From DARPA to Black Hat: An SRT Researcher’s Next Chapter
Synack Red Team researcher Malcolm Stagg takes the stage at Black Hat USA 2026 on August 6 to present three years of independent research on a new class of network infrastructure attacks. Here's who he is and why the talk belongs on your calendar.
Key Takeaways
- Synack Red Team researcher Malcolm Stagg presents new network infrastructure research at Black Hat USA 2026 on Thursday, August 6.
- Synack will publish a full technical breakdown of the research and a conversation with Malcolm the day of his talk.
- His talk, "Breaking Trust Boundaries," has already been tested against real-world network infrastructure products from multiple vendors.
- Malcolm conducts the research independently through his own consultancy, SODIUM-24, LLC, while hacking exclusively with Synack.
On Thursday, August 6, Synack Red Team researcher Malcolm Stagg will step on stage at Black Hat USA 2026 to present research he’s been building, largely on his own time, for close to three years. His talk, “Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure,” has already been tested against real-world network infrastructure products from multiple vendors, using independent codebases. Malcolm’s research focuses on network infrastructure design assumptions that no one has revisited in decades. We’ve collectively made these assumptions that made sense when networks were cooperative, but they can no longer withstand adversarial conditions.
What we can tell you now is a little more about Malcolm and why it’s worth your calendar. The day of his talk, we’ll publish the full technical breakdown of his research plus a full conversation with Malcolm as part of our We’re In podcast series.
Who Is Malcolm Stagg?
Malcolm’s research career started early on. He competed in Canada’s National Science Fair five times (one gold, two silver, two bronze) and represented Canada at the International Science and Engineering Fair twice, placing fourth in the world in computer science one of those years. At LSU, he joined a DARPA-funded computer vision research group working on the VIRAT program, which earned him the Computing Research Association Undergraduate Research Award (Honorable Mention) and a U.S. patent (US 10,757,369 B1). He graduated at the top of his class and was awarded the University Medal and Edward McLaughlin Dean’s Medal for engineering.
For fun, Malcolm spent two years reverse-engineering Blu-ray players. In fact, NCC Group presented that research at Securi-Tay in 2015, and it was picked up by outlets well outside the security trade press. It’s a pattern that shows up again and again in Malcolm’s career: the side project outgrows the day job.
After LSU, Malcolm spent three years at Microsoft fixing network bugs in Remote Desktop and helping to ship the Remote Desktop Web Client in 2017. Then he went independent, taking on DARPA’s hardest open competitions as a one-man team. He was a finalist in the Spectrum Collaboration Challenge, ranking 10th place. And for the DARPA Subterranean Challenge Virtual Tunnel Circuit, he placed 3rd overall (2nd among self-funded teams) and took home a $150,000 prize. In 2020, he found 6 of the 10 valid vulnerabilities DARPA accepted during its FETT hardware bug bounty. That’s how he ended up on the Synack Red Team (SRT).
Since then, he’s kept finding things nobody asked him to look for: a vulnerability in Intel processors reported privately under Intel’s Project Circuit Breaker, a Microsoft Remote Desktop RCE (CVE-2021-34535) that was his first CVE, and a Google Chrome extension vulnerability (CVE-2024-0333) that started as a Synack client engagement and turned into a browser-vendor disclosure.
What Is He Presenting at Black Hat?
At Black Hat, Malcolm will talk more about network-based attacks that have been successfully performed against dozens of real-world network infrastructure products. He’ll walk through his discovery process, demo proof-of-concept exploitation in a controlled environment, and cover mitigation strategies. If you’re already in Vegas, you can catch him live on Thursday, August 6, at 10:15-10:45 am PT in Oceanside D, Level 2.
Why This Matters for the SRT Community
Malcolm first got the idea for his research while on an SRT assignment. After that, he kept digging in to build out a substantial body of research that he’ll present on behalf of SODIUM-24, LLC, his own consultancy. We’re proud that the SRT will be credited alongside him, because he’s exactly the kind of researcher the team is built around. Malcolm is someone who gets curious about a system, keeps investigating well past the point most people would stop, and only brings us in when there’s something real to show. It’s also worth saying that Malcolm hacks exclusively with Synack.
Malcolm has spent nearly three years on this research. Give him 30 minutes on Thursday, August 6 to hear his talk live, then come back here for what it means for your network.
Related reading: How I Hacked My Way to the Top of DARPA’s Hardware Bug Bounty • This Microsoft Windows RCE Vulnerability Gives an Attacker Complete Control • Exploits Explained: Zip Embedding Attack on Google Chrome Extensions
Frequently Asked Questions
Malcolm Stagg, an independent researcher and Synack Red Team member, is presenting “Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure” at Black Hat USA 2026. The talk covers a previously unrecognized class of network infrastructure attacks that has been demonstrated against dozens of real-world products from multiple vendors.
Thursday, August 6, 2026, from 10:15 to 10:45 am PT, in Oceanside D, Level 2. It’s a 40-minute Briefing listed under the Cloud Security and Network Security tracks.
The research is independent, conducted by Malcolm under his own research banner, SODIUM-24, LLC. He is also a longtime member of the Synack Red Team, which is credited alongside him, and he hacks exclusively through Synack.
Yes. Synack will publish a technical breakdown with mitigation guidance the same day the session goes live.


