22/01/2026
2025 in review at FORTBRIDGE
A year of original security research, community, and sharing knowledge - across three continents.
๐๐ถ๐ด๐ต๐น๐ถ๐ด๐ต๐๐ ๐ณ๐ฟ๐ผ๐บ ๐ฎ๐ฌ๐ฎ๐ฑ
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต
This year we published and presented three original research projects , including:
โข ๐๐ฒ๐ฒ๐น๐ฑ ๐ฑ๐ฎ๐๐ถ๐ป๐ด ๐ฎ๐ฝ๐ฝ - critical issues exposing highly sensitive user data
โข ๐ฉ๐ฒ๐๐๐ฎ ๐๐ฑ๐บ๐ถ๐ป ๐ง๐ฎ๐ธ๐ฒ๐ผ๐๐ฒ๐ฟ - exploiting reduced seed entropy in bash RANDOM to achieve full control panel compromise
โข ๐๐ผ๐ป๐ฐ๐ฟ๐ฒ๐๐ฒ ๐๐ ๐ฆ: Two races, one RCE - two race conditions leading to remote code ex*****on.
Our work on Vesta was also nominated for ๐ฃ๐ผ๐ฟ๐๐ฆ๐๐ถ๐ด๐ด๐ฒ๐ฟ ๐ง๐ผ๐ฝ ๐ญ๐ฌ ๐ช๐ฒ๐ฏ ๐๐ฎ๐ฐ๐ธ๐ถ๐ป๐ด ๐ง๐ฒ๐ฐ๐ต๐ป๐ถ๐พ๐๐ฒ๐ ๐ผ๐ณ ๐ฎ๐ฌ๐ฎ๐ฑ, which weโre particularly proud of.
Our work was also covered by The Guardian and The Register, helping bring responsible security research into the mainstream.
๐๐ผ๐ป๐ณ๐ฒ๐ฟ๐ฒ๐ป๐ฐ๐ฒ๐ & ๐ฐ๐ผ๐บ๐บ๐๐ป๐ถ๐๐
We had the chance to present our research across the US, Canada, Europe, and Asia including:
โข ๐๐๐ฟ๐ผ๐ฝ๐ฒ: APIDays London, BSides Kent, BSides Bournemouth, BSides Bristol, SteelCon & DotNetSheff (Sheffield), BSides Budapest, BSides Dresden, BSides Galway, Pass the SALT Lille, Owasp Porto
โข ๐ก๐ผ๐ฟ๐๐ต ๐๐บ๐ฒ๐ฟ๐ถ๐ฐ๐ฎ: BSides Calgary, HackMiami, DEF CON 33 (Las Vegas)
โข ๐ ๐ถ๐ฑ๐ฑ๐น๐ฒ ๐๐ฎ๐๐: BlueHat (Tel Aviv)
๐๐ถ๐๐ถ๐ป๐ด ๐ฏ๐ฎ๐ฐ๐ธ & ๐๐ฟ๐ผ๐๐ถ๐ป๐ด ๐๐ต๐ฒ ๐ป๐ฒ๐
๐ ๐ด๐ฒ๐ป๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป
We worked with ๐๐ต๐ฟ๐ฒ๐ฒ ๐ถ๐ป๐๐ฒ๐ฟ๐ป๐ this year, focusing on hands-on offensive security, real-world tooling, and research workflows.
As part of giving back to the community, we also sponsored BSides Dresden, supporting independent, community-driven security events in Europe.
Thanks to everyone who attended our talks, asked tough questions, reviewed our research, or collaborated with us along the way - and to the organisations who trusted us with responsible disclosure and remediation.
Looking forward to building on this in 2026.
โ
FORTBRIDGE
*******ontesting