Recent posts
-

What a $40k red team should actually deliver
EDR-heavy environments expose weak red team scoping fast. Here is how to design an engagement that produces decision-quality evidence, not a CVE list.
-

What red teaming delivers now that EDR grew up
Modern EDR ended the era of dropping a default beacon and calling it a red team. What replaced it is detection-engineering work the SOC…
-

What MSSPs get wrong when they sub out pentesting
Scan, pentest, red team: three different things. MSSPs that blur the line are running out of runway as auditors and underwriters get better at…
-

Your AI agent is reliably breakable. We tested it.
June 2026 research confirms frontier LLMs break under automated pressure. For agents with tool access, that is no longer a PR problem.
-

Megalodon and the CI/CD trust problem
5,561 repos got malicious GitHub Actions workflows in six hours. No zero-day, just a merge. Detection and change-control guidance for defenders.
-

Your IDE is in the supply chain now: the GitHub 3,800 Repo Exfiltration Dissected
GitHub confirmed ~3,800 internal repos exfiltrated via a poisoned VS Code extension. We separate vendor-confirmed facts from campaign reporting and inference.
-

What a roomful of threat hunters taught us about detection engineering
Intel 471 skipped the vendor pitch and ran a live threat-hunting CTF. Every team found something different. The complete picture required the room.
-
BitLocker downgrade chains: boot trust still owns your disk
TPM-only BitLocker can fail faster than runbooks assume when legacy Secure Boot trust allows old boot managers. Here is what to change this week.
-

The MCP server attack surface
MCP servers are running on engineering laptops at most companies, holding production credentials, with no inventory. Here’s the threat model and what to do.
