See what we're thinking about, working on, & blogging about.

Explore the latest insights, ideas, & opinions from our talented team of experts & researchers.

BOD 26-04: A new era of prioritized remediation runZero Perspective

A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your team.

Subscribe Now

Get our latest Rapid Responses, insights, and blogs delivered directly to your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Rapid Response
How to find Veeam software on your network
June 9, 2026
Certain versions of Veeam Backup & Replication contain a vulnerability that allows an authenticated domain user to achieve RCE on the Backup Server.
Rapid Response
How to find LiteLLM instances on your network
June 8, 2026
LiteLLM has disclosed that certain versions of LiteLLM Proxy are susceptible to multiple vulnerabilities that can be chained together to achieve RCE.
Rapid Response
How to find Check Point devices
June 8, 2026
Critical Check Point VPN vulnerability allows unauthenticated attackers to bypass IKEv1 authentication. Here's how to find affected assets.
Rapid Response
How to find Palo Alto Networks devices running PAN-OS
May 29, 2026
PAN has disclosed that certain versions of PAN-OS are affected by an authentication bypass vulnerability in the GlobalProtect portal and gateway.
Rapid Response
How to find Gogs installations on your network
May 29, 2026
Certain versions of Gogs are affected by an argument injection vulnerability within the pull request "Rebase before merging" style merge handling.
runZero Perspective
LLMs are dual use, so use them
May 27, 2026
AI is flooding vulnerability handlers with bug reports. Discover how automation, security.txt, and AI-driven triage can help us fight fire with fire.
Rapid Response
How to find Drupal core instances on your network
May 22, 2026
Certain versions of Drupal core are affected by a SQL injection vulnerability in the database abstraction API. Here's how to find affected assets.
Use Cases
NIS2: Don’t panic. Start preparing.
May 19, 2026
Ready for NIS2? Legacy scans won't cut it. See how runZero delivers the real-time asset visibility and attack path mapping you need to meet all 10...
Rapid Response
How to find Vercel Next.js instances on your network
May 18, 2026
Self-hosted Next.js applications using the built-in Node.js server are vulnerable to SSRF within the WebSocket upgrade handling mechanism.
Rapid Response
How to find Cisco Catalyst SD-WAN installations on your network
May 14, 2026
Cisco disclosed versions of Cisco Catalyst SD-WAN Controller & Manager contain a vulnerability in the peering auth mechanism. How to find affected...
runZero Perspective
OT and Zero Trust: First things first
May 14, 2026
New guidance from CISA and the DoD adapts Zero Trust principles for OT systems. Learn why OT remains a target and how to safely map your attack...
Rapid Response
How to find Exim mail servers on your network
May 13, 2026
Certain versions of Exim are susceptible to a critical RCE vulnerability caused by a use-after-free condition in the BDAT body parsing path.