---
title: "Research - Red Balloon Security"
description: "Research from the Red Balloon Security team, including CVE disclosures and work funded by DARPA, NAVSEA, and AFRL across U.S. DoD and DHS programs."
date: "2021-11-19T17:31:35+00:00"
language: "en-US"
canonical_url: "https://xckd6kzuxte054o.onstatic.studio/research/"
source_url: "https://xckd6kzuxte054o.onstatic.studio/research/"
content_type: "text/markdown"
---

[
			Skip to content		](#content)








											[
			![Red Balloon Security](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2026/01/Client-Logos-RBS-Website-2025Asset-33.svg)				](https://xckd6kzuxte054o.onstatic.studio/)



										[

									CONTACT

					](https://xckd6kzuxte054o.onstatic.studio/contact/)















						RESEARCH


# Cutting edge insights with
 direct commercial applications




Members of the Red Balloon Security team have led research activities funded by the U.S. Government’s DoD and DHS, including DARPA, NAVSEA, and AFRL.












![Siemens SIMATIC S7-1500 programmable logic controller](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/AF3I0415-1-e1673343417196-1024x547.jpg)



### [Critical Architectural Vulnerabilities in Siemens SIMATIC S7-1500 Series Allow for Bypass of All Protected Boot Features](https://xckd6kzuxte054o.onstatic.studio/siemens-discovery/)

Red Balloon has discovered critical architectural vulnerabilities in the Siemens SIMATIC and SIPLUS S7-1500 series that allow for bypass of all protected boot features. 









					[![Plum Island Animal Disease Center research thumbnail](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2026/09/research-piadc-thumb.webp)](https://xckd6kzuxte054o.onstatic.studio/research/piadc-facility/)

### [PIADC FACILITY](https://xckd6kzuxte054o.onstatic.studio/research/piadc-facility/)

U.S. Government-funded Red Balloon research to bring advanced on-device security with real-time detection to production-network building controllers.





					[![NyanSat project artwork with a rainbow trail and satellite dish](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2021/11/982a18_b77c660d04bc4cc2951b4866a699790f_mv2.png-728x488-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/nyansat/)

### [NYANSAT​](https://xckd6kzuxte054o.onstatic.studio/research/nyansat/)

Research for NyanSat resulted in a workshop for the Department of the Air Force and U.S. Defense Digital Service





					[![Red Balloon Security sticker on a metal surface](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2021/11/982a18_cce631b0d8bf44b88321b312c4b1da88_mv2.png-728x488-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/hsbcl/)

### [HSBC&L​](https://xckd6kzuxte054o.onstatic.studio/research/hsbcl/)

Persistent bypass of Nautilus Hyosung's ATM security measures.





					[![Gilded picture frame containing pixel art portraits](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2026/01/982a18_12e210ffb93e4a8aa2a516afa936ed42_mv2.png-668x448-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/thrangrycat/)

### [THRANGRYCAT​](https://xckd6kzuxte054o.onstatic.studio/research/thrangrycat/)

Red Balloon discovered a vulnerability which allows an attacker to persistently bypass Cisco's proprietary secure boot mechanism and lock out future updates.





					[![A Monitor Darkly research thumbnail showing a desk and monitor in red light](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2021/11/982a18_73f47ce9c9cf4526a21e775871e19136_mv2.png-728x488-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/a-monitor-darkly/)

### [A MONITOR DARKLY​](https://xckd6kzuxte054o.onstatic.studio/research/a-monitor-darkly/)

Reversing and exploiting ubiquitous on-screen display controllers in modern monitors.





					[![BADFET research thumbnail](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2021/11/982a18_8283f9f748a145cc9155e0bc4a5c7cfa_mv2.png-728x488-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/badfet/)

### [BADFET](https://xckd6kzuxte054o.onstatic.studio/research/badfet/)

Defeating modern secure boot using second-order pulsed electromagnetic fault injection.





					[![Funtenna research thumbnail showing a green enclosure](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2026/09/research-funtenna-thumb.webp)](https://xckd6kzuxte054o.onstatic.studio/research/funtenna/)

### [FUNTENNA](https://xckd6kzuxte054o.onstatic.studio/research/funtenna/)

Improvisation of an RF transmitter via GPIO to overcome air-gapped systems.





					[![DARPA RADICS program — power grid security research](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2021/11/982a18_563ba8803b254d3d88501672e846f865_mv2.png-668x448-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/darpa-radics-program/)

### [DARPA RADICS](https://xckd6kzuxte054o.onstatic.studio/research/darpa-radics-program/)

Red Balloon provided embedded defense to protection relays, RTUs and network equipment to increase device protection, detect attacks and bring device level forensics.





					[![LADS research thumbnail in ultraviolet tones](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2026/09/research-lads-thumb.webp)](https://xckd6kzuxte054o.onstatic.studio/research/lads/)

### [LADS​](https://xckd6kzuxte054o.onstatic.studio/research/lads/)

Optically isolated monitoring of embedded device cybersecurity status for the US military.












						// CONTACT




## PROTECT YOUR SYSTEMS AGAINST EXPLOITATION















      Thanks! Your message was sent. We’ll get back to you shortly.





      There was a problem submitting the form. Please try again.
























        1067
