Join              the

JOIN THE

research team

Find Threats.       Publish findings. Compete globally.

OFFENSIVE MINDSET. DEFENSIVE PURPOSE. NO SHORTCUTS IN BETWEEN.

Engaged Research

EVERY CVE STARTS WITH
SOMEONE WHO LOOKED HARDER.

[01]

You find vulnerabilities, verify them, publish them. Not advisory alerts, you write the research that matters.

[02]

Your name on real discoveries. Credibility built from operating in the field, not consuming theory.

[03]

Move from learning to leading. Share the knowledge you’ve gained and shape how others see security.

Research That
lands.

Research That lands.

Our research team turns cybersecurity knowledge into discoveries that matter. From identifying CVEs to contributing to security research used by leading organizations, our work helps strengthen the systems that millions rely on.

Patching the planet, one CVE at a time.

CVE-2026-20685

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

CVE-2023-23512

High-risk vulnerability enabling denial of service via malicious web content

CVE-2023-35990

Medium-risk vulnerability allowing unauthorized disclosure of installed

CVE-2023-26482

Critical-risk vulnerability enabling remote code execution

CVE-2023-48239

High-risk vulnerability allowing arbitrary user storage updates

CVE
Vendor
Details
Maliciously crafted web content may trigger a use-after-free vulnerability, potentially causing crashes in WebKit-based applications.
An out-of-bounds read in Apple's Heimdal authentication component could allow a malicious application to cause a denial of service.
A buffer overflow in Apple's kernel NFS handling could lead to kernel memory corruption when connecting to a malicious network file server.
An authorization vulnerability could allow unauthorized users to access or modify application data under certain conditions.
Insufficient access-control checks could allow unauthorized users to perform actions they should not be permitted to perform.
An out-of-bounds read in libmodplug can be triggered by a specially crafted MIDI file, potentially causing an application crash.
Missing authorization checks could allow authenticated users to access or modify notes belonging to other users, including administrators.

STEP 1

No bureaucracy. Just steps.

Fill out the application. No corporate fluff.

Apply

Fill out the form. No essays, no corporate fluff.

Interview

Meet one of our mentors.
Expect honest questions.

decision

If you’re in, you’ll get your mission pack and start date.

We choose commitment over credentials.

STEP 2

Read this before you hit submit.

We move forward only when your file is complete. No exceptions, no extensions.

Letter(s) of Recommendation

Previous Education – Diplomas or Certificates

Timeline reminder:

We review applications on a rolling basis. Incomplete files are not reviewed.

Follow instructions. It’s your first test of discipline.

STEP 3

YOU'LL FIT HERE IF YOU OPERATE.

This is not a course. There are no lectures, no hand-holding, and no participation trophies. You find things, verify them, and publish. If that sounds like work — it is.

You'll fit right in if you're:

Not for you if you're:

Prove THAT you're serious.

Takes 5 minutes. Be real. Be precise.
We’re looking for drive, not perfect grammar.

NOT READY YET? THAT'S WHAT THE PATHWAYS ARE FOR.

Pick a path, build the skills, and come back when you're ready to contribute.