For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to…
News
How a software provider closed unknown paths to cloud compromise
A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed…
How a global investment firm reduced security surprises
Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests,…
An Irregular testing that caused Meta, OpenAI, and Anthropic AI agents to go rogue
Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI…
You’re only as secure as your last evaluation
The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense…
Cybersecurity needs a new operating model
For decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure. Deploy patches. Verify that…
The exploit window is shrinking. Most security workflows are not
AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability…
CTEM isn’t failing. It’s not being operationalized
Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA,…
Autonomy is earned, not claimed
After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of…
Attackers hid malware inside Oracle Database after SQL injection breach
Huntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which…