See what we're thinking about, working on, & blogging about.

Explore the latest insights, ideas, & opinions from our talented team of experts & researchers.

Lights Out: The server in your server, exposed and disclosed runZero Research

runZero discloses critical authentication bypass and privilege escalation flaws in OpenBMC IPMI implementations. Here’s what you need to know.

Subscribe Now

Get our latest Rapid Responses, insights, and blogs delivered directly to your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

runZero Research
From legacy to liability: New research report on end-of-life assets
October 1, 2025
End-of-life (EOL) operating systems don’t just fade away. They linger in enterprise networks like the undead — unchanging, unpatched, and...
Rapid Response
How to find VMware Aria installations on your network
September 30, 2025
VMware has disclosed a local privilege escalation vulnerability in its VMware Aria Operations and VMware Tools. Here's how to find impacted assets.
Rapid Response
How to find Fortra GoAnywhere MFT installations
September 29, 2025
Fortra has disclosed a deserialization of untrusted data vulnerability in the license servlet of its GoAnywhere Managed File Transfer (MFT).
Rapid Response
How to find Cisco IOS & IOS-XE devices
September 29, 2025
Cisco has disclosed a vulnerability, CVE-2025-20352, in its IOS and IOS-XE software. Here's how to find affected assets with runZero.
Rapid Response
How to find Trend Micro Apex One installations on your network
September 29, 2025
Trend Micro has disclosed two OS command injection vulnerabilities in certain versions of its Apex One Management Console (on-premises).
runZero Research
Fast ≠ careless: cutting exposure time without breaking things
September 26, 2025
This month’s runZero Hour wasn’t just another CVE rundown. We went deeper to uncover what it means to move fast without breaking things.
Rapid Response
How to find Cisco firewalls on your network
September 25, 2025
Cisco has disclosed three vulnerabilities on certain versions of Cisco Secure Firewall ASA and Cisco Secure FTD software.
runZero Research
Grappling with a post-CVE world
September 25, 2025
The writing is on the wall: an over-reliance on CVEs and agent-based approaches won’t keep you safe. So what else can you do to regain the upper hand?
Rapid Response
How to find Daikin Security Gateway devices on your network
September 18, 2025
Daikin has disclosed a vulnerability in DELMIA Apriso that may allow a remote, unauthenticated adversary to perform remote code execution.
runZero Research
Webcast recap: see + secure everything in your OT environment
September 17, 2025
A recap of last week’s webcast, where the runZero research team dug into the hard-earned lessons of managing sensitive OT environments.
Rapid Response
How to find Dassault Systèmes DELMIA Apriso installations on your network
September 12, 2025
Dassault Systèmes (3DS) has disclosed a vulnerability in DELMIA Apriso that may allow a remote, unauthenticated adversary to perform remote code...
Rapid Response
How to find Adobe Commerce & Magento installations on your network
September 9, 2025
Adobe has disclosed an improper input validation vulnerability in the Commerce REST API, affecting certain versions of Adobe Commerce and Magento...