THE LOGBOOK
Dispatches from
the breach.
Findings, releases, research, and the occasional time we made it onto the news. ▋
★ NEW RELEASE
Introducing Niro — the AI pentester that lives in your pull requests.
Niro reviews every PR, pentests the diff, and drafts the fix with your coding agent — so no security issue ever reaches production. Here's how we built it.
Jun 14, 2026·6 min read·Releases
niro › PR #418 ⚠ SQL injection videos.ts:42 › fix → claude-code ✓ patch committed ✓ re-tested · 0 findings status: SAFE TO MERGE ✓
⌖
RESEARCH
Three bugs, one chain: RCE on crAPI in under 2 hours.
How Cipher reasoned its way from mass assignment to a full server shell.
Jun 02, 2026 · 5 minPREVIEW
📰
IN THE NEWS
"We rob you first" — APX raises the stakes on AI pentesting.
Coverage of our approach to offensive security for the AI era.
May 09, 2026 · 3 minPREVIEW
💭
PERSPECTIVE
A finding without an exploit is just an opinion.
Why we refuse to ship a report we can't prove with working code.
Apr 28, 2026 · 4 minPREVIEW
⚙️
ENGINEERING
Niro now drafts fixes with Claude Code, Codex & Copilot.
Bring your own agent — Niro hands it a ready patch and re-tests the result.
Apr 12, 2026 · 5 minPREVIEW
🏦
CASE STUDY
"Cipher found an auth bypass three pentests missed."
How a fintech got robbed first — and patched before anyone else tried.
Mar 30, 2026 · 6 minPREVIEW
subscribe --to dispatches
Get robbed in your inbox.
New findings, releases, and research. No noise.
$ you@company.com
Subscribe →