Our researchers discover 0-day vulnerabilities in the products of the world's largest software and hardware vendors, SonicWall, VMware, Sophos, validated by the Zero Day Initiative and published in the global CVE registry.

Beyond client audits, our research team hunts for previously unknown (0-day) vulnerabilities in the products of the world's largest software and hardware vendors, then reports them under coordinated disclosure. Our findings are validated by the Zero Day Initiative (ZDI), published in the global CVE registry and credited to DigitalCanion SA in official vendor advisories, offensive expertise that directly strengthens our clients' protection.
Three critical vulnerabilities validated by the Zero Day Initiative (ZDI-CAN-29024, 29025, 29029). Our demonstration shows how swiftly a malicious insider, or an attacker with read/write access to the hypervisor, can compromise the security of the SSLVPN access system, a risk SonicWall refused to fix.
An attacker with R/W access to the VM's storage can tamper with system binaries. Modifying the SSH daemon injects an arbitrary shell, guaranteeing highly persistent remote access that survives reboots, despite deceptive integrity-validation messages. Furthermore, cleartext communication between the GUI and the backend enables theft of administrator credentials. Sophos declined to fix these design flaws; no patch is expected.
Following a real cyberattack in which a company's firewall had been compromised to maintain persistence, our in-depth analysis of Sophos XG revealed several weaknesses, including an authentication bypass achieved by manipulating the virtual machine's memory snapshot, enabling arbitrary code execution and long-term persistence. Reported to Sophos, left unpatched after three weeks.
A vulnerability discovered in the latest version of VMware 17.6, not yet fixed by the vendor. Although Broadcom acknowledged the issue, it stated it would only resolve it "in upcoming versions", with no clear timeline. A full technical report documents the finding.
Three vulnerabilities identified in the SonicWall Email Security (antispam) solution that may put the email infrastructure at risk: CVE-2026-3468, CVE-2026-3469 and CVE-2026-3470. Prompt remediation is essential to reduce exposure of a critical messaging layer.
Two security vulnerabilities identified and disclosed in SonicWall products, reported through the appropriate channels and fixed by the vendor. An illustration of the importance of continuous security testing, transparency and responsible disclosure.
Zero Day Initiative : upcoming advisories → 🏆 SonicWall Hall of Fame →
Vulnerabilities credited to the research team of DigitalCanion SA, validated by the Zero Day Initiative and published in official vendor advisories and the global CVE registry.
Over 12 years of Swiss expertise at your service. Reply within 24 business hours.