Vulnerability research, competitions, and insights from the front lines of offensive security.
BunkyoWesterns, a team including our members, took 1st place worldwide at CODEGATE 2026 CTF Finals (General track) held in South Korea, earning a first-place prize of ₩50,000,000.
Read more →
Our member discovered an information disclosure vulnerability in the Privacy component of Firefox for Android and reported it to Mozilla.
Read more →
We are launching Ikotas Exploit Development Training, a practical training program centered on LLM-assisted exploit development. A hands-on training tailored to each participant, covering the major targets researchers work against from an attacker's perspective and walking through the flow from vulnerability analysis to constructing exploits that actually succeed.
Read more →
Our team discovered multiple memory safety vulnerabilities that lead to arbitrary code execution in tools shipped with the TeX Live typesetting system, and reported them to the developer under coordinated disclosure. We demonstrated that arbitrary code execution is achievable on the official distribution binaries simply by compiling a malicious document.
Read more →
We are launching Ikotas AI×Security Training, a practical training program for putting AI agents to work in real security operations. A hands-on series covering AI utilization across security workflows from an attacker's perspective.
Read more →
BunkyoWesterns, a team including our members, took 1st place worldwide at Midnight Sun CTF 2026 Finals held in Sweden.
Read more →
Our member discovered a local privilege escalation 0-day on the latest Linux kernel, chaining two kernel bugs, and reported it to the vendor.
Read more →
Our member discovered vulnerabilities in Firefox's DOM: Bindings (WebIDL) and Popup Blocker components and reported them to Mozilla.
Read more →
Our member competed on day 3 of Pwn2Own Berlin 2026 and successfully exploited OpenAI Codex, an AI coding agent.
Read more →
Our member competed on day 1 of Pwn2Own Berlin 2026 and successfully exploited NVIDIA Megatron Bridge and LiteLLM.
Read more →
Our member discovered a new privilege escalation variant of the Dirty Frag family in the Linux kernel's RxRPC RxGK security class.
Read more →
Our member discovered vulnerabilities in Firefox's Networking: Cookies and Debugger components and reported them to Mozilla.
Read more →