Skip to content
New kind of attack — caught and fixed before it was publicly known·Read the timeline
Research & disclosure

We find what others miss, and ship the fix before the CVE is filed.

Research, open-source disclosures, and upstream fixes — the full record of everything we've shipped. Back to the overview →

Catching known attacks is table stakes. The real signal is finding attack classes nobody has named yet: this URL-smuggling trick is the first of a research pipeline, not a one-off.

Apr 23New vulnerability class found: a URL-smuggling trick (no public advisory yet)
Apr 25Disclosed to the upstream security team
Apr 30Shipped MIT-licensed detection rules, before any advisory
May 4Opened the same rules as upstream pull requests to CodeQL and Semgrep, under review
NextMore disclosures as we map the agent attack surface
Open source & disclosure

Real bugs, fixed in the open.

We found a brand-new way to smuggle a banned web address past a security check — no name, no public record until we named it. One discovery, six public moves: free rules released, fixes merged into the scanners developers run, and the report sent upstream first.

Hover over (or tap) the i on any card for a plain-English explanation of what it is and why it matters.

Open-sourced detection library

We found a new way to sneak a banned IP address past a security check, then open-sourced the rules to catch it. Free for anyone to use.

astrogilda/idna-ip-literal-smuggle-rules · MIT

Detection rule shipped to CodeQL

We added a rule to GitHub's own code-scanner so it flags this attack for every project that runs it. The change is public.

github/codeql · PR #21784

Detection rule shipped to Semgrep

We gave the same catch to Semgrep, the scanner millions of developers run outside GitHub, so it becomes a default there too.

semgrep/semgrep-rules · PR #3841

Bug fix shipped to the A2A agent SDK

While stress-testing agent-to-agent protocols we found the official A2A toolkit leaking background tasks on shutdown, and sent the fix upstream ourselves.

a2aproject/a2a-python · PR #1105

Auto-fixer contributed to gopatch

We wrote a tool that automatically rewrites vulnerable Go code to add the missing check, and sent it to Uber's gopatch project.

uber-go/gopatch · PR #186

Reported upstream to the Go team

We told Go's security team first; they called it the caller's job to guard, so we shipped the public rules ourselves.

security@golang.org · disclosed Apr 2026

Get this depth on your own pipeline.

The same research that finds these attack classes ships in the Gate. Request access, or re-verify a signed verdict yourself first.

Get access

Run your agents through Probity.

A few details about your setup and we'll get you gating agents fast.