Without user interaction.
Investigating vulnerabilities in software that processes content automatically, with no action from the user.
Targeted research · Based in Australia
We discover security flaws in the applications and platforms people rely on every day, and take them through to full exploit chains. Our focus: widely deployed software, and zero-click and one-click attack surfaces.
Full-chain exploitationIoTMobileWeb
The public record
A core research specialism
Research across Word, Excel and shared document-processing components. Our published findings cover memory corruption, remote code execution and information disclosure.
Read about our Office researchRemote code execution
Remote code execution
Remote code execution
Disclosure record
Impactful CVEs in widely deployed products

Discovery, impact & disclosure
Full exploit chains across IoT, mobile
and web platforms with large user bases.
Investigating vulnerabilities in software that processes content automatically, with no action from the user.
Research into security flaws exposed when a user opens a document or follows a link in a widely used application.
Reverse engineering, root-cause analysis and reliable end-to-end exploitation across IoT devices, mobile platforms and web applications.
Published analysis
A deep dive into CVE-2023-39475 and CVE-2023-39476 — two critical (CVSS 9.8) deserialization vulnerabilities in Inductive Automation's Ignition SCADA platform that …
Read the analysisHow we discovered and exploited CVE-2023-28760, a stack-based buffer overflow in the MiniDLNA service on the TP-Link Archer AX20 router, during preparation for …
Read the analysisResearch enquiries
For commissioned research and technical collaboration.
TEC Security Research · research@tecsecurity.io
44BE DC3A 43B1 F394 BA67 2327 AF4A A46E 5093 3325