PhllapsNET is a security advisory site for the people who actually have to patch things. Every post takes a single vulnerability and answers three questions: what it is, what you should do about it, and how worried your leadership needs to be.
Who writes it
I am Ross Phillips. I have spent about two decades in enterprise network and security operations — routing and switching, firewalls, VPN and remote access, SD-WAN, and the change-control machinery that surrounds all of it. This site is a personal project, unaffiliated with and unfunded by any vendor.
The perspective is deliberately operational rather than academic. I am not interested in exploit development or threat-actor attribution; I am interested in whether the thing is in your estate, whether it is reachable, and what the change record needs to say.
What it covers
The archive started as Cisco PSIRT coverage and has since widened. Today it tracks:
- CISA KEV additions — the “actively exploited” gold standard, whatever the vendor. Microsoft, Apple, Zimbra, Apache, VMware and others appear here.
- Critical-severity flaws in network and edge kit — firewalls, VPN gateways, load balancers, routers, switches and management consoles.
- Named vulnerabilities that reach enough of the industry to need a position.
Everything else gets logged and skipped. The filter exists so the archive stays useful rather than exhaustive.
How a post is built
Transparency matters more than mystique here, so:
Sources are structured feeds only, never page scrapes. The CISA KEV JSON catalogue, Cisco PSIRT per-advisory CSAF documents, Fortinet and Palo Alto PSIRT feeds, and the NVD 2.0 API for authoritative CVSS data.
The severity banner, CVSS figures, KEV status and fixed-release tables are extracted programmatically from those sources. They are not retyped, and they are not written by a language model.
The written analysis is drafted with AI assistance and then checked. A model drafts the prose from the extracted fields — it never sees raw advisory HTML — and a second pass verifies it against the source data. There are hard programmatic checks on top: no CVE identifier may appear that is not in the source advisory, no version number may appear that is not in the source facts, and no claim of active exploitation is allowed unless CISA KEV says so. A draft that fails any of those is discarded rather than corrected.
That last rule is the important one. On a site about vulnerabilities, a confident-sounding invention is worse than silence.
Every post links its primary source. If my summary and the vendor advisory disagree, the vendor advisory is right — go and read it.
See Methodology for the longer version.
Who it is for
Network and security engineers, infrastructure architects, and the managers who need the “so what” in under a minute. If you have ever had to explain a CVSS score in a change advisory board meeting, this is written for you.
Contact
Corrections are genuinely welcome — email [email protected] or see the contact page. If I have got something wrong about a product you own, I would rather know.