Research and guidance

Security insights

Vulnerability research and practical observations from the work of testing, protecting, and improving real environments.

From Cyber Evidence to Fiduciary Oversight and Resilience

Connect ownership, material-risk decisions, remediation, escalation, and recovery evidence to executive oversight, incident-loss reduction, and insurance readiness.

Read the article

Why a Technical Baseline Cannot Prove Your Environment Is Secure

An audit records what exists. A defensible security conclusion requires approved business functions, ownership, access, data flow, and recovery context.

Read the article

From Point-in-Time Assessment to Continuous Assurance

Map the business, establish the observed baseline, define the target, verify remediation, and monitor for unauthorized drift.

Read the article

Least Privilege Begins With Business Functions, Not Groups

Directory membership shows assigned access. It does not prove that the access is required for a person's position and allocated functions.

Read the article

i-GEN opLYNX Central Authentication Bypass

CVE-2012-4688. Client-side authentication logic allowed access when JavaScript was disabled.

Read the disclosure

AxxonSoft Axxon Next Directory Traversal

CVE-2018-7467. A directory traversal issue in the AxxonSoft client web interface.

Read the disclosure

Managed Vulnerability Scanning as a Service

Why recurring authenticated discovery, reporting, remediation, and validation are foundational to a durable security program.

Read the article