Security Research

Vulnerability Research & Disclosures

Original security research from the SableOffensive team. We find vulnerabilities in AI infrastructure and modern web applications, and track real-world exposure of critical CVEs, so you can build safer products.

HIGH 8.8

Chrome Zero-Days in Skia and V8: 3.5B Users Affected

CVE-2026-3909 and CVE-2026-3910 -- Actively Exploited, Patched in Chrome 146

Two actively exploited zero-days hit Chrome: CVE-2026-3909 (Skia memory corruption) and CVE-2026-3910 (V8 type confusion). A single malicious page could trigger arbitrary code execution on Windows, macOS, and Linux. Both are patched in Chrome 146.

3.5B+
Chrome Users
2
Zero-Days
Chrome 146+
Patched
CVEBrowserZero-DayHigh
Read Full Report
HIGH 8.6

Crunchyroll Breach: 6.8M Users Exposed via Supply Chain

One Compromised BPO Employee, 100GB Exfiltrated in 24 Hours

Malware on a Telus International BPO employee's workstation led to stolen Okta session tokens, granting attackers access to Crunchyroll's Zendesk platform. 6.8 million user records -- emails, IP addresses, and partial card details -- were exfiltrated in under 24 hours.

6.8M
Users Exposed
100GB
Data Stolen
1
Compromised Employee
Data BreachSupply ChainOktaBPO
Read Full Report
CRITICAL 9.8

DarkSword: iOS Zero-Day -- Visit a Website, Lose Your iPhone

6-Vulnerability Chain, Zero Clicks, 270M iPhones Affected

DarkSword chains 6 vulnerabilities (3 zero-days), including CVE-2025-31277, to compromise iPhones on iOS 18 with zero clicks -- just by visiting a website. Discovered by Google GTIG and linked to Russian state actors and commercial spyware vendors. Patched in iOS 18.7.5.

270M
iPhones Vulnerable
6
Vulns Chained
9.8
CVSS Score
CVEiOSZero-ClickCritical
Read Full Report
HIGH 9.2

6 Startups Scanned, 47 Vulnerabilities Found

Real Pentest Results — No Brand Names, Just Stacks and Findings

We performed free security assessments for 6 real startups across different industries. We found 47 vulnerabilities — including a fully compromised server, SSRF via known CVEs, exposed Discord webhooks, and leaked API keys. Every single startup had at least one high-severity issue.

6
Startups Scanned
47
Vulnerabilities
100%
Had High+ Issues
PentestStartupsOWASPReal Data
Read Full Report
CRITICAL 9.8

CVE-2026-22778 (Orca Security): vLLM RCE Exposure Analysis

Send a Video, Get a Shell — Our Exposure Recon on a Critical vLLM Bug

Orca Security discovered a critical Remote Code Execution vulnerability in vLLM (versions 0.8.3 through 0.14.0), exploitable via malicious video input. Our own exposure analysis found over 175,000 unpatched servers still reachable across 130 countries with no authentication required.

175K+
Servers Exposed
9.8
CVSS Score
130
Countries
CVERCEExposure AnalysisAI/MLCritical
Read Full Report
HIGH 8.8

OpenClaw Security Research: 900+ Exposed Instances

Same Vulnerabilities, New Name

Comprehensive security audit of OpenClaw (formerly Moltbot/Clawdbot) reveals 900+ exposed instances, 8 critical vulnerabilities including an unprompted gateway WebSocket connection (CVE-2026-25253), and 181 leaked secrets across the ecosystem.

900+
Instances Exposed
8
Critical Vulns
181
Secrets Leaked
CVEAuth BypassAI AgentsCritical
Read Full Report
HIGH 8.8

1,673 AI Gateways Exposed: Moltbot Research

The Original Discovery

Our initial research uncovered 1,673 exposed Moltbot/Clawdbot servers via Shodan. Over 1,000 instances lacked authentication entirely, exposing 55 RPC methods including arbitrary shell command execution.

1,673
Servers Found
1,000+
Without Auth
3
CVEs Found
ShodanRPCAI GatewaysHigh
Read Full Report

Concerned About Your Security?

The vulnerabilities we find in the wild exist in startups too. Get your application scanned before someone else finds the flaws.

Get a Security Scan