< ciso
brief />
Tag Banner

All news with #exposure management tag

73 articles

DecryptAds reveals who’s tracking you online

🔍 DecryptAds is a free service that scrapes and correlates public adtech files (ads.txt, app-ads.txt, buyers.json, sellers.json) to reveal which companies can run ads or harvest data from websites and apps. The site presents consolidated profiles, legal dossiers, and geo-risk warnings to help researchers and security teams trace malvertising, ad fraud, and opaque ad-supply chains. Its API and quiet-removals feed enable automation and visibility into removed sellers and reseller relationships.
read more →

Top Exposure Management Questions Security Leaders Ask

🔎 This article answers common questions security leaders ask when evaluating Check Point Exposure Management, covering asset discovery, cloud coverage, supplier monitoring, dark web intelligence, leaked credentials, IOC feeds, and integrations. It explains how EASM and CAASM discover external and internal assets, how findings are enriched with vulnerabilities and controls, and how unified visibility supports prioritization and remediation. The piece emphasizes integrations and operational workflows that accelerate response and reduce organizational risk.
read more →

Why exposure management is replacing vulnerability management

🔍 Traditional vulnerability management finds issues, but that doesn't equal reduced risk. Modern environments are interconnected, and attackers chain weaknesses, identities, and permissions to reach valuable targets. The Gartner CTEM framework shifts the focus from individual findings to the broader exposures attackers can exploit. Organizations must prioritize reducing exposure, not just counting or patching vulnerabilities.
read more →

Operationalizing CTEM: From framework to repeatable model

🔍 Most organizations understand the CTEM framework but struggle to operationalize it. The Gartner CTEM phases—scope, discover, prioritize, validate, mobilize—define what to do, yet fail to prescribe how to embed accountability, ownership, and measurement. The core gap is execution: discovered exposures often move between teams without clear end-to-end ownership, delaying remediation and weakening validation. CTEM success requires building repeatable processes that verify remediation and demonstrate reduced exposure over time.
read more →

Over 4,400 Rockwell PLCs Exposed on Internet

🔍 Forescout's August 3 scan found 4,407 internet-exposed Rockwell Automation PLCs worldwide, including 2,844 in the US; 22 were in cities hit by recent water utility attacks. The firm noted attackers can alter IPs and set passwords on reachable controllers without exploiting a vulnerability, and 19 of 22 in affected cities used the same mobile carrier network. The FBI and EPA urge strong authentication, firmware updates and isolation of remote access to reduce public exposure.
read more →

Top cybersecurity product announcements from Black Hat 2026

📰 Black Hat 2026 features many AI-driven product announcements as vendors move from simple copilots to embedding AI into operational security workflows. Companies are combining automation with governance, exposure management, and recovery to support practical autonomous security in enterprises. Common themes include attack path analysis, integration of external threat intelligence into workflows, and purpose-built AI agents to speed investigations without requiring infrastructure replacement.
read more →

Check Point Named Visionary in Frost Radar 2026

🔍 Frost & Sullivan evaluated 30+ vendors and benchmarked 15 that meet strict ERMM platform criteria; only five achieved Visionary Leader status, including Check Point Exposure Management. The report required native integration of attack surface management, threat intelligence, and digital risk protection, plus both outside-in and inside-out visibility. Frost credits Check Point’s correlated intelligence, telemetry, and targeted acquisitions for strong innovation and growth scores.
read more →

Risk‑Based Patching: Rethinking Vulnerability Prioritization

🛡️ CISA’s Binding Operational Directive (BOD) 26-04 shifts federal vulnerability management from uniform deadlines to risk-based remediation, prioritizing exposures most likely to be exploited. The directive recognizes that CVSS scores alone don’t capture exploitability, reachability or operational context. With AI accelerating attack lifecycles and expanding the attack surface via copilots and integrations, defenders must adopt continuous exposure mapping and validation. The article argues defenders need adversary-aware testing, business-aligned prioritization and a move from patch counts to exposure-centric strategies.
read more →

Infoblox enters EASM market with DNS-first focus

🔍 Infoblox has launched an External Attack Surface Management (EASM) capability and a Supply Chain Intelligence feature to expand its exposure management suite. The DNS-centric approach discovers internet-facing assets without agents, credentials, or active scanning and highlights DNS-specific risks like dangling CNAMEs. The new capabilities integrate with Infoblox’s existing Digital Risk Protection Services and aim to help security teams continuously identify and prioritize external exposures based on exploitability and business impact.
read more →

2026 Exposure Gap Report: Remediation Insights

🔍 The 2026 Exposure Gap Report finds that while many organizations can identify and prioritize exposures, turning those insights into timely remediation is inconsistent. Some sectors, like Utilities, remediate in roughly 12.6 hours, whereas Healthcare averages about 158 hours. The report highlights that delays often begin before remediation—during validation and ownership assignment—and that connected workflows enable faster, repeatable remediation at scale.
read more →

