Articles
Findings from our data11
Results from our own corpus that are not published anywhere else.
- One control to satisfy them all? We measured the Secure Controls Framework against its own set theory10 Aug 2026
- The compliance hub you cannot audit: reading the Unified Compliance Framework through its patents10 Aug 2026
- Where the defensive playbook runs out30 Jul 2026
- Article: Thirty AI risks, and the one that maps to nothing29 Jul 2026
- Article: 170 AI attacks, four weaknesses29 Jul 2026
Show all 11
- NVD does not have a word for prompt injection25 Jul 2026
- The flood that came in slow18 Jul 2026
- Where LLM-driven code scanning earns its keep — and where it doesn’t | Cyber Posture03 Jul 2026
- Grading the machine: how reliable are LLM-authored security cross-walks?03 Jul 2026
- Attributed CVEs — research scatter01 Jun 2026
- The patch-obfuscation crossover30 May 2026
Framework explainers5
Guidance for deciding which control framework to adopt, and what each one actually buys you.
- Which control framework should you actually adopt?26 Jul 2026
- The framework everything maps through26 Jul 2026
- What ASVS verifies, and what it skips26 Jul 2026
- The broad catalog and the deep one26 Jul 2026
- What a control framework can and cannot prevent26 Jul 2026
Opinion5
Signed, first-person arguments. Our position, not our data.
- Was the Hugging Face incident just human misconfiguration?30 Jul 2026
- We Still Need Offensive AI for Defense26 Jun 2026
- LLMs Discovering Vulnerabilities04 Jun 2026
- The customer side of the LLM-CVE arms race02 Jun 2026
- How will attackers react?12 May 2026
Regional2
Where a region is the subject of the piece rather than a passing mention.
How to read security data8
What a number does and does not support, and why we map the way we do.
- Coverage is not a single number26 Jul 2026
- The shortcut that always had an answer25 Jul 2026
- Software is not an industry25 Jul 2026
- How to read a vendor's CVE count25 Jul 2026
- Absent beats derived25 Jul 2026