Pigfox
Blog
Field notes on OSINT, security checks, SEO, and safer hiring and vendor due diligence.
-
How to vet an offensive security startup when the story shifts
2026-07-19
A troubling headline is only the start. For security buyers, the real work is checking whether a high-trust vendor’s identity, infrastructure, claims, and operating process line up under ordinary scrutiny.
-
What CISA’s GitHub Leak Should Make Defenders Inspect
2026-07-18
A public GitHub leak is rarely just about one exposed secret. The useful investigation is around token scope, CI trust paths, logs, and the quiet defaults that turn a commit mistake into broader risk.
-
Welcome to the pigfox blog
2026-07-17
Field notes on OSINT techniques, verification workflows, and due-diligence tooling.