Security research

The proof is the work.

Good security tools come from people who understand how attacks actually work. Our team finds real vulnerabilities in real systems, and what we learn goes straight back into BuildSecure.

research

Our long-form research has a home of its own.

The deeper write-ups live at research.kahulabs.com. Each one takes a real failure we found in an authorized assessment and explains the idea behind it, from the assumption that broke to how to build the control correctly.

Read the research at research.kahulabs.com
publicly verified

Acknowledged by Deutsche Telekom.

We reported authentication bypass and PII exposure across Deutsche Telekom, one of the largest telecom companies in the world, and its sibling organizations. Their security team lists us publicly among their acknowledged contributors.

See the acknowledgment on telekom.com

Selected findings.

/client work

A sample of what we have found in client systems. Details are anonymized and published only after the issue was fixed.

Authentication bypass, admin takeover

Gained full administrator access to a client's production analytics platform by defeating the way its login tokens were signed.

Remote code execution in a public web app

A client's public application could be made to run our code. We proved it safely and it was patched before anyone else found it.

Remote code execution via an outdated component

An old browser component inside a client's environment gave attackers a foothold into their core operations.

Exposed build server

A build system left open to the internet, publishing source code and configuration files, plus live API keys, to anyone who looked.

Cloud storage keys in public code

Storage credentials sitting inside a public JavaScript file, granting read and write access to a production storage account.

Debug mode left on in production

A live application exposing its database credentials, sign-in secrets, and API keys through a developer setting nobody turned off.

A chain of small flaws

Three low-severity issues combined into one real attack path through a client's firewall. Single-purpose scanners miss that kind of chain.

Weak access controls on an internal platform

Staff documents could be viewed and edited, and even exported, by people who should never have had access to them.

Client names, affected systems, and technical detail are never published. We share the class of issue and its impact, never anything that could help someone repeat it.

Get started

Want to know what we would find in yours?

A short call, then a scoped review of a system you choose. You see real findings from your own systems.

Talk to us or email hello@kahulabs.com