Hacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO

Latent Space
We found a flaw in Cluely. it's built to be invisible. that's the selling point. but think about it. an app nobody can see is also an app nobody can check. it had your screen and your mic. one missing guard meant a single click could've handed both to a stranger. no warning, no prompt. (found and patched back in 2025.) AI apps are getting deeper access every month, and almost nobody reviews what they're shipping. that's what we do. we check before it's watching you. full breakdown here: hacktron.ai/blog/hacking-clu…
1
38
2,850
oh wow!! agents scary!!! escaping sandboxes!! thermal side channels!! how about you let us try escaping your sandbox first? patch what we find, implement defense in depth, then we’ll see if your agents can do shit. be like vercel.
8
7
268
19,991
Google Chrome. Full break-in. Your product isn't secure. it's just been expensive to break. those are not the same thing, and a lot of founders are about to learn the difference. One AI just ran the full chain into Chrome for $1,597. weeks of expert human work, done for the cost of a weekend trip. The wall around your code was never "how good is this." it was "how much does it cost to find the crack." that cost is collapsing. If breaking in is getting this cheap, checking your own code before someone else does can't be the thing you skip. That's the gap we sit in. we run this on your code first. We published every number. Read the full benchmark: hacktron.ai/blog/watching-gp…
6
29
185
24,530
15
8
457
62,539
An OpenAI model hacked Hugging Face. Nobody wrote that exploit. Nobody asked for it. It was stuck on a challenge it couldn't solve, so it went looking for the answer somewhere else. Security has always assumed an attacker is a person. Someone with a motive, a budget, a reason to pick you. Threat models, red teams, patch cycles, all built on that. Two things just broke: → Intent is optional. It wasn't told to break in. That was just the shortest path to finishing the task → Patience is free. A model doesn't get tired or bored. Give it enough compute and it will read your entire codebase until it finds something Which is a rough spot for open source. If your code is public, it's already being read that way. So the question isn't "who would bother targeting us." It's "what happens when we're the easiest way for something to finish its job." That’s the gap we sit in. Hacktron reviews every code change before it ships, because the only thing fast enough to catch what AI breaks is AI. Read the full blog here {12 min read}: hacktron.ai/blog/here-is-how…
1
49
3,859
𝗛𝗮𝗰𝗸𝘁𝗿𝗼𝗻 𝗶𝘀 𝗻𝗼𝘄 𝗦𝗢𝗖 𝟮 𝗧𝘆𝗽𝗲 𝗜𝗜 𝗰𝗼𝗺𝗽𝗹𝗶𝗮𝗻𝘁 🎉 This means greater assurance over how we protect data and operate our systems. Next up: 𝗖𝘆𝗯𝗲𝗿 𝗧𝗿𝘂𝘀𝘁 𝗠𝗮𝗿𝗸, 𝗜𝗦𝗢 𝟮𝟳𝟬𝟬𝟭 𝗮𝗻𝗱 𝗖𝗥𝗘𝗦𝗧 as we continue strengthening the standards behind how we operate and deliver security services.
3
2
55
3,562
We Hacked OpenAI. Here's what didn't fit in 90 seconds: → OpenAI was only one target. It was part of a bigger research project we call the HEIF Heist → 2 months, 3 researchers, under $3,000 in AI tokens → The bug we used had already been fixed upstream. It just never got a CVE, so it never got patched downstream → The older Claude model got stuck. Claude Opus 5 cracked it within hours of release → OpenAI paid us $6,500 for the finding :). The scary part isn't OpenAI. They fixed it in 14 hours. It's every other company running the same image software, still unpatched, with no CVE telling them to care. Harsh, Mohan and Rahul wrote up everything. Visit - Hacktron.ai/blog/hacking-ope…
6
16
157
9,380
A single malicious image led to demonstrated access to an internal OpenAI repository 👇 This is the exploit chain that took our researchers from a vulnerable libheif dependency in the OpenAI Community forum to internal repo access. Full technical breakdown: hacktron.ai/blog/hacking-ope…
4
30
237
10,423
@mobbin achieves near-immediate triage with every pull request with Hacktron. In its first eight weeks, 21 findings reached a final verdict with a median triage time of 32 minutes. See how security review now keeps pace with code generation: hacktron.ai/customer-stories…
1
5
22
2,978
another one! if you’re running an Astro server, upgrade to the latest version, 7.2.8. It is all over the internet, please reach out to us if you need any details, for now we won't be disclosing the poc.
