See what we're thinking about, working on, & blogging about.

Explore the latest insights, ideas, & opinions from our talented team of experts & researchers.

LLMs are dual use, so use them runZero Perspective

AI is flooding vulnerability handlers with bug reports. Discover how automation, security.txt, and AI-driven triage can help us fight fire with fire.

Subscribe Now

Get our latest Rapid Responses, insights, and blogs delivered directly to your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Rapid Response
How to find Drupal core instances on your network
May 22, 2026
Certain versions of Drupal core are affected by a SQL injection vulnerability in the database abstraction API. Here's how to find affected assets.
Rapid Response
How to find Vercel Next.js instances on your network
May 18, 2026
Self-hosted Next.js applications using the built-in Node.js server are vulnerable to SSRF within the WebSocket upgrade handling mechanism.
Rapid Response
How to find Cisco Catalyst SD-WAN installations on your network
May 14, 2026
Cisco disclosed versions of Cisco Catalyst SD-WAN Controller & Manager contain a vulnerability in the peering auth mechanism. How to find affected...
runZero Perspective
OT and Zero Trust: First things first
May 14, 2026
New guidance from CISA and the DoD adapts Zero Trust principles for OT systems. Learn why OT remains a target and how to safely map your attack...
Rapid Response
How to find Exim mail servers on your network
May 13, 2026
Certain versions of Exim are susceptible to a critical RCE vulnerability caused by a use-after-free condition in the BDAT body parsing path.
Rapid Response
How to find F5 NGINX installations on your network
May 13, 2026
F5 published a security advisory that a high vulnerability was identified in multiple versions of NGINX products. Here's how to find NGINX...
Rapid Response
How to find Fortinet FortiAuthenticator on your network
May 12, 2026
Fortinet disclosed in an advisory that a critical vulnerability was identified in versions of FortiAuthenticator.
Rapid Response
How to find Fortinet FortiSandbox on your network
May 12, 2026
Fortinet disclosed in an advisory that a critical vulnerability was identified in versions of FortiSandbox.
Rapid Response
How to find LiteLLM instances on your network
May 8, 2026
LiteLLM has disclosed that certain versions of LiteLLM Proxy are susceptible to multiple vulnerabilities that can be chained together to achieve RCE.
Product
Validate your network segmentation assumptions with runZero
May 7, 2026
Is your network really segmented? Don't assume, validate. runZero shows you the truth by visualizing real attack paths and exposing hidden...
Rapid Response
How to find Ollama instances on your network
May 6, 2026
Certain versions of Ollama are susceptible to a heap out-of-bounds read vulnerability within the GGUF model loader. Here's how to locate affected...
Rapid Response
How to find Android Debug Bridge (ADB) on your network
May 5, 2026
Google disclosed that certain Android versions are susceptible to an authentication bypass vulnerability within the wireless ADB mutual...