What we find, we publish.
Field notes, security advisories and redacted sample deliverables — written and produced by the people who did the work. This section is new; here is how it is organized.
Blog
Field notes and research write-ups by the people who did the work.
Inside CVE-2026-48282: ColdFusion's RDS path traversal to RCE
A CVSS 10.0 path traversal in ColdFusion's Remote Development Services lets an unauthenticated attacker write a webshell into the web root. CISA added it to the Known Exploited Vulnerabilities catalog within a week of the patch.
Research note · 25 Jul 2026Inside wp2shell, the WordPress core RCE chain, and how to detect it
wp2shell chains CVE-2026-63030 and CVE-2026-60137 into an unauthenticated remote code execution path in WordPress core. Here is how the chain works, what to look for in logs and files, and how to confirm and fix an affected site.
Research note · 14 Jul 2026Detecting and responding to CVE-2025-3248, the Langflow unauthenticated RCE
CVE-2025-3248 lets an unauthenticated attacker run code on a Langflow host with one API call, and it is on the CISA KEV list. Here is how defenders spot it in telemetry, hunt past attempts, and respond.
Explainer · 12 Jul 2026The DPDP compliance clock: what applies now and what lands in May 2027
The DPDP Rules, 2025 stagger their obligations across eighteen months, and the heaviest land on 14 May 2027. Here is what is already in force, what comes next, and what a compliance team should build this quarter.
Advisories
Vulnerability disclosures and security advisories from engagements and research.
Nothing published yet — disclosures from our research land here.
Sample reports
Redacted sample deliverables — a web-app VAPT report, a compliance gap report — to download and judge the work before you buy.
Nothing published yet — the first downloadable sample report lands here.
Talk to the people who did the work.
Need a framework question answered or a technical detail on an engagement type? Skip the waiting room and ask us directly.