Research

Living intelligence analysis

Long-form deep-dives that stay current — each post is revisited as new CVEs, threat-actor activity, and FlagThis stories land, linking directly into our own tracked entities. Sorted by most recently updated. Every update is logged in a revision history at the bottom of the post.

Midnight Spike: Unmasking the mysterious crawler
Research Updated 2026-09-14 Published 2026-09-14
How an unexpected crawler swarm made our database sweat, why classical rate limiting failed so spectacularly, and how a slightly painful week turned into an impromptu distributed systems lab experiment.
The Evolution of Ransomware: From Floppy Disks to Industrialized Extortion
Research Updated 2026-09-13 Published 2026-09-13
How ransomware grew from a 1989 mail-order scam into a franchised, multi-extortion criminal economy — the eras, the family trees, the business model, and where to watch it operate.
Where the 2026 CVE Increase Is Coming From
Research Updated 2026-09-07 Published 2026-08-30
The CVE count is heading for 95,000 in 2026. Broken down by which organization issues each identifier, most of the rise traces to the industry disclosing more vulnerabilities — in more detail, from more sources, with the first vendor AI programs now finding bugs at scale — rather than to more or worse bugs.
Phantom Squatting: Weaponizing AI Hallucinations for Zero-Recon Supply Chain Attacks
Research Updated 2026-09-07 Published 2026-08-22
How adversaries exploit statistically deterministic package and domain hallucinations across frontier LLMs to poison open-source software ecosystems — mechanics, empirical benchmarks, agentic threat modeling, and defense.
Iran's State AI Playbook: Sovereignty on a Sanctions Budget
Research Updated 2026-09-07 Published 2026-08-16
How Tehran turned open-source LLMs, Chinese hardware, and hijacked Western cloud accounts into a functioning wartime AI program — and what it means for anyone tracking Iranian threat activity.
China's Digital Front in India
Research Updated 2026-09-07 Published 2026-08-16
How China has systematically worked to infiltrate Indian government, defense, and corporate networks -- live campaigns, a leaked contractor's own target lists, and documented account-takeover tradecraft -- and how much of it holds up once every claim is checked against primary sources.

LINK COPIED TO CLIPBOARD