Skip to content

To foresee is to protect. We develop strategies that keep your team always ahead of new cyber threats.

Institutional illustration

More than a team, a revolution in bits and bytes. We challenge, endure, and evolve together.

Hakai is a cybersecurity company founded by experienced specialists.

We prioritize technical excellence and provide customized services with the latest attack techniques, threat detection and monitoring technologies, as well as secure development procedures to minimize or prevent new vulnerabilities.

Get in Touch

Discover our services

Excellence in cybersecurity: Pentest, Red Team, DevSecOps, and specialized services leading your digital defense.

Some of our clients

  • Auren Energia
  • Bexs
  • CAF
  • Carrefour
  • Athletico Paranaense
  • Feedz
  • Copersucar
  • Genial
  • Icatu
  • Acelen
  • Atacadão
  • Jusbrasil
  • Pravaler
  • Joes
  • Cliente Hakai
  • Totvs
  • Videplast

Don't wait to be the target! Invest in your peace of mind and in the success of your company's and your customer's data.

Big projects done

Here we highlight some of the main CVEs and Vulns that we've found.

Trend Micro

Hall Of Fame 2016 and 2019 at Trend Micro

D-Link

CVE-2017-11436 - Hidden Backdoor User - D-Link

NXfilter

CVE-2023-3840 (XSS relfected - NXfilter)

CVE-2023-3841 (CSRF - NXfilter)

CVE-2023-6905 (LDAP Injection - NXfilter)

CVE-2023-6904 (CSRF - NXFilter)

Znuny

CVE-2025-26845 (command injection - znuny)

Seq Log Datalust

CVE-2018–8096 - Admin Auth Bypass - Seq Log Datalust

Apache Airflow

CVE-2024-50378 - Insertion of Sensitive Information Into Sent Data

Audiobookshelf

CVE-2025-46338 - cross-site scripting (XSS)

Whistle

CVE-2025-5880 - path traversal

Appdynamics by CISCO

CVE-2018-0225 - SQL Injection - Appdynamics (CISCO)

ADAudit

CVE-2018-19118 - Stack overflow - ADAudit

3CX

CVE-2018-7654 - Path Traversal - 3CX

CVE-2018-14905 - Cross-Site Scripting - 3CX

CVE-2018-14906 - Cross-Site Scripting - 3CX

CVE-2018-14907 - Information Leakage - 3CX

Centreon

CVE-2015-7672 - Cross-Site Scripting - Centreon

CVE-2018-19311 - Cross-Site Scripting - Centreon

CVE-2018-191312 - SQL Injection - Centreon

ForgeRock

CVE-2017-7590 - Cross-Site Scripting - ForgeRock

CVE-2017-7591 - Cross-Site Scripting - ForgeRock

CVE-2017-7589 - Information Disclosure - ForgeRock

Our team

Work with us