
Latest perspective · September 8, 2026
Introducing ARES for automated penetration testing
See how Meridian ARES validates exploitable attack paths, preserves evidence, and connects authorized penetration testing to remediation and retesting.
CulperSec perspectives
Practical analysis for teams making decisions about security, resilience, risk, and compliance.

Latest perspective · September 8, 2026
See how Meridian ARES validates exploitable attack paths, preserves evidence, and connects authorized penetration testing to remediation and retesting.
The archive
Threat analysis, practical guidance, and lessons from the work of protecting modern organizations.

September 7, 2026 · 9 min read
A BGP hijack redirected Virtualizor update traffic and delivered malware to hypervisors. Operators need evidence, credential rotation, and clean rebuilds.
Read article
September 2, 2026 · 8 min read
PaperCut Release 3 closes an exploited RCE chain, but exposed servers still need evidence preservation, hunting, and rebuild decisions.
Read article
September 2, 2026 · 9 min read
CVE-2026-73570 is under active exploitation. Zimbra teams need to identify the vulnerable configuration, upgrade, and investigate for compromise.
Read article
July 20, 2026 · 8 min read
How SMA1000 owners should patch CVE-2026-15409 and CVE-2026-15410, then verify the appliance was not used for internal access.
Read article
July 14, 2026 · 11 min read
The CMMC Phase II suspension pauses some third-party pressure, not CUI duties. Here is what SMB defense contractors should review and document.
Read article
March 17, 2026 · 9 min read
A practical lessons-learned look at the recent Stryker cyber incident, with concrete steps healthcare and medtech security teams can take to improve containment, continuity, and recovery.
Read article