RESEARCH &
PUBLIC WORK.
Published vulnerability research, technical advisories, and disclosure updates. Cody's work includes the security of MSP assessment software and internet-connected industrial control systems. Each project documents the findings, their impact, and the available guidance for defenders.
Vulnerability Research & CVEs
Industrial Lighting Controller Vulnerabilities
Joint research with Nick Schroeder examining security gaps in industrial lighting controllers (ETC Mosaic, Pharos LPC/TPC/MSC) deployed at high-profile landmarks. Unauthenticated information disclosure and default configuration weaknesses affecting stadium and entertainment venue infrastructure.
VIEW FULL RESEARCH →Kaseya RapidFire Tools Network Detective
Two high-severity credential storage vulnerabilities in Kaseya's network assessment platform, used by thousands of MSPs, affecting Network Detective 2.0.16.0 and earlier. Cleartext credential storage and deterministic encryption allow trivial password extraction from temporary files. Disclosed to Kaseya and fixed before publication.
- > Cleartext credentials in temp files (CVE-2025-32353)
- > Hardcoded encryption keys enable decryption (CVE-2025-32874)
- > Full environment takeover via credential harvesting
The Book
LEVEL UP: vCSO EDITION
Co-authored with Bruce McCully, Level Up: vCSO Edition presents a framework for MSPs and MSSPs delivering security leadership to their clients. It draws on the practical work of building and advising security programs.
GET THE BOOK →