← OrangeStealth
Security research & field notes
Original findings from passively scanning real startups — the same public-data view an attacker or an enterprise buyer already has. No company is ever named.
2026-09-04AI slop is eating the world. Trust is the first casualty | TechRadarIf you're a small B2B SaaS founder using AI to draft your outbound emails, your investor updates, or your website copy, the ground is shifting under you — and it isn't about gettin
2026-09-04New SynkLoader malware pushed in Microsoft Teams phishing campaignIf your company runs Microsoft Teams, one of your employees could get a message today from "IT Helpdesk" asking them to install a cleanup tool. It looks internal. It isn't. A newly
2026-09-04The domains actively sending mail with no authentication at allIf a company's mail domain has no SPF alignment and no DMARC policy, anyone on the internet can send email that looks like it came from that domain — landing in a customer's inbox
2026-09-03The SPF setting that looks done but rejects nothingIf your SPF record ends in ~all , it can feel like a settled line on the checklist — the DNS record exists, some tool somewhere said "SPF: configured," done. It isn't done. That si
2026-08-31The free security most sites leave switched offMost security advice for a small SaaS company costs money: a consultant, a SIEM, a headcount you don't have yet. Response headers aren't that. They're a handful of lines in your se
2026-08-27Two in three startups publish no security page at allWhen an enterprise buyer's security reviewer opens a vendor's website for the first time, they are usually not reading the pricing page yet. They are looking for one specific thing
2026-08-26Most startups can't list the vendors their own website loadsThe list your website already gave away Ask a ten-person SaaS founder to list every third-party service running on their own marketing site, and most can't do it from memory. That'
2026-08-25Hundreds of leaked AWS keys give full control over corporate accountsIf you've ever pasted an AWS access key into a shell script, a `.env` file, or a debug commit "just to get the deploy working," you're not alone — and that's exactly the problem. A
2026-08-25Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000K Kristen Jarosinski @KJRyan413 #GRIT_Intel’s investigation points to a new twist on ransomware extortion and assesses Ransom Busters to be a ransomware affiliate—not the helpful t
2026-08-2445% of Startups Have DMARC That Protects Nothing (We Checked 705 of Them)We passively scanned 705 US B2B startups. Nearly half publish a DMARC policy that protects nothing — here's what that means and how to fix it.
2026-08-24Security should never be an afterthought.Most early-stage B2B SaaS founders don't lie awake worrying about IT architecture. They worry about churn, runway, and whether the roadmap ships on time. But the costs quietly pili
2026-08-24Only 1 in 5 Startups Have SPF That Actually Rejects ForgeriesOnly about 1 in 5 startups have SPF set to actually reject a forged email. We checked 705 of them. Here's the softfail trap and the fix.