Are ransomware attacks caused by one failure, or a chain of them?
At THREATCON1 2026, Alexander Waintraub will break down a real-world ransomware intrusion from initial access to payload detonation, based on DFIR investigations.
Register: threatcon1.org/registration
Heading to GrrCON? Meet the VulnCheck team Sept. 24-26 in Grand Rapids!
Patrick Garrity will break down what “exploited in the wild” really means and how defenders can better evaluate exploitation evidence.
Plus, grab a coffee on us! ☕ grrcon.com
As THREATCON1 approaches, we’d like to thank our sponsors!
@armada_ai, a full-stack edge computing platform bringing connectivity, compute and AI where they’re needed most, is supporting THREATCON1 2026 as a Silver Sponsor.
Register: threatcon1.org/registration
What happens when AI turns vulnerabilities into working exploits in minutes?
At THREATCON1, Mehul Revankar of @QuantroSecurity will share findings from 3,029 CVEs, including a 72% verified exploit rate.
Register for October 6 threatcon1.org/registration
THREATCON1 is less than two weeks away!
Thank you to @awscloud for supporting THREATCON1 2026 as a Premier Sponsor.
Join us Oct. 5-7 for keynotes, technical sessions and more: threatcon1.org/registration
Which cyber threats are hitting healthcare hardest in 2026?
At THREATCON1, Health-ISAC’s Ethan Muntz will reveal the top ransomware actors, malware families, vulnerabilities and MITRE ATT&CK tactics affecting the sector.
Register for Oct 7: threatcon1.org/registration?…
Attackers start building long before they strike.
At THREATCON1, John Fitzpatrick will show how domains, servers, certificates and proxies can reveal patterns before a campaign becomes public, giving defenders an earlier chance to disrupt it.
Register: threatcon1.org/registration?…
A CVE can be public and still not be usable.
At THREATCON1, Kazuki Omo will use daily NVD snapshots collected since January 2025 to measure how long records take to gain the context defenders need to act.
Oct. 6, Sheraton Reston
Register: threatcon1.org/registration?…
Two attackers. Two playbooks. One target.
In the next VulnCheck In the Wild, Kimber Duke and Patrick Garrity unpack what VulnCheck Canaries observed when attackers exploited Langflow, from credential theft to cryptomining.
📅 Sept. 30 at Noon pm CT
🔗 linkedin.com/events/75038941…
MSSP, MDR, XDR and platform describe how security is delivered, not what customers are buying.
At THREATCON1, Mike Reed maps four modern buying models and explains why vendor incumbency does not transfer between them.
Oct. 6, Sheraton Reston
Register: threatcon1.org/registration?…
How is AI changing vulnerability disclosure, and how do we separate valuable insights from the “slop”?
On Sept. 16, VulnCheck’s Kimber Duke joins @runZeroInc to discuss disclosure norms, hacker meetups and the Rapid Response Roundup.
Register: runzero.com/research/runzero…
Attackers controlled Cisco SD-WAN fabrics across U.S. critical infrastructure for at least three years. How?
At THREATCON1, VulnCheck’s Landon Rice will break down the CVE-2026-20127 exploit step by step.
Oct. 6
Register: threatcon1.org/registration?…
Public PoC volume is surging. So is the noise.
By mid-August, VulnCheck had reviewed 17,800+ PoCs and write-ups, 87% of its 2025 total. GitHub PoC acceptance fell from 51% to 45% as AI-generated content added to the volume.
Read: vulncheck.com/blog/death-by-…
A router anyone can buy on Amazon. A backdoor in its firmware, running as root and phoning home.
At THREATCON1, VulnCheck CTO @Junior_Baines will reveal how ENDLESSDOORS was discovered, how it works and why it’s dangerous.
Oct. 6 | 11:10 am ET
Register: threatcon1.org/registration
Anthropic says Project Glasswing identified 26,000+ potential vulnerabilities, but only 202 have been fixed after five months.
Just 9.8% reached maintainers, while Claude rated 91.5% high or critical vs. 51.3% by maintainers.
Read the full analysis: vulncheck.com/blog/anthropic…
Ready to put your skills to the test?
VulnCheck is sponsoring the Capture the Flag competition at LABScon 2026, Sept. 16-19 in Scottsdale. Take on hands-on challenges alongside top security researchers, exploit developers and defenders.
vulncheck.com/events/labscon…
Federal cybersecurity takes center stage in D.C., Sept. 8-10.
VulnCheck is a Bronze sponsor of the 17th Annual Billington CyberSecurity Summit. Stop by our table to see how exploit intelligence helps defenders focus on the threats that matter: vulncheck.com/events/billing…
KindaRails2Shell is now under active attack.
Last week, VulnCheck Canaries detected exploitation of CVE-2026-66066 in Singapore, Israel and the UK. @SecurityWeek has the details on the critical Ruby on Rails flaw.
securityweek.com/critical-ru…
Attackers are turning their attention to the AI stack.
New VulnCheck research examines exploitation of Langflow, an open source platform for building AI agents and workflows, including 11 additional CVEs reported exploited in the wild in 2026.
vulncheck.com/blog/pwning-th…
We’re partnering with @RilianTech to expand access to VulnCheck’s exploit intelligence across EMEA.
Building on 319% YoY ARR growth and 2X customer growth in the region, the partnership will help sovereign and critical infrastructure defenders act faster:
vulncheck.com/press/vulnchec…