Threat reviews, security news, and notes from the team.
A ransomware leak-site listing led us to a CTO's LinkedIn profile - and from there, to a second company quietly carrying an active compromise nobody had connected to the first. Here's exactly how the correlation works, what evidence backs it, and what we do about it before and after.
Read article →We monitor the dark web, ransomware leak sites, and dozens of other threat feeds around the clock for every company you track - and surface it the moment you look at that company in OSINT or External Exposure Assessments, evidence and screenshots included.
Read article →A vendor's login without network segmentation. A patch that sat unapplied for four months. Two of the most expensive breaches in recent history trace back to a single unanswered compliance question. A look at why audit prep is exhausting, what it's actually protecting against, and why the proof usually already exists before anyone goes looking for it.
Read article →A catch-up briefing on July to September 2026, with the numbers. The most-used way in was a fake CAPTCHA. Vulnerability exploitation became the #1 initial-access vector for the first time in DBIR history. A curated top 20 of the CVEs actually doing damage. ShinyHunters claimed 1.5 billion Salesforce records. And a nursery school got extorted with photos of the children.
Read article →Twelve months of threats aimed at the people who write the code, not the servers that run it. Self-replicating npm worms that steal your token and publish themselves onward. Malicious MCP servers that hide instructions in a tool description. The .claude and rules files that ship a policy downgrade inside your repo. Model files that are really just pickled code. And what DevGuard catches before you push.
Read article →A network scan finds a medium. A DAST tool logs an info. A pentest PDF has a note about session handling. Three tickets, three owners, no priority. An attacker reads the same three findings and walks from the internet to the payment database. Here is that walk, step by step.
Read article →Three months of threat reporting, June to September 2026. The through-line is not a new technique - it is a shrinking gap between the moment something becomes reachable and the moment it is used against you. Five signals, and what they mean for how you test.
Read article →Scanners tell you what might be vulnerable. Attack validation proves what an attacker can actually do with it - continuously, and again after every fix. Here is what that means in practice and how it differs from a scan or an annual pentest.
Read article →A company is not just a domain. A person is not just an email. And OSINT should not be a pile of noisy facts thrown into a dashboard. What if the intelligence we gather could be reused across security workflows instead of sitting as dead weight?
Read article →Upload 50,000+ companies and check each one in seconds to minutes - open mail relays, phishing exposure, leaks, active malware, dark-web mentions, how often companies like this get hacked, exposed domains and services, basic compliance, scoring and OSINT. Here's the thinking behind the feature.
Read article →Modules aren't created detached from the product narrative. A new one has to account for the architecture, the APIs, the data structure - and the data has to be reusable as a source for other modules. Here's how one such chain grew from a single customer case into a full external exposure scanner.
Read article →A recruiter sends a "small paid technical task" as a Git repo before the interview. The code looks fine, the dependencies look normal - but the trap isn't in the application code. It's in Git behaviour, and almost nobody checks .git/hooks/ before running an unknown repo.
Read article →A VC asked which LLMs we train on and what data we use. We use LLMs - but not as the core engine, and not trained on customer data. Disable the LLM layer entirely and the product keeps working, with maybe an 8-15% quality hit in specific edge cases. Here's why that's intentional.
Read article →There is a lot of noise around free, open-source AI pentesters and IDE plugins right now - drop in your API key and go. This breaks down the two main product types, why their false negatives are more dangerous than having no tool at all, and how a privacy-first alternative is built.
Read article →Talk to us about your environment - network, web, cloud, or on-prem.