In 2014 Esage took the first place in the PHDays IV "Critical Infrastructure Attack" contest (alternative name: "Hack the Smart City"), successfully hacking a mock-up smart city and detecting several zero-day vulnerabilities in Indusoft Web Studio 7.1 by
Schneider Electric. In 2014-2018 Esage was credited for discovering multiple zero-day security vulnerabilities in popular software products from tech giants such as Microsoft, Firefox, and Google. Part of those vulnerabilities were responsively disclosed via the Zero Day Initiative (ZDI) security bounty program, previously owned by U.S. tech giant HP, and credited under various pseudonyms. Esage has presented her research at multiple international security conferences: RECON, Positive Hack Days, Zero Nights, POC x Zer0con, Chaos Communications Congress. Her work has been featured in various professional security industry publications such as
Virus Bulletin, Secure List, and
Phrack Magazine.
Pwn2Own On 8 April 2021 Esage was the first woman to win in the
Pwn2Own, the advanced hacking competition running since 2007. As part of her competition entry at Pwn2Own Vancouver 2021 Esage targeted
Parallels Desktop for Mac version 16.1.3 with a zero day exploit developed by herself, and was able to demonstrate a guest-to-host virtual machine escape with arbitrary code execution on MacOS, on a fully patched system. The entry was declared a partial win by the contest due to the fact that the targeted software vendor knew internally about the zero day bug that was leveraged in Esage's exploit. == Controversy ==