home.social

#attacksurfacemanagement — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #attacksurfacemanagement, aggregated by home.social.

fetched live
  1. “Legacy scanning technologies were designed for smaller networks and struggle at enterprise scale.”

    - Larry Slusser, VP of Strategy, SixMap
    Why external visibility gaps persist during growth and M&A.

    Read more:

    technadu.com/looking-the-right

    #InfoSec #AttackSurfaceManagement #ExternalRisk

  2. “Legacy scanning technologies were designed for smaller networks and struggle at enterprise scale.”

    - Larry Slusser, VP of Strategy, SixMap
    Why external visibility gaps persist during growth and M&A.

    Read more:

    technadu.com/looking-the-right

    #InfoSec #AttackSurfaceManagement #ExternalRisk

  3. “Legacy scanning technologies were designed for smaller networks and struggle at enterprise scale.”

    - Larry Slusser, VP of Strategy, SixMap
    Why external visibility gaps persist during growth and M&A.

    Read more:

    technadu.com/looking-the-right

    #InfoSec #AttackSurfaceManagement #ExternalRisk

  4. “Legacy scanning technologies were designed for smaller networks and struggle at enterprise scale.”

    - Larry Slusser, VP of Strategy, SixMap
    Why external visibility gaps persist during growth and M&A.

    Read more:

    technadu.com/looking-the-right

    #InfoSec #AttackSurfaceManagement #ExternalRisk

  5. Over 25,000 Fortinet devices have been identified with FortiCloud SSO exposed online amid active exploitation of an authentication bypass vulnerability.

    The attack path involves malicious SAML authentication, enabling admin access to web management interfaces and sensitive configuration data. CISA has already mandated patching for U.S. federal systems.

    From an operational security standpoint, this reinforces the need for:
    - Restricted admin interface exposure
    - Identity-aware access controls
    - Continuous external attack surface monitoring
    What mitigation strategies have proven most effective in your environment?

    Source: bleepingcomputer.com/news/secu

    Engage in the discussion and follow TechNadu for practitioner-relevant cyber reporting.

    #InfoSec #ThreatHunting #IdentitySecurity #AttackSurfaceManagement #Fortinet #CyberDefense #TechNadu

  6. Over 25,000 Fortinet devices have been identified with FortiCloud SSO exposed online amid active exploitation of an authentication bypass vulnerability.

    The attack path involves malicious SAML authentication, enabling admin access to web management interfaces and sensitive configuration data. CISA has already mandated patching for U.S. federal systems.

    From an operational security standpoint, this reinforces the need for:
    - Restricted admin interface exposure
    - Identity-aware access controls
    - Continuous external attack surface monitoring
    What mitigation strategies have proven most effective in your environment?

    Source: bleepingcomputer.com/news/secu

    Engage in the discussion and follow TechNadu for practitioner-relevant cyber reporting.

    #InfoSec #ThreatHunting #IdentitySecurity #AttackSurfaceManagement #Fortinet #CyberDefense #TechNadu

  7. Over 25,000 Fortinet devices have been identified with FortiCloud SSO exposed online amid active exploitation of an authentication bypass vulnerability.

    The attack path involves malicious SAML authentication, enabling admin access to web management interfaces and sensitive configuration data. CISA has already mandated patching for U.S. federal systems.

    From an operational security standpoint, this reinforces the need for:
    - Restricted admin interface exposure
    - Identity-aware access controls
    - Continuous external attack surface monitoring
    What mitigation strategies have proven most effective in your environment?

    Source: bleepingcomputer.com/news/secu

    Engage in the discussion and follow TechNadu for practitioner-relevant cyber reporting.

    #InfoSec #ThreatHunting #IdentitySecurity #AttackSurfaceManagement #Fortinet #CyberDefense #TechNadu

  8. Over 25,000 Fortinet devices have been identified with FortiCloud SSO exposed online amid active exploitation of an authentication bypass vulnerability.

    The attack path involves malicious SAML authentication, enabling admin access to web management interfaces and sensitive configuration data. CISA has already mandated patching for U.S. federal systems.

    From an operational security standpoint, this reinforces the need for:
    - Restricted admin interface exposure
    - Identity-aware access controls
    - Continuous external attack surface monitoring
    What mitigation strategies have proven most effective in your environment?

    Source: bleepingcomputer.com/news/secu

    Engage in the discussion and follow TechNadu for practitioner-relevant cyber reporting.

    #InfoSec #ThreatHunting #IdentitySecurity #AttackSurfaceManagement #Fortinet #CyberDefense #TechNadu

  9. In cybersecurity, what you don’t know can hurt you. That’s why periodic external network scanning is not just a best practice - it’s a necessity.

    🚨 Why it matters:
    External-facing assets are prime targets for attackers. Misconfigurations, unpatched services, and forgotten subdomains create entry points that adversaries actively seek. Without regular scanning, you’re essentially flying blind, unaware of the vulnerabilities that could be exploited.

    🔍 What you gain:
    ✅ Identify exposed services before attackers do
    ✅ Detect shadow IT and rogue assets
    ✅ Ensure compliance with security policies
    ✅ Reduce the risk of zero-day exploitation
    📅 How often should you scan?

    While continuous monitoring is ideal, at a minimum:
    🔹 Monthly scans for critical infrastructure
    🔹 Quarterly assessments for broader attack surface mapping
    🔹 Ad-hoc scans after major changes (e.g., new deployments)

    ⚠️But scanning alone isn’t enough❗
    Proper remediation and integration with vulnerability management programs are key. Findings should lead to action, not just reports.

