The Portuguese cybersecurity company founded in 2022 and responsible for some of the most relevant vulnerability discoveries internationally in recent months, formally begins its commercial activity in Spain.
The company lands in the Spanish market with an outstanding international portfolio of clients in countries such as England, Germany and Spain itself. In the latter market, its ambition is to become the reference partner for those organizations that need to determine, in a continuous and demonstrable manner, what part of their digital exhibition surface is really exploitable by an attacker.
Agent-based AI engine
Ethiack’s services differ from traditional annual pentests—which only offer a static snapshot that expires in a matter of weeks—and from conventional vulnerability scanners, which simply deliver endless lists of alerts ordered by theoretical criticality, without reflecting what an attacker can exploit in practice.
Ethiack reverses this logic through its agent-based AI engine, Hackian, which permanently maps the attack surface, chains intrusion paths, executes exploitation routines, and provides a proof of concept on every confirmed risk. The result, according to company data, is a false positive rate of less than 0.5%.
Ethiack was born in 2022 in Coimbra, the city that is home to the oldest university in Portugal (founded in 1290, some seven decades after Salamanca) and which remains the country’s main academic cradle. The company took its first steps at the Pedro Nunes Institute – the incubator linked to the University of Coimbra, recognized on several occasions as one of the best in the world – and from there it made the leap to the international market.
The company was founded by André Baptista and Jorge Monteiro, two complementary profiles. Monteiro, CEO, provides the business and internationalization vision. Baptista, chief technology officer (CTO), is probably the most recognized ethical hacker on the Iberian Peninsula. Born in Coimbra in 1994 and graduated from its university, he won the title of Most Valuable Hacker in 2018 in the H1-202 competition, organized by HackerOne in Washington; a distinction that earned him the nickname “Cristiano Ronaldo of cybersecurity” in the Portuguese press.
In August 2024, he defended the title in Las Vegas in an invitational competition centered on TikTok and Epic Games, becoming one of only five hackers in the world to do so twice. He is also a guest professor for the Master in Computer Security at the University of Porto and coach of the Portuguese team in the European Cyber Security Challenge.
A history of discoveries with international reach
The Ethiack research team, led by André Baptista, recently identified a critical remote code execution vulnerability in Ruby on Rails, the open source web framework that supports more than half a million applications and some of the largest digital platforms in the world. The flaw, called KindaRails2Shell and registered as CVE-2026-66066 with a score of 9.5, was located in the framework’s default image processor: it was enough for a user to upload an image (a profile photo, an avatar or a thumbnail) to open the door to reading files, executing malicious code and, ultimately, full control of the server.
Ethiack quietly notified the Ruby on Rails team and coordinated a responsible disclosure process with them. The company warns that updating the framework may not be enough: the entire solution requires several steps, including the separate update of a third-party image processing library, so many implementations could still be exposed after applying the major patch.
Weeks earlier, researcher Rafael Castilho had documented four vulnerabilities in GeoNetwork, the geospatial metadata catalog originally developed within the FAO and currently maintained by the Open Source Geospatial Foundation. Two of them could be chained together to achieve remote code execution without the need for credentials.
The issue is especially sensitive in Europe, as GeoNetwork is a central pillar of the continent’s spatial data infrastructures and underpins the INSPIRE geoportal. Ethiack identified 121 exposed installations running vulnerable versions in 39 countries — 89% belonging to government, military or national agencies, with Europe representing 77.7% of the total — and contacted affected organizations before an official patch was available.
These findings add to an outstanding list of planned research carried out by Ethiack, among which natively stand out:
· In OpenClaw: https://ethiack.com/info-hub/research/one-click-rce-openclaw
· In Grafana: https://ethiack.com/info-hub/research/grafana-cve-2025-6023-bypass-a-echnical-deep-dive
· In Git: https://ethiack.com/info-hub/research/git-arbitrary-configuration-injection-cve-2023-29007
Cyberdefense: operational continuity without pauses
Ethiack’s technology is currently used in environments where operational continuity does not allow pauses. In the field of defense, the company participated in the AI Ethical Hacking project developed by the General Staff of the Portuguese Armed Forces, through the Cyberspace Defense Operations Command. This project was intended to automate and increase the frequency of security testing in the three branches of the armed forces and was designed to also operate on isolated (air-gapped) networks. The work was completed in June 2026 and was validated on August 31 by the Agency for Administrative Modernization (AMA) and the European Commission.
Outside the military sphere, among the success stories published by the company itself, the University of Porto stands out, with more than 5,000 assets protected and two million euros in potential losses avoided during 2025, and that of the pharmaceutical group Bluepharma, with a thousand critical assets under permanent supervision. In total, Ethiack reported more than 150,000 exploitable vulnerabilities and avoided financial damages estimated at more than €150 million throughout 2025.
Spain, in full regulatory boiling
Ethiack’s entry into Spain coincides with a time of great regulatory pressure in the local market. The transposition of the NIS2 Directive, which will extend to thousands of entities the obligation to manage digital risk and report incidents within strict deadlines, is still pending parliamentary processing in the Cortes and is accumulating a delay that has already caused warnings and formal actions by the European Commission. Added to this are DORA, fully applicable to the financial sector; the National Security Scheme (ENS), which requires public administrations and their suppliers to carry out periodic audits and tests; and the Cyber Resilience Regulation (CRA), whose first vulnerability reporting obligations just came into force this month.
Ethiack has identified 121 exposed facilities running vulnerable versions in 39 countries, 89% of them belonging to government, military or national agencies.
For Jorge Monteiro, co-founder and CEO of Ethiack: «Spain is a natural market for us. We share a European regulatory framework and, in many cases, the same business groups operate on both sides of the border. “We already work with Spanish organizations and what they ask us is always the same: stop managing infinite lists of theoretical alerts and start mitigating the real demonstrated risk.”
For his part, André Baptista, co-founder and CTO of the company, states: “When you find a critical flaw that affects half a million applications or geoportals in dozens of countries, you realize that the real problem is not the lack of tools, but the time that passes between the appearance of a vulnerability and the moment when someone checks if it is exploitable. “That gap is where the attacker operates and that is exactly what we help close.”
In December 2024, Ethiack closed a €4 million seed financing round led by private equity firm Explorer Investments, with the participation of CoreAngels, Startup Wise Guys, Aralab, Amena Ventures, Start Ventures and investor Paulo Marques, with the aim of accelerating its international expansion. The company is ISO 27001 certified and has been awarded the World Summit Award, the United Nations initiative that recognizes excellence in global digital innovation.
