// research archive

Research

Case studies show the affected boundary, root cause, validation method, practical impact, disclosure status, and remediation. Working exploit material stays out of the public record until coordinated disclosure is complete.

Research domains

Trust boundaries across connected systems.

01

AI Infrastructure

Model serving, inference systems, AI SDKs, agents, remote resources, model loading, cloud integrations, and isolation boundaries.

02

Robotics & Distributed Systems

Workload orchestration, distributed control, authorization boundaries, messaging infrastructure, robotics middleware, and component-to-component trust.

03

IoT & Industrial Systems

Embedded and connected devices, industrial software, firmware, device-management tools, network services, management interfaces, certificate validation, device communication, edge infrastructure, and supporting protocols.

04

Open Source Infrastructure

Security-sensitive libraries, container systems, parsers, protocols, package handling, cryptographic validation, and other upstream infrastructure.

IoT & Industrial Research

Active research

Current work examines security boundaries in connected and industrial systems, including management applications, firmware, embedded software, network-facing services, certificate validation, device protocols, and cloud-connected edge components.

Published industrial research includes two Lantronix G520 vulnerabilities disclosed through CISA, with researcher credit in ICS Advisory ICSA-26-272-01 and vendor remediation.

Only publicly disclosed vulnerabilities appear as individual case studies. Findings still under vendor or coordinator review remain private until disclosure is complete.

01 / MLflowPublished | CVE-2026-64849 | Critical 9.3

Unauthenticated full-read SSRF in webhook delivery

A Critical SSRF flaw let an unauthenticated caller cross the MLflow server network boundary through webhook redirects and DNS rebinding.

Read case study
02 / Lantronix G520Published | CISA ICSA-26-272-01 | 2 CVEs

Update integrity and package authenticity in an industrial gateway

Two vulnerabilities in the Lantronix G520 update and package-handling mechanisms could allow arbitrary code execution under the conditions described by CISA. The disclosure resulted in two CVEs, a public CISA ICS advisory, and vendor remediation.

Read case study
03 / Eclipse AnkaiosPublished | CVE-2026-84173 | High 8.3

Authorization bypass in workload control rules

A flaw in the agent-side Control Interface authorizer allowed a scoped workload to access or modify cluster state outside its authorized subtree.

Read case study
04 / vLLMPublished | CVE-2026-73560 | Moderate 6.5

Multimodal media path bypassed hardened retrieval controls

A model-specific multimodal processor bypassed centralized media-retrieval protections, exposing network and local-file trust boundaries.

Read case study
05 / Google GenkitGoogle Cloud VRP recognition

Provider endpoint trust-boundary failure

SSRF, API-key exposure, and response forgery were validated in an AI SDK integration that accepted a caller-influenced provider endpoint.

Read case study
06 / LMDeployPublished | CVE-2026-46517 | High

Unsafe remote-code trust during model initialization

LMDeploy enabled Hugging Face remote code by default during model loading, removing the operator decision that peer inference systems expose as an explicit opt-in.

Read case study