Tag: Vulnerability
-

The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure
The loudest story in security is AI. The quietest one is the same problem we have had for twenty years: someone forgot to turn off a server.
-

State of the Vulnerability: Q2 2026
Q2 2026 closed with 18,400 new CVEs assigned. The number is up 22 percent year over year. The number that matters is different, and the gap between the two is the story.
-

Supply Chain Attacks: When the Software You Trust Is the Problem
Traditional security assumes the dangerous code arrives from somewhere obviously untrusted. Supply chain attacks invert that model. The malicious component may arrive through a signed update, a trusted maintainer, or a dependency your team never knew it was running.
-

A Field Guide to the Secure Code Review
A field guide to the secure code review in 2026, with what the review actually catches, what the review is going to miss, and the right way to set up a review programme that scales without burning out the engineering team.
-

The CVE Tsunami: When the Database Becomes the Breach
The CVE database in 2026 hit 240,000+ entries, with 28,000+ new CVEs in 2025, with the typical enterprise unable to patch the CVEs at the rate the CVEs come in. The CVE tsunami amounts to the situation where the patching program runs behind the patching demand, the database becomes the breach vector the typical enterprise…
-

When Bug Bounties Pay and When They Are Marketing
A field guide to the bug bounty in 2026, with when the bug bounty actually pays for itself, when the bug bounty is pure marketing, and the indicators that tell you which one you are running.
-

The Red Team Bluff: Why Your Annual Pen Test Is a Waste
The annual penetration test is one of the most expensive line items in the security budget, and one of the least useful. The defender who runs the annual test gets a report. The defender who does the continuous testing gets the security. Here is why the annual test fails, and what works instead.
-

Real Hacking vs the Movies: What They Got Right and Wrong
The movies have been getting hacking wrong for decades, but every once in a while they get something right. The 2026 list of what the movies got right, what they got wrong, and what they got so wrong it is actually insulting to the people who do the work.
-

The Firmware Attack Surface You Have Never Looked At
Every modern endpoint runs firmware that the operating system cannot see. The OS patch cadence is monthly. The firmware patch cadence is whenever the vendor bothers. Here is what is actually in your fleet, and what to do about it.
-

The Raspberry Pi in Production Is a Security Incident Waiting to Happen
The Raspberry Pi in a homelab is a learning tool. The Raspberry Pi in a production rack is an unmanaged device running unpatched firmware on the same network as the payment system. Here is what to do about it.