The Anvil Signal

Sign up to receive the latest technical research, tool releases, whitepapers, and security insights from our team.

No spam. Unsubscribe anytime.

Recent Research & Insights
Predictable Usernames and Passwords | Field Notes, Issue 1
October 5, 2026
During a code review of a healthcare platform's temporary account system, we found predictable usernames and passwords generated from the same weak random string. Read why the two weren't actually independent, and why fixing the RNG wouldn't have solved it.
Demystifying Passkeys — Under Attack (Whitepaper)
October 1, 2026
In Part 3 of a three-part series, Security Engineer Matteo Giordano maps the passkey attack surface in a downloadable whitepaper, covering authenticators, hybrid transport, clients, relying parties, sync fabric, and recovery, plus a test-case reference for pentesters.
Introducing PQCDump: A Real Look at PQC Adoption
September 9, 2026
Senior Security Engineer Nicholas O'Shea introduces PQCDump, a passive analysis tool that parses SSH and TLS captures to show what post-quantum algorithms were actually negotiated, not just advertised, giving a fuller picture of real-world PQC adoption than active scanning alone.
Passkey Editor: a Burp Suite Extension for Attacking WebAuthn
August 10, 2026
Security Engineer Matteo Giordano introduces Passkey Editor, a Burp Suite extension that decodes and edits WebAuthn ceremonies, drives one-click attacks against them, and re-signs across eleven COSE algorithms, all inside Burp itself.
Predictable Usernames and Passwords | Field Notes, Issue 1
October 5, 2026
During a code review of a healthcare platform's temporary account system, we found predictable usernames and passwords generated from the same weak random string. Read why the two weren't actually independent, and why fixing the RNG wouldn't have solved it.
Demystifying Passkeys — Under Attack (Whitepaper)
October 1, 2026
In Part 3 of a three-part series, Security Engineer Matteo Giordano maps the passkey attack surface in a downloadable whitepaper, covering authenticators, hybrid transport, clients, relying parties, sync fabric, and recovery, plus a test-case reference for pentesters.
Introducing PQCDump: A Real Look at PQC Adoption
September 9, 2026
Senior Security Engineer Nicholas O'Shea introduces PQCDump, a passive analysis tool that parses SSH and TLS captures to show what post-quantum algorithms were actually negotiated, not just advertised, giving a fuller picture of real-world PQC adoption than active scanning alone.
Passkey Editor: a Burp Suite Extension for Attacking WebAuthn
August 10, 2026
Security Engineer Matteo Giordano introduces Passkey Editor, a Burp Suite extension that decodes and edits WebAuthn ceremonies, drives one-click attacks against them, and re-signs across eleven COSE algorithms, all inside Burp itself.
Predictable Usernames and Passwords | Field Notes, Issue 1
October 5, 2026
During a code review of a healthcare platform's temporary account system, we found predictable usernames and passwords generated from the same weak random string. Read why the two weren't actually independent, and why fixing the RNG wouldn't have solved it.
Demystifying Passkeys — Under Attack (Whitepaper)
October 1, 2026
In Part 3 of a three-part series, Security Engineer Matteo Giordano maps the passkey attack surface in a downloadable whitepaper, covering authenticators, hybrid transport, clients, relying parties, sync fabric, and recovery, plus a test-case reference for pentesters.
Introducing PQCDump: A Real Look at PQC Adoption
September 9, 2026
Senior Security Engineer Nicholas O'Shea introduces PQCDump, a passive analysis tool that parses SSH and TLS captures to show what post-quantum algorithms were actually negotiated, not just advertised, giving a fuller picture of real-world PQC adoption than active scanning alone.
Passkey Editor: a Burp Suite Extension for Attacking WebAuthn
August 10, 2026
Security Engineer Matteo Giordano introduces Passkey Editor, a Burp Suite extension that decodes and edits WebAuthn ceremonies, drives one-click attacks against them, and re-signs across eleven COSE algorithms, all inside Burp itself.