The Anvil Signal

Sign up to receive the latest technical research, tool releases, whitepapers, and security insights from our team.

No spam. Unsubscribe anytime.

Recent Research & Insights
Passkey Editor: a Burp Suite Extension for Attacking WebAuthn
August 10, 2026
Security Engineer Matteo Giordano introduces Passkey Editor, a Burp Suite extension that decodes and edits WebAuthn ceremonies, drives one-click attacks against them, and re-signs across eleven COSE algorithms, all inside Burp itself.
Internal AI Adoption Hackathon: What We Learned
July 22, 2026
Anvil Secure's internal AI adoption hackathon gave engineers dedicated time to explore practical AI use cases. Technical Director Antonios Papadopoulos shares what the team learned and what comes next.
Identifying and Chasing RCE in SAP’s CommonCryptoLib
July 16, 2026
Director of Research Tao Sauvage shares the latest chapter in his SAP research, chasing a bug from SAP's archive tool into CommonCryptoLib, a flaw reachable before authentication on SAP HANA. He breaks down the root cause and his attempts to exploit it.
Finding Crown Jewels: Hunting Through 180,000 Ruby Gems
June 17, 2026
CTO Vincent Berg mirrored more than 180,000 Ruby gems and built a scanner to analyse them at scale. What he uncovered offers a fascinating look at the hidden risks and exposed data scattered throughout the Ruby ecosystem.
Passkey Editor: a Burp Suite Extension for Attacking WebAuthn
August 10, 2026
Security Engineer Matteo Giordano introduces Passkey Editor, a Burp Suite extension that decodes and edits WebAuthn ceremonies, drives one-click attacks against them, and re-signs across eleven COSE algorithms, all inside Burp itself.
Internal AI Adoption Hackathon: What We Learned
July 22, 2026
Anvil Secure's internal AI adoption hackathon gave engineers dedicated time to explore practical AI use cases. Technical Director Antonios Papadopoulos shares what the team learned and what comes next.
Identifying and Chasing RCE in SAP’s CommonCryptoLib
July 16, 2026
Director of Research Tao Sauvage shares the latest chapter in his SAP research, chasing a bug from SAP's archive tool into CommonCryptoLib, a flaw reachable before authentication on SAP HANA. He breaks down the root cause and his attempts to exploit it.
Finding Crown Jewels: Hunting Through 180,000 Ruby Gems
June 17, 2026
CTO Vincent Berg mirrored more than 180,000 Ruby gems and built a scanner to analyse them at scale. What he uncovered offers a fascinating look at the hidden risks and exposed data scattered throughout the Ruby ecosystem.
Passkey Editor: a Burp Suite Extension for Attacking WebAuthn
August 10, 2026
Security Engineer Matteo Giordano introduces Passkey Editor, a Burp Suite extension that decodes and edits WebAuthn ceremonies, drives one-click attacks against them, and re-signs across eleven COSE algorithms, all inside Burp itself.
Internal AI Adoption Hackathon: What We Learned
July 22, 2026
Anvil Secure's internal AI adoption hackathon gave engineers dedicated time to explore practical AI use cases. Technical Director Antonios Papadopoulos shares what the team learned and what comes next.
Identifying and Chasing RCE in SAP’s CommonCryptoLib
July 16, 2026
Director of Research Tao Sauvage shares the latest chapter in his SAP research, chasing a bug from SAP's archive tool into CommonCryptoLib, a flaw reachable before authentication on SAP HANA. He breaks down the root cause and his attempts to exploit it.
Finding Crown Jewels: Hunting Through 180,000 Ruby Gems
June 17, 2026
CTO Vincent Berg mirrored more than 180,000 Ruby gems and built a scanner to analyse them at scale. What he uncovered offers a fascinating look at the hidden risks and exposed data scattered throughout the Ruby ecosystem.