Our research.

0sec

The harness we use internally for research is completely open source.

Foxguard

First-pass code scanner, written in Rust.

Notes from the lab.

The public track record.

Every vulnerability we've disclosed. Each one links to its public record.

Engineers at these companies reviewed fixes we submitted.

GoogleMetaIBMNVIDIAIntelRed HatAMDQualcommCiscoArmEricssonNXPSUSECitrixAlibaba
CriticalRX buffer overflow on zero-length serial framesLinux kernel · mctp
CVE-2026-68124 · CNA 9.6 Critical
CriticalArbitrary code execution via crafted expressionsjsonata
CVE-2026-77413 · GHSA-8gq3-vp5j-2grp
CriticalCross-tenant agent API-token minting@paperclipai/server
GHSA-47wq-cj9q-wpmp
MediumAnonymous /api/systemstatus leaks exception detailSwiss Federal Chancellery · government code
GHSA-32p4-g4fj-cg95
HighSlab use-after-free in AEAD decrypt completionLinux kernel · TIPC
CVE-2026-63801
HighUse-after-free in MACsec offload RXLinux kernel · mlx5e
CVE-2026-72072
HighMissing CAP_NET_ADMIN check on changelinkLinux kernel · vxlan / geneve
CVE-2026-68142 + CVE-2026-68432
HighOOB read on frames shorter than the auth tagLinux kernel · mac802154
CVE-2026-68125
HighMemory corruption in 802.15.4 llsec decryptLinux kernel · mac802154
CVE-2026-63831
HighUse-after-free of metadata_dst in eswitch repr releaseLinux kernel · ice
Queued upstream
HighResource-exhaustion denial of servicejsonata
CVE-2026-52746
HighUse-after-free in LE Audio CIG/CIS setupLinux kernel · Bluetooth
CVE-2026-63944
HighStack buffer overflow in NFC digitalLinux kernel · NFC
CVE-2026-80803
HighDouble-completion / double-free on resumeLinux kernel · xen-blkfront
Merged upstream
HighCertificate-chain validation bypassnode-forge
CVE-2026-33896
HighDenial of service via unbounded recursionprotobuf.js
CVE-2026-44289
HighInteger overflow in HTTP chunked-transfer parser → heap OOB readnng (nanomsg)
GHSA-cmhr-c7mj-hgx7
HighOOB from unvalidated ioctl buffer sizesLinux kernel · atomisp
In review
HighUse-after-free on inrange_timer at teardownLinux kernel · HID uclogic
In review
HighStale pen_input pointer on partial registrationLinux kernel · HID uclogic
In review
HighUse-after-free of in-use VP9 framesLinux kernel · meson vdec
In review
MediumOOB read on LLCP PDUs shorter than the headerLinux kernel · NFC
CVE-2026-80798
CVSS pendingNULL-deref DoS paths via AMDXDNA_EXEC_CMDLinux kernel · amdxdna
CVE-2026-72091 + CVE-2026-72092
CVSS pendingOOB read from assoc length underflowLinux kernel · ath6kl
CVE-2026-89524
CVSS pendingNULL deref on HT-cap without HT-oper in TDLSLinux kernel · mwifiex
CVE-2026-68197
CVSS pendingOut-of-bounds read from unset MAC header on packet-socket TXLinux kernel · net/packet
CVE-2026-74667
MediumOOB read in LLCP connect_sn TLV walkLinux kernel · NFC
CVE-2026-80800
MediumOOB read in st21nfca ATR_REQ handlingLinux kernel · NFC
CVE-2026-80823
CVSS pendingOOB read from unvalidated directory-index countsLinux kernel · ocfs2
CVE-2026-89492
CVSS pendingUse-after-free from carrier_work rearm on disconnectLinux kernel · ipheth
CVE-2026-74677
CVSS pendingUse-after-free of ghl_poke_timer / ghl_urb at driver unbindLinux kernel · HID sony
CVE-2026-89625
MediumHeap out-of-bounds write in ciscodump extcapWireshark
CVE-2026-15164
MediumTemplate injection → arbitrary file readUptime Kuma
CVE-2026-33130
MediumStack overflow via deeply nested collectionsyaml
CVE-2026-33532
MediumOut-of-bounds read in LLCP SNL TLV parserLinux kernel · NFC
Merged upstream
MediumInteger overflow in frame-size calculationLinux kernel · atomisp
In review
MediumOOB read from unvalidated AV1 frame indicesLinux kernel · v4l2-ctrls
In review
MediumOOB in NPU cmdstream tile validationLinux kernel · accel/ethosu
In review
MediumOOB read in firmware-request handlerLinux kernel · Bluetooth btnxpuart
In review
MediumOOB read in HT/VHT capability IE parsingLinux kernel · mwifiex
In review
MediumOOB read in pairwise-cipher OUI walkLinux kernel · mwifiex
In review
MediumECRED deferred-recvmsg race → list corruptionLinux kernel · Bluetooth L2CAP
In review
MediumOOB read in port100 frame length handlingLinux kernel · NFC
In review
LowReachable WARN DoS in rsa-pkcs1pad empty digestLinux kernel · crypto
Queued upstream

Updated continuously. Embargoed findings appear once they're fixed.

Work with the lab.

You build critical software, or you break it for a living. Let's talk.