WarrenBarr
SEC-01
Advisories
Published findings
OPS-02
Methodology
How an engagement runs
ENG-03
IT & Dev
Build and administer
ARM-04
Software
Tooling I wrote
MSP-05
MSSP
Flat-rate managed
REC-06
Case Studies
Work, in full
WEB-07
Websites
Sites that convert
SUP-08
Gear
Coming soon
DOC-09
Doctrine
What I will not do
WHO-10
About
Who you'd be hiring
Latest
ADV-022Langflow unauthenticated RCE — CVE-2026-9198, actively exploitedAug 2026 ADV-021Tomcat bypass exploited by an autonomous AIAug 2026 ADV-020N-able N-central — the first patch did not holdAug 2026 SOFTWAREMailbox Viewer — offline .mbox viewer, releasedMay 2026 CASEThree-layer asset protection under $300 in hardwareMay 2026
Barr Cyber chip logo
Operational · Barr Cyber LLC · Kalispell, Montana

I find the way in before someone else does.

Adversarial security, IT, and custom software from one engineer who works every layer — network architecture to endpoint hardening to the tools that run on top.

"A black-box view of your organization. I don't follow a checklist — I follow the logic of an adversary, then show you exactly how to stop it."

See the Methodology → Start a Conversation
Warren Barr 713-882-0902 warren@barr-cyber.com
01 // Security

Adversarial Assessments

A full-lifecycle, black-box engagement run the way a real adversary would — reconnaissance through action-on-objectives, then graded findings and a re-test. Open or blind.

Explore the T-ALC →
02 // IT & Dev

IT, Done By One Person

Network setup, endpoint hardening, web development, AI automation, gaming diagnostics — every layer, no hand-offs, no markups, no fluff.

See services →
03 // Products

Licensed Software

Purpose-built tools: a Google Workspace forensic platform, an offline Mailbox Viewer, and HESUS — a development brain leased per project.

Browse software →
[ THE PRACTICE, LATELY // EVERYTHING PUBLISHED, ONE FEED ]

Recently, Across The Practice

Advisories, shipped builds, and software releases, newest first. This is the heartbeat of the practice — if it's moving, someone is watching.

⚠ Advisory · CriticalAug 2026
Langflow Unauthenticated RCE — CVE-2026-9198
CVSS 9.8 on a default deployment, actively exploited. The real problem is that nobody inventoried the instance.
⚠ Advisory · HighAug 2026
Tomcat Bypass, Exploited By An Autonomous AI
An agent that picked its own targets and researched alternative vulnerabilities when its first exploit failed.
⚠ Advisory · CriticalAug 2026
N-able N-central Authentication Bypass
CVE-2026-18556/18577, actively exploited. The first patch was incomplete — patching once was not enough.
Software releaseMay 2026
Mailbox Viewer
Converts a Google Takeout .mbox into an offline, read-only HTML viewer. Memory-safe, encrypted delivery, no server required.
Case studyMay 2026
Budget-Grade Asset Protection — Self-Storage Stack
Three independent security layers — GPS, dual auto-tracking cameras, cellular uplink — under $300 in hardware.
Case studyApr 2026
Hospitality Endpoint Hardening & PCI DSS
Workstation migration, full endpoint hardening, and PCI DSS v4.0 compliance documentation — with the MSP held accountable.
Case studyApr 2026
ASUS ROG Zephyrus G16 Out-Of-Box Diagnostic
Slow and overheating from the factory — full diagnostic, root cause, and remediation.
The T-ALC

The Total Adversarial Lifecycle

Twelve phases, sequenced by dependency, that describe exactly how an engagement runs — from scope and authorization to ongoing posture. The full, published methodology lives on its own page, explorable by the wheel or readable end to end.

Open the Methodology →
// Get In Touch

Scoping an assessment, or need an engineer who covers every layer?

Reach out directly — you'll talk to Warren, not a sales desk. Want plans, pricing, and the full picture first? Start here →

Get in Touch

No generic quotes, no wasted time. Whether you need a full adversarial engagement or just want your network cleaned up — let’s talk about what you actually need.

Or just call / email directly — whichever’s easier.

✓ Message sent — I’ll be in touch shortly.

Software Bug Report

Using a Barr Cyber software product and hit an issue? Submit a report here. Include as much detail as possible — what you were doing, what happened, and what you expected.

Current Products
Omniscient — MSSP Operator Platform
Forensic G-Suite
Hesus
Encrypted MBOX Viewer