top of page


Endpoint Capability Risk: Why Approved Software is Your Biggest Security Blind Spot
Most security tools ask whether software is malicious. Endpoint Capability Risk asks what it enables. Here is why that distinction matters, backed by current breach data.
Jacob Hughes
Apr 33 min read
Zero-Day Security Alert — March 21, 2026: Apple iOS, macOS, and Safari Actively Exploited
Daily Security Briefing March 21, 2026 CISA added three Apple vulnerabilities to the Known Exploited Vulnerabilities catalog on March 20, 2026. These affect iOS, iPadOS, macOS, watchOS, visionOS, tvOS, and Safari. All three are confirmed actively exploited in the wild and require patching by April 3, 2026. 1. Safari and WebKit Memory Corruption CVE-2025-31277 | CVSS 8.8 | HIGH Severity | Actively Exploited Affected Product Apple Safari (prior to 18.6), iOS and
Jacob Hughes
Mar 203 min read


Capability Risk Remediation Can Be Unsettling
While developing Endpoint Capability Risk (ECR) framework and scoring into LARCK, instantly seeing all of the endpoint risk data populate the system really uncovered just how powerful, dangerous, and 'over-tooled' a lot of my computers and servers were. In other words, it worked exactly as intended. Truly Eye-Opening. When importing CVE insights into the system for analysis and enrichment, I quickly saw all of the vulnerabilities and supporting information about them. Exact
Jacob Hughes
Feb 202 min read
bottom of page
