What we do
What we build.
- AI-enabled pentesting Foxhound Automated assessment steps inside a scope you approve, with a tester signing off findings before delivery.
- Extension intelligence RiskyPlugins Risk profiles for 550K+ browser and IDE extensions across nine marketplaces.
- Private extension marketplace Private preview PrivateStores Your developers install from a catalogue you approved, with risk thresholds and release holds enforced as policy.
- Open source We also build in the open. Fenko Vault keeps passkeys on your own devices, dnsmonster captures passive DNS, and foxymirror quarantines fresh npm and PyPI releases. See our open-source work →
Vulnerability research
We publish what we find.
Our own tooling is pointed at client scope, but the same passes surface bugs in the software underneath. Some of this we found. Some of it we verified for the vendor after another researcher reported it. Each card says which.
-
CVE-2026-65819 CVSS 7.5
Eleven layer decoders panic on crafted packets
Decoders across TLS, DHCPv4, sFlow, Diameter, GTPv1-U, RadioTap and more slice packet data using attacker-controlled length and offset fields before checking them against the buffer. A malformed packet panics the decoding goroutine.
Credited to Fenko. Published 27 July 2026 as GHSA-8mcr-459q-5mx2, fixed in 1.7.1. Read the advisory -
CVE-2026-54345 7 Jun 2026
Diameter AVP decoder: uint32 underflow on vendor header size
An integer underflow on the vendor header size lets a single crafted message drive an unbounded allocation of roughly 4 GiB, exhausting memory without authentication.
Reported by tonghuaroot. Fenko is credited as remediation verifier: we confirmed the fix, we did not find the bug. Published 7 June 2026, fixed in 1.6.1. Read the advisory -
CVE-2026-54332 7 Jun 2026
sFlow decoder: unbounded allocation from a 104-byte datagram
A 104-byte UDP datagram reaches an attacker-controlled
makein the ExtendedGatewayFlow decoder and can request up to 16 GiB, exhausting memory without authentication.Reported by tonghuaroot. Fenko is credited as remediation verifier: we confirmed the fix, we did not find the bug. Published 7 June 2026, fixed in 1.6.1. Read the advisory -
CVE-2026-12606 7 Jun 2026
HTTP request smuggling via header-name parsing
The parser ends a header name at the first colon without checking for CR, LF or space, so a
Content-Lengthtucked into a header name never gets treated as framing.Same defect and same fix as CVE-2026-12606, which Eclipse assigned from a separate trailer-section report. Our analysis reached security@eclipse.org on 7 June 2026 and reproduces back to 2.1.11, wider than the 4.0.0 to 5.0.1 range published against that ID. Read the research
Further advisories are in coordinated disclosure and will be listed here once they are published.
Let’s talk.
Whether you have a scoped engagement in mind or want to think out loud, we’re listening.
Contact Us