Passkey Editor: a Burp Suite Extension for Attacking WebAuthn
By Matteo Giordano This tool, Passkey Editor, comes out of the same work as the Demystifying Passkeys Under the Hood series: The Protocol (ceremonies at the byte level), The Architecture,…
Internal AI Adoption Hackathon: What We Learned
By Antonios Papadopoulos Overview Anvil Secure's Technical Director, Antonios Papadopoulos, breaks down how the company ran a remote, company-wide AI Adoption Hackathon: two cohorts, dedicated build days, tracks drawn from…
Identifying and Chasing RCE in SAP’s CommonCryptoLib
By Tao Sauvage Overview In his third SAP blog post, Anvil Secure's Director of Research, Tao Sauvage, explores how a low-speed fuzzing target became a focused custom harness and why…
Finding Crown Jewels: Hunting Through 180,000 Ruby Gems
Overview Anvil CTO, Vincent Berg, pointed a homemade scanner at nearly 180,000 Ruby gems and started pulling on threads when he found something funny. What started as a simple experiment…
How We Use LLMs in Secure Code Review
By Tao Sauvage Overview This post explains how Anvil Secure uses LLMs as analyst-guided tools during secure code review engagements, not as autonomous reviewers. It covers the process-focused workflow, its…
How We Test AI: LLM & GenAI Security Methodology at Anvil Secure
By George Damiris Overview The company's methodology for testing LLM and GenAI services is based on industry best practices as well as hands-on experience testing AI agents and models across…
Demystifying Passkeys โ Under the Hood: The Architecture
By Matteo Giordano A three-part series on passkeys for security engineers and offensive security specialists. You are reading the second blogpost. Under the Hood: The Protocol. How passkey ceremonies work…
Demystifying Passkeys โ Under the Hood: The Protocol
By Matteo Giordano A three-part series on passkeys for security engineers and offensive security specialists. You are reading the first blogpost. Under the Hood: The Protocol. How passkey ceremonies work…
Introducing OffTempo, Statistical Timing Side-Channel Analysis for Burp Suite
Overview Introducing OffTempo, a new no-configuration Burp Suite extension designed to assist pentesters as they perform timing-based attacks. In this post, Senior Security Engineer Riccardo Nannini walks through OffTempo's ability…

