Research
Living intelligence analysis
Long-form deep-dives that stay current — each post is revisited as new CVEs, threat-actor activity, and FlagThis stories land, linking directly into our own tracked entities. Sorted by most recently updated. Every update is logged in a revision history at the bottom of the post.
Where the 2026 CVE Increase Is Coming From
The CVE count is heading for 95,000 in 2026. Broken down by which organization issues each identifier, most of the rise traces to the industry disclosing more vulnerabilities — in more detail, from more sources, with the first vendor AI programs now finding bugs at scale — rather than to more or worse bugs.
Phantom Squatting: Weaponizing AI Hallucinations for Zero-Recon Supply Chain Attacks
How adversaries exploit statistically deterministic package and domain hallucinations across frontier LLMs to poison open-source software ecosystems — mechanics, empirical benchmarks, agentic threat modeling, and defense.
Iran's State AI Playbook: Sovereignty on a Sanctions Budget
How Tehran turned open-source LLMs, Chinese hardware, and hijacked Western cloud accounts into a functioning wartime AI program — and what it means for anyone tracking Iranian threat activity.
China's Digital Front in India
How China has systematically worked to infiltrate Indian government, defense, and corporate networks -- live campaigns, a leaked contractor's own target lists, and documented account-takeover tradecraft -- and how much of it holds up once every claim is checked against primary sources.