Targeted research · Based in Australia

Vulnerability Research
for widely used products

We discover security flaws in the applications and platforms people rely on every day, and take them through to full exploit chains. Our focus: widely deployed software, and zero-click and one-click attack surfaces.

Full-chain exploitationIoTMobileWeb

Microsoft Security Response Center
2023

Top 3 Microsoft Office security researchers

Rocco CalviFounder, TecSecurity

Recognised for contributions to Office security.

16 Microsoft Office
CVEs published
View Microsoft’s recognition
ZDI Zero Day Initiative · Trend Micro
2025

Ranked 1st Most Prolific Researcher 2025 ZDI Vanguard Award

Rocco CalviFounder, TecSecurity

Recognised for the highest number of contracted vulnerability cases.

300+ RCE vulnerabilities
reported
Read about the Vanguard Award
358Published advisories 300+RCE vulnerabilities reported 18+Years publishing research 2025 ZDI Vanguard AwardMost Prolific Researcher Rocco Calvi · Founder, TecSecurity

The public record

Recent CVE disclosures

All 358 advisories

A core research specialism

Deep experience in
Microsoft Office.

Research across Word, Excel and shared document-processing components. Our published findings cover memory corruption, remote code execution and information disclosure.

WordExcelOffice graphics
Read about our Office research

Disclosure record

Impactful CVEs in widely deployed products

  • Microsoft
  • Apple
  • Google
  • Meta
  • Adobe
  • Siemens
  • TP-Link
  • Autodesk
  • NVIDIA
  • Foxit
  • Schneider Electric
  • IBM
  • Rockwell Automation
  • Inductive Automation
  • NETGEAR
  • Mozilla
  • Trimble

Discovery, impact & disclosure

Research where exposure matters.

Full exploit chains across IoT, mobile
and web platforms with large user bases.

0-click research

Without user interaction.

Investigating vulnerabilities in software that processes content automatically, with no action from the user.

1-click research

One interaction. Real impact.

Research into security flaws exposed when a user opens a document or follows a link in a widely used application.

Full-chain exploitation

From discovery to a working chain.

Reverse engineering, root-cause analysis and reliable end-to-end exploitation across IoT devices, mobile platforms and web applications.

Published analysis

Selected technical research

All publications

Research enquiries

Discuss a research engagement.

For commissioned research and technical collaboration.

research@tecsecurity.io Download PGP public key
Verify key fingerprint

TEC Security Research · research@tecsecurity.io

44BE DC3A 43B1 F394 BA67 2327 AF4A A46E 5093 3325