SECURITY RESEARCH
Security research
Real incidents, investigated first-hand: how attackers got in, what they did, how I found them and what changed afterwards. Client and service names are always withheld; the techniques, evidence and lessons are shared in full.
28 Days of Stolen CPU: React2Shell to Root
An automated bot exploited React2Shell (CVE-2025-55182) in an unpatched Next.js app, inherited root and quietly mined Monero for four weeks, planting an SSH backdoor along the way. How it got in, why our SIEM missed it, and how we hardened the estate.
Read the incident report →Anatomy of a Breach: The Alfa Shell
A client's website started redirecting visitors all over the place. The trail led to a brute-forced WordPress login, fake plugins hiding the notorious ALFA TEaM web shell, layered obfuscation built to beat antivirus, and a wiped web root.
Read the case study →Need a second pair of eyes?
If you think your systems may have been compromised, or you would like an independent view of how exposed they are, get in touch. I reply personally, usually within a working day.