Our research.

Rooted in Zurich, we advance novel vulnerability research with leading AI labs in San Francisco, hyperscalers and defence organizations. Our ambition is global: the best security, made easy for everyone. We combine models because no single model finds everything, research which model works best for each task, and share reproducible research and open tools others can build on. The goal: software that secures itself.

Read the full manifesto
The Swiss Applied AI & Cybersecurity Research Lab

Notes from the lab.

The public track record.

Every vulnerability we've disclosed. Each one links to its public record.

Engineers at these companies reviewed fixes we submitted.

CriticalRX buffer overflow on zero-length serial framesLinux kernel · mctp
CriticalArbitrary code execution via crafted expressionsjsonata
CriticalCross-tenant agent API-token minting@paperclipai/server
MediumAnonymous /api/systemstatus leaks exception detailSwiss Federal Chancellery · government code
HighSlab use-after-free in AEAD decrypt completionLinux kernel · TIPC
HighUse-after-free in MACsec offload RXLinux kernel · mlx5e
HighMissing CAP_NET_ADMIN check on changelinkLinux kernel · vxlan / geneve
HighOOB read on frames shorter than the auth tagLinux kernel · mac802154
HighMemory corruption in 802.15.4 llsec decryptLinux kernel · mac802154
HighUse-after-free of metadata_dst in eswitch repr releaseLinux kernel · ice
HighResource-exhaustion denial of servicejsonata
HighUse-after-free in LE Audio CIG/CIS setupLinux kernel · Bluetooth
HighStack buffer overflow in NFC digitalLinux kernel · NFC
HighDouble-completion / double-free on resumeLinux kernel · xen-blkfront
HighCertificate-chain validation bypassnode-forge
HighDenial of service via unbounded recursionprotobuf.js
HighInteger overflow in HTTP chunked-transfer parser → heap OOB readnng (nanomsg)
HighOOB from unvalidated ioctl buffer sizesLinux kernel · atomisp
HighUse-after-free on inrange_timer at teardownLinux kernel · HID uclogic
HighStale pen_input pointer on partial registrationLinux kernel · HID uclogic
HighUse-after-free of in-use VP9 framesLinux kernel · meson vdec
MediumOOB read on LLCP PDUs shorter than the headerLinux kernel · NFC
CVSS pendingNULL-deref DoS paths via AMDXDNA_EXEC_CMDLinux kernel · amdxdna
CVSS pendingOOB read from assoc length underflowLinux kernel · ath6kl
CVSS pendingNULL deref on HT-cap without HT-oper in TDLSLinux kernel · mwifiex
CVSS pendingOut-of-bounds read from unset MAC header on packet-socket TXLinux kernel · net/packet
MediumOOB read in LLCP connect_sn TLV walkLinux kernel · NFC
MediumOOB read in st21nfca ATR_REQ handlingLinux kernel · NFC
CVSS pendingOOB read from unvalidated directory-index countsLinux kernel · ocfs2
CVSS pendingUse-after-free from carrier_work rearm on disconnectLinux kernel · ipheth
CVSS pendingUse-after-free of ghl_poke_timer / ghl_urb at driver unbindLinux kernel · HID sony
MediumHeap out-of-bounds write in ciscodump extcapWireshark
MediumTemplate injection → arbitrary file readUptime Kuma
MediumStack overflow via deeply nested collectionsyaml
MediumOut-of-bounds read in LLCP SNL TLV parserLinux kernel · NFC
MediumInteger overflow in frame-size calculationLinux kernel · atomisp
MediumOOB read from unvalidated AV1 frame indicesLinux kernel · v4l2-ctrls
MediumOOB in NPU cmdstream tile validationLinux kernel · accel/ethosu
MediumOOB read in firmware-request handlerLinux kernel · Bluetooth btnxpuart
MediumOOB read in HT/VHT capability IE parsingLinux kernel · mwifiex
MediumOOB read in pairwise-cipher OUI walkLinux kernel · mwifiex
MediumECRED deferred-recvmsg race → list corruptionLinux kernel · Bluetooth L2CAP
MediumOOB read in port100 frame length handlingLinux kernel · NFC
LowReachable WARN DoS in rsa-pkcs1pad empty digestLinux kernel · crypto

Updated continuously. Embargoed findings appear once they're fixed.

Work with the lab.

You build critical software, or you break it for a living. Talk to us.