What We Do
The Process
Latest Posts
[Technical Research]We warned 800 organizations about their exposed VPNs. Most never replied.
[Technical Research]wp2shell (CVE-2026-63030 & CVE-2026-60137): Unauthenticated SQL Injection in WordPress Core
[Advisory]TIBER-EU and DORA: What Financial Institutions Need to Understand Before the Notification Arrives
[Advisory]NIS2 Compliance in Portugal: Evidence Over Documentation
[Technical Research]Killing EDR visibility at the kernel: BYOVD
What we build
Our operators build and maintain open-source security tools. What we learn in engagements feeds directly into the tooling we release publicly.
We work with independent researchers, security teams, and academic groups. If you have something worth investigating, get in touch.
Get In Touch