AV Threat Labs

Research

Notes and research.

Notes on infrastructure, the tools we build, and the security research behind them.

June 24, 2026

The S3 misconfiguration we keep finding in 2026

Public buckets are mostly solved. The access we keep finding now is quieter: over-broad IAM conditions, forgotten replication rules, and presigned URLs that outlive their purpose.

Read article →

May 12, 2026

SOC 2 for a 15-person startup: a pragmatic path

You do not need a GRC platform, a policy binder, or a compliance hire. You need scoped controls, evidence that collects itself, and about a quarter of calendar time.

Read article →

April 7, 2026

Why your pentest report shouldn't be a PDF graveyard

Most pentest findings die in a PDF nobody opens twice. The fix is structural: findings as tickets, severity in context, and a retest baked into the engagement.

Read article →

March 3, 2026

Zero trust without the vendor bingo

Zero trust is four architectural decisions, not a product category. Here is the version you can build with the identity provider and cloud primitives you already pay for.

Read article →

May 22, 2024

The Silent Threat: Data Exfiltration via RAG

How an attacker can use indirect prompt injection to force your enterprise RAG system to exfiltrate confidential documents.

Read article →

April 12, 2024

The boundaries of model trust in security automation

Why deploying an LLM into a security workflow without a harness is a recipe for silent failure, and how to verify output before shipping.

Read article →

Want to try Casefile?

Join the waitlist. We will email you when early access opens.