SwissApplied AI Cybersecurity Research Lab

We hack your company
before attackers do.

AI lets attackers discover new vulnerabilities every day. 0sec does it first across everything your company runs and depends on.

Engineers reviewed vulnerabilities found and fixed by 0sec. Affecting over 3 billion computers, smartphones & servers worldwide.

As more software gets written by AI, quarterly pentests become less useful by the day. If your security testing happens because compliance needs a report or legal wants a checkbox, it’s not going to end well.

Scanners run constantly, but create so much noise that teams learn to ignore them. Bug bounties incentivize hunters to report vulnerabilities to the good guys first, but only find what someone happens to look for. And a new wave of “always-on AI pentesting” companies is turning pentests into SaaS: another dashboard, another queue of findings to triage, another security tool your team has to learn and operate.

But running the old model more does not fix the model itself.

AI is removing the human bottleneck from vulnerability research. Finding new attack paths is no longer limited by how many researchers you can hire or how many hours they can spend looking. Software can now be attacked at machine speed, and vulnerabilities can be discovered, weaponized, and exploited while defenders are still waiting for the next scan, pentest, or patch cycle.

Cybersecurity cannot keep operating as a sequence of checks.

At 0sec, we’re building for what comes next: autonomous security systems that continuously attack, and fix your software before someone else does. A security team that operates itself, and gets out of your way as much as possible.

0-day vulnerabilities we found.

Benchmarks test yesterday's vulnerabiltiies. The frontier is novel vulnerability discovery.

RX buffer overflow on zero-length serial frames
Linux kernel · mctpCritical
CVE-2026-68124 · CNA 9.6 Critical
Arbitrary code execution via crafted expressions
jsonataCritical
CVE-2026-77413 · GHSA-8gq3-vp5j-2grp
Cross-tenant agent API-token minting
@paperclipai/serverCritical
GHSA-47wq-cj9q-wpmp
Anonymous /api/systemstatus leaks exception detail
Swiss Federal Chancellery · government codeMedium
GHSA-32p4-g4fj-cg95
Slab use-after-free in AEAD decrypt completion
Linux kernel · TIPCHigh
CVE-2026-63801
Use-after-free in MACsec offload RX
Linux kernel · mlx5eHigh
CVE-2026-72072
Read our research

Frequently asked questions.

What do you test?+

We begin with an agreed scope: selected codebases, packages, web applications, or AI systems. The target and test plan are set before work begins.

Is it autonomous?+

The harness automates investigation and evidence collection. Humans set authorization and scope, then review findings before delivery.

How is this different from a scanner?+

Scanners flag potential issues. We investigate approved leads and return reproducible evidence when a finding survives verification.

Can you run this against production?+

Only with explicit written authorization and an agreed test plan. When production is not appropriate, we can use a staging environment.

What happens to our data?+

Data handling is agreed for each engagement. Targets and findings stay within the approved engagement boundary.

Can we use this for SOC 2 or ISO 27001?+

We do not sell certifications. Evidence from an engagement may support your own assurance work, subject to your review.

Is the harness open source?+

The 0sec source and CLI are published under MIT OR Apache-2.0. 0cloud operations, customer data, target scopes, and internal records are not part of that release.

What does it cost?+

You choose the target, number of agents, and hours per agent. We agree the scope and price before work starts, then stop at the approved ceiling.

Start with the tools.

We've open sourced 2 of our research tools already so you can test them out for free!

Foxguard

First-pass scanner. Local, no account.

0sec

The full engine and CLI. Findings stay on your machine.

Want us to make your company more secure with the latest research?

Let's work together to see how the latest AI research can hack your company within 24 hours.