RESEARCH &
PUBLIC WORK.

CVE disclosures, vulnerability research, and responsible disclosure.

Vulnerability Research & CVEs

Industrial Lighting Controller Vulnerabilities

Joint research with Nick Schroeder examining critical security gaps in industrial lighting controllers (ETC Mosaic, Pharos LPC/TPC/MSC) deployed at high-profile landmarks. Unauthenticated information disclosure and default configuration weaknesses affecting stadium and entertainment venue infrastructure.

VIEW FULL RESEARCH →

Kaseya RapidFire Tools Network Detective

Critical credential storage vulnerabilities in Kaseya's widely-deployed MSP network assessment platform. Cleartext credential storage and deterministic encryption allow trivial password extraction from temporary files. Affects thousands of MSPs running Network Detective for customer assessments.

  • > Cleartext credentials in temp files (CVE-2025-32353)
  • > Hardcoded encryption keys enable decryption (CVE-2025-32874)
  • > Full environment takeover via credential harvesting
VIEW FULL TECHNICAL ADVISORY →

The Book

Level Up: vCSO Edition book cover
Level Up: vCSO Edition back cover
THE MANUAL

LEVEL UP: vCSO EDITION

Co-authored with Bruce McCully. A simple, scalable vCSO framework for MSPs/MSSPs that grows your bottom line while reducing liability.

HOVER OVER BOOK TO VIEW BACK COVER

GET THE BOOK →