17 million routers.
One Dutch raid.
A quiet cybercrime economy built on disguising malicious activity as ordinary Wi-Fi traffic.
Your router may not be the target. It may be the mask.
Read the full blog: https://t.co/Bw4STmzOmb
An auth bypass on an internet-facing VPN is not just another CVE.
CVE-2026-0257 shows why exposure context matters more than the score alone.
Patch, yes. But first, know whether your configuration is actually exposed.
Read the full blog: https://t.co/JPehXk4UZH
npm shut one door.
TrapDoor found another through AI assistants.
Our latest blog explores how AI assistants are becoming a new attack surface organisations cannot ignore.
Read the full blog here: https://t.co/lBD9zUd9lR
X
18 minutes was enough.
The recent GitHub breach shows how quickly credential-based attacks can compromise trusted software platforms.
Our latest blog explores what happened and how organisations can strengthen security.
Read the full blog : https://t.co/vtsKbLlIaX
X
5,561 GitHub repositories compromised in six hours.
The Megalodon attack shows how infostealer logs.
Our latest blog breaks down what happened and how organisations can reduce exposure.
Read the full blog here: https://t.co/CIHHjEKmyU
Most organisations do not have complete visibility of their external attack surface.
DarkInvader provides free access and insights into your internet-facing footprint, helping organisations understand what attackers can already see.
Find out more: https://t.co/4DO6ZQrllg
48 hours after the patch release, attackers were already exploiting CVE-2026-9082 targeting Drupal sites.
Once patches become public, threat actors can quickly reverse engineer vulnerabilities and automate attacks at scale.
full blog: https://t.co/Y3Zpo8CzCe
Attackers just used AI to build a zero-day 2FA bypass, then weaponised it at scale.
Not targeted. Mass exploitation.
When exploit development speeds up, your exposure window has to shrink.
Read the full blog here: https://t.co/ftai7GeN59
Ticket closed does not mean risk closed.
Most remediation programs never actually verify the fix is live, effective, and still holding.
The only real test is from the outside, looking in.
Read the full blog here: https://t.co/DcE9TfOmhp
Most organisations think they know their attack surface.
Then they watch it for 45 days.
Forgotten subdomains, shadow IT, exposed staging environments. The footprint is always bigger than the inventory.
Read the full blog here: https://t.co/Mx9pRsnzK2
Phishing has evolved.
Smishing attacks through SMS and messaging apps are becoming increasingly effective as organisations move further into mobile-first environments.
Our latest blog explores how EASM helps organisations detect exposure.
Full blog : https://t.co/r9U1vjB2J8
Cybersecurity is shifting from reactive to proactive.
By 2026, External Attack Surface Management (EASM) will play a major role in helping organisations detect threats before attackers exploit them.
Read the full blog here:
https://t.co/xvbcF2WkSh
GlassWorm is back, hiding in malicious VS Code extensions.
Developer machines hold cloud creds, source code, and production access. EDR misses it. Scanners miss it.
Your attack surface just expanded.
Read more here: https://t.co/vWX2moBzRv
Most exposure management platforms look identical on paper.
The real differences only show up after you've signed.
5 red flags most buyers miss when evaluating an EASM vendor.
Read more here: https://t.co/LwLLFlHJOl
How long does it take your team to actually understand a new EASM finding?
For most teams the honest answer is: too long.
Nyx scales senior analyst thinking across every risk on every asset.
Read more here: https://t.co/clNc8dSk7g
Are passwords still your first line of defence?
That’s the problem.
Passwords were never designed for today’s threat landscape:
• Reused across multiple systems
• Easily phished or socially engineered
• Frequently exposed in data breaches
Read blog: https://t.co/palxctsfeJ
Are you prepared for threats that aren’t just criminal, but geopolitical?
Cyber risk is no longer just about opportunistic attackers.
It’s strategic, persistent, and often state-linked.
Read the full blog: https://t.co/nmntvycaZb
How long could an attacker stay inside your systems undetected?
FIRESTARTER shows the answer: longer than you think.
Backdoors don’t break in. They persist.
Without continuous visibility, you won’t see them.
Read more: https://t.co/CjCOx7cjOc
How many unused accounts still have access to your systems?
Ghost identities = hidden risk.
Old employees. Forgotten vendors. Dormant accounts.
They expand your attack surface without you realising.
If you can’t see them, you can’t secure them.
Read: https://t.co/ZklU6rPRaj
How many IoT devices are exposed in your organisation?
Attackers like Nexcorium are already scanning for them.
Default creds. Outdated firmware. Weak configs.
If you can’t see your IoT exposure, you can’t secure it.
Read more: https://t.co/3gT7beIzCF