Insights
Threat analysis, methodology deep-dives, and industry commentary.
The State of Zero-Day Exploitation in Critical Infrastructure
An analysis of zero-day disclosure trends across ICS, SCADA, and telecom sectors in 2025–2026, with recommendations for defensive posture.
July 2026 MethodologyBeyond the Checklist: Threat-Modelled Auditing
Why generic compliance checklists miss critical attack paths, and how STRIDE/PASTA-driven threat modelling produces measurable security outcomes.
June 2026 EngineeringFirmware Patching When the Vendor is Gone
Technical deep-dive into reverse-engineering proprietary firmware and engineering kernel-level patches for end-of-life edge devices.
May 2026 RegulationNIS2 and EU CRA: What It Means for Your Attack Surface
Mapping the new EU regulatory requirements to technical controls, with a gap analysis framework for organisations operating in Europe.
April 2026 ResearchAttack Surface Inflation in Cloud-Native Architectures
How microservices, service meshes, and serverless functions expand the attack surface — and how to model and contain the blast radius.
March 2026 Case StudyLessons from a Cross-Boundary Federation Attack Chain
Deconstructing a multi-hop attack path across identity federation layers, with detection and prevention guidance for enterprise architects.
February 2026