See what we're thinking about, working on, & blogging about.

Explore the latest insights, ideas, & opinions from our talented team of experts & researchers.

Subscribe Now

Get our latest Rapid Responses, insights, and blogs delivered directly to your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Rapid Response
How to find SAP NetWeaver instances on your network
September 9, 2025
On September 9th, 2025, SAP issued patch note 3634501 to disclose an insecure deserialization vulnerability that affects certain versions of SAP...
Rapid Response
How to find Citrix NetScaler ADC & Gateway instances on your network
September 5, 2025
Citrix has published Security Bulletin CTX694938, documenting multiple vulnerabilities that impact customer-managed installations of NetScaler ADC...
Rapid Response
How to find Fortinet assets on your network
September 5, 2025
In August 2025, Fortinet disclosed vulnerabilities in certain versions of their FortiWeb and FortiSIEM and products. Here's how to find impacted...
Rapid Response
How to find N-able N-central installations on your network
September 5, 2025
N-able has disclosed two actively exploited vulnerabilities in certain versions of N-central. Here's how to find affected assets with runZero.
Rapid Response
How to find Plex Media Server installations on your network
September 5, 2025
Plex released a security update for a currently undisclosed vulnerability in certain versions of Plex Media Server.
Rapid Response
How to find Trend Micro Apex One installations on your network
September 5, 2025
Trend Micro has disclosed two OS command injection vulnerabilities in certain versions of its Apex One Management Console (on-premises).
Rapid Response
How to find FreePBX installations on your network
September 3, 2025
Sangoma has disclosed multiple flaws in certain versions of its FreePBX telephony software. Here's how to find affected assets.
Rapid Response
How to find Arcserve Unified Data Protection installations on your network
August 29, 2025
Arcserve has disclosed two heap overflow vulnerabilities in all versions of its Unified Data Protection (UDP).
runZero Research
runZero Hour, ep. 21 recap: highlights from Hacker Summer Camp
August 26, 2025
Our top insights, tools and stories from Hacker Summer Camp 2025.
Rapid Response
How to find Rockwell Automation devices
August 22, 2025
Rockwell Automation has disclosed a remote code execution (RCE) vulnerability in certain models and versions of ControlLogix Ethernet modules.
runZero Perspective
Operational technology (OT): just like all the other horses
August 21, 2025
We need to make OT subnets just like all the other horses. Normal, stable, and just like all the others — not a fragile glass unicorn of technology.
runZero Research
Introducing EPSS Pulse: monitoring volatility in vulnerability risk
August 7, 2025
Learn about the origins of EPSS Pulse — the free tool that highlights recent 'fast movers' among EPSS-evaluated, CVE-identified vulnerabilities.