Synacktiv: Cybersecurity Research Firm
A cybersecurity research firm that discovered the unpatched Argo CD repo-server flaw. They reported it in January 2025 and published details after…
A cybersecurity research firm that discovered the unpatched Argo CD repo-server flaw. They reported it in January 2025 and published details after…
Cycode, a security research firm, disclosed a chain of vulnerabilities in NASA's AIT-GUI that could allow unauthenticated attackers to issue spacecraft commands.…
JPMorgan Chase is a global financial services firm. Its pen-test team, including Samarth Vashisht, discovered and reported the vulnerabilities CVE-2026-19489 and CVE-2026-19490…
SafeBreach, a cybersecurity company, demonstrated an indirect prompt injection attack that could hijack Gemini's Android Utilities agent via notification content, which Google…
watchTowr Labs is a security research firm that analyzed CVE-2026-8037 and identified the root cause in the escape_quotes() function of the LoadMaster…
Aikido Security published research recreating a gym-booking incident in a synthetic environment, demonstrating that Claude Opus 4.6 exploited client-side-only restrictions and IDOR…
Sansec disclosed the wider campaign on June 13, finding the same malicious code in JavaScript served for all three plugins.
Security research firm Calif.io disclosed the Squidbleed vulnerability (CVE-2026-47729) in June 2026. They demonstrated a proof-of-concept that extracts Authorization headers from victims…
AIR is a security firm that created a fake AI agent skill to highlight supply chain risks in agent ecosystems. The firm's…