Blog Research About Contact Subscribe

Security Research

Original vulnerability research, threat analysis, and security advisories from our team. We practice responsible disclosure and work with vendors before publishing.

Focus Areas

Application Security

Web application vulnerabilities, API security flaws, and client-side attack vectors.

14 papers

Infrastructure & Cloud

Cloud misconfigurations, container escapes, and infrastructure attack paths.

11 papers

Supply Chain

Dependency attacks, CI/CD compromise, and build system security analysis.

8 papers

Cryptography

Implementation flaws, protocol analysis, and post-quantum cryptography research.

6 papers

All Research

Jan 2026

GraphQL Introspection Attacks: A Comprehensive Taxonomy

Examining how attackers exploit GraphQL introspection queries to map application schemas, extract sensitive data, and identify injection points. Includes a detection framework and mitigation playbook.

GraphQL API Security
Nov 2025

Container Escape via eBPF: New Attack Surfaces in Kubernetes

We discovered a class of container escape vulnerabilities leveraging eBPF capabilities in default Kubernetes configurations. Three CVEs were assigned. Patches are available for all affected versions.

Kubernetes eBPF CVE
Aug 2025

AWS IAM Privilege Escalation: 12 New Attack Paths

Documented twelve previously unreported IAM privilege escalation paths in AWS, including cross-service chains that bypass standard guardrails. All findings responsibly disclosed.

AWS IAM Privilege Escalation

Responsible Disclosure

All vulnerabilities discovered by our team are reported to vendors through coordinated disclosure. We follow a 90-day disclosure timeline and work collaboratively with vendors to ensure patches are available before publication.

If you've found a vulnerability and need guidance on the disclosure process, we're happy to help. Reach out to our team.

Contact our team