Site map
Everything, in one place.
The full index of the OSec site. If you’re looking for a specific page, it’s here: solutions, the Incenter platform, services, industries, resources and company.
Insights
2026
- The Wrapper Trap: Silent Persistence in Gradle and Maven
- The exploit window went negative. Here's what that breaks.
- EAP, AEV, CTEM: what the acronyms mean and where Incenter fits
- The Persistence Bridge: When npm Writes pnpm's Future
- OSec and Faction Networks Announce Partnership to Deliver Continuous Cyber Assurance for Owner-Controlled Zero Trust Networks
- The Persistence Engine: Configuration Reinstatement in uv
- Pip Dreams and Security Schemes, Part II: The Interpreter in the Machine
- Rotten Apples Returns — macOS Codesigning Translocation Revisited
- What Claude Security gets right — and what it misses
- Hollywood Has Always Run on Fragmentation. AI Is Making That Everyone's Problem.
- CIP-003-11 Is Here. Here's How to Comply Without Breaking Your OT Environment
- Test Your People, Not Just Your Filters
- Nobody Gives a S##t About Cybersecurity: A Postcard from the Edge of the Industry
- The Validation Layer for AI: Why Verifying Vulnerabilities Matters as Much as Finding Them
- The Day Zero Trust Died
- Wrongfully Accused: AI and the Death of Cyber Security
- AI Agents Are Already Hacking You. Your Internal Controls Won't Save You.
- The $10M Distraction: Why 50,000 CVEs Don't Matter (But 3 Attack Paths Do)
2025
- AI Security Checklist 2025
- The Sandworm in Your Dependencies
- Why JLR's £3.5bn Cyber Loss Should Change How You Budget Security
- Five AI Cyber Use Cases That Actually Work (and Two That Don't)
- From Point-in-Time Testing to Continuous Exposure Management
- Top 7 Cloud Security Trends Every Business Must Know in 2025
- Executive Order Strengthens U.S. Cybersecurity
- Financial Services Threat Briefing
- IIoT and OT Cybersecurity: The Next Battleground for Cyber Adversaries
- Stop Worrying About The Quantum Apocalypse
- Security Awareness Training Is Mostly Pointless: A Practitioner's Perspective
2024
- Threat Led Pen Testing and DORA
- When chatbots strike
- Cyber insurance — friend or foe?
- Enhancing Vulnerability Management with Incenter Tag Filtering
- Cisco Breached Data Posted on Dark Web Forums
- Pip Dreams and Security Schemes: Chaos in your Configuration Files
- Microsoft Patch Tuesday Analysis — September 2024
- Microsoft Patch Tuesday Analysis — July 2024
- Microsoft Patch Tuesday Analysis — April 2024
- LLMs Behaving Badly, Part 1 — Malware Creation
- Purple Teams — The Business Benefits of Cost-Effective Purple Penetration Testing
- Microsoft Patch Tuesday Analysis — February 2024
- Living off the Land: An Introduction to Blending In for Red Teams
- Unleashing the Power of Purple Teaming with MITRE ATT&CK
- Indicators of Compromise (IOC): Understanding, Identifying, and Utilizing Cyber Threat Indicators
- OSINT in Threat Hunting
2023
- What's Up, Doc? An OSec Approach to the Looney Tunables Bug (CVE-2023-4911)
- Protecting Education: Cybersecurity's Vital Mission
- Will Continuous Penetration Testing Lead to More Zero-Days?
- A Threat Model for Space-Based Data Centers
- Navigating the SEC Cybersecurity Risk Management Rules
- Cracked Open: Why Overlooking Lower-Risk Vulnerabilities Can Backfire
- The Human Touch in Cybersecurity: Why AI Can't Fully Replace Penetration Testers
- Is the SQL Injection Optional?
- Mastering FortiOS Exploitation: No Direct Debugging Required
- Unmasking Hidden Dangers: The Critical Need for Threat Hunting
- Major Incenter Updates Cover Mobile, API, Cloud and More
- Exploit for CVE-2023-2825
- Getting Root — A Technical Walkthrough
- Don't Put All Your Faith in Cyber Insurance
2022
2021
2020
- OWASP London / Suffolk Chapter Meeting
- Establishing a Beachhead
- What Is the Future of Commercial Drone Security?
- A Security Strategy for the New Normal
- More Secure Zoom Use
- Hostage Negotiation and Cyber Security
- In the Race to the Cloud, What Could Possibly Go Wrong?
- Emerging Trends in Threat Actor Communication Methods
2019
- The Industry Guide to Being a Successful "Bad Actor"
- Tales From the Red Team Crypt — Episode 1
- Everyone Can Be Taught New Tricks — Considerations for Application Pen Tests
- Lessons Learned from Healthcare Security Assessments
- LinkedIn Pwnage: Why We Can't All Be Friends
- Do Better Penetration Tests — for Buyers and Testers
- M&A Cybersecurity
- Lessons Learned from Working with Media Companies
Threat briefs
2026
- Weekly Situation Report — 8/3/26
- Weekly Situation Report — 7/27/26
- Weekly Situation Report — 7/20/26
- Weekly Situation Report — 7/13/26
- Weekly Situation Report — 7/6/26
- Weekly Situation Report — 6/29/26
- Weekly Situation Report — 6/22/26
- Weekly Situation Report — 6/15/26
- Weekly Situation Report — 6/8/26
- Weekly Situation Report — 6/1/26
- Weekly Situation Report — 5/25/26
- Weekly Situation Report — 5/18/26
- Weekly Situation Report — 5/11/26
- Weekly Situation Report — 5/4/26
- Weekly Situation Report — 4/27/26
- Weekly Situation Report — 4/20/26
- Weekly Situation Report — 4/13/26
- Weekly Situation Report — 4/6/26
- Weekly Situation Report — 3/30/26
- Weekly Situation Report — 3/23/26
- Weekly Situation Report — 3/16/26
- Weekly Situation Report — 3/9/26
- Weekly Situation Report — 3/2/26
- Weekly Situation Report — 2/23/26