Brief published 07:00 · 52 sources assessed today

Know your external attack surface before someone else does.

StratQuad maps every host, service and exposure an attacker can reach from the internet, grades what it finds against your frameworks, and delivers the result as an audit-ready report.

Security headersSubdomainsEmail spoofabilityOrigin exposure

No agent, no install, nothing to deploy. Results in under three minutes.

app.stratquad.co.uk/scan/acme.co.uk
Posture score
acme.co.uk
62/100
Exposure48
Email security55
TLS & certificates71
Security headers74
CriticalAdmin panel exposed without authentication
HighOrigin IP exposed behind CDN
HighSPF and DMARC not enforced
MediumLegacy TLS 1.0 and 1.1 enabled
18 findings totalExport · PDF
52
Intelligence sources monitored continuously
73/day
Articles read, deduplicated and ranked
378
CVEs correlated in the last 24 hours
07:00
Brief in your inbox, every weekday
The brief · 14 September 2026

Today's intelligence

Risk LOW 0
KEV 0
CVEs 378
Articles 73
Sources 52
Analyst readGenerated 07:00 BST · reviewed

Apache ships patches for six critical vulnerabilities across four products.FreeMarker path traversal, Impala SAML forgery, Nutch reflection flaws, and two Chrome renderer bugs.all affecting current production releases.

StratQuad analysisRead the full brief →
Vendor watch

Key vendor activity, last seven days

Microsoft13 · 1 newCVE-2026-55040 and CVE-2026-63520 represent a critical authentication bypass in Microsoft SharePoint JWT token handling disclosed today by Rapid7, allowing attackers to forge…
Google1414 advisories in the last seven days.
Amazon Web Services2 · 2 new2 advisories in the last seven days.
Cisco77 advisories in the last seven days.
Fortinet11 advisory in the last seven days.
Ivanti1010 advisories in the last seven days.
VMware11 advisory in the last seven days.

Get the brief at 07:00, every weekday.

The day's UK security intelligence, read and ranked: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.

From recon to report

Every scan produces a result you can act on.

A posture score, findings graded by severity, and clear remediation guidance. On the platform, the full result exports as a PDF report you can hand to a client or an auditor.

app.stratquad.co.uk/scan/acme.co.uk
Posture score
acme.co.uk
62/100
Exposure48
Email security55
TLS & certificates71
Security headers74
Findings · 18Fix first
CriticalAdmin panel exposed without authentication
HighOrigin IP exposed behind CDN
HighSPF and DMARC not enforced
MediumLegacy TLS 1.0 and 1.1 enabled
MediumSecurity headers missing: CSP, HSTS
LowServer version disclosed in response
PDF report

External Security Report

acme.co.uk · Example export
Export · PDF
01

Recon

Map the external perimeter as an attacker would see it, across every host we can identify.

02

Analyse

Findings are scored and graded by severity, with clear remediation guidance for each.

03

Report

A risk assessment aligned to industry frameworks, exported as a PDF you can hand to a client or auditor.

Coverage

Multi-vector reconnaissance.

Active scanning and passive intelligence run on every assessment, each source feeding a single posture score. The result is a complete picture of the external surface rather than a partial check.

Active scanning
Vulnerability detection
Template based scanning across web, network and cloud surfaces.
Web server analysis
Configuration scanning for known misconfigurations and exposures.
TLS and cipher analysis
Certificate chain validation and protocol downgrade checks.
Content discovery
URL fuzzing with response baseline fingerprinting.
Port scanning
Fast port scanning for exposed services on discovered hosts.
Passive intelligence
Certificate transparency
CT log queries for subdomain enumeration.
Subdomain discovery
Passive discovery across public DNS and archive sources.
Service enumeration
IP and domain intelligence with banner data.
Technology fingerprinting
Detected software and versions across discovered hosts.
OSINT correlation
Cross referencing across public data sources.
URL reputation
Domain reputation checks against recent scan history.

All tooling runs server side. No agent, no install, nothing to deploy on your infrastructure.

The platform

Take it further with commercial access.

The free scan covers a single domain on demand. Commercial access opens the full platform across your estate and your team.

UK data residencySSO / SAMLAnnual invoicingDPA on request

Your whole estate

Run the complete assessment across every domain you add, including the active checks excluded from the free scan.

Audit-ready assurance

Findings and controls mapped to your frameworks, evidence attached, exported as audit-ready PDFs.

Change tracked over time

Re-scan on a schedule and review exactly what has changed between assessments, across multiple estates.

Built for teams

Multiple users, API access, and the daily brief delivered inside your account.