How a software provider closed unknown paths to cloud compromise
A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily […]
How a global investment firm reduced security surprises
Most security teams don’t suffer from a lack of data. They suffer from a lack of […]
Meta joins OpenAI, Anthropic in latest AI test breach
Meta has become the third frontier AI developer in recent weeks to disclose a security incident […]
You’re only as secure as your last evaluation
The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War […]
Cybersecurity needs a new operating model
For decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. […]
The exploit window is shrinking. Most security workflows are not
AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. […]
CTEM isn’t failing. It’s not being operationalized
Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero […]
Autonomy is earned, not claimed
After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise […]
Attackers hid malware inside Oracle Database after SQL injection breach
Huntress has documented a case where the Oracle database itself became the malware host. The security […]
Verification closes the loop
Most organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch […]