ShellvoideShellvoide

Offensive security, shown in full.

The Shellvoide security blog: AI-driven penetration testing, vulnerability research, and application security insights from the team behind KLUE.

Latest·

KLUE vs. a Hardened Target: One Bug, No Signature Required

A detailed bug bounty writeup. Our autonomous agent KLUE spent hours proving a hardened crypto-mining marketplace was hardened, then reverse-engineered its HMAC signing scheme, mapped a STOMP WebSocket buried in the authenticated app bundles, and discovered it performed no authentication at all, routing private per-tenant channels off a client-supplied parameter. An unauthenticated, cross-tenant data leak, responsibly disclosed and rewarded.

kluecase-studybug-bounty
Read more

More writeups

13 posts

Low, Medium, Critical: How Four Frontier Models Graded the Same Live Target

We ran KLUE against the same live production target four times, once each behind GLM 5.2, DeepSeek V4 Pro, Kimi K2.7 and Opus 4.8, all on an identical thirty minute budget. Same target, same clock, four risk verdicts from Low to Critical. A field report on what each model sees, what it walks past, whether it got the severity right, and why the cheapest run came back with the most.

ai-pentestingklue

Six CVEs in 163 Minutes: An Autonomous Pentest, Reasoning Included

We gave our autonomous pentesting agent, KLUE, one real engagement against a mature open-source codebase and 2 hours 43 minutes on the clock. It came back with six CVE-assigned vulnerabilities, including a chained second-order SQL injection and a template injection that reached a shell. This is the annotated reasoning trace.

kluecase-study

Crawling Isn't Attacking: A Live-Fire DAST Benchmark

We pointed OWASP ZAP, Burp Suite, Acunetix, and our own KLUE at the same live, deliberately-broken web app. Three of them crawled it and reported headers. One forged an admin token, dumped every user, and reset the admin password, all from two requests, unauthenticated. A field report on what dynamic scanners can and cannot reach.

dastdynamic-analysis

Four SAST Tools, One Broken App, and the AI That Hit Zero False Positives

A SAST benchmark on OWASP Juice Shop pitting Semgrep, SonarQube, and Snyk Code against KLUE, our autonomous source code analysis platform. The story is in the precision column, and in the vulnerability classes that have no pattern to match at all.

saststatic-analysis

Could Kimi K2.6 Hold Its Own Against Claude Opus on Real Pentest Work?

We ran four frontier models through the same autonomous pentest engagement. Recall, time to finish, and dollars per run all tell different stories, and Kimi K2.6 turned out to be the surprise on the leaderboard.

ai-pentestingklue

Inside a 61 Minute Pentest: How KLUE Found 11 Critical Flaws in a Public Sector Web Application

A case study from an autonomous AI pentest run by KLUE. Eleven confirmed findings in just over an hour, including a blind SQL injection that led to full database takeover. A practitioner walkthrough of the discoveries, the methodology, and the takeaways.

ai-pentestingsql-injection

Blockchain Fundamentals for Security Engineers: Web3 Security Mental Model

Blockchain fundamentals for security engineers covering cryptographic primitives, block structure, consensus (PoW/PoS), Web3 tooling, transaction anatomy, and core Web3 security concepts.

blockchainweb3

JWT Security Guide: Common JWT Vulnerabilities, Attacks, Exploits, and Defenses

A practical JWT security guide covering what JWT is, common JWT vulnerabilities, JWT attacks, exploit techniques, and defensive best practices for developers, pentesters, and API security teams.

jwt-securityapi-security

Want a run like this against your own stack?

Powered by KLUE and a certified team, Shellvoide finds the security gaps across your apps, cloud, and systems, and delivers full penetration tests in hours, not days, so you can fix what matters before anyone else finds it.