Tag: Vulnerability
-

Hardware Firmware Extraction in 2026
The hardware firmware extraction in 2026 sits as the security research technique the attacker uses to find the vulnerabilities the defender does not know about. The attacker extracts the firmware from the device, the attacker analyses the firmware, the attacker finds the backdoor the manufacturer left, the attacker finds the hardcoded credential the developer forgot,…
-

DDoS Mitigation on a Budget
The DDoS attack in 2026 amounts to the attack the typical enterprise faces 5-20 times per year, with the attack peaking at 1-10 Tbps, with the attack lasting 1-24 hours, with the attack costing the enterprise $20K-$200K per hour in lost revenue. The mitigation in 2026 amounts to the work the typical enterprise does on…
-

The Windows Event Log Primer
The Windows event log in 2026 amounts to the single most underused source of security data in the typical enterprise. The enterprise buys the SIEM, the enterprise points the SIEM at the network, the enterprise misses the threats that the Windows event log would have caught. The primer for what the events are, what they…
-

The Secrets Rotation Playbook
A field guide to secrets rotation in 2026, with what the right cadence is, what to rotate and what to retire, and the automation that makes the rotation actually happen without breaking the production.
-

SIEM Cost Optimization: The Honest Guide
SIEM cost optimisation in 2026 amounts to a $5B annual problem for the enterprises running the legacy SIEMs, and a $1B annual problem for the enterprises that already moved to the cloud native SIEMs. The cost has not gone down, the data volumes have not gone down, the licensing model has gotten worse. The honest…
-

Password Reuse Is Still Winning in 2026
Password reuse is still winning in 2026. People reuse passwords. They reuse the same password across work and personal accounts. They reuse the same password across the work accounts of every job they have ever had. The advice to use unique passwords is good advice. The advice is not being followed. The attackers know.
-

Critical Infrastructure Attacks in 2026: The Patterns
The critical infrastructure attack has stopped being the hypothetical scenario the national security advisor uses to justify the budget. It has become the operational reality the utility operator, the water utility, the hospital network has started to live with.
-

The Zero Day Economy in 2026: The Prices, the Buyers, the Deals
The zero day economy in 2026 sits at a $2B annual market, up from $300M in 2020, with the prices for the most valuable exploits reaching seven figures per buyer. The state of the zero day economy in 2026 amounts to a market that has matured, professionalised, and consolidated into a few large players.
-

A Field Guide to the Zero Trust Rollout
Zero trust in 2026 stands as the security framework that has been overhyped for a decade and that has finally started to deliver on the value. The 2026 zero trust rollout looks like the maturity of the tooling, the maturity of the standards, the maturity of the patterns, the maturity of the operational practice. The…
-

What osquery Tables Actually Tell You in 2026
osquery in 2026 amounts to the most underused endpoint visibility tool in the typical enterprise. The enterprise deploys the EDR, the EDR catches the known threats, the EDR misses the unknown threats, the unknown threats sit on the endpoint unobserved. The osquery tables expose the endpoint state in a way the EDR cannot. The guide…