Insights

Research, advisories, and field notes.

What we're seeing in the wild, what we're publishing, and what we're learning across engagements. Written by the consultants doing the work.

RSS feed

Research

Chaining SSRF and IMDSv1 fallback in modern EKS clusters

A pattern we've hit on three separate engagements this quarter — how a small misconfiguration in a legacy service opens the door to full node compromise.

Jul 12, 2026 9 min

Advisory

CVE-2026-XXXX: Authentication bypass in a popular Node ORM

Discovered during a routine code review. Coordinated disclosure timeline, PoC constraints, and mitigation guidance for teams still on the affected release line.

Jun 28, 2026 6 min

Field Notes

What 40 SOC 2 audits taught us about evidence automation

The controls auditors actually scrutinize, the ones they wave past, and the automation patterns that survive year-two continuous monitoring.

Jun 15, 2026 12 min

Compliance

India's DPDP Act one year in: what actually changed for startups

Consent artifacts, data-principal request workflows, and the cross-border transfer questions we're being asked most often by founders.

May 30, 2026 8 min

Research

Prompt-injection meets SSRF: agentic LLM apps as a new pivot point

When an LLM can invoke tools, the classic web vulns don't disappear — they get a new attacker interface. A taxonomy plus concrete mitigations.

May 18, 2026 11 min

Field Notes

Tabletop exercises that don't get ignored the next Monday

The format shift that turned our IR rehearsals from checkbox theater into a driver of real runbook changes across engineering and legal.

May 4, 2026 7 min

Get research in your inbox.

One email a month. New advisories, deep dives, and the patterns we're seeing across engagements. No pitch.

Working on something specific? Talk to a consultant.