Threat reviews, security news, and notes from the team.
A catch-up briefing on July to September 2026, with the numbers. The most-used way in was a fake CAPTCHA. Vulnerability exploitation became the #1 initial-access vector for the first time in DBIR history. A curated top 20 of the CVEs actually doing damage. ShinyHunters claimed 1.5 billion Salesforce records. And a nursery school got extorted with photos of the children.
Read article →A network scan finds a medium. A DAST tool logs an info. A pentest PDF has a note about session handling. Three tickets, three owners, no priority. An attacker reads the same three findings and walks from the internet to the payment database. Here is that walk, step by step.
Read article →Three months of threat reporting, June to September 2026. The through-line is not a new technique - it is a shrinking gap between the moment something becomes reachable and the moment it is used against you. Five signals, and what they mean for how you test.
Read article →Scanners tell you what might be vulnerable. Attack validation proves what an attacker can actually do with it - continuously, and again after every fix. Here is what that means in practice and how it differs from a scan or an annual pentest.
Read article →A company is not just a domain. A person is not just an email. And OSINT should not be a pile of noisy facts thrown into a dashboard. What if the intelligence we gather could be reused across security workflows instead of sitting as dead weight?
Read article →Upload 50,000+ companies and check each one in seconds to minutes - open mail relays, phishing exposure, leaks, active malware, dark-web mentions, how often companies like this get hacked, exposed domains and services, basic compliance, scoring and OSINT. Here's the thinking behind the feature.
Read article →Modules aren't created detached from the product narrative. A new one has to account for the architecture, the APIs, the data structure - and the data has to be reusable as a source for other modules. Here's how one such chain grew from a single customer case into a full external exposure scanner.
Read article →A recruiter sends a "small paid technical task" as a Git repo before the interview. The code looks fine, the dependencies look normal - but the trap isn't in the application code. It's in Git behaviour, and almost nobody checks .git/hooks/ before running an unknown repo.
Read article →A VC asked which LLMs we train on and what data we use. We use LLMs - but not as the core engine, and not trained on customer data. Disable the LLM layer entirely and the product keeps working, with maybe an 8-15% quality hit in specific edge cases. Here's why that's intentional.
Read article →There is a lot of noise around free, open-source AI pentesters and IDE plugins right now - drop in your API key and go. This breaks down the two main product types, why their false negatives are more dangerous than having no tool at all, and how a privacy-first alternative is built.
Read article →Start with the free tier or talk to us about your environment - network, web, cloud, or on-prem.