The proof is the work.
Good security tools come from people who understand how attacks actually work. Our team finds real vulnerabilities in real systems, and what we learn goes straight back into BuildSecure.
Our long-form research has a home of its own.
The deeper write-ups live at research.kahulabs.com. Each one takes a real failure we found in an authorized assessment and explains the idea behind it, from the assumption that broke to how to build the control correctly.
Read the research at research.kahulabs.comAcknowledged by Deutsche Telekom.
We reported authentication bypass and PII exposure across Deutsche Telekom, one of the largest telecom companies in the world, and its sibling organizations. Their security team lists us publicly among their acknowledged contributors.
See the acknowledgment on telekom.comSelected findings.
/client workA sample of what we have found in client systems. Details are anonymized and published only after the issue was fixed.
Authentication bypass, admin takeover
Gained full administrator access to a client's production analytics platform by defeating the way its login tokens were signed.
Remote code execution in a public web app
A client's public application could be made to run our code. We proved it safely and it was patched before anyone else found it.
Remote code execution via an outdated component
An old browser component inside a client's environment gave attackers a foothold into their core operations.
Exposed build server
A build system left open to the internet, publishing source code and configuration files, plus live API keys, to anyone who looked.
Cloud storage keys in public code
Storage credentials sitting inside a public JavaScript file, granting read and write access to a production storage account.
Debug mode left on in production
A live application exposing its database credentials, sign-in secrets, and API keys through a developer setting nobody turned off.
A chain of small flaws
Three low-severity issues combined into one real attack path through a client's firewall. Single-purpose scanners miss that kind of chain.
Weak access controls on an internal platform
Staff documents could be viewed and edited, and even exported, by people who should never have had access to them.
Client names, affected systems, and technical detail are never published. We share the class of issue and its impact, never anything that could help someone repeat it.