3on

3ON × SecuureIT · Security Research & Response

Security Lab.

Technical field reports and lessons from incidents, recoveries and systems running in production. We publish methods, measurements, limitations and mitigations — while anonymising client work where confidentiality requires it.

SecuureIT Web Intelligence

SecuureIT is the security practice within the 3ON group. Security Lab brings together production experience from incident response, web and application security, hosting and emerging risks from AI agents and crawlers.

Field reports & response cases

Real incidents. Verified mitigations.

FIELD REPORT · AUG 2026 · MITIGATED

When an AI crawler behaves like a DDoS.

Meta-ExternalAgent generated 161,989 requests in the analysed dataset, with 154,206 targeting a WooCommerce cart. After an early crawler guard was deployed, observed CPU fell from 99.7% to 1.8% while the bot continued attempting cart requests.

Read the field report →
ANONYMISED CLIENT CASE · WEBSITE COMPROMISE · RECOVERED

Two compromised websites recovered for a larger business in the workshop sector.

The client suffered a compromise where weaknesses had been exploitable over an extended period. We recovered two websites, analysed intrusion paths and underlying weaknesses, removed residual risk and hardened the environments to reduce the likelihood of re-entry. The client name and technical details that could increase attack surface are not published.

Incident response & recovery →

Security operations

Not only emergency help after something has already gone wrong.

01

Service & security agreements

Ongoing responsibility for websites, including updates, security checks, backups, recovery readiness, logging and a prioritised incident path.

02

Incident response

Fast analysis during compromise or abnormal load, prioritising recovery first and then root cause, persistence, weak points and hardening.

03

Web & application security

WordPress, web apps, APIs, WAF, permissions, forms, file handling, hosting and safer architecture from day one.

Lab principles

Evidence before drama.

01

Production evidence

We separate log data and verified measurements from conclusions and hypotheses. Raw evidence is retained when privacy and security allow.

02

Reproducible method

We describe which data was analysed, what was counted and which limitations apply so conclusions can be reviewed.

03

Mitigation first

The first goal is to stabilise production. Then we document root cause, residual risk and what other operators can do.

What belongs here?

Security work does not always leave a public report.

Security Lab covers classic web and WordPress security, hosting, incident response and application risk — but also emerging production failures where legitimate automated systems behave in ways that create unintended damage. Client cases are published only when this can be done without exposing the client, infrastructure or useful attack details.

Need help?

Active incident or ongoing protection?

We can step into active incidents or take ongoing service and security responsibility for websites where operations, backup, updates and security need a clear technical owner.

Security / SecuureIT →