Malcolm Stagg Portrait

Malcolm Stagg

Malcolm Stagg is a security researcher on the Synack Red Team who joined after completing Synack's capture-the-flag qualifier for DARPA's FETT bug bounty program, which gave him rare access to DARPA's SSITH secure hardware. A former Microsoft software engineer who worked on Remote Desktop network transport, he discovered CVE-2021-34535, an RCE vulnerability in Remote Desktop Client, and CVE-2024-0333, a Google Chrome flaw that could enable installation of malicious extensions. He was nominated for the 2022 CyberScoop 50 Awards.