Research & news

Dream researchers push technology to its furthest edge, building and testing breakthrough capabilities, from artificial intelligence and advanced threat hunting to malware reverse engineering, and vulnerability research in existing and emerging attack surfaces.

Operating at the frontier of cyber and artificial intelligence research, we turn bold ideas into working innovation that strengthens how nations anticipate, understand, and neutralize the most complex threats.

Our Latest Black Hat Asia Talk: Introducing the RFC Analyzer
Dream Research Labs
April 30, 2026

Arad Inbar, a security researcher from our research group at DREAM, recently presented at Black Hat Singapore. The talk focused on using protocol specifications, specifically RFCs, as a primary surface for vulnerability discovery.

How We Discovered The Microsoft’s Plan For Mitigating Local NTLM Relay
Dream Research Labs
April 28, 2026

One of the most powerful ways to understand what a security patch actually fixes is to reverse engineer the binaries before and after the update. Vendors rarely disclose full vulnerability details immediately, but the code always tells the truth. By performing a binary diff, researchers can quickly identify which parts of the code changed and infer the class of vulnerabilities that the patch mitigates.

Six Lessons From Making Our AI Security Agent Explainable
The Dream Team
April 16, 2026

We built an AI agent for security teams. It analyzes configs, hunts for vulnerabilities, investigates threats. Here’s what we underestimated: security people are paid to be paranoid. They don’t trust systems they can’t audit.And honestly? They shouldn’t.So we built an explainability layer. Not just “here’s what we found” but “here’s why we think that, and here’s how you can check.”Here’s what worked, what didn’t, and what surprised us.

Port 23, 30 Years Later: A Pre-Auth LINEMODE Bug in GNU Telnetd (CVE-2026-32746)
Dream Research Labs
April 10, 2026

A bug rooted in Telnet's early-1990s LINEMODE logic survived into modern GNU Inetutils telnetd, leaving a pre-auth memory corruption path reachable before /bin/login, before passwords, and before PAM.

The Sovereign Pivot: Why Governments are Rebuilding Control Over Their AI Infrastructure
David Thompson
March 31, 2026

The Sovereign Pivot: Why Governments are Rebuilding Control Over Their AI Infrastructure

How a Security Scanner Took Down the AI Supply Chain
Dream Research Labs
March 27, 2026

A vulnerability scanner trusted to protect a CI pipeline was the entry point. An AI proxy handling your LLM API keys was the target. The credentials stolen from the first were used to compromise the second - and the cascade didn't stop there.

Fill out the form to get in touch with our Expert Team.

Thank you!
Your submission has been received!
Oops! Something went wrong while submitting the form.