Independent security research
We find what attackers find first.
AF Digital Security is a research group studying how real systems fail under adversarial pressure — network infrastructure, embedded firmware, and the software supply chain behind them. We publish what we learn and work directly with the teams who need it.
01 — Research areas
Four domains, one adversarial mindset
Offensive research
Building and testing exploit chains against production-grade systems to understand what a capable attacker can actually do, not just what a scanner flags.
View domain →Vulnerability disclosure
Coordinated reporting for vendors and open-source maintainers, from first reproduction through patch verification and public writeup.
View domain →Threat intelligence
Tracking active campaigns and infrastructure to give clients early warning that's grounded in observed behavior, not vendor speculation.
View domain →Applied cryptography
Auditing protocol implementations and key management systems where a subtle design error becomes a systemic failure.
View domain →02 — How an engagement runs
From first hypothesis to verified fix
Discover
We map the target system's real attack surface — code paths, trust boundaries, and the assumptions its design depends on.
Analyze
Findings are reproduced independently and ranked by actual exploitability and business impact, not raw severity scores.
Disclose
We report privately to the owning team first, on a timeline we agree together, with full technical detail and a suggested fix.
Verify
Once a patch ships, we retest against the original proof of concept before the case is closed, not before.
03 — Recent advisories
Public writeups from closed cases
04 — Track record