exploit-forge

2 articles in this topic.

March 2026

2 articles
  1. CVE-2026-24289: Windows Kernel IOCP Race Condition - The Ghost We Proved by Salting the Circle

    WinForge's maiden voyage: a brand new pipeline module - QEMU VMs instead of Docker, WinDbg instead of GDB, binary diffing instead of source - pointed at a use-after-free in ntoskrnl.exe. 363 functions changed between builds, 8 needles in the haystack, and a PoC that ran 500,000 iterations without crashing. Because that was the point.

    20 min read
  2. Six AI Agents, One Security Company: The Paperclip AI Experiment

    We used Paperclip AI to stand up a six-agent AI company that now runs our exploit research pipeline almost entirely on autopilot - CVE candidate selection, forge dispatch, results collection, and SEO all managed autonomously. A CEO, a security researcher, a software engineer, a QA reviewer, a research intern, and a pipeline operator - all AI agents. They refactored four codebases into a clean monorepo, hardened the security, and built the MCP tools that now let the whole chain run without us touching a terminal. Four days, 135 issues, $180. The $1.38 QA agent found a bypass in the $115 engineer's security fix. This is the full story of the Paperclip AI experiment.

    22 min read