Security Researcher | AI for Security | AI for Code
Black Hat Asia 2026
More JVM Memory Shells – JVM Memory Shell Auto Searching Program
Singapore
An automated framework for discovering JVM memory shells through static analysis, runtime instrumentation, and in-memory inspection.
Alibaba Cloud White Hat Conference 2025
Breaking Consensus: From Raft Leader Hijacking to Distributed System Takeover
Analysis of security assumptions in the Raft consensus protocol and a full exploit chain from leader hijacking to distributed system compromise by combining consensus abuse with deserialization vulnerabilities.
https://www.yulate.com/post/LGnP-XXPvc/
Xianzhi Security Salon 2025
Deep JDBC Security: Special URL Constructs and In-Network Deserialization Exploit Techniques
Research on JDBC URL parsing inconsistencies, driver-level attack surfaces, and practical exploitation techniques with PoC demonstrations.
https://github.com/yulate/jdbc-tricks
- CVE-2024-21182 : Oracle Critical Patch Update Advisory - July 2024
- CVE-2024-21216 : Oracle Critical Patch Update Advisory - October 2024
- CVE-2024-42323 : Apache HertzBeat: RCE by snakeYaml deser load malicious xml
- CVE-2024-45505 : Apache HertzBeat (incubating): Exists Native Deser RCE and file writing vulnerabilities
- CVE-2024-56180 : Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution
- CVE-2025-27103 : Dataease Mysql JDBC Connection Parameters Not Verified Leads to Arbitrary File Read Vulnerability
- CVE-2025-27526 : Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass
- CVE-2025-27528 : Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read
Email: yulate531@gmail.com
Website: https://yulate.com

