UK security & IT consultancy

We find the bugs
before someone else does.

Goldberg Security Research is an independent IT and security consultancy — penetration testing, vulnerability research, and responsible disclosure. Our published work speaks for itself.

about

Who we are.

Goldberg Security Research provides information technology consultancy and services with a security-first focus. We work across vulnerability research, penetration testing, reverse engineering, and low-level systems security — and we publish our findings. Everything here is conducted against our own infrastructure or under authorization, and disclosed responsibly.

19
writeups published
4
researchers
100%
responsible disclosure
UK
based

services

IT consultancy & security services.

01

Security Assessments

Penetration testing and security reviews of applications, networks, and infrastructure — with clear, prioritised, actionable reporting.

02

Vulnerability Research

Deep-dive research, reverse engineering, and responsible disclosure. The advisories in our research section are a sample of our work.

03

IT & Security Consultancy

Advisory on secure architecture, secure development, and technology decisions — tailored to your environment and risk profile.

04

Bespoke Tooling & IT Services

Custom security tooling, automation, and broader IT services to support your team's day-to-day needs.

team

The people behind the work.

Fabian Sommerfeld

Fabian Sommerfeld

CEO · Malware Analysis

Leads Goldberg Security Research. Specialises in malware analysis and reverse engineering, with a track record of discovering CVEs across multiple npm packages.

J

John

Security Researcher

Generalist security researcher working across web, application, and infrastructure security — wherever the interesting bugs are.

L

Lukas

Security Researcher

Broad-spectrum researcher spanning reverse engineering, vulnerability discovery, and the tooling that supports them.

J

Jacob

Security Researcher

All-rounder across offensive security, exploit research, and automation — comfortable from kernel to cloud.

research

Independent technical re-analysis of notable public vulnerabilities and threats — root cause, exploitation, and defence. (Analysis of public, third-party research; discovery credited to the original researchers.)

contact

Engagements, consultancy, or responsible disclosure.

Get in touch.
contact@goldbergsecurity.co.uk
Email us