Security Research

Intelligence from the team
building Outrightly

CVE analysis, threat research, and security engineering from the people watching the feed all day.

FeaturedStrategy

Why CISA KEV Should Be Your First Alert Filter

The Known Exploited Vulnerabilities catalog changed how security teams should prioritize CVEs. Here is how to build your alerting strategy around it.

Outrightly Security ResearchJune 30, 20267 min readRead article
CVE Analysis11 min read

CVE-2024-6387 RegreSSHion: Anatomy of a Critical OpenSSH Vulnerability

A deep dive into the unauthenticated RCE in OpenSSH's signal handler, why it matters even without reliable exploitation, and what you should have done on day one.

June 12, 2026Read
Data & Research9 min read

The 197-Day Problem: Why Breach Detection Lags the Threat

We analyzed 3 years of CVE publication data against breach disclosure timelines. The gap between a CVE being known and a team acting on it is still measured in months.

May 28, 2026Read
Engineering8 min read

Zero-Trust CVE Monitoring for Small Security Teams

You do not need a 10-person security team to have mature CVE monitoring. This is the lightweight, high-coverage approach we recommend for teams of 1 to 5.

May 14, 2026Read
Strategy6 min read

The Transitive Dependency Blind Spot Most Teams Miss

Your direct dependencies are monitored. But what about the packages your packages depend on? We quantified the exposure gap and show you how to close it.

April 29, 2026Read
Strategy5 min read

CVSS Score Is Not a Priority Queue

A CVSS 9.8 sitting dormant in a library nobody calls is less urgent than a CVSS 7.2 in your authentication flow. Here is how to build context-aware prioritization.

April 8, 2026Read