We share our expertise to make the world a safer place.
InfoSec moves at a rapid pace and sometimes it’s hard to keep up—that’s where we enter the chat.

Discover current cybersecurity insights
Get vital information straight from the experts, without all the noise.

Risk at the Edge: Managing Cyber Exposure Across IT & OT Assets
Join Senior Security Consultant Steph Saunders for a practical look at how to close gaps and build cyber resilience across converged IT/OT environments.

waf-fu, or Some Log Replay Nonsense
AWS WAF logs are keeping receipts, including your session tokens. In this blog, we walk through the risk of default WAF logging configurations and the tool…

Security Noise - Hacker Summer Camp 2026
We're back from Hacker Summer Camp and are ready to get "Reel" about our experiences in Las Vegas! Join us on this episode of Security Noise as we sit down to…

SpooNMAP Grows Up: Findings, Local LLM Detection, and a Whole Lot Less Waiting
SpooNMAP used to hand you a list of open ports; the latest update tells you which ones actually matter. In this blog, we detail the new automated findings…

AMA: CMMC Phase II Suspension and Beyond
Join Director of Advisory Services Chris Camejo and Compliance Practice Lead Lee Quinton for an expert breakdown of the recent CMMC changes and how to prepare…

We've Seen This Movie: The OT/IT Technology Divide
Manufacturing knows what happens when IT and OT divide; AI governance is an unexpected chance to do it differently. In this blog, we walk through a unified…

AI Offense is Not Noclip Mode
AI doesn't let attackers walk through walls, but it makes finding the cracks more efficient. In this blog, we cut through the hype and explain what AI-driven…

A Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI
This blog post should not exist, but it does. In this blog, we detail the improper CMMC Level 2 flow-down problem and the most cost-effective path to…

The Art of Hunting Azure Cloud Secrets
The difference between a standard cloud test and a subscription takeover? Finding the right secrets. In this blog, we introduce two open-source tools for…

TLS Encryption and Compliance
Transport Layer Security: the compliance checkbox that's harder to get right than it looks. In this blog, we cover the most common TLS misconfigurations and…

Black Hat USA Training - Supply-Chain to Runtime: Attacking & Defending the Modern DevOps Stack
During our Black Hat training, go beyond network pentesting fundamentals and gain the attacker and defender perspective needed to conduct modern,…

AMA: CCPA's New Cybersecurity Audit Requirement
During this live AMA, you’ll get the chance to ask your pressing questions about the new CCPA regulations and find out how your organization can prepare for…
Loading...
Get our best blogs, latest webinars, and podcasts sent to your inbox.
Our monthly newsletter makes it easy to stay up-to-date on the latest in security.
