What this site is

infosecpwn publishes defender-focused analysis of vulnerabilities and intrusion campaigns that are actually being exploited.

Most security news tells you that something is broken. This site is written to answer the questions you have twenty minutes later, when someone asks whether it affects you:

  1. What broke — the vulnerability class, in plain terms.
  2. Who is affected — exact products and version ranges.
  3. Is it being exploited in the wild — with dates and sources.
  4. What to patch — fixed versions, workarounds, and the post-patch steps vendors bury in paragraph nine.
  5. How to detect it — IOCs, log queries, and hunting guidance.

What this site will not publish

This is a defensive publication. It does not publish:

  • Proof-of-concept exploit code
  • Step-by-step exploitation walkthroughs
  • Payloads, gadget chains, or working attack tooling

Where exploitation detail matters for understanding impact, it is described conceptually and the reader is pointed at the vendor advisory. If you need weaponized detail, this is the wrong site — and that is deliberate.

Independence

This is an independent project with no connection to any employer. Nothing here is sourced from anyone’s internal work, customer data, or private vulnerability disclosures. Every claim traces back to a public source, and those sources are cited.

No vendor sponsors this site’s coverage, and no vendor sees a post before it publishes.

Corrections

Security writing ages badly and sometimes starts wrong. If something here is inaccurate, tell us and we will fix it in place, with a dated note saying what changed. Corrections are never made silently. The address is on the Contact page.