We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
We shipped post-quantum crypto to Python, watched GPT-5.5-Cyber build a zlib fuzzing lab in a day, and shared our /goal playbook for finding real bugs. Plus 9 new public reviews, mutation testing for DAML, and more. July Tribune:
This Sunday, WAC8 at UC Santa Barbara: Dan Boneh, TEE.fail, message injection attacks on Signal, and more. Co-organized by our very own Keegan Ryan.
Full program: wac8.cryptanalysis.fun
PATCH THE PLANET BUG SPOTLIGHT: We found a medium-severity bug in aiohttp, Python's HTTP engine that had 600M+ downloads last month. Denys Pakizh caught oversized requests dodging its size limits. Now patched. CVE-2026-54277 in the dashboard:
We're a day-one auditor for @signalapp's new Automatic Key Verification, which depends on external auditors to confirm everyone sees the same keys.
We built our auditing software from scratch, open-sourced it, and run it as a public good.