Image

We hack software
before attackers do.

The Swiss Applied AI & Cybersecurity Research Lab

0-day vulnerabilities we found.

Benchmarks test yesterday's vulnerabilities.
The frontier is novel vulnerability discovery.

CriticalRX buffer overflow on zero-length serial framesLinux kernel · mctp
CVE-2026-68124 · CNA 9.6 Critical
CriticalArbitrary code execution via crafted expressionsjsonata
CVE-2026-77413 · GHSA-8gq3-vp5j-2grp
CriticalCross-tenant agent API-token minting@paperclipai/server
GHSA-47wq-cj9q-wpmp
MediumAnonymous /api/systemstatus leaks exception detailSwiss Federal Chancellery · government code
GHSA-32p4-g4fj-cg95
HighSlab use-after-free in AEAD decrypt completionLinux kernel · TIPC
CVE-2026-63801
HighUse-after-free in MACsec offload RXLinux kernel · mlx5e
CVE-2026-72072
Read our research

Traditional security tests don’t protect you from today’s cyberattacks.

Pentesting was designed for a slower, human-led attacker. The times are changing, and fixing things by hand is no longer fast enough.

01

Legacy approach

Rank individual findings by severity.

With 0sec

Provide fixes for verified vulnerabilities, ranked by business impact.

A primitive alone is not a proven attack path. Our research goal is to connect your threat model to a demonstrated business consequence and the fix that prevents it.

02

Legacy approach

Test once a year.

With 0sec

Test continuously.

03

Legacy approach

Only find known vulnerabilities.

70%of today’s exploits are 0-days, previously unknown

With 0sec

Find and fix the known and the unknown.

04

Legacy approach

Only test your web app.

44%of 0-days hit the operating system, not the web app

With 0sec

Test everything your company runs on.

05

Legacy approach

Hand over a PDF for a human to read.

With 0sec

Ship fixes your own agents can apply.

06

Legacy approach

One more SaaS dashboard to learn and log into.

With 0sec

Arrive in the tools your team already uses.

07

Legacy approach

Trust vendor benchmarks and take their word for it.

With 0sec

Run an open-source engine you can audit.

Questions
answered.

What do you test?

We begin with an agreed scope: selected codebases, packages, web applications, or AI systems. The target and test plan are set before work begins.

Is it autonomous?

The harness automates investigation and evidence collection. Humans set authorization and scope, then review findings before delivery.

How is this different from a scanner?

Scanners flag potential issues. We investigate approved leads and return reproducible evidence when a finding survives verification.

Can you run this against production?

Only with explicit written authorization and an agreed test plan. When production is not appropriate, we can use a staging environment.

What happens to our data?

Data handling is agreed for each engagement. Targets and findings stay within the approved engagement boundary.

Can we use this for SOC 2 or ISO 27001?

We do not sell certifications. Evidence from an engagement may support your own assurance work, subject to your review.

Is the harness open source?

The 0sec source and CLI are published under MIT OR Apache-2.0. 0cloud operations, customer data, target scopes, and internal records are not part of that release.

What does it cost?

You choose the target, number of agents, and hours per agent. We agree the scope and price before work starts, then stop at the approved ceiling.

We love open source.

We've open sourced 2 of our research tools so you can try them for free.

Want us to make your company more secure with the latest research?

Let's work together to see how the latest AI research can hack your company within 24 hours.