Vorpcel Blog

Product.
Security.
Operations.

Published articles

Perspectives on application security, cloud risk and the operational work of protecting digital services.

Vorpcel Research

CVE-2026-71309: Technical Analysis of the Root Escape in rclone serve restic

A technical analysis of CVE-2026-71309, a path traversal in rclone's restic-compatible REST server (rclone serve restic). A URL path starting with ../ could escape the operator's published root and read, create, overwrite, or delete objects outside it, depending on the storage backend. We break down the root cause (treating path canonicalization as containment), why the outcome depended on the backend, how exploitation worked, and the fix in rclone 1.75.0.

Fundamentals

What Is an Attack Surface and Why Does Your External Inventory Age Every Day?

A practical guide to understanding internet-facing assets, ownership drift, discovery gaps, and the operational case for continuous visibility.

Fundamentals

Web Application Firewalls, Network Firewalls, and Secure Code: What Each Layer Actually Solves

Where major web security controls overlap, where they stop, and how to build layered protection without assigning impossible expectations to one tool.

Fundamentals

Browser-Side Security: Why Third-Party Scripts Are Part of Your Risk

The browser is an execution environment, not a passive display. Learn how script trust, page changes, and outbound destinations shape client-side risk.

Security Engineering

From DNS to Exposed Services: Mapping an External Attack Surface with Verifiable Evidence

A technical workflow for turning domains, certificates, services, technologies, and exposures into evidence-backed attack-surface findings.

Security Engineering

How to Design Web Application Firewall Policies Without Blocking Legitimate Users

A disciplined approach to policy precedence, inspection modes, bot controls, staged enforcement, exceptions, and evidence-based tuning.

Security Engineering

Bot Detection Beyond Rate Limiting: Sessions, Fingerprints, and Behavior

Why request volume alone is not enough, and how multiple behavioral signals support more reliable challenge, score, and blocking decisions.

Security Engineering

Script Integrity and Payment Card Industry Data Security Standard Requirements 6.4.3 and 11.6.1

How script inventory, authorization, integrity baselines, change detection, and investigation evidence support payment-page security work.

Security Engineering

Content Security Policy, Subresource Integrity, and Outbound Telemetry Against Browser Supply-Chain Attacks

Three complementary control families for constraining browser execution, detecting script changes, and observing where page data travels.

Vorpcel Research

Surface Drift Index: A Vorpcel Method for Measuring Continuous Exposure

A transparent model for combining asset churn, severity, persistence, ownership confidence, and remediation delay into one directional metric.

Vorpcel Research

Closed-Loop Web Defense: Correlating Surface, Request, and Response Signals

An original operating model for connecting exposed assets, inbound decisions, browser-side changes, and outbound behavior during triage.

Want to evaluate the platform?

Request a guided trial aligned with your environment and security priorities.