What is wp2shell and what can it teach us about vulnerability management?

What is wp2shell and what can it teach us about vulnerability management?

When wp2shell hit WordPress Core, no single check was enough. A look at how a WAF rule can make vulnerable servers appear patched, and why we shipped three checks instead of one.
Introducing AI-powered pentesting for web apps: test on every major release

Introducing AI-powered pentesting for web apps: test on every major release

AI-powered web app pentesting is now live in Intruder. Connect your repo, launch on demand, and get a full pentest report the same day.
Introducing our Free plan: making security accessible for the 99%

Introducing our Free plan: making security accessible for the 99%

Professional security tooling, free forever. Intruder's new free plan is built for lean teams who face enterprise risks on a fraction of the budget.
AI-driven vulnerability management: broader, faster coverage against new threats

AI-driven vulnerability management: broader, faster coverage against new threats

Intruder now uses AI to build vulnerability checks for newly disclosed threats, giving Enterprise customers faster, broader detection coverage.
8 best AI pentesting tools for 2026

8 best AI pentesting tools for 2026

AI pentesting means different things from vendor to vendor. Compare the top 2026 tools on autonomy, coverage, strengths, and pricing.
See what's exposed with Attack Surface view

See what's exposed with Attack Surface view

Attack Surface view is now on Cloud and Pro. See the most commonly exposed ports across your targets, the services running on them, and what needs attention, all in one place.
How AI is changing the defender’s toolkit

How AI is changing the defender’s toolkit

We explore where AI fits in the defender's toolkit, how it's closing the gap between scanning and pentesting, and what the future of pentesting looks like.
See TODAY’S CVE TRENDS
Clear all filters
Overconfident and under resourced: navigating the midmarket security gap

Overconfident and under resourced: navigating the midmarket security gap

Too complex for SMB tools, too lean for enterprise stacks — midmarket security teams are stuck in the middle. The Security Middle Child report reveals how bad the gap really is.
Insights
Our Reports
Registry vs. runtime: where to scan your container images

Registry vs. runtime: where to scan your container images

Container image scanning should happen at the registry level, not at runtime inside clusters. Centralized registry scanning gives teams full visibility, reduces operational overhea
Cloud security
Vulnerability management
The Vulnerabulletin Issue #5

The Vulnerabulletin Issue #5

Issue 5 of our monthly newsletter, packed with research, industry news and Intruder updates.
In the News
Insights
Product
Why attack surface reduction is your first line of defense

Why attack surface reduction is your first line of defense

Proactive attack surface reduction is about reducing unnecessary internet exposure before it becomes a problem.
Attack surface management
Guides
EPSS vs. CVSS: what’s the best approach to vulnerability prioritization?

EPSS vs. CVSS: what’s the best approach to vulnerability prioritization?

Learn all about the Exploit Prediction Scoring System (EPSS), how it compares to CVSS and why it's a game changer for your vulnerability prioritization process.
Attack surface management
Vulnerability management
Guides
The Vulnerabulletin Issue #4

The Vulnerabulletin Issue #4

Issue 4 of our monthly newsletter, packed with research, industry news and Intruder updates.
In the News
Insights
Product
Beyond Compliance: What Actually Builds Customer Trust

Beyond Compliance: What Actually Builds Customer Trust

Compliance frameworks help you pass an audit; continuous compliance helps you keep customer confidence.
Compliance
Guides
Building a Secure Container Registry Strategy

Building a Secure Container Registry Strategy

Container registries are a critical attack surface. Learn how to secure them and how Intruder automates image discovery and scanning.
Cloud security
Guides
19 Cyber Leaders to Follow on LinkedIn (and Why They Deserve Your Attention)

19 Cyber Leaders to Follow on LinkedIn (and Why They Deserve Your Attention)

Cut through LinkedIn noise with 20 security leaders sharing real-world insights. From malware analysis to AppSec to vulnerability intel—voices that help you do better work.
Insights
Ghost CVEs: The Vulnerabilities You Don't Know About (Yet)

Ghost CVEs: The Vulnerabilities You Don't Know About (Yet)

Ghost CVEs are vulnerabilities disclosed in GitHub and advisories before hitting NVD. Tracking them lets us patch threats days faster than teams waiting for official databases.
Vulnerabilities and Threats
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.