2
6
85
15,170
Our team discovered a critical remote code execution vulnerability in Next.js. If you self-host Next.js, update immediately. Vercel managed Next.js hosts are safe! We’ll publish the technical details and proof of concept soon!
20
65
479
109,241
Hacktron already reviews your code, detects real vulnerabilities, and learns from your feedback. Now it fixes the vulnerabilities too. Set the conditions once. When a new finding matches your rules, Hacktron automatically validates its exploitability, and generates a ready-for-review fix. You choose where the Automation runs, which findings qualify, and who gets notified. Like a real engineer, Hacktron understands your repositories, test suite, and tech stack, allowing it to execute and test your code end-to-end. That means fewer false positives, faster patches, and more time for your engineers to focus on shipping.
6
14
77
10,906
With the help of Hacktron, Novu catches second-order vulnerabilities across a codebase 400+ contributors touch, without adding process or noise fatigue. Around half the security issues found by Hacktron in the first 30 days were fixed, and 83% were actionable. It also found a high-severity NoSQL injection that could have led to an attacker viewing, editing, or deleting a conversation that wasn't theirs. Hacktron’s Review caught this by tracing the call chain across three files: the ingest controller that accepts the raw event payload, the type cast without deep validation, and the sink service that passes the unvalidated ID into the NoSQL query.
1
3
9
4,752
patch your wordpress. cve-2026-63030 is a pre-auth rce via sql injection. 6.8.5 and below: not affected 6.9.0–6.9.4: affected 7.0.0–7.0.1: affected props to our friends at @assetnote for the crazy find
5
56
308
40,047
The best conversations at @defcon never happen at DEF CON. They happen in a hallway with people who found each other by accident. So we're skipping to that part. On August 7, @HacktronAI and @osec_io are putting one private dinner together in Vegas. No pitches or slides. Just good food, a strong technical crowd and conversations a conference floor makes impossible. At the table: top bug bounty hunters, CTF players, and security leaders worth knowing. Friday, August 7 · 6:30 PM @ Las Vegas. Seats are limited and by request. If you're in town, tell us a bit about yourself. Link in comments.
2
4
25
7,570
GLM and DeepSeek are catching frontier models at finding vulnerabilities, and in some cases performing better than Opus 4.8. If open-weight models keep this trend for the next 6 months, we could move most of our workflow onto them and reserve frontier models for the critical parts: advising, orchestrating, and handling the hardest calls. At some point, excess intelligence becomes unnecessary for a lot of security workflows. Link below to read the blog.
3
13
1,711
there is no way you’re going to make people read all their AI-generated code. it was already cognitively hard to review PRs when your colleagues were writing the code. now it’s even harder when AI is generating half of it. you should just assume people won’t read everything and put checks in the PR that surface vulnerabilities where the real risk is.
2
3
8
2,100
Hacktron now powers security review for every pull request in @RocketChat. In the first 20 days of integration, Rocket․Chat has found and fixed 17 real vulnerabilities, including a critical-severity account takeover (CVE-2026-55666), and a token replay attack (CVE-2026-55759).
1
3
10
2,112
Almost every vulnerability we have exploited started as a pull request someone approved. That means your pull requests are not just code review events. They are security events too. Think about an open source project. A scanner finds a vulnerability and posts it right there as a public comment on the pull request: the full title, the description, the exact file and line. Great for the maintainer who has to fix it, but it’s also great for any hacker lurking around. The bug has been published before even closing it. So on public repos, Hacktron handles security issues differently. For findings outside the code a PR actually touched, the public comment shows only a link to view the details within the Hacktron platform. The real details stay private, visible to only the maintainers. Private and internal repos show full details as normal.
