Home Services About Insights Contact

From the Field

Research, threat analysis, and security thinking from our team.

Research March 2026

The Hidden Risk in Your AI Agent Stack

How harmful skills can weaponize enterprise automation, and what security teams should do about it.

Threat Landscape February 2026

The Rise of Cybercrime as a Service

What every business leader needs to know about the industrialized threat landscape in 2026.

Research January 2026

When Your AI Agent's Skills Become Weapons

Inside the skill-reading exploit and why current safety guardrails aren't enough.

Emerging Threats May 2024

When the Virtual Becomes Physical

Can AI police the metaverse? Embodied cyber threats in social VR and the double-edged sword of generative AI moderation.

Threat Analysis June 2023

MOVEit and the Zero-Day Supply Chain Problem

Why no vendor can solve the supply chain zero-day problem alone, and what your organization should do about it.

Strategy October 2023

Why Your Pentest Report Is Gathering Dust

Closing the gap between findings and fixes, and why most pentest deliverables fail to produce actual security improvement.

Web3 Security March 2023

The Move Language Problem

Why new smart contract languages need new auditing approaches, and what the shift from Solidity means for security.

Compliance November 2022

SOC 2 for Startups

How to get audit-ready without building a compliance team, and why SOC 2 is a revenue enabler, not a cost center.

Threat Analysis August 2022

The MFA Bypass Wave

Why your second factor isn't as safe as you think, and how adversary-in-the-middle attacks are changing the authentication landscape.

Vulnerability Analysis December 2021

Log4Shell and the Open Source Trust Problem

The Log4j vulnerability exposed the fragility of open source dependencies, and why startups are uniquely exposed.

Web3 Security October 2021

DeFi Hacks Are Security Audits by Other Means

The wave of DeFi exploits in 2021 proves that on-chain security auditing is no longer optional for any protocol handling user funds.

Threat Analysis July 2021

Ransomware Is Not a Technical Problem

Why startups need a negotiation playbook, and how the ransomware surge of 2021 changed the calculus of incident response.

Threat Analysis December 2020

SolarWinds Changed Everything

What the supply chain attack means for startups, and why vendor trust is a liability you need to manage.

Strategy September 2020

Why Your Startup's First Security Hire Should Be a Pentester

Early-stage companies should think differently about security hiring, and why finding problems beats building policy.

Industry April 2020

The Remote Work Security Crisis Nobody Planned For

The sudden shift to remote work exposed security gaps that most startups didn't know they had. Here's what to fix first.

Have a Security Question
We Should Write About?

We write about what we see in the field. If there's a topic you want covered, let us know.

Get in Touch