We research the 1-day
The 1-day is the interval between a patch landing and widespread exploitation - defenders racing to deploy, attackers racing to reverse-engineer. We sit in the middle: analyzing, documenting, publishing.
Not a patch-diff feed. We turn CVE claims into evidence and go past the single bug to the techniques behind it - and we are building a community of practitioners to share methods and argue findings in public.
ÂLIM analyses CVEs on its own.
ÂLIM is our AI-driven analysis engine. Point it at a disclosed CVE in open-source software and it works the flaw end to end without an analyst driving each step: it studies the vulnerability, rebuilds it in an isolated containerised lab, develops a working proof-of-concept, and validates that exploit against both the vulnerable and the patched build.
That last part is the point. A result is only reported once the exploit has been shown to fire on the unpatched build and to stop working on the fixed one - so what we publish is demonstrated, not asserted.
The latest from the lab.
Each write-up follows a disclosed CVE from the patch to the root cause in the source, and ends with a proof-of-concept we have actually run - against the vulnerable build and the fixed one. The full archive lives in the blog.
| 2026-08-27 | CVE-2026-77998 | CVE-2026-77998: miniOrange SAML - Joomla Auth Bypass | PoC | |
| 2026-08-25 | CVE-2026-10053 | CVE-2026-10053: GitLab npm Path Traversal RCE | PoC | |
| 2026-08-25 | CVE-2026-18963 | CVE-2026-18963: Keycloak - Auth Bypass | PoC |
Found something? Want to publish with us?
Send us a write-up, a CVE worth analysing, or a correction to something we published - corrections are welcome and credited. For sensitive reports, use our PGP key. If you would like to support the project, the same address reaches us.

