September 1, 2026
Access-Control-Allow-Origin: * paired with Access-Control-Allow-Credentials: true is a spec-violating pattern most CORS middleware shouldn't produce. 13.7% of the index serves it live, and 93.3% of those companies have zero HackerOne bounty coverage.
Read More
August 30, 2026
More than a third of the index has a legacy mail protocol reachable from the open internet. 96.9% of those companies have zero HackerOne bounty coverage — a sixth consecutive report finding the same disclosure gap.
Read More
August 28, 2026
FTP sends credentials and file contents in plaintext by default. 32.2% of the index has at least one server answering on port 21, and 96.6% of those companies have zero HackerOne bounty coverage.
Read More
August 25, 2026
No X-Frame-Options, no Content-Security-Policy. 82.0% of the index has at least one live host with neither header, and the affected companies have the same near-total bounty coverage gap as every prior report.
Read More
August 24, 2026
HSTS is a single free response header that stops downgrade attacks cold. 61.3% of the index doesn't send it on at least one live host, and 97% of those companies have zero HackerOne coverage.
Read More
August 23, 2026
We ran reverse WHOIS by registrant org across the whole index and confirmed 1,621 live sister domains for 25 companies. 17 of those companies have zero bounty coverage anywhere, and 11 have a version-matched CRITICAL CVE sitting on one of these domains right now.
Read More
August 22, 2026
We cross-referenced every certificate domrecon has recorded against the latest HTTP probe for that host. 208 companies have an expired cert somewhere; 157 are still serving 2xx/3xx traffic on it right now. One lapsed in January 2015.
Read More
August 21, 2026
We checked live port-scan results for Redis, MySQL, PostgreSQL, RDP, and Telnet across the whole index. One in five companies has at least one exposed. 95.5% of those have zero HackerOne coverage.
Read More
August 19, 2026
We matched live technology fingerprints against our CVE cache across the whole index. 62.8% of companies have at least one CRITICAL, version-matched vulnerability. 96.8% of those have zero HackerOne coverage.
Read More
August 18, 2026
We cross-referenced archived-but-still-live admin panels, backup files, and staging endpoints against HackerOne bounty coverage. 92% of companies with a live legacy exposure have nowhere to report it.
Read More
August 17, 2026
We scanned every GraphQL endpoint we could find across 541 S&P 500 companies. 37 have introspection enabled — including 22 with zero bug-bounty coverage on the exposed asset.
Read More
August 16, 2026
We cross-referenced HackerOne's public scope data against our S&P 500 attack-surface scans. Most companies with real, live risk have nowhere for a researcher to report it.
Read More
July 29, 2026
We scanned all 520 constituents. Here's what the internet actually knows about corporate America's biggest companies.
Read More
Oct 12, 2025
As we move towards autonomous systems, the concept of identity must evolve.
We discuss how Zero Trust principles apply to AI agents in the fed space.
Read More
Sep 28, 2025
ShadowMQ patterns are becoming prevalent in inference stacks. Here's how we
identified and hardened a critical infrastructure client against this vector.
Read More