The clock is running out — and pentesting is no longer optional
Attackers used to give you a month to patch and now give you five days, while regulators remove the choice about testing. What good looks like in 2026.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
114 posts
Attackers used to give you a month to patch and now give you five days, while regulators remove the choice about testing. What good looks like in 2026.
Read the post →DNSDumpster shows you the same public DNS picture an attacker starts from. How to use it to map your own external attack surface, for free, this afternoon.
Read the post →Dashboards enumerate assets. None of that is defense. Why discovery does not equal security, and where identity multiplies an exposure into a breach.
Read the post →Compliance verifies that controls exist. Security verifies they hold. Here is where the gap opens up, and why breached organizations were often fully certified.
Read the post →Attackers chain low-severity findings into serious compromise. Why severity scores rank issues badly on their own, and what to prioritize instead.
Read the post →CVSS v4 changes how severity is scored, and what your reports will look like. What is new, what improved, and how to read the two versions side by side.
Read the post →The most damaging incidents are quiet ones built for leverage. Five things worth doing this quarter, in the order that reduces the most risk soonest.
Read the post →The findings we reported most often on external network engagements in 2025, ranked, with what each one usually means about the environment behind it.
Read the post →Data poisoning, adversarial input, prompt injection, and model extraction. The five AI threats worth modeling once AI is embedded in how the business runs.
Read the post →External assets stay the most attacked entry point into any organization. What external testing looks like in 2026, and how we approach the engagement.
Read the post →