• Shai-Huluda, a self-replicating npm worm named after the sandworms in Dune, had struck again. This time, the attack was devastating in scale and sophistication, compromising over 800 npm packages with a combined 132 million monthly downloads across the ecosystem. The timing proved particularly strategic. The attack occurred just weeks before npm’s December 9 deadline to […]

    The post Sha1-Hulud Attack Hits 800+ npm Packages and Thousands of GitHub Repos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical security flaw has been discovered in HashiCorp’s Vault Terraform Provider that could allow attackers to bypass authentication and access Vault without valid credentials.

    The vulnerability, tracked as CVE-2025-13357, affects organizations using LDAP authentication with Vault. The security issue stems from an incorrect default configuration in Vault’s Terraform Provider.

    Specifically, the provider set the deny_null_bind parameter to false by default for the LDAP authentication method.

    HashiCorp Vault Vulnerability

    This misconfiguration created a dangerous security gap because the underlying LDAP server permitted unauthenticated connections.

    When exploited, this vulnerability allows threat actors to authenticate to Vault without providing legitimate credentials.

    This authentication bypass poses significant risks to organizations storing sensitive secrets, encryption keys, and other critical data in Vault.

    CVE IDAffected ProductsAffected VersionsImpact
    CVE-2025-13357Vault Terraform Providerv4.2.0 to v5.4.0Authentication Bypass

    HashiCorp has released fixes addressing this vulnerability. Organizations should take the following actions:

    Update to Vault Terraform Provider v5.5.0, which correctly sets the deny_null_bind parameter to true by default.

    Additionally, upgrade to Vault Community Edition 1.21.1 or Vault Enterprise versions 1.21.1, 1.20.6, 1.19.12, or 1.16.28.

    Ensure the deny_null_bind parameter is explicitly set to true in LDAP auth method configurations.

    Organizations using older provider versions should explicitly set the parameter in their Terraform files and apply the changes immediately.

    The patched Vault versions no longer accept empty password strings, effectively preventing unauthenticated LDAP connections via the authentication method.

    HashiCorp has announced that this outdated parameter will be removed in future releases. This vulnerability was identified by a third-party researcher who responsibly disclosed it to HashiCorp.

    Organizations using Vault with LDAP authentication should prioritize applying these security updates to protect their infrastructure from potential exploitation.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune.

    The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register and control.​

    How the Vulnerability Works

    The vulnerability exists in version 1.0 of the Update Health Tools, which uses Azure Blob storage accounts following a predictable naming pattern (payloadprod0 through payloadprod15.blob.core.windows.net) to fetch configuration files and commands.

    Eye Security researchers found that Microsoft had left 10 of the 15 storage accounts unregistered and unused.

    After registering these abandoned endpoints, the researchers observed over 544,000 HTTP requests within seven days from nearly 10,000 unique Azure tenants worldwide.

    The tool’s uhssvc.exe service, located at C:\Program Files\Microsoft Update Health Tools, was actively resolving these domains across multiple enterprise environments.​

    uhssvc.exe file
    uhssvc.exe file

    The critical issue lies in the tool’s “ExecuteTool” action, which allows execution of Microsoft-signed binaries.

    By crafting malicious JSON payloads that point to legitimate Windows executables such as explorer.exe, attackers can achieve arbitrary code execution on vulnerable systems.​

    The newer version 1.1 implements a proper web service at devicelistenerprod.microsoft.com, though backward-compatibility options could still expose systems.​

    Eye Security reported the vulnerability to Microsoft on July 7, 2025, and Microsoft confirmed the behavior on July 17.

    Hashicorp researchers transferred ownership of all compromised storage accounts back to Microsoft on July 18, 2025, effectively closing the attack vector.​

    Organizations should ensure they are running the latest version of Update Health Tools and verify no legacy configurations remain enabled.

