Home / About
ABOUT

Why SubZeroSec exists.

Offensive security that finds exploitable weaknesses before adversaries do.

SubZeroSec was founded in 2026 on a simple conviction: most organizations learn how they are breakable only after they have been breached. We exist to deliver that lesson safely and early - by attacking your systems the way a real adversary would, before a real adversary does.

SubZeroSec is an offensive security firm. We intercept vulnerabilities on the path to becoming zero-days - through VAPT, red teaming, threat hunting, OSINT and attack surface analysis - so a breach never happens.

The name is the thesis. A zero-day is a flaw no one is defending yet. We work to get below zero - to intercept exposure on the path to becoming a zero-day, while there is still time to fix it quietly. That is what Before Zero. Beyond Breach. means.

Every engagement is run by operators who compromise systems for a living, reproduced by hand, and proven with a working exploit. No theoretical severity, no scanner noise - just an honest, ranked picture of where you are actually breakable and a clear path to closing it.

Research by our team has found & disclosed vulnerabilities in
Better Authn8nSAPTwilioFusionAuth
0+
Critical Findings
0+
Assessments Delivered
0%
Remediation Rate
0+
Industries Secured
Industries

Where we work, and the pressure each sector faces.

Regulated, high-target environments where a breach carries outsized operational and regulatory consequences.

Banking

Fraud, account takeover, and transaction abuse.

  • Account takeover via credential stuffing and weak multi-factor enforcement
  • Business-logic abuse in transfer, lending, and payment workflows
  • API authorization flaws exposing accounts and balances
  • Insider and third-party access to core banking systems

Healthcare

Patient data, connected devices, and ransomware exposure.

  • Ransomware reaching clinical systems through flat, unsegmented networks
  • Exposure of patient records via misconfigured applications and APIs
  • Insecure connected and legacy medical devices on the production network
  • Phishing against clinical staff leading to credential compromise

Government

Nation-state adversaries and critical infrastructure.

  • Nation-state espionage targeting sensitive data and communications
  • Disruption or sabotage of critical infrastructure and operational technology
  • Supply-chain compromise reaching trusted government systems
  • Long-dwell persistent access designed to evade detection

Technology

Supply-chain, source code, and cloud-native risk.

  • Supply-chain compromise through dependencies and build pipelines
  • Source code, secret, and signing-key exposure in repositories and CI/CD
  • Cloud-native misconfiguration and over-privileged service identities
  • Multi-tenant isolation failures exposing customer data

Telecommunications

Signaling, subscriber data, and network core.

  • Signaling protocol abuse for interception and location tracking
  • Subscriber data exposure across billing and provisioning systems
  • Compromise of the network core and management plane
  • SIM-swap and account-takeover attacks against subscribers
Leadership

The operators behind the work.

SB

Saad Bukhari

Co-Founder & CEO

Saad co-founded SubZeroSec to put offensive security within reach of organizations that can't afford to learn from a breach. He still reads every critical finding before it reaches a client.

StrategyOffensive securityClient advisory
SU

Subhan Umer

Co-Founder & CTO

Subhan co-founded SubZeroSec and leads the technical practice - setting the bar for every engagement across application security, cloud, and the messy seams where they meet.

VAPTRed teamingCloud security
Meet the team
Get ahead of zero

Ready to see yourself the way an adversary would?

Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.

Book a free scoping call