Research
Our research teams investigate emerging threats, secure software, digital identity, and the societal impact of connected systems—so defenders can act on evidence, not fear.
Threat Research
Tracks adversaries, campaigns, exposure patterns, and the defensive signals organizations can use.
AI Security
Studies agent safety, model misuse, prompt attacks, and reliable controls for AI-enabled systems.
Privacy & Identity
Examines identity abuse, data exposure, verification, and privacy-preserving security systems.
Malware Analysis
Analyzes malicious files, infrastructure, and behavior to improve detection and response.
Vulnerability Research
Finds software weaknesses and develops practical, responsibly disclosed remediation guidance.
Human Solving Services and the Limits of Asking "Are You Human?"
A captcha solved by a paid human is solved by a human. The defence cannot be a harder puzzle, because the puzzle is not what failed. What actually separates a genuine visitor from a relayed one is continuity and cost.
What a Router Traffic Counter Actually Measures
A gateway counter is a total, not a rate. It resets without warning, and on a fast connection a 32-bit one can wrap in under a minute. Every honest traffic graph is built on top of those three facts, and the graphs that ignore them fail in the same three ways.
Vulnerability Research · Aug 27, 2026A Monitoring Agent Is Not an API Client
Continuous telemetry and request-driven API calls arrive over the same transport and look identical at the door. Metering them the same way builds a system where a customer's own monitoring throttles their production integration — a denial of service nobody had to attack you to cause.
Malware Analysis · Aug 27, 2026Antivirus and Anti-Cheat Want the Same Access. Only One of Them Is Trusted.
A resident security scanner needs kernel drivers, memory inspection and filesystem hooks. A kernel anti-cheat treats exactly those capabilities as the attack it exists to stop. On a competitive gaming machine, "just install antivirus" is not free advice.
Threat Research · Aug 22, 2026An IP Flag Is Not a Fact
Every IP intelligence product answers "is this a VPN?" with true or false. The honest answer has a second half — how well-evidenced that is — and dropping it moves the risk onto whoever is blocking real users.
Publications
| Date | Research team | Title |
|---|---|---|
| Aug 27, 2026 | Threat Research | What a Router Traffic Counter Actually Measures |
| Aug 27, 2026 | Vulnerability Research | A Monitoring Agent Is Not an API Client |
| Aug 27, 2026 | Malware Analysis | Antivirus and Anti-Cheat Want the Same Access. Only One of Them Is Trusted. |
| Aug 25, 2026 | Threat Research | Human Solving Services and the Limits of Asking "Are You Human?" |
| Aug 22, 2026 | Threat Research | An IP Flag Is Not a Fact |
| Aug 22, 2026 | Threat Research | Why Residential Proxies Defeat the Standard Playbook |
| Aug 15, 2026 | Privacy & Identity | reCAPTCHA Alternatives: What Actually Differs |
| Aug 15, 2026 | Threat Research | The Controls Cyber Insurers Ask About |
| Aug 15, 2026 | AI Security | Prompt Injection Is an Architecture Problem, Not a Filter Problem |
| Aug 15, 2026 | Privacy & Identity | Why Credential Stuffing Survives MFA |
| Aug 2, 2026 | Threat Research | Defending the Origin: Mitigating CDN Bypass and Multi-Vector Attacks |