Introducing Hacktron Review
Hacktron Review is an AI security reviewer for pull requests that understands codebase context, reduces false positives, and catches exploitable vulnerabilities before they are merged.
Continuously surfaces exploitable vulnerabilities in pull requests, with enough context for your security team to triage and prioritize without chasing down developers.
$40/ developer / mo.
Detect vulnerabilities automatically in your development workflow.
Start 14-Day Free TrialUnlimited PR security reviews for your entire team
Fix with AI using prompts delivered in PR comments
Auto-assigns coverage to new developers on their first PR
GitHub, GitLab, and Bitbucket integrations
Enterprise-grade modules with custom rule configuration per repo
Custom integrations with your existing security toolchain
SSO, audit logs, and role-based access controls
24/7 priority support with a dedicated account team
HTAI-001
Pre-Authentication Remote Code Execution via deserialization vulnerability in BeyondTrust Remote Support and Privileged Remote Access (PRA) products.
Hacktron Review is an AI security reviewer for pull requests that understands codebase context, reduces false positives, and catches exploitable vulnerabilities before they are merged.
I pointed Claude Opus at Discord's bundled Chrome (version 138, nine major versions behind upstream) and asked it to build a full V8 exploit chain. The V8 OOB we used was from Chrome 146, the same version Anthropic's own Claude Desktop is running. A week of back and forth, 2.3 billion tokens, $2,283 in API costs, and about ~20 hours of me unsticking it from dead ends. It popped calc.
Hacktron AI discovers a critical pre-authentication RCE in OpenAM through a forgotten deserialization parameter that the original CVE-2021-35464 fix missed.
Cloudflare built a Next.js replacement in a week with AI for $1100. We pointed Hacktron at it to find what the tests missed.