RSS Amplifier

Blog

Empiric Security

Ryan Basden on offensive security, and the distance between what companies believe about their defenses and what happens when someone tests them. Published first at ryanbasden.com.

empiricsecurity.substack.comSource feed ↗7 posts

Live Last read · last published · next check

Written by

Latest posts

You Can’t Just Publish Partial Exploits Anymore

A ‘safely’ disclosed WordPress RCE, taken most of the way to a full unauthenticated exploit chain with public research and an LLM, and the rest with a public PoC.

Everyone Has A Plan Until They Get Punched In The SonicWall

Challenge your mental model of how attackers work before it's too late.

How to Ensure Your Purple Team Fails Miserably

Your ultimate guide to guaranteeing one of security's most beneficial exercises does nothing for you.

Ocean's Eleven Heists In a Louvre Four World

Are physical security assessments a fun novelty? Or are fewer businesses taking them as seriously as they should?

How Shadow Incentives Harm Real Security

Despite the millions upon millions of dollars thrown at penetration testing ever year, big data breaches are still as common as ever.

You Will Definitely Get Phished, So Stop Simulating It

At this point, it's hurting more than helping.

What's In a Name?

An introduction to Empiric Security. Let's get real.