Our Research

Philosophy

Somewhere right now, a researcher is finding a vulnerability nobody has named. The only question is which side they're on. Searchlight Labs exists to make sure it's ours. Our offensive researchers hunt zero-days in the enterprise software the world runs on, and every discovery becomes a check in Searchlight Exposure before public disclosure, so our customers close exposures while everyone else waits for a CVE that doesn't exist yet.

Everything Searchlight Labs publishes holds the same standard: research from the source, proven before it's published. If it's in a Labs report, we found it, we proved it, and you can act on it.

Latest Research

Research

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

July 20, 2026

Research

wp2shell: Pre Authentication RCE in WordPress Core

July 17, 2026

Research

Smashing the ServiceNow Sandbox – Pre Authentication RCE

July 14, 2026

Research

CargoWise WebTracker – The Keys Were in the Cargo

June 25, 2026

Research

Two Bypasses for Chrome's Sanitizer API

May 22, 2026

Research

Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)

May 21, 2026

Open Source Tools

Python

BatchQL

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Markdown

Blind SSRF Chains

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

Python

Commonspeak2

Leverages publicly available datasets from Google BigQuery to generate content discovery and subdomain wordlists

Python

Ghostbuster

Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.

Golang

Hyoketsu

Automatically filter out vendor code that doesn't contribute to the exposed attack surface of an application, cross-referencing against a database of known filenames and hashes.

Go

Kiterunner

Contextual Content Discovery Tool for API Discovery

Python

Newtowner

Abuse trust-boundaries to bypass firewalls and network controls

Java

Nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Go

Surf

Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.

No result to show

Try looking for something else.

See all

Looking for browser-based security testing tools?