1
2
7
1,663
Hacktron x @krispHQ Krisp is deployed on 200M+ devices, processes 80 billion minutes of voice conversations every month, and powers Discord's built-in AI noise suppression. At that scale, security is not just an internal priority. It is critical to Krisp and the customers who rely on them. Like many security teams, Krisp relied on traditional SAST tools, but high alert volumes and false positives made it difficult to separate real risk from noise. As engineering teams began using AI to ship software faster, Krisp needed a way to catch meaningful vulnerabilities earlier in the development process without slowing developers down or changing how teams work. Learn why Krisp partnered with Hacktron to bring an AI-native security workflow to their SDLC. Link below👇
1
3
14
4,410
🚨 NPM supply chain alert  🚨 There is an active compromise affecting Immobiliare packages. Check your dependency tree, remove affected packages, and rotate any secrets exposed in affected environments. github.com/immobiliare/backs…
1
3
15
2,010
Introducing the Hacktron MCP. Give Claude Code, Codex, or Cursor a PR URL. With the Hacktron MCP, it will fetch the relevant security findings, write the fixes, and update Hacktron when the issue is resolved. All done before your coffee gets cold.
3
25
5,916
The outcome: a faster, more cost-effective security assessment that does not compromise on quality. This is not just checkbox compliance. Hacktron Whitebox helps teams generate evidence for SOC 2 and ISO 27001, while giving engineers valuable, actionable findings they can fix.
1
4
746
We also want to be clear: automated security testing still produces false positives. That's why every Hacktron Whitebox assessment is human-reviewed. Our team of world-class pentesters validates findings and confirms severity, so that reports are actually useful to engineers.
1
4
446
Whitebox compresses the traditional pentest cycle with AI-assisted security assessment. Because it works with source-code context, it can reason about the areas black-box testing often misses: business logic, auth boundaries, payment flows, and other complex vulnerabilities.
1
5
810
Introducing Hacktron Whitebox: get white-box security assessments with audit-ready reports without waiting on a traditional pentest cycle. AI has roughly tripled the rate of code shipped in the past year. But penetration testing has not kept pace, often taking weeks to months.
1
5
51
11,288
Hacktron Review plugs into your pull requests and catches exploitable vulnerabilities other scanners walk straight past. Find real security issues within 24 hours of onboarding. Try it free → hacktron.ai
3
10
2,635
what can go wrong?
This is a critical auth bypass (affecting GlobalProtect VPN), not sure why this was marked as high. I have already managed to get VPN access to major corps! Unlike the buffer overflow this isn't limited to PAN OS. Will be disclosing full details later next week on @HacktronAI blog. security.paloaltonetworks.co…
1
1
18
16,572
TL;DR: If a large model finds a 0day with 90% probability, and a small model with 50% probability, but the small model costs 10x less, it is better to use the small model.
1
7
967
Hacktron automatically closes issues once they’re fixed, keeping stale findings out of your backlog. It sends real-time alerts to Slack, and creates Linear tickets so remediation fits into the workflow your team already uses.
1
1
13
1,113
Hacktron behaves like a security engineer, getting sharper with every review. Triage comments and project context, including .hacktron/rules.md, help Hacktron understand your attack surface and threat model, so reviews become more specific to your codebase over time.
1
12
772
Agentic software engineering has expanded the attack surface. Security needs to keep pace. Hacktron finds real issues across the languages, frameworks, and application types that teams rely on — from web apps to native software, and from business logic flaws to supply chain risk.
1
14
1,100
Introducing Hacktron Review: an AI security reviewer for your pull requests. It understands your whole codebase, builds a threat model, takes your feedback, and catches exploitable vulnerabilities before they reach production. Try for free: app.hacktron.ai
22
42
285
72,333
As part of our efforts in securing open source, here's our latest finding: Pre-Auth RCE in OpenAM via jato.clientSession (CVE-2026-33439) hacktron.ai/blog/openam-dese…
2
16
64
5,035
Read the details of the bugs here. app.hacktron.ai/disclosed/pe…
2
29
5,185
We found a vulnerability in Cluely that could've turned it into malware. Link to blog in comments:
2
2
80
9,412
We found a RCE in Google's AI code editor Antigravity - $10000 Bounty Link to the blog in comments:
18
98
553
72,508
🚨 CVE-2026-1731 🚨 Our team discovered a critical pre-auth RCE affecting BeyondTrust Remote Support & Privileged Remote Access. SaaS/Cloud instances have been patched. If you're running self-hosted deployments, apply the patches immediately. More info in the comments.
