§ Field Notes
Field Notes
NexGuard Labs' reporting on the industry we work in: how detection actually works, what it costs, and where it has failed before.
A Brief History of the Computer Virus
Before ransomware and nation-state malware, there was a program that just wanted to say hello.
Signatures Still Work: The Case for Exact Matching
Hash-based detection is treated as the industry's oldest, least glamorous tool. It is also its most reliable.
What Heuristics Actually Buy You, and What They Cost
Behavioral detection promises to catch the malware nobody has seen yet. It delivers that, and a second bill that rarely gets discussed.
Inside the Ransomware Economy
What began as a niche extortion tactic became a business model with suppliers, affiliates, and customer support.
Zero-Days and the Market Nobody Talks About
Software flaws nobody has patched yet are worth real money, and there is a functioning market to prove it.
When the Update Is the Attack: Supply Chain Compromise
The SolarWinds breach showed how attackers can skip the target and compromise the software everyone already trusts instead.
No Antivirus Catches Everything, and That's Worth Saying
The industry rarely advertises its own limits. It should, because understanding them is what makes the rest of a security strategy make sense.
Why Auditable Code Matters More Than Marketing Claims
Security software asks for more trust than almost any other category of program. Very little of it earns that trust the same way.
Mac Malware Grows Up
"Macs don't get viruses" was never quite true. It has become far less true as Apple's install base grew.
AI in Malware Detection: Promise, Hype, and the Fine Print
Machine learning genuinely changed parts of the detection landscape. It did not change all of the marketing claims made in its name.