My First HammerCon: Reflections on a CTF Win

My First HammerCon: Reflections on a CTF Win

Overview Security Engineer Shoshana Makinen recounts her personal experience at her first Anvil HammerCon and the methodology she used to win the 2026 Capture the Flag challenge. Drawing upon her…
Exploiting AQL Injection Vulnerabilities in ArangoDB

Exploiting AQL Injection Vulnerabilities in ArangoDB

Overview In perhaps the first and most publicly comprehensive paper of its kind, Principal Security Engineer Daniel Kachakil explores how insecure handling of user input in ArangoDB's Query Language (AQL)…
AI at Anvil Secure: Evolving Technology. Unchanging Standards

AI at Anvil Secure: Evolving Technology. Unchanging Standards

By Dana Hehl Over the last few months, we’ve been asked some version of the same questions by customers, friends, and competitors: “Where are you guys on AI?” and “Do you use AI internally?”  The honest answer…
Reverse Engineering Garmin Watch Applications with Ghidra

Reverse Engineering Garmin Watch Applications with Ghidra

By Luigi Fragale Garmin smartwatches have quietly evolved into powerful embedded platforms. Beneath the fitness metrics, navigation features, and custom watch faces lie a proprietary Garmin Virtual Machine which executes…