3
63
242
36,084
We're excited to announce that Hacktron has successfully achieved compliance with the SOC 2 framework. By undergoing a comprehensive audit conducted by a reputable third-party firm, we have demonstrated our ability to effectively manage security risks and protect customer data. This allows us to work better with customers who require SOC 2 compliance, or are otherwise interested in our security posture. Because we build security software, we hold ourselves to the same standards we expect from every vendor we trust. Hacktron is built on dogfooding: we run our own product continuously across our entire software development lifecycle to surface vulnerabilities early and often. SOC 2 compliance is external validation of that discipline, and a signal to customers that our security posture, processes, and platform are designed to earn trust in real production environments. We extend our sincere appreciation to Insight Assurance for their thorough evaluation and validation of our compliance efforts, and Vanta for their platform and support.
2
4
22
2,211
Happy holidays! To celebrate the end of a great year, we are giving away 500 Hacktron CLI credits (worth $20) to 10 people! 1. Sign up to Hacktron 2. Run the Hacktron CLI on a codebase and give it a vulnerability research task 3. Share the bug you found on social media and tag us in the post This is a perfect chance to try out our new vulnerability scan planning and Hacktron Skills features! Winners will be announced next week. docs.hacktron.ai
1
4
36
4,110
Introducing a new way to control how vulnerability scanning tasks are done in the Hacktron CLI. When you give a security audit task to Hacktron in an interactive session, it enters deep vulnerability research mode. Hacktron automatically identifies and utilises the most suitable agents to perform the task. You can now customise this vulnerability scanning plan by editing both known patterns and AI-suggested ones. Happy holidays, and have fun hacking!
12
93
16,706
Some CLI announcements: - The newest version fixes a DNS resolution issue with macOS clients that prevents some users from logging in. Your client will auto-update to this version on its next startup. We apologise for the inconvenience and thanks for reporting this bug to us! - We've gotten some questions on purchasing credits. The free plan comes with 200 credits. You can track your usage at app.hacktron.ai/usage and upgrade to our Pro Plan at app.hacktron.ai/billing, which will give you much more credits to use for just $20/month. - We've released a new agent to check for CVE-2025-9501, a bug potentially affecting 1M+ WordPress installs. Our agent packs are updated by our research team continuously, allowing users to check whether the codebase is affected by a supply-chain issue or a new 0-day, and find variants of vulnerabilities in new codebases. Try it out with: hacktron --agent CVE-2025-9501
1
14
3,269
what are we flexing the new logo or the bounty?
5
4
219
35,101
Team Hacktron at @defcon! It was great to meet many of you and talk about the future of AI-powered security.
4
3
83
8,547
The Hack is Tron-ing at @defcon! Swing by C203 in Hall 4.
1
2
29
2,458
In the first cohort, we are joined by five other incredible teams. @Cerebionics @ZellifyApp @haicker_app zeroindustries.eu philon.ai
8
1,188
Hacktron is the first company to be backed by @ProjectEurope_, and we're incredibly excited to be part of the it's cohort. From the day we met the Project Europe and @20vcFund team, we knew that they were the kind of people we wanted on our side. We had an oversubscribed pre-seed and decided to work with Project Europe because we firmly believed in their mission. Here's a little bit more about us. • In the past, we've collectively done 500+ security penetration tests, and audited the products of many Fortune 500 companies. • Each of us has presented original research at conferences like DEF CON, Black Hat, and BSides. • Total ~1M followers on YouTube, X (Twitter), and LinkedIn. • Top competitive hacking (CTF) team in 2023, 2x DEF CON CTF runner-up. Hacktron will be the definition of offensive security. More to come — watch this space!
5
7
105
15,956
Anti-Cluely - the cheating detector suspect someone's using @cluely during interviews/calls? make them visit anticluely.hacktron.ai and find out in real-time. If you cheat, there should be an anti-cheat. The best hack is truth.
8
11
104
21,519
nothing to see here, just humans and AI working together to secure the world.
2
2
35
4,412