


We're a team of highly skilled IT security professionals dedicated to tackling the most diverse and complex problems in the industry.


With a holistic mindset, we provide a wide range of offensive and defensive IT security services. From hacking your website, company or IoT device, to implementing security features in your app, we help you drive positive change in your organization.

Our bank's AI Agent was vulnerable to Cross-Site Scripting and Indirect Prompt Injection, leading to session compromise via malicious PDFs or transaction references.
We looked at the internals of JavaScript/TypeScript's most popular utility libraries and found interesting issues. The post contains hacking challenges/live demos. We recommend checking it out if you work with the affected libraries.
A significant portion of Europe's renewable energy production can be remotely controlled via longwave radio. While this system is intended to stabilize the grid, it can also be abused to destabilize it by remotely toggling energy loads and power plants, or to create a massive art installation.
Or send an email to hi@positive.security
