Original adversary-tracking and methodology pieces. Every quantitative claim is sourced to the platform's own aggregated feed (verifiable at the linked detail pages) or to named third-party reporting. No anonymous claims.
MyThreatIntel indexes 5,592 active leak listings right now. Have I Been Pwned ships 250 verified breaches covering 4.6 billion accounts. The two aren't competing; they answer different IR questions, and the difference is the methodology lesson.
22 CVEs were added to CISA's Known Exploited Vulnerabilities catalog in the last 30 days. 9 are Microsoft. That's 40% of the active-exploitation evidence the federal government has compiled, attributable to one vendor.
A look at the architectural decisions behind the platform: why Cloudflare Workers, what the KV/D1 split actually does, how the 30 upstream feeds stay inside the subrequest budget, and what I would change in a v2. Engineering notes, not a sales pitch.
1,815 of 1,888 currently-tracked C2 servers run Cobalt Strike. 73 run Metasploit. Everything else is statistical noise. Defenders who plan their detection coverage as if 'C2 framework diversity' is real are mis-allocating.
This platform scans 7,779 indicators across 18 IOC feeds and surfaces 141 that two or more sources agree on. The 98.2% that get dropped are the methodology lesson, not the success.
The top three operators on this platform's ransomlook feed for May 2026 each say something different about how to read a leak-site board. One is loud, one is quiet, one is structural.