// the big data blog

Field intel, published continuously.

Written from real deployments and real incidents — ransomware remediations, Shadow AI audits, and the architecture debates behind them.

FortiBleed: 430,000 Firewalls, and Why the Stolen Credential Was Never the Real Problem

Attackers harvested VPN credentials straight off compromised firewalls, and researchers have now tied that haul to INC and Lynx ransomware. The uncomfortable lesson isn't about passwords — it's about what a valid credential buys.

Jul 11, 2026 · 7 minRead →

2026 Is the Year the VPN Appliance Became the Attack Surface

SonicWall, Ivanti, Fortinet, Citrix — four vendors, one pattern. The internet-facing remote access appliance has become a liability as a category, and even governments are now saying so.

Jul 10, 2026 · 6 minRead →

You Can't Exploit What You Can't See: Why Cloaked Networks Were Ready for Mythos Before It Had a Name

Mythos-class AI can find and exploit vulnerabilities at machine speed — but every exploit still begins with reconnaissance. If your infrastructure is cloaked, the AI's greatest strength finds nothing to aim at.

Jul 7, 2026 · 6 minRead →

Effective Endpoint Security Options Explained

Every laptop, phone, and desktop is a potential entry point. Here's how the endpoint security options actually differ — and how to choose one that fits your budget and scales with your business.

Jun 22, 2026 · 5 minRead →

Shadow AI Is Already Running on Your Network

Teams underestimate their AI footprint by an order of magnitude — 3 to 5 AI tools per employee, connected through OAuth tokens approved in seconds. Here's how to get it back under control.

Jun 18, 2026 · 4 minRead →

Remediation from a Ransomware Attack: Zero Trust from the Top Down

Field guidance from a customer network that had just been hit — the engagement the breach story on our homepage is drawn from. What we did, in what order, and why.

Jun 2, 2026 · 9 minRead →