My First HammerCon: Reflections on a CTF Win
Overview Security Engineer Shoshana Makinen recounts her personal experience at her first Anvil HammerCon and the methodology she used to win the 2026 Capture the Flag challenge. Drawing upon her…
Exploiting AQL Injection Vulnerabilities in ArangoDB
Overview In perhaps the first and most publicly comprehensive paper of its kind, Principal Security Engineer Daniel Kachakil explores how insecure handling of user input in ArangoDB's Query Language (AQL)…
AI at Anvil Secure: Evolving Technology. Unchanging Standards
By Dana Hehl Over the last few months, we’ve been asked some version of the same questions by customers, friends, and competitors: “Where are you guys on AI?” and “Do you use AI internally?” The honest answer…
Reverse Engineering Garmin Watch Applications with Ghidra
By Luigi Fragale Garmin smartwatches have quietly evolved into powerful embedded platforms. Beneath the fitness metrics, navigation features, and custom watch faces lie a proprietary Garmin Virtual Machine which executes…
Locked Up But Not Locked Out: iOS App Pentesting Without Jailbreak
By Anatolii Shatylo TL;DR This post covers the core steps needed to decrypt and re-sign iOS apps so they can be tested in a non-jailbroken (jailed) environment. We'll also introduce…
Breaking SAPCAR: Four Local Privilege Escalation Bugs in SAR Archive Parsing
By Tao Sauvage Earlier this year, I published a blog post discussing two SAP vulnerabilities I found during a client engagement, as part of a friendly competition with my CTO…
Cross-Site Scripting Vulnerabilities in jSuites Components
By Daniel Kachakil JSuites is an open-source collection of web components and JavaScript plugins, including HTML Editor, Calendar, Image Cropper, Tabs, among others. I came across some of these components…
Introducing ByteBanter, an LLM based BurpSuite Intruder Payload Generator
By Andrea Braschi TL; DR The problem: Testing LLM security could be difficult, time-consuming, and sometimes could lead to non-deterministic findings. The solution: One possible solution could be to use…
Cybersecurity for Satellites — New Whitepaper from Anvil Secure and D-Orbit
The commercial space sector is scaling fast, and security needs to keep pace. In this new joint whitepaper, Anvil Secure and D-Orbit map the core cyber risks facing satellites and…

