Research
Chaining SSRF and IMDSv1 fallback in modern EKS clusters
A pattern we've hit on three separate engagements this quarter — how a small misconfiguration in a legacy service opens the door to full node compromise.
Insights
What we're seeing in the wild, what we're publishing, and what we're learning across engagements. Written by the consultants doing the work.
Research
A pattern we've hit on three separate engagements this quarter — how a small misconfiguration in a legacy service opens the door to full node compromise.
Advisory
Discovered during a routine code review. Coordinated disclosure timeline, PoC constraints, and mitigation guidance for teams still on the affected release line.
Field Notes
The controls auditors actually scrutinize, the ones they wave past, and the automation patterns that survive year-two continuous monitoring.
Compliance
Consent artifacts, data-principal request workflows, and the cross-border transfer questions we're being asked most often by founders.
Research
When an LLM can invoke tools, the classic web vulns don't disappear — they get a new attacker interface. A taxonomy plus concrete mitigations.
Field Notes
The format shift that turned our IR rehearsals from checkbox theater into a driver of real runbook changes across engineering and legal.
One email a month. New advisories, deep dives, and the patterns we're seeing across engagements. No pitch.