Clear your external findings backlog
How we broke the default sandboxes in Claude Code, Gemini CLI, and Codex — leaking credentials from all three, including a CVSS 10.0 chain. DefCon 2026 research.
How a CVSS 10.0 pre-task RCE in Google Gemini CLI ran attacker code before the sandbox started. No prompt injection required. Full DefCon 2026 research.
Novee Security reveals critical flaws in Anthropic, Google, and OpenAI coding agents, showing how zero-privilege inputs trigger remote code execution, data exfiltration, and supply chain compromise.
Novee Security researchers uncovered 12 vulnerabilities across major Enterprise Java platforms, demonstrating how unauthenticated attackers can exploit middleware components to achieve remote code execution.
We found the first 7 UXSS vulnerabilities through manual reverse engineering. Then, we formalized the patterns and pointed Novee at 20 Android apps. It found five more, plus a critical…
Dark Reading covered Novee Security's Cordyceps findings, highlighting how attackers can exploit CI/CD workflow weaknesses to hijack repositories at some of the world's largest organizations — no special privileges required.
Novee Security's research on Cordyceps CI/CD vulnerabilities was covered by The Hacker News — exposing how over 300 GitHub repositories, including those of Microsoft, Google, and Cloudflare, are vulnerable to…
Novee's research team discovered Cordyceps, a critical supply chain flaw hiding in plain sight, impacting code repositories at thousands of organizations, including Microsoft, Google, Apache, and Cloudflare.
Novee Security discloses CVE-2026-41241, a CVSS 8.7 stored XSS in pretalx that bypasses CSP and innerHTML defenses to achieve full account takeover — and shows why chained exploits break traditional…
Get the latest insights on AI, cybersecurity, and continuous pentesting delivered to your inbox