RESEARCH
BRIEFS.
Adversary analysis, vulnerability research, and threat intelligence published without redaction.
APT Cluster Attribution: Mapping the Infrastructure Behind Q1 2026's Largest Campaign
A twelve-week investigation into the command-and-control infrastructure used in coordinated attacks against financial sector targets across Southeast Asia, uncovering shared tooling that links three previously unconnected threat groups.
Silent Entry: Firmware-Level Persistence in Enterprise Network Equipment
Detailed technical analysis of a firmware modification technique that survives factory resets and full OS reinstallation, identified across three major enterprise networking vendors during routine red team operations.
Zero Trust in Practice: The Implementation Failures That Create False Security
Across 47 zero-trust implementations reviewed in 2025, the same five failure modes appeared consistently. This report documents each failure, its root cause, and the specific detection telemetry that would have caught it.
Dwell Time Analysis: How Ransomware Operators Spend Their 21 Days
Post-incident analysis of 31 ransomware cases reveals a consistent pre-encryption timeline. Understanding it changes how organizations should prioritize detection.
The Grammar Is Perfect Now: AI-Assisted Spear Phishing at Scale
The tell-tale linguistic markers that security awareness training taught employees to recognize are disappearing. New research on AI-generated phishing campaigns and what detection actually looks like now.
Exposed by Default: OT/ICS Security Gaps in Critical Infrastructure
A structured red team engagement against a regional energy utility revealed operational technology systems accessible from the internet that the client's security team did not know existed.