RESEARCH // 01

Maliq Barnard

Vulnerability Researcher & Apple Security Researcher

Maliq Barnard leads vulnerability research at FARPSEC and runs disclosure with Apple, HackerOne, and enterprise vendors. Most of his work is on macOS system daemons: reverse-engineering them, auditing their XPC and IPC surfaces, finding privilege escalations through things like symlink races and entitlement checks that regressed between releases. He also builds the lab's FARP and FALE pipelines and takes each finding through to coordinated disclosure.
ENGINEERING // 02

Tolga Cohce

Security Researcher

Tolga Cohce has reported security issues to Google, Samsung, Red Hat, and Patchstack. At FARPSEC he works on web application security, enterprise product audits, and Android research. He's found hardcoded cryptographic keys in shipping enterprise software, and he's run coordinated disclosure with vendors including Zoho and Malwarebytes.

How we operate

We're a small group of systems engineers and vulnerability researchers. The work is the point: finding specific, well-defined failures and working out how to shut them down.

Everything we publish or ship is something we've checked ourselves, end to end. We'd rather go deep on one real bug than wide on a marketing claim.