ACTIVE RESEARCH · LATAM

Adversarial ML.
Studied publicly.

Cinder Security is an AI red team research firm. Published research, disclosed vulnerabilities, and 5 AI scenarios cleared at HTB GCSB 2026.

$
0
Launches analyzed
0
Public disclosures
0
HTB GCSB 2026 points
0h
Observation window
Featured Research

The Print Job

A measurement study of industrial deployment patterns on Solana memecoin launchpads.

Live data · Snapshot v1.0.0

Deployer concentration

Distribution of the 12,926 creator addresses observed during the 89-hour window, grouped by launch volume tier. Blue bar: share of creator addresses. Orange bar: share of launches produced.

Share of creator addresses
Share of captured launches
Controlled Evaluation

HTB Project Nightfall 2026

Global Cyber Skills Benchmark 2026 — 15–20 May. Team Cinder Security ranked 337 of 589 teams with 4,700 points across 6 solved challenges.

337th
Team Ranking
6/126
Solved Challenges
4,700
Total Points
589
Total Teams
Official Certificate (PDF)

AI attack surfaces exercised

Selected vectors from AI-related scenarios cleared during the event.

ML SUPPLY CHAIN

Watermark backdoor

PyTorch model with behavioral backdoor. 26 trigger images produced class predictions 0–127 that decoded to ASCII. Weights carried the payload; the model looked clean.

750 pts · ML / Watermark
ML SUPPLY CHAIN

PickleScan bypass

torch ZIP supply chain compromise: PickleScan reported the artifact safe, torch.load executed the payload anyway. Full SIEM compromise through a poisoned sensor model.

ML registry RCE
AGENTIC

Tool result spoofing

Compliance agent trusted fabricated tool observations without authenticating the tool response. Agent reasoned faithfully over spoofed data.

Compliance Agent bypass
RAG

Retrieval → charting → exec

RAG broken access control chained into charting agent prompt injection, culminating in Python exec via generated chart code.

Multi-step trajectory
Public Track Record

Vulnerability disclosures

Coordinated disclosures with acknowledgement from the affected vendors.

High Severity
GHSA-m4rw-22q2-87j8
ModelEngine SSRF
Server-side request forgery vulnerability patched in fit-framework v3.6.4. Vendor acknowledged Cinder Security.
CVSS 7.6
GHSA-4fpw-hjmg-x4qr
LangGraph RAG poisoning
Retrieval-augmented generation poisoning vector in LangGraph. Coordinated disclosure with maintainers.
Coordinated Disclosure
huggingface/safetensors · April 2026
Conda release SHA-256 verification
Non-blocking checksum verification identified in an internal conda release workflow. Analysis confirmed by HuggingFace Security team; affected workflow removed (PR #745). Published safetensors package was never affected.
About Cinder

Solo research firm, LATAM-first.

Cinder Security is founded and operated by Esteban Ramos Castellanos from Zapopan, México. We focus on adversarial ML, LLM security, and on-chain autonomous system risks.

Cinder is Spanish-first for LATAM clients, and publishes in English for the broader research community. All research is reproducible against public datasets.

We are currently pursuing ISO/IEC 42001 Lead Auditor certification, with audit services planned for Q1 2027.

01 Reproducibility over rhetoric. Every quantitative claim ties to a verifiable dataset.
02 Coordinated disclosure only. We don't publish weaponizable details before patches ship.
03 Scope discipline. We only report vulnerabilities that a vendor cannot credibly argue are intended behavior.
04 Honest limits. Research papers explicitly list what the data cannot validate.
Get in touch

Research collaboration
or disclosure inquiries

contact@cindersecurity.io
SHA-256 copied to clipboard