Vulnerability research

We publish what we find.

Our own tooling is pointed at client scope, but the same passes surface bugs in the software underneath. Some of this we found. Some of it we verified for the vendor after another researcher reported it. Each card says which.

Further advisories are in coordinated disclosure and will be listed here once they are published.

Let’s talk.

Whether you have a scoped engagement in mind or want to think out loud, we’re listening.

Contact Us