Exposure Window: The Metric That Really Matters

🛡️ This piece examines how Anthropic's Mythos accelerated vulnerability discovery but did not create the core problem: the exposure window. It explains that while AI has pushed discovery and prioritization to machine speed, mobilization—the organizational steps to actually fix vulnerabilities—remains slow. The article argues security teams must adopt speed-based metrics and attack-path analysis to reduce the blast radius and convert remediation into a measurable business risk.
read more →

CISOs Must Rethink Vulnerability Management Now

🔍 Security experts urge enterprises to shift from scheduled patch cycles to risk-based, continuous approaches such as just-in-time patching, citing AI-driven vulnerability discovery and exploitation that outpace traditional models. Vendors warn that AI tools can rapidly surface and validate flaws, widening the gap between discovery and remediation and overwhelming teams. Compensating controls like virtual patching can help, but they are stopgaps; organizations need continuous asset visibility, real-time exploitation intelligence, and prioritization based on exposure and exploitability.
read more →

Why clearinghouses aren’t the core solution

🛠️ Athena joins a crowded set of recently announced clearinghouses, but the author argues the clearinghouse itself is the least important part of the equation. Clearinghouses are simply pools of vulnerability data; the real value is in actuation — rebuilding, testing, signing, and delivering fixes where users will actually consume them. The rise of private pre-disclosure findings is a byproduct of models tested against running applications, and scale plus fast throughput matters more than the mere existence of another database.
read more →

AWS Security Hub adds impact analysis for exposures

🔍 Today, AWS Security Hub introduces impact analysis for exposure findings, enabling security teams to see the downstream resources an attacker could reach if an exposure is exploited. The feature maps privilege escalation paths by analyzing effective IAM permissions and displays potential attack paths in a graph. A new Impact Assessment tab prioritizes chains of compromise and shows the permissions at each step, while severity scores are adjusted to reflect downstream reach.
read more →

2026 Exposure Gap Report: Rising Vulnerability Risk

🔍 The 2026 Exposure Gap Report reveals that vulnerabilities now account for 42.6% of critical exposure, up from 18.7% in 2025, shifting the focus of risk across connected environments. Only 7.8% of vulnerability alerts are validated as exploitable and classified as Critical or High, highlighting the need for context-aware prioritization. The report emphasizes validation, asset criticality, and evidence of exploitation to narrow large alert volumes into actionable priorities. Teams that apply consistent validation and filtering can close the exposure gap more effectively and prioritize remediation where it matters.
read more →

Legacy Infrastructure Enables AI Agent Hijacking

🔒 This article explains how attackers bypass AI security by exploiting legacy infrastructure that AI agents inherit, such as Active Directory, cloud storage, and unpatched servers. It outlines a staged attack where a CVE-exploited perimeter server leads to credential theft, lateral movement, and compromise of an AI Co-Pilot's knowledge base. The piece urges exposure management that maps dependencies and fixes choke points to protect AI environments.
read more →

Survey Finds AI Attacks Top Concern for Security Leaders

🔍 A Filigran survey of 168 security leaders at Infosecurity Europe 2026 found AI-powered attacks are the leading worry, cited by 41% of respondents, outpacing supply chain and unknown threats. Teams report alert fatigue as a major time sink, with chasing false positives (26%) and validating risks (25%) common. Trust in threat intelligence and AI decision-making remains low, and only 28% have a continuous exposure management program.
read more →

Top 10 Attack Surface Exposures in 2026

🔍 Intruder analyzed 3,000 internet-facing attack surfaces to identify services that have no business being publicly reachable. Their 2026 Attack Surface Management Index found widespread exposure: 60% had at least one HTTP admin panel exposed, 49% had risky ports/services, 42% had internet-accessible databases, and 30% had publicly accessible files or documentation. The report lists the ten most common exposures and urges a shift from pure patching to active attack surface reduction.
read more →

NCSC Warning: Prepare for an Unprecedented Patch Wave

🔔 The NCSC warns organisations to brace for a large-scale “patch wave” as AI accelerates exploitation of technical debt. Check Point outlines how Exposure Management helps public sector and CNI teams identify internet-facing assets, prioritise exploitable vulnerabilities, and remediate safely. The guidance emphasises discovery, exploitability-based prioritisation, and compensating controls to reduce MTTR.
read more →

Compute Optimizer detects idle resources across services

🔍 AWS Compute Optimizer now detects idle resources for Amazon DynamoDB provisioned tables, Amazon ElastiCache (Redis and Valkey), Amazon MemoryDB, Amazon DocumentDB (provisioned and serverless), Amazon WorkSpaces, and Amazon SageMaker endpoints. It analyzes utilization metrics over a configurable lookback period and evaluates service-specific signals like consumed capacity, cache hits, active connections, and CPU utilization. Recommendations include detailed utilization metrics and estimated savings, viewable in the console and in the Cost Optimization Hub across AWS Organizations.
read more →