The expertise of a real attacker, working for your defense.
Fenrisk is an offensive security firm founded by researchers. We find and exploit vulnerabilities, including previously unknown ones, to faithfully reproduce the attack scenarios that threaten you. Every engagement is carried out manually, tailored to your context, and ends with concrete recommendations.
We think like an attacker, and act like a researcher
We don't stop at known vulnerabilities. We analyze your environment in depth, chain flaws together the way a determined adversary would and, when needed, discover new ones.
Automated pentesting
- ✕ Automated vulnerability scanners
- ✕ Hunting for known public CVEs
- ✕ Vulnerabilities handled in isolation
- ✕ Generic, standardized report
The Fenrisk approach
- Manual analysis and in-depth code review
- Discovery of previously unknown vulnerabilities (0day)
- Full attack chains up to critical objectives
- Contextualized report, reproducible evidence and remediation plan
- Every engagement overseen by a senior consultant
Research is our proof.
Our research never stops. Every vulnerability we publish is one more technique for putting your security to the test.

Remote code execution in CentOS Web Panel - CVE-2025-70951
As part of our ongoing research into web hosting control panels, we recently published an analysis of Control Web Panel (CWP), a widely used open-source administration panel designed to manage web servers running…
Read the full write-up- vector command injection
- impact RCE
- affected CentOS Web Panel
- status Patched
MCPwned: a Burp Suite extension for auditing MCP servers
This blog post quickly outlines the MCP protocol before presenting a Burp Suite extension developed by Fenrisk that enables pentesters to effectively test MCP servers.
Supply Chain Attacks on Linux distributions - Fedora Pagure
As discussed in the meta-article, we picked Pagure from the Fedora Apps Directory and already had a technical approach in mind. A software forge is likely to be a good target for an argument injection: we can expect the…
Gadget chains in Wordpress
Exploiting an unserialization vulnerability in WordPress never was a small issue. Unlike other PHP frameworks, and until very recently, WordPress was not known for hosting gadget chains.
Where technical excellence meets client support
No more choosing between technical excellence and understanding your business risks.
Scoping D-30
Definition of the scope, context, schedule and prerequisites
Kickoff D-7
Presentation of the approach and validation of prerequisites
Engagement D0
Testing phase with regular progress updates
Report writing D+3
Writing the deliverables with actionable, prioritized recommendations
See what a report containsReport delivery and debrief D+10
Debrief tailored to your needs (technical, managerial or both)
Support ongoing
Tailored client support, with the option of a follow-up audit
Reconnaissance
Detailed mapping of the attack surface
Foothold
Exploiting previously unknown vulnerabilities to gain access to your infrastructure
Privilege escalation
Going from a user account to an administrator account
Lateral movement
Pivoting to the heart of your infrastructure
Objective reached
Now on to the report, so you avoid a real compromise
Four ways to improve.
Pentests
Black box or grey box. External, internal or application. We find critical flaws across your attack surface, whatever it may be.
Red Team — adversary simulation
We put you to the test the way an APT (organized cybercriminal group) would: targeted phishing, physical intrusion, network pivoting, exfiltration. Our objective: reach your critical assets without alerting your defense teams.
Source code, configuration and architecture audits
When the black-box approach reaches its limits, we switch to a white-box approach and analyze the code, configuration and architecture of your assets.
Offensive training
We pass our attacker reflexes on to your teams. On-site sessions, 10 people max, real-world cases.
A scope worth testing?
Your first point of contact will guide you. Let's talk about your context, your challenges and the attack scenario most relevant to you.