Security Research

Intelligence from the team
building Outrightly

CVE analysis, threat research, and security engineering from the people watching the feed all day.

FeaturedProduct
Strategy7 min read

Why CISA KEV Should Be Your First Alert Filter

The Known Exploited Vulnerabilities catalog changed how security teams should prioritize CVEs. Here is how to build your alerting strategy around it.

June 30, 2026Read
CVE Analysis11 min read

CVE-2024-6387 RegreSSHion: Anatomy of a Critical OpenSSH Vulnerability

A deep dive into the unauthenticated RCE in OpenSSH's signal handler, why it matters even without reliable exploitation, and what you should have done on day one.

June 12, 2026Read
Data & Research9 min read

The 197-Day Problem: Why Breach Detection Lags the Threat

We analyzed 3 years of CVE publication data against breach disclosure timelines. The gap between a CVE being known and a team acting on it is still measured in months.

May 28, 2026Read
Engineering8 min read

Zero-Trust CVE Monitoring for Small Security Teams

You do not need a 10-person security team to have mature CVE monitoring. This is the lightweight, high-coverage approach we recommend for teams of 1 to 5.

May 14, 2026Read
Strategy6 min read

The Transitive Dependency Blind Spot Most Teams Miss

Your direct dependencies are monitored. But what about the packages your packages depend on? We quantified the exposure gap and show you how to close it.

April 29, 2026Read
Strategy5 min read

CVSS Score Is Not a Priority Queue

A CVSS 9.8 sitting dormant in a library nobody calls is less urgent than a CVSS 7.2 in your authentication flow. Here is how to build context-aware prioritization.

April 8, 2026Read
Case Studies14 min read

Three Breaches. Three Tools That Weren't Watching.

Equifax, Log4Shell, and MOVEit Transfer: real incidents where the CVE was public, the patch existed, and the tools in place still missed it. Here is exactly why, and what a different monitoring architecture would have caught.

July 18, 2026Read