Research Blog

Field notes from the fleet

Threat breakdowns, vulnerability analysis, and what our production honeypots are catching in the wild.

Vulnerability2026-06-27

CVE-2026-12569: Unauthenticated RCE in PTC Windchill and FlexPLM

A 9.3-critical unauthenticated remote code execution flaw in the PLM platforms that hold manufacturers' crown-jewel designs, now on CISA's KEV list.

Read →
Vulnerability2026-06-24

Lantronix EDS Device Servers on CISA KEV: Why Serial Gateways Matter

The Lantronix device-server KEV listing and why serial-to-IP gateways are high-value, under-watched OT targets.

Read →