Security Research

Security Research

ThreatCanary uses an automated researcher workflow to find, interpret and test offensive techniques before they become another unverified intelligence feed.

Published research

See the work behind the methodology.

Research is useful when readers can inspect the technique, assumptions and evidence—not merely read that a platform is “AI-powered”.

01 / AI SECURITY RESEARCH

Exploring the Vulnerabilities of AI: Kicking the Python Sandbox with ChatGPT-5

A practical investigation into AI-generated code, Python sandbox assumptions and the security boundaries that fail when model output meets an execution environment.

Andrew HortonMatt FlanneryThreatCanary Research
Read the published research
Global inputs

Track research across languages, regions and technical communities while retaining source context.

Controlled reproduction

Separate interesting claims from techniques that can be safely and deterministically reproduced.

Reusable capability

Promote validated methods with provenance, constraints and evidence requirements attached.

Explore the library

Research that changes what defenders can prove.

The workflow follows work across languages and regions, forms target-relevant hypotheses and promotes a technique into platform coverage only after controlled testing produces reproducible evidence.

01

Global research coverage

  • Follow disclosures, exploit analysis, technical writing, code and practitioner discussion across the global community.
  • Research Chinese- and Russian-language material that is difficult for an English-speaking analyst to track continuously.
  • Preserve source context, affected technology, prerequisites and confidence through translation and interpretation.
02

Automated researcher workflow

  • Extract attack conditions, affected components and potential impact from new work.
  • Correlate techniques with technologies, assets, APIs and trust represented in ExposureGraph.
  • Generate testable hypotheses instead of turning every mention into another alert.
03

From hypothesis to capability

  • Reproduce candidate techniques in controlled environments.
  • Generate constrained tests when existing coverage cannot answer the hypothesis.
  • Record provenance, inputs, observations and deterministic results for review.
04

Evidence over volume

  • Separate relevant and reproducible techniques from speculation and low-value noise.
  • Prioritise research that changes what ThreatCanary can safely prove against an authorised target.
  • Feed validated methods into the methodology and vulnerability-intelligence platform.