By simulating advanced persistent threats, we put your security measures to the test, revealing real-world risks and enhancing your response strategies.
Learn more about Red TeamTo foresee is to protect. We develop strategies that keep your team always ahead of new cyber threats.
More than a team, a revolution in bits and bytes. We challenge, endure, and evolve together.
Hakai is a cybersecurity company founded by experienced specialists.
We prioritize technical excellence and provide customized services with the latest attack techniques, threat detection and monitoring technologies, as well as secure development procedures to minimize or prevent new vulnerabilities.
Get in TouchDiscover our services
Excellence in cybersecurity: Pentest, Red Team, DevSecOps, and specialized services leading your digital defense.
Some of our clients
Don't wait to be the target! Invest in your peace of mind and in the success of your company's and your customer's data.
Big projects done
Here we highlight some of the main CVEs and Vulns that we've found.
- Trend Micro
-
Hall Of Fame 2016 and 2019 at Trend Micro
- D-Link
-
CVE-2017-11436 - Hidden Backdoor User - D-Link
- NXfilter
-
CVE-2023-3840 (XSS relfected - NXfilter)
CVE-2023-3841 (CSRF - NXfilter)
CVE-2023-6905 (LDAP Injection - NXfilter)
CVE-2023-6904 (CSRF - NXFilter)
- Znuny
-
CVE-2025-26845 (command injection - znuny)
- Seq Log Datalust
-
CVE-2018–8096 - Admin Auth Bypass - Seq Log Datalust
- Apache Airflow
-
CVE-2024-50378 - Insertion of Sensitive Information Into Sent Data
- Audiobookshelf
-
CVE-2025-46338 - cross-site scripting (XSS)
- Whistle
-
CVE-2025-5880 - path traversal
- Appdynamics by CISCO
-
CVE-2018-0225 - SQL Injection - Appdynamics (CISCO)
- ADAudit
-
CVE-2018-19118 - Stack overflow - ADAudit
- 3CX
-
CVE-2018-7654 - Path Traversal - 3CX
CVE-2018-14905 - Cross-Site Scripting - 3CX
CVE-2018-14906 - Cross-Site Scripting - 3CX
CVE-2018-14907 - Information Leakage - 3CX
- Centreon
-
CVE-2015-7672 - Cross-Site Scripting - Centreon
CVE-2018-19311 - Cross-Site Scripting - Centreon
CVE-2018-191312 - SQL Injection - Centreon
- ForgeRock
-
CVE-2017-7590 - Cross-Site Scripting - ForgeRock
CVE-2017-7591 - Cross-Site Scripting - ForgeRock
CVE-2017-7589 - Information Disclosure - ForgeRock