What is wp2shell and what can it teach us about vulnerability management?

What is wp2shell and what can it teach us about vulnerability management?

When wp2shell hit WordPress Core, no single check was enough. A look at how a WAF rule can make vulnerable servers appear patched, and why we shipped three checks instead of one.
Introducing AI-powered pentesting for web apps: test on every major release

Introducing AI-powered pentesting for web apps: test on every major release

AI-powered web app pentesting is now live in Intruder. Connect your repo, launch on demand, and get a full pentest report the same day.
Introducing our Free plan: making security accessible for the 99%

Introducing our Free plan: making security accessible for the 99%

Professional security tooling, free forever. Intruder's new free plan is built for lean teams who face enterprise risks on a fraction of the budget.
AI-driven vulnerability management: broader, faster coverage against new threats

AI-driven vulnerability management: broader, faster coverage against new threats

Intruder now uses AI to build vulnerability checks for newly disclosed threats, giving Enterprise customers faster, broader detection coverage.
See what's exposed with Attack Surface view

See what's exposed with Attack Surface view

Attack Surface view is now on Cloud and Pro. See the most commonly exposed ports across your targets, the services running on them, and what needs attention, all in one place.
How AI is changing the defender’s toolkit

How AI is changing the defender’s toolkit

We explore where AI fits in the defender's toolkit, how it's closing the gap between scanning and pentesting, and what the future of pentesting looks like.
2026 ASM Index: the most common attack surface exposures

2026 ASM Index: the most common attack surface exposures

We analyzed 3,000 attack surfaces to find out how widespread exposure is, what organizations are exposing, and how long it takes to remove it.
See TODAY’S CVE TRENDS
Clear all filters
Log4j vulnerability: what is it and how to detect it?

Log4j vulnerability: what is it and how to detect it?

Apache Log4j is a logging package for Java which has been widely adopted and integrated into many applications. Developers need a way of ...
Vulnerabilities and Threats
Announcing Changes to our Essential plan

Announcing Changes to our Essential plan

To ensure our product keeps pace and remains relevant for our customers and their requirements, we’re always asking for feedback to learn...
Product
Interview With Chris Wallis, the Founder & CEO of Intruder

Interview With Chris Wallis, the Founder & CEO of Intruder

Safety Detectives: What motivated you to start Intruder? Chris Wallis: I was working in a finance organization when a new vulnerability...
In the News
9 minutes to breach: the life expectancy of an unsecured MongoDB honeypot

9 minutes to breach: the life expectancy of an unsecured MongoDB honeypot

Our research shows that Mongo databases are subject to continual attacks when exposed to the internet. Attacks are carried out ...
Vulnerabilities and Threats
SMBGhost: Strange SMB Vulnerability Disclosures and Wannacry 2.0?

SMBGhost: Strange SMB Vulnerability Disclosures and Wannacry 2.0?

A new critical vulnerability in affecting Windows systems came to light on Tuesday, affecting SMB services used by the latest versions of...
Vulnerabilities and Threats
User Enumeration in Microsoft Products: An Incident Waiting to Happen?

User Enumeration in Microsoft Products: An Incident Waiting to Happen?

Intruder’s latest research reveals that up to 13,000 organisations are affected by little-known user enumeration flaws in a range of…
Vulnerabilities and Threats
Critical RDP Flaw Leaves up to 2.3 Million Servers Exposed (CVE-2019–0708)

Critical RDP Flaw Leaves up to 2.3 Million Servers Exposed (CVE-2019–0708)

Yesterday (May 14th 2019), Microsoft published a security advisory bulletin for a critical vulnerability in its remote login service…
Vulnerabilities and Threats
How to secure the Kubernetes API behind a VPN

How to secure the Kubernetes API behind a VPN

Earlier this week, the first major vulnerability (CVE-2018–1002105) was discovered in Kubernetes, the container management platform taking…
Insights
Cyber security: 7 top tips for SMEs

Cyber security: 7 top tips for SMEs

With news headlines focused on security breaches in large organisations, it would be easy for small to medium enterprises (SMEs) to…
Insights
Hacking The Entire Internet Just Got Easier

Hacking The Entire Internet Just Got Easier

The recent release of the new hacking tool ‘AutoSploit’ marks the dawn of a new era for unskilled attackers. It provides a fully-automated…
Insights
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.