    Are you sure of your visibility of the external attack surface❓

    Find out how we approach external infrastructure testing 👇

    securitum.com/periodic_externa

    #CyberSecurity #EthicalHacking #NetworkSecurity #AttackSurfaceManagement #VulnerabilityManagement #WAN

  10. 👀 DefCamp 2024 felt like scanning a whole range of IPs - each moment unique, some wide open, others hidden, all worth exploring.

    From the open ports of excitement to the filtered pings of exhaustion.
    From flagged vulnerabilities in candid chats to firewalled moments of reflection.
    And always, the steady pings of shared knowledge keeping us connected.

    ▶️ Hit play and dive into the moods we scanned at DefCamp - every bit as rich and powerful as the tools we create.

    #ethicalhacking #penetrationtesting #attacksurfacemanagement

  11. 👀 DefCamp 2024 felt like scanning a whole range of IPs - each moment unique, some wide open, others hidden, all worth exploring.

    From the open ports of excitement to the filtered pings of exhaustion.
    From flagged vulnerabilities in candid chats to firewalled moments of reflection.
    And always, the steady pings of shared knowledge keeping us connected.

    ▶️ Hit play and dive into the moods we scanned at DefCamp - every bit as rich and powerful as the tools we create.

    #ethicalhacking #penetrationtesting #attacksurfacemanagement

  12. 👀 DefCamp 2024 felt like scanning a whole range of IPs - each moment unique, some wide open, others hidden, all worth exploring.

    From the open ports of excitement to the filtered pings of exhaustion.
    From flagged vulnerabilities in candid chats to firewalled moments of reflection.
    And always, the steady pings of shared knowledge keeping us connected.

    ▶️ Hit play and dive into the moods we scanned at DefCamp - every bit as rich and powerful as the tools we create.

    #ethicalhacking #penetrationtesting #attacksurfacemanagement

  13. 👀 DefCamp 2024 felt like scanning a whole range of IPs - each moment unique, some wide open, others hidden, all worth exploring.

    From the open ports of excitement to the filtered pings of exhaustion.
    From flagged vulnerabilities in candid chats to firewalled moments of reflection.
    And always, the steady pings of shared knowledge keeping us connected.

    ▶️ Hit play and dive into the moods we scanned at DefCamp - every bit as rich and powerful as the tools we create.

    #ethicalhacking #penetrationtesting #attacksurfacemanagement

  14. Your next breakthrough might be one read away! Our most-read blogs of 2024 are packed with practical examples:

    1️⃣ The XZ Utils Backdoor (CVE-2024-3094): Learn how this critical Linux vulnerability impacts SSH systems and how to secure against it.

    2️⃣ The Ultimate List of Hacking Books: resources to master ethical hacking from beginner to expert.

    3️⃣ Regresshion (CVE-2024-6387): Dive deep into this SSH vulnerability, with actionable insights for detecting and mitigating it.

    💡 Bonus: Roundcube: Exfiltrating Emails with CVE-2021-44026: See how attackers exploited email systems and how you can prevent similar breaches (public exploit included!).

    👇 Links are in the comments

    #ethicalhacking #penetrationtesting #attacksurfacemanagement

  15. Your next breakthrough might be one read away! Our most-read blogs of 2024 are packed with practical examples:

    1️⃣ The XZ Utils Backdoor (CVE-2024-3094): Learn how this critical Linux vulnerability impacts SSH systems and how to secure against it.

    2️⃣ The Ultimate List of Hacking Books: resources to master ethical hacking from beginner to expert.

    3️⃣ Regresshion (CVE-2024-6387): Dive deep into this SSH vulnerability, with actionable insights for detecting and mitigating it.

    💡 Bonus: Roundcube: Exfiltrating Emails with CVE-2021-44026: See how attackers exploited email systems and how you can prevent similar breaches (public exploit included!).

    👇 Links are in the comments

    #ethicalhacking #penetrationtesting #attacksurfacemanagement

  16. Your next breakthrough might be one read away! Our most-read blogs of 2024 are packed with practical examples:

    1️⃣ The XZ Utils Backdoor (CVE-2024-3094): Learn how this critical Linux vulnerability impacts SSH systems and how to secure against it.

    2️⃣ The Ultimate List of Hacking Books: resources to master ethical hacking from beginner to expert.

    3️⃣ Regresshion (CVE-2024-6387): Dive deep into this SSH vulnerability, with actionable insights for detecting and mitigating it.

    💡 Bonus: Roundcube: Exfiltrating Emails with CVE-2021-44026: See how attackers exploited email systems and how you can prevent similar breaches (public exploit included!).

    👇 Links are in the comments

    #ethicalhacking #penetrationtesting #attacksurfacemanagement

  17. Your next breakthrough might be one read away! Our most-read blogs of 2024 are packed with practical examples:

    1️⃣ The XZ Utils Backdoor (CVE-2024-3094): Learn how this critical Linux vulnerability impacts SSH systems and how to secure against it.

    2️⃣ The Ultimate List of Hacking Books: resources to master ethical hacking from beginner to expert.

    3️⃣ Regresshion (CVE-2024-6387): Dive deep into this SSH vulnerability, with actionable insights for detecting and mitigating it.

    💡 Bonus: Roundcube: Exfiltrating Emails with CVE-2021-44026: See how attackers exploited email systems and how you can prevent similar breaches (public exploit included!).

    👇 Links are in the comments

    #ethicalhacking #penetrationtesting #attacksurfacemanagement