research
Research is one of our founding principles and we invest in it heavily. All of our researchers have the privilege to use 25% of their time exclusively for self-directed research.
By discovering new vulnerabilities and attack techniques, we are constantly improving our capabilities and contributing to the security of the digital world.
Comparing AI Application Security Testing Platforms: Aikido vs. XBOW
Publication
This whitepaper provides a comprehensive comparison of Aikido and XBOW, two leading AI application security testing platforms. It evaluates their features, capabilities, and performance in identifying security vulnerabilities in modern web applications.
Whitepaper: Download Here (PDF, 5 MB)
Resources: Download Here (ZIP, 44 KB)
ELBaph - AWS Elastic Load Balancer Configuration Auditor
Code
ELBaph whitebox CLI tool for pentesters and security engineers to enumerate AWS Application Load Balancers and detect common routing misconfigurations that expose internal services to the public Internet.
Code: https://github.com/doyensec/elbaph
Navigating Lax Load Balancers: When an Intersection Gets You Inside
Blog
CloudSec Tidbits is a blogpost series showcasing interesting bugs found by Doyensec during cloud security testing activities. Each blogpost will discuss a specific vulnerability resulting from an insecure combination of web and cloud related technologies. Every article will include an Infrastructure as Code (IaC) laboratory that can be easily deployed to experiment with the described vulnerability.
Episode 5 (post): https://blog.doyensec.com/2026/05/25/cloudsectidbits-elbaph-alb.html
Episode 5 (code): https://github.com/doyensec/cloudsec-tidbits/tree/main/lab-elbaph
Anthropic's Project Glasswing
Advisory
Doyensec is proud to share that we were selected by Anthropic as one of six independent security research firms supporting Project Glasswing. Our contribution focused on vulnerability triaging and helping validate security findings as part of the broader effort to strengthen Mythos capabilities and research workflows. We're excited to support initiatives that advance AI-driven vulnerability security research and responsible disclosure practices.
Read Anthropic's update here: https://www.anthropic.com/research/glasswing-initial-update
Vulnerability disclosure dashboard: https://red.anthropic.com/2026/cvd/
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
Blog
Our second blogpost on NASA's CFITSIO library. This time we are presenting our research on logical and architectural issues identified in the Extended Filename Syntax.
We show how documented filename-processing features can be chained into security-relevant primitives, including arbitrary file copy, server-side request forgery, HTTP header injection, and local file exfiltration through the legacy root:// driver.
Blog Post: https://blog.doyensec.com/2026/05/19/cfitsio-weaponized-filenames.html
Participation in PWN2OWN Berlin 2026
Advisory
Leonardo Giovannini of Doyensec participated in the internationally renowned Pwn2Own competition held in Berlin. While his demonstration on stage was successful, the exploit targeting OpenAI Codex in the Coding Agent category relied on a vulnerability that had been previously disclosed to the vendor. Nevertheless, the team was awarded $10,000 and earned 2 Master of Pwn points.
Our Public Tools
- Electrong Premium ElectronJS Security Scanning Tool](https://get-electrong.com/)
- Electronegativity OpenSource ElectronJS Security Scanning Tool](https://github.com/doyensec/electronegativity)
- InQL GraphQL Security Testing Tool](https://github.com/doyensec/inql)
- Burp-Rest-API Rest/JSON API for Burp Suite](https://github.com/vmware/burp-rest-api)