Red team
Full-spectrum, time-boxed adversarial engagements. 2–6 weeks. Goal-oriented (your call). Initial access, lateral movement, exfil, dwell — the works.
NOX//SEC is a 12-person offensive security shop. We break into your stack on a schedule, find what your blue team didn't, and write the patch ourselves.
Time-boxed adversarial engagements, always-on recon, disclosed zero-days and a 4-hour incident response line. Every retainer has receipts.
explore servicesEvery retainer starts with a 25-minute intake and ends with a written engagement contract. We say no more often than yes — but we say it within 48 hours.
Full-spectrum, time-boxed adversarial engagements. 2–6 weeks. Goal-oriented (your call). Initial access, lateral movement, exfil, dwell — the works.
Always-on attack surface monitoring. We watch your perimeter the way an attacker would — assets, certs, exposed creds, leaked tokens.
We find unpatched bugs in software you ship. We disclose them properly. We don't sell them to anyone except you.
When the worst day arrives, we are on a plane within four hours. Forensics, containment, eradication, and a written-down version of what happened.
Deep-read of a single critical codebase (auth, crypto, payments). Two engineers, two weeks, one report. No bug-bounty re-runs.
Sit down with your executives and walk through the day your worst breach goes public. We play journalist, regulator, attacker, lawyer.
Every disclosure follows a coordinated 90-day window. When the patch ships, the advisory ships. No exceptions.
| CVE | Target | Vector | Severity | Disclosed | Status |
|---|---|---|---|---|---|
| NX-2026-014 | Major payments SaaS | Auth bypass via JWT replay | CRITICAL · 9.8 | 2026-05-22 | PATCHED |
| NX-2026-013 | EU bank · core ledger | SSRF → internal services | CRITICAL · 9.4 | 2026-05-11 | PATCHED |
| NX-2026-012 | Identity provider | SAML signature wrap | HIGH · 8.6 | 2026-04-30 | PATCHED |
| NX-2026-011 | Major HRIS · upload | RCE via crafted PDF | CRITICAL · 9.1 | 2026-04-12 | PATCHED |
| NX-2026-010 | Hardware wallet firmware | Memory disclosure | HIGH · 8.2 | 2026-03-28 | LIVE 90D |
| NX-2026-009 | Web framework · v8.x | Prototype pollution → RCE | HIGH · 8.0 | 2026-03-14 | PATCHED |
| NX-2026-008 | EDR product · agent | Privilege escalation | MEDIUM · 7.4 | 2026-02-21 | CONTAINED |
NOX//SEC has been running since November 2018. In that time, no client of ours has had a credential-stuffed account compromise, no client has paid a ransom, and exactly one client has had a public breach — which they reported, with our incident report, in the same press release.
We don't sell fear. We sell a small, quiet number: zero regrettable incidents on retainer.
Two retainer slots open for Q3 '26. Intake is a 25-minute call. NDA mutual. We say no more often than yes — but we say it within 48 hours.