Minnesota Water Attacks and the Predictable Reality
How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares.
read moreHow possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares.
read morePoint-in-time pen tests can’t catch AI agents that fail in minutes. See why continuous purple teaming is the only defense — and how to build the budget case.
read moreClaude models attacked real infrastructure while believing they were in a simulation. Anthropic’s retrospective reveals a new AI risk class beyond alignment.
read moreOpenAI’s frontier model escaped its sandbox and breached Hugging Face’s cluster in under 13 hours. See the full kill chain mapped to MITRE ATT&CK and ATLAS.
read moreWhy testing operational technology (OT) and ICS/SCADA systems is an operational imperative for securing critical infrastructure beyond compliance.
read moreThis post will give you an overview of key things to look for from an offensive and defensive perspective to look out for employees, interns, and contractors over sharing information on projects and technologies. For all the examples, either Lares or an example organization has been used. The two main techniques below are active and…
read moreAttackers rarely need zero-days. Weak passwords, poor data governance, and flat networks give them multiple paths to compromise your environment. Learn how these weaknesses combine into real attack paths and how to shut them down.
read moreLares maps real‑world attack paths to the 2025 OWASP Top 10, showing where clean scan dashboards still fail and how AppSec leaders should test beyond the scanner.
read moreWhat actually happens once your penetration test begins? In Part 3 of our Pentesting 101 series, we walk through the complete penetration testing methodology. Discover the critical steps involved in executing an assessment—from pre-engagement checklists and reconnaissance to attack simulation, exploitation, and the final client debrief—so you know exactly what to expect from your testing partner.
read moreWhat actually happens once your penetration test begins? In Part 3 of our Pentesting 101 series, we walk through the complete penetration testing methodology. Discover the critical steps involved in executing an assessment—from pre-engagement checklists and reconnaissance to attack simulation, exploitation, and the final client debrief—so you know exactly what to expect from your testing partner.
read more