Security research
Security research behind the Vulkro detectors
The work behind the detectors: what goes wrong in Salesforce orgs and packages, how Vulkro decides a finding is real, and the benchmark we publish with its misses.
01From the blog
Latest blog posts
- ResearchThe attacks of 2025, and the checks that flag their root causesTwelve incidents, from Salesforce guest sites to poisoned npm packages, each with the Vulkro check that flags the weakness behind it.
- EU lawThe EU Cyber Resilience Act is live: what software teams must do nowThe 24-hour and 72-hour reporting clocks, SBOMs and security updates, and the evidence Vulkro produces toward them.
- ResearchHow Salesforce orgs get breached, shown as attack pathsThe 2025 and 2026 data thefts used trust the orgs had already granted. Three paths, and the cheapest place to stop each.
- Token efficiencySecurity analysis without wasting tokensWhy an agent reading a repository for bugs uses up its context, and what to give it instead.
- SalesforceAnatomy of a guest user data leakSite, guest profile, sharing, Apex: four hops from an anonymous visitor to private records, and how to close each.
- AgentExchangeAgentExchange Security Review: what fails, and how to passThe failures reviewers find most often, with the code that causes them and the fix.
- SalesforceConnected apps and OAuth tokensThe integration attack surface: scopes, refresh tokens, integration users and a review checklist.
- Attack pathsWhy attack paths matter more than lists of findingsA list of 400 findings does not say which one matters most. An attack path does.
- SalesforceIntroducing Vulkro Cloud for SalesforceEvery org under continuous review: Fix first, attack paths and the changes between scans.
02Salesforce
Salesforce orgs, packages and Security Review
- GuideApex CRUD and FLS: the top review failureWhat a reviewer checks, the API 67.0 fork, and the fixes that compile.
- ChecklistAgentExchange Security Review readinessThe review checklist, section by section, before you submit a managed package.
- ReferenceThe AppExchange top 20The most common review failures, each mapped to the check that finds it.
- MapBreach classes in SalesforceHow real incidents map to the configuration and code that allowed them.
- ConceptMetadata versus the live orgWhy what you deployed and what is true now diverge, and what to check in each.
- GuideScanning an unreleased managed packageA full security scan of a package that has not shipped, on your own hardware.
03Detection method
How Vulkro decides a finding is real
- MethodAttack pathsHow an entry point, a missing check and a sink are joined into one path.
- MethodThe confidence modelProven, unproven, not checked: what each disposition means and how it is reached.
- MethodReachabilityWhether vulnerable code can actually be reached from where an attacker starts.
- MethodTaint analysisFollowing untrusted input across functions and files, and where it stops.
- ReferenceExploitability, KEV and EPSSRanking known vulnerabilities by what is being exploited, not only by score.
- ReferenceAI-written codeThe patterns AI coding assistants introduce, and how they are checked.
- BriefingWhy now: recent attacks and EU lawEach recent attack with the Vulkro check that flags its root cause, and the EU laws that now require the evidence.
- PrincipleSecurity analysis without wasting tokensWhy Vulkro answers an AI agent instead of making it read the codebase.
- GuideUse casesNine buyer scenarios, each with the workflow from first scan to fixed.
04Benchmark
Benchmark results, including misses
181 of 229 planted vulnerabilities found and 48 missed across 9 blind holdout applications, 32 of 90 Criticals rated Critical, 39 of 152 safe controls flagged (vulkro 0.30.0, 2026-10-05).