Independent security research

We find what attackers find first.

AF Digital Security is a research group studying how real systems fail under adversarial pressure — network infrastructure, embedded firmware, and the software supply chain behind them. We publish what we learn and work directly with the teams who need it.

signal / active research feed --:--:--
0
disclosures filed
0
active engagements
0
days avg. triage

01 — Research areas

Four domains, one adversarial mindset

Offensive research

Building and testing exploit chains against production-grade systems to understand what a capable attacker can actually do, not just what a scanner flags.

View domain →

Vulnerability disclosure

Coordinated reporting for vendors and open-source maintainers, from first reproduction through patch verification and public writeup.

View domain →

Threat intelligence

Tracking active campaigns and infrastructure to give clients early warning that's grounded in observed behavior, not vendor speculation.

View domain →

Applied cryptography

Auditing protocol implementations and key management systems where a subtle design error becomes a systemic failure.

View domain →

02 — How an engagement runs

From first hypothesis to verified fix

01

Discover

We map the target system's real attack surface — code paths, trust boundaries, and the assumptions its design depends on.

02

Analyze

Findings are reproduced independently and ranked by actual exploitability and business impact, not raw severity scores.

03

Disclose

We report privately to the owning team first, on a timeline we agree together, with full technical detail and a suggested fix.

04

Verify

Once a patch ships, we retest against the original proof of concept before the case is closed, not before.

03 — Recent advisories

Public writeups from closed cases

AFDS-2026-041 Auth bypass in a widely used VPN concentrator's session handling HIGH · CVSS 9.1 Aug 2026
AFDS-2026-037 Firmware downgrade path in an IoT gateway's update signing HIGH · CVSS 8.6 Jul 2026
AFDS-2026-029 Race condition in a CI provider's secret-scoping logic MEDIUM · CVSS 6.4 Jun 2026
View all advisories

04 — Track record

214
disclosures filed since founding
96%
patched within agreed timeline
11 days
average vendor triage time
40+
organizations advised

05 — Work with us

Get an outside perspective on your attack surface.

engage@afdigitalsec.com
Start an engagement