A security company started by a researcher

Muneeb Amin Bhat opened Vulnara in August 2026, after years as an independent security researcher.

  • FoundedAugust 2026Business commenced 1 August 2026
  • Based inKulgam, Jammu and Kashmir33.64° N, 75.02° E
  • RegisteredMSME, Government of IndiaMicro enterprise, services
  • Udyam numberUDYAM-JK-11-0024606Udyam Registration Number

Vulnara started with one person and a lot of bug reports.

From bug reports to a company

We test web apps, APIs, smart contracts, mobile and desktop apps, networks, cloud and firmware. We know how software breaks, so we build it too.

  1. 2022

    First reports

    Muneeb starts hunting on bug bounty and disclosure programs.

    The timeline
  2. 2022 onwards

    A record builds

    CVEs, halls of fame and a NITI Aayog profile.

    The record
  3. Aug 2026

    Vulnara opens

    MSME registered, in Kulgam.

  4. Now

    Open for work, with our own apps in progress

    Plumb, Aegis and imgosint are ours, all pre-release.

    The products

Rules we don’t bend

  • Prove it

    If we can’t show it, it isn’t a finding. Every one comes with evidence, steps to reproduce and a fix.

  • Write for two readers

    A short summary for whoever signs off. Full detail for whoever fixes it.

  • Price it first

    One scoping call, then a fixed price in writing. Fix what we found and we retest it free, within an agreed window.

  • Build it to be attacked

    The threat model comes before the features. Plumb removes nothing until you’ve reviewed the list and run a dry run.

The researcher behind Vulnara

I’m Muneeb. I’ve been finding security holes as an independent researcher since 2022, and I’ve reported more than three hundred of them.

Oracle credited me with CVE-2022-21500 in that first year. By July 2026 it was Apple, for a kernel out-of-bounds write. The rest is on the record.

I opened Vulnara in August 2026 to do this work for clients, and to build software that holds up to it.

Halls of fame and bounties

  • NVIDIA
  • SimScale
  • Oracle
  • Kraken
  • Apple
  • Google
  • USAA
  • Indeed
  • NASA
  • FFmpeg
  • Vercel
  • Acronis
  • Lightspark
  • Anthropic
  • Nextcloud
  • McDonald’s
  • Fireblocks
  • Pinterest
  • AXIS OS
  • Zendesk
  • Binance
  • Asana

Web3: audits and rewards

  • VeChainThor
  • Multipli Smart Contracts
  • Internet Computer Protocol (ICP)
  • Snowbridge On-Chain Code
  • Olas
  • Injective Peggy Bridge

Where to next

  • Security testing

    Pentests and audits for web apps, APIs, smart contracts, mobile, cloud and firmware.

  • Build

    Web, mobile, desktop and security tooling, attacked before every release.

  • Our products

    Plumb, Aegis and imgosint. All pre-release.

  • The record

    The timeline, the CVEs, the halls of fame and the press.

Tell us what to break. Or what to build.

Send the scope and your deadline, and we’ll set up a call.