The Vulnerabilities That Never Get a CVE
July 2026
Most vulnerability programmes run on a simple assumption: if a flaw matters, it gets a CVE, and if
External Attack Surface Management: Seeing What Attackers Already See
July 2026
For years, security ran on a simple mental model: build the walls high, dig the moat deep, and
Your AI Coding Assistant's Config Folder Is a Persistence Surface
Supply-chain malware started writing into the config files your coding agent reads on every run. Nothing in the usual toolchain is watching that surface.
What Is Scanning My Server? An Internet Scanner Reference
You found a line in your logs you do not recognise. CensysInspect, Shodan-Pull/1.0, visionheight.com/scan, a
What is a JA3 Fingerprint? How TLS Client Fingerprinting Works
Recognise the software behind any encrypted connection from its TLS handshake alone. How JA3 fingerprinting works, how to read one, and what a single hash reveals about shared attacker tooling.
AndroxGh0st and the limits of TLS fingerprinting
May 2026
The same scanner toolkit AWS attributed to Interlock ransomware in March 2026 also runs AndroxGh0st credential theft and
Inside the Scanners Hunting Exposed AI Infrastructure: 72 Hours of Findings
460 source IPs, 11,643 requests, 72 hours. The AI-aware operators in the data enumerated; the exploitation observed targeted credentials, not AI capabilities.
Fable 5 Is Frozen and Glasswing Still Leaves Two Problems Open
Last updated: 30 June 2026 | What's changed: both models were suspended on 12 June under a US export
Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next
April 2026
Scattered Spider is a financially motivated cybercrime collective responsible for some of the most disruptive attacks in recent
Axios NPM Supply Chain Attack (2026): What Happened and What to Do
On March 31, 2026, two malicious versions of the axios npm package were published using a compromised maintainer account. The