research Intern (N-day) · Exodus Intelligence
- Security Researcher · Confidential (NDA)
- Security Cloud Trainee · Ericsson R&D
Education
- MSc Cybersecurity & Privacy · Universitat Oberta de Catalunya · 2024-2025 Final grade: 9.13 out of 10
- BSc Cybersecurity Engineering · Universidad Rey Juan Carlos · 2020-2024 Top graduate across all degrees at the School of Computer Engineering (ETSII), with the school's highest GPA (9.25 out of 10) 23 Honors distinctions · Bachelor's Degree Extraordinary Award Thesis: "A Methodological Proposal for Hypervisor Exploitation: A Practical Approach" (10 out of 10), co-authored with my colleague David Billhardt
The lists below are a selection of highlights, not an exhaustive record.
CVEs & exploits
- CVE-2026-47047 VirtualBox arbitrary host file write via a malicious OVA, leading to host code execution (High severity)
- CVE-2026-35275 VirtualBox VM escape abusing the Shared Folders feature (High severity)
- CVE-2026-35247 VirtualBox guest-to-host infoleak, enabling an ASLR bypass (Medium severity)
- CVE-2024-24178 to CVE-2024-24184 Unauthenticated RCE, DoS and auth-bypass chain in an IoT device family, found with the IoTAK0S research team
- CVE-2023-22098 (N-day) Published exploit and in-depth analysis for a VirtualBox VM escape abusing an out-of-bounds write in the virtio-net device, featured in the Exploits.club Newsletter.
- CVE-2023-4911 (N-day) Published exploit for Looney Tunables, a local privilege escalation via GLIBC tunables
Competitions
- First place in the JNIC 2025 CTF Capture-the-Flag at the Spanish National Cybersecurity Research Conference
- First place in the Airbus Cyber Day 2024 CTF Capture-the-Flag competition hosted by Airbus
- First place in the Guardia Civil National CyberLeague, 5th Edition (2023) One of the largest cybersecurity competitions in Spain, won with the Jinchomaniacos team
- Full Member of the Spanish National Selection (ECSC 2022) Representing Spain at the European Cybersecurity Challenge in Vienna
Talks
- Speaker at Mundo Hacker 2024 Talk on hypervisor exploitation, from virtualization theory and VirtualBox internals to an N-day VirtualBox escape (CVE-2021-2119), given with my colleague David Billhardt
- Speaker at HackOn 2024 Workshop "Practical Fuzzing: Crashing Programs for Fun and Profit", given with my colleague Daniel Monzón