Notes & analysis
Blog
Shorter notes between the reports — what the pipeline caught this week, how a detector works, and where the supply chain is heading.
2 posts
28 Jul 2026
Why we attribute every indicator to a package
Most threat feeds hand you a list of domains and no provenance. Ours name the package, version and file each indicator came from — so you can check whether it even concerns you, and verify it before you block.
5 min · Read → 30 Jun 2026A false positive is an asset, not an embarrassment
Every confirmed false positive becomes a permanent negative test case. Here is how that feedback loop actually changes detector behaviour — and why we treat clearing a package as a result, not a wasted scan.
5 min · Read →Stay current
New editions, in your inbox.
Get notified when codelake Research publishes a new report, threat brief or quarterly advisory roundup. No marketing — just the research.