    Security teams should monitor for unusual network traffic to Azure Blob storage endpoints from update services.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert warning that multiple cyber threat actors are actively exploiting commercial spyware to target users of popular mobile messaging applications, including Signal and WhatsApp. The advisory, published on November 24, 2025, highlights sophisticated attack techniques aimed at compromising victim accounts and gaining unauthorized access […]

    The post CISA Warns of Commercial Spyware Targeting Signal and WhatsApp Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday issued an alert warning of bad actors actively leveraging commercial spyware and remote access trojans (RATs) to target users of mobile messaging applications. “These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are weaponizing Blender Foundation project files to deliver the notorious StealC V2 infostealer, targeting 3D artists and game developers who download community assets from popular marketplaces. In recent months, Morphisec has blocked multiple sophisticated campaigns abusing Blender’s embedded scripting capabilities to silently deploy StealC V2, highlighting a growing nexus between creative tools and […]

    The post Threat Actors Exploit Blender Files to Deploy StealC V2 Infostealer appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Exposure Management is a proactive cybersecurity discipline that systematically identifies, assesses, prioritizes, and remediates security vulnerabilities and misconfigurations across an organization’s entire attack surface both internal and external.

    Unlike traditional, periodic vulnerability scanning, EM leverages continuous monitoring, threat intelligence, and a holistic, graph-based view of risk to anticipate and neutralize potential attack paths before adversaries can exploit them.

    It is the practical application of the Continuous Threat Exposure Management (CTEM) framework, which defines a cyclical five-step process: Scoping, Discovery, Prioritization, Validation, and Mobilization.

    The core value of an EM platform lies in its ability to consolidate findings from diverse security tools (such as vulnerability scanners, cloud posture management, and EDR) and enrich them with business context (e.g., asset criticality, owner) and attacker context (e.g., exploitability in the wild).

    This consolidation drastically reduces alert fatigue by focusing security teams on the few exposures that pose the greatest, most exploitable risk to the business, rather than a massive, unprioritized list of Common Vulnerabilities and Exposures (CVEs).

    Ultimately, EM drives measurable reduction in the organizational risk posture and improves the efficiency of security operations.

    How We Choose An Exposure Management Tools

    Selecting the right Exposure Management Tool requires a strategic approach focused on holistic coverage, actionable intelligence, and seamless integration with existing Security Operations Center (SOC) workflows.

    Our methodology for evaluating the top tools is based on several key criteria:

    1. Scope and Discovery Coverage: The tool must offer comprehensive, continuous discovery of all assets including known, unknown (Shadow IT), and third-party/vendor-related assets—across the full spectrum of modern infrastructure (on-premise, multi-cloud, SaaS, and code). Look for agentless and API-based scanning capabilities for minimal friction.
    2. Risk Prioritization & Context: The platform’s ability to prioritize vulnerabilities must go beyond simple severity scores (CVSS). The best tools use a risk-based approach incorporating:
      • Attacker Context: Real-time threat intelligence on active exploitation.
      • Business Context: Asset criticality, data sensitivity, and owner.
      • Attack Path Visualization: Mapping how an exposure can be chained with others to create an end-to-end attack path.
    3. Validation and Remediation Integration: A top-tier tool validates whether an exposure is actually exploitable (often via integrated Breach and Attack Simulation – BAS) and provides clear, actionable remediation guidance, including one-click fixes or direct integration with ticketing/workflow systems (like Jira, ServiceNow) to accelerate Mean Time to Remediate (MTTR).
    4. Scalability and Architecture: The solution must be highly scalable to accommodate a dynamic, rapidly expanding digital footprint, especially in cloud-native environments.
      • A cloud-native, agentless architecture often simplifies deployment and reduces operational overhead.

