Mint Secure conducts active and ethical IT security research. As part of this, security vulnerabilities are identified responsibly and in accordance with current best practice. When security vulnerabilities are discovered, manufacturers are given a reasonable period of time to address them in accordance with the ‘responsible disclosure’ process, before further details are published. The findings are only subsequently made available to the public in presentations or blog posts.
IT Security Research
We investigate current security risks, responsibly disclose vulnerabilities and support manufacturers in resolving them in a sustainable manner. In doing so, we rely on established responsible disclosure procedures, the highest ethical standards and the responsible handling of sensitive information.
Contact us nowSecurity Research and Vulnerability Reporting
In the past, Mint Secure has already identified and responsibly disclosed security risks in the following technologies:
- Systems and architecture of the e-passport photo infrastructure
- Data protection and IT security risks in payment card IT infrastructure
- Data protection and security risks in age verification systems
- Reconnaissance devices (for video and audio monitoring)
- Delegated User Management (DeBeV) at the BAMF
- Security risks associated with bund.de domains (typo and Bitsquatting)
In addition, numerous CVEs were reported in products and technologies (excerpt): CVE-2014-1500 (Mozilla Firefox), CVE-2024-36399 (Kanboard), CVE-2025-7375 (TP-Link Omada), CVE-2025-43928 (Infodraw), CVE-2025-53911 (Syslink Xandria / Avantra), CVE-2025-65348 (Linergy), and others.
Presentations and awareness-raising
Mint Secure sees itself as an active player in the hacking scene, which also involves carrying out awareness-raising work, giving presentations and carrying out Live-Hacking demonstrations. In the past, for example, employees from Mint Secure GmbH have given talks at the Chaos Communication Congress, the GPN and the Chaos Computer Club’s Easterhegg. In addition, workshops on hacking, IT security and privacy were held at Tincon 2025 and 2026, amongst other events.
We are delighted to make IT security accessible to everyone and, in doing so, to make an important contribution to a resilient society.
