Turning Cluely Into Malware
How we found a vulnerability in Cluely's Electron app that let any website silently capture screenshots, record audio, and exfiltrate everything - all because of a missing will-navigate handler.
Connect your GitHub repository. Deploy Hacktron agents into your CI/CD pipeline within minutes.
Our agents analyze your code, uncover vulnerabilities, and triage them by impact.
Every vulnerability gets a working proof-of-concept. If we report it, we can break it.
Receive actionable patches via a pull request, and merge them into your codebase.
Cambridge CS dropout. Ex-TikTok and ex-military. DEF CON CTF runner-up (Blue Water) 2023-24. Credited for 15 CVEs. Topped Singapore's government and military bug bounties.
Ex-Cure53 Senior Security Researcher. Featured on PortSwigger & Vice. BlackHat & DEF CON speaker. Previously founded €1.5M revenue security auditing company.
Ex-ProjectDiscovery. Top-ranked bug bounty hunter. Featured in Forbes for hacking Apple. Ekoparty & BSides speaker.
Security educator with 1M+ YouTube followers. Cure53 Senior Auditor. Previously founded leading cybersecurity education platform.
Ex-Millennium, ex-Binance. Full-stack engineer across government, fintech, and leading startups in Asia. Graduate of Asia's #1 computer science university.
Ex-ProjectDiscovery. Expert in web security, patch analysis, and automation. Speaker at multiple security conferences such as Ekoparty, Hacktivity and NoNamecon.
We’re looking for world-class engineers and researchers. Please apply if you think you fit the bill.
APPLY
How we found a vulnerability in Cluely's Electron app that let any website silently capture screenshots, record audio, and exfiltrate everything - all because of a missing will-navigate handler.
Hacktron AI Research Team discovered a critical RCE in Google’s Antigravity IDE that lets attackers take over your system just by opening a malicious website.
Hacktron AI's agents identified a critical pre-authentication remote code execution (RCE) vulnerability in BeyondTrust Remote Support (RS) and older versions of Privileged Remote Access (PRA). This has been assigned CVE-2026-1731 with a CVSS 9.9 critical score.
If you're deeply motivated by building in a small team, high ownership, high impact environment where your code will directly help secure the world's best software companies against a generational threat, we want you to join us.