    Comparison Table: Top 10 Best Exposure Management Tools In 2026

    Tool NameExternal Attack Surface Management (EASM)Cloud Attack Surface Management (CASM)Breach & Attack Simulation (BAS)Risk-Based PrioritizationAgentless Deployment
    Mandiant✅ Yes✅ Yes (Multi-Cloud)❌ No (Focus on Intel)✅ Yes✅ Yes
    Wiz❌ No (Focus on Cloud)✅ Yes (Cloud-Native)❌ No✅ Yes✅ Yes
    RiskProfiler✅ Yes✅ Yes (Multi-Cloud)❌ No✅ Yes✅ Yes
    CrowdStrike Falcon✅ Yes✅ Yes (via Falcon)❌ No✅ Yes❌ No (Sensor-based)
    Tenable One✅ Yes✅ Yes (Multi-Cloud)❌ No✅ Yes✅ Yes / ❌ No (Hybrid)
    Qualys✅ Yes✅ Yes (via VMDR)❌ No✅ Yes✅ Yes
    CyCognito✅ Yes (Attacker’s View)✅ Yes❌ No✅ Yes✅ Yes
    Microsoft Defender✅ Yes (External focus)✅ Yes (via Defender)❌ No✅ Yes✅ Yes
    Cymulate✅ Yes (via Discovery)✅ Yes (via Validation)✅ Yes (Core Feature)✅ Yes✅ Yes / ❌ No (Hybrid)
    Bitsight✅ Yes✅ Yes (Cloud Configs)❌ No✅ Yes✅ Yes

    1. Mandiant

    Best Exposure Management Tools
    Mandiant

    Why We Picked It

    Mandiant is chosen for its world-class, frontline threat intelligence, which directly informs its risk prioritization engine.

    This allows organizations to prioritize exposures that Mandiant’s consultants know adversaries are actively exploiting in real-world attacks.

    Specifications & Features

    • Intel-Informed Checks: Uses Mandiant’s own threat intelligence for active and passive checks of external assets.
    • Continual Asset Discovery: Automated, continuous discovery and inventory of internet-facing assets, including Shadow IT.
    • Multicloud Assessment: Ability to assess cloud-hosted external assets and unify visibility across hybrid/multicloud.
    • Centralized Risk Mitigation: Consolidates visibility and provides clear paths for remediation, driven by threat context.

    Reason to Buy

    You need an exposure management tool that is directly fed by the industry’s most current, credible, and real-world attacker intelligence to ensure your security team focuses exclusively on the most exploitable risks.

    Pros & Cons

    • Pros: Direct integration with Mandiant’s proprietary threat intel; Strong external focus and shadow IT detection; Effective for large, complex enterprises.
    • Cons: Less focus on integrated validation (BAS) than some competitors; Pricing can be complex; May require Mandiant-specific expertise for full value.

    ✅ Best For: Enterprises prioritizing real-world threat intelligence and wanting an outside-in, attacker’s view of their external attack surface.

    Official Home Page: Mandiant Attack Surface Management

    2. Wiz

    Best Exposure Management Tools
    Wiz

    Why We Picked It

    Wiz is the undisputed leader in Cloud Security Posture Management (CSPM) and has expanded to offer deep exposure management features rooted in its unique, agentless Security Graph.

    It’s ideal for organizations that are cloud-first or heavily invested in multi-cloud environments.

    Specifications & Features

    • Agentless-First Scanning: Provides 100% coverage of the cloud environment without agents, using API and snapshot reading.
    • Graph-Based Risk Prioritization: Correlates security findings across workloads, network, identity, and data to identify critical attack paths.
    • Unified Vulnerability Management: Centralizes and prioritizes vulnerabilities across cloud, code, and on-premises using the same context model.
    • Shift-Left Capabilities: Integrates with code (SAST/DAST) tools to find and fix vulnerabilities early in the development lifecycle.

    Reason to Buy

    Your primary risk is in the cloud, and you need a consolidated, context-aware platform that can identify exploitable security gaps that span across multiple cloud resources, identities, and data stores.

    Pros & Cons

    • Pros: Deepest cloud security context and coverage; Exceptional ease of deployment (agentless); Industry-leading Security Graph technology; Excellent for modern DevOps pipelines.
    • Cons: Originally cloud-centric, with less native EASM/on-prem heritage; Can be expensive for smaller operations; Remediation often relies on integrations.

    ✅ Best For: Cloud-Native and Multi-Cloud organizations that need to prioritize risk based on exploitability within the cloud environment.

    Official Home Page: Agentless Cloud Vulnerability Management - Wiz

    3. RiskProfiler

     cloud attack surface management
    RiskProfiler

    Why We Picked It

    RiskProfiler is selected for its focus on providing a unified view of risk that extends beyond the organization’s perimeter to include third-party vendor risk and brand risk (phishing, impersonation), making it a comprehensive CTEM solution.

    Specifications & Features

    • Unified CTEM Ecosystem: Consolidates External, Cloud, Vendor, and Brand risk into a single platform.
    • Brand Risk Protection: Monitors for brand impersonation, typosquats, phishing, and fake apps.
    • AI-Enabled Third-Party Risk Management: Automates the exchange and scoring of vendor security questionnaires.
    • Context-Based Graph Models: Pinpoints and ranks exposed assets by evaluating risks through a hacker’s lens.

    Reason to Buy

    You need to manage your total external risk, including the exposure introduced by supply chain vendors and threats to your brand reputation outside of your technical infrastructure.

    Pros & Cons

    • Pros: Strong integration of third-party risk management; Dedicated brand protection features; Contextual threat insights for prioritization; Unified view across four major risk domains.
    • Cons: Focus is heavily external, may require other tools for deep internal security; Smaller market presence compared to industry giants; Initial setup for all modules can be complex.

    ✅ Best For: Organizations with significant third-party vendor reliance and high exposure to brand-related threats (phishing, impersonation).

    Official Home Page: RiskProfiler - External Threat Exposure Management

    4. CrowdStrike Falcon

     cloud attack surface management
    CrowdStrike Falcon

    Why We Picked It

    CrowdStrike is included for its ability to integrate Exposure Management natively within the Falcon platform, leveraging its ubiquitous single, lightweight sensor for real-time asset discovery and vulnerability assessment across the internal and external attack surface.

    Specifications & Features

    • Unified Falcon Sensor: Uses a single, lightweight agent for real-time, maintenance-free vulnerability assessment and continuous visibility.
    • AI-Powered Asset Criticality: Automatically classifies assets (Critical, High, Non-Critical) based on business context and peer insights.
    • Full Lifecycle Vulnerability Management: Covers asset discovery, assessment, prioritization, and effective remediation within a single product.
    • Active, Passive, & API Discovery: Discovers all assets, including sensorless devices (routers, IoT), without traditional network scanning appliances.

    Reason to Buy

    You are already a CrowdStrike customer and want to consolidate your endpoint security, threat intelligence, and exposure management into a single, high-performance platform with minimal footprint.

    Pros & Cons

    • Pros: Real-time visibility without scan windows; Excellent threat intelligence integration; Reduces the need for multiple security agents; Seamlessly integrates with EDR/XDR workflows.
    • Cons: Heavily reliant on the Falcon sensor (not fully agentless); Primarily focuses on the asset visibility the sensor can provide; Higher cost for the full unified platform.

    ✅ Best For: Organizations committed to the CrowdStrike Falcon platform who prioritize real-time, continuous visibility over periodic scanning.

    Official Home Page: Falcon Exposure Management - CrowdStrike

    5. Tenable

    Mandiant attack surface
    Tenable

    Why We Picked It

    Tenable is a long-standing leader in Vulnerability Management (VM) that has successfully pivoted to the holistic Exposure Management model with its Tenable One platform, offering deep, comprehensive coverage across IT, cloud, and operational technology (OT).

    Specifications & Features

    • Converged Exposure Platform: Unifies data from Tenable’s VM, EASM, Cloud Security, and AD Security products.
    • Predictive Prioritization Scoring (PPS): Uses machine learning to anticipate which vulnerabilities are most likely to be exploited in the near future.
    • Unified Attack Surface Visualization: Provides a consolidated view of the entire attack surface and the paths an attacker could take.
    • Broadest Asset Coverage: Includes IT, Web Apps, OT, Cloud, and Active Directory security posture.

    Reason to Buy

    You require a solution from a trusted VM vendor that offers the broadest coverage of assets and the ability to leverage predictive analytics to prioritize remediation based on future exploit likelihood.

    Pros & Cons

    • Pros: Deepest history and coverage in core vulnerability management; Strong support for diverse environments (OT/AD); Predictive risk scoring for proactive prioritization; High potential for upselling existing Tenable customers.
    • Cons: Can be perceived as scan-heavy (though API-based for cloud); Platform integration is newer than individual products; Transitioning from a VM mindset to an EM mindset can be a learning curve.

    ✅ Best For: Large enterprises seeking to consolidate and modernize their legacy vulnerability and asset management programs under a single, unified exposure platform.

    Official Home Page: Tenable One Exposure Management

    6. Qualys

    Mandiant attack surface
    Qualys

    Why We Picked It

    Qualys is a veteran in the security space that has tightly integrated its External Attack Surface Management (EASM) into its comprehensive Cloud Platform, providing a seamless “outside-in” and “inside-out” view for existing customers.

    Specifications & Features

    • EASM as a Feature: Provides an outside-in view of internet-facing assets within the Qualys Cloud Platform (CSAM).
    • Continuous Monitoring: Continuously monitors the external attack surface to discover new domains, unsolicited ports, certificates, and applications.
    • Asset Discovery: Discovers all domains, subdomains, and associated assets, including unknown/unmanaged assets.
    • Integration with VMDR: Directly feeds EASM findings into the Vulnerability Management, Detection, and Response (VMDR) workflow for prioritization and remediation.

    Reason to Buy

    You are a current Qualys customer looking to extend the reach of your existing security platform to continuously discover and manage your external digital footprint and integrate findings with a familiar VMDR workflow.

    Pros & Cons

    • Pros: Deep integration with the Qualys ecosystem; Comprehensive visibility of external assets; Robust for large organizations with complex IT infrastructure; Consolidates EASM under a single vendor.
    • Cons: EASM features can feel like an add-on to the VMDR core; Full feature set requires adoption of the full Qualys Cloud Platform; Initial EASM feature may have started as a beta.

    ✅ Best For: Existing Qualys Cloud Platform users who want to centralize EASM and vulnerability data under a single vendor.

    Official Home Page: External Attack Surface Management - Qualys

    7. CyCognito

     attack path visualization
    CyCognito

    Why We Picked It

    CyCognito stands out for its attacker-centric approach, which automatically discovers and tests all internet-exposed assets (both known and unknown) from the perspective of a malicious actor, prioritizing risks based on the probability and impact of exploitation.

    Specifications & Features

    • Attacker-Centric Discovery: Discovers all internet-exposed assets to build a complete picture of the attack surface from the outside.
    • Automated Security Testing: Automatically detects and validates potential attack vectors across the external IT ecosystem.
    • Business Context Mapping: Graphs asset relationships and determines business context (owner, purpose, data sensitivity) for better prioritization.
    • Comprehensive Prioritization: Ranks attack vectors based on attacker priorities, business context, ease of exploitation, and remediation complexity.

    Reason to Buy

    You need an EM solution that goes beyond inventorying assets to actively and continuously testing them for exploitable flaws, helping you see and fix your exposure exactly as an attacker would.

    Pros & Cons

    • Pros: Powerful, continuous security testing at scale; Strong focus on unknown/unmonitored assets; Prioritization based on attacker logic; Provides clear remediation guidance.
    • Cons: Not a traditional internal vulnerability scanner; Focus is heavily on the external/perimeter attack surface; Higher price point reflective of its advanced testing capabilities.

    ✅ Best For: Organizations that prioritize continuous, active security testing and require an outside-in, attacker-focused view of their risk.

    Official Home Page: Exposure Management - CyCognito

    8. Microsoft Defender

     attack path visualization
    Microsoft Defender

    Why We Picked It

    Microsoft is a strategic choice for its deep integration into the Microsoft Defender suite and its ability to provide a comprehensive view of external risks by leveraging Microsoft’s vast threat intelligence and cloud infrastructure presence.

    Specifications & Features

    • Attack Surface Discovery: Maps the organization’s external attack surface by identifying all internet-facing assets, services, and applications.
    • Threat Intelligence Integration: Leverages up-to-date Microsoft threat intelligence feeds for proactive threat identification and response.
    • Automated Vulnerability Assessment: Automates the assessment of external defenses to find and address weaknesses.
    • Integration with Defender Ecosystem: Seamlessly works with other Microsoft Defender components (e.g., EDR, Cloud Security Posture Management) for unified security.

    Reason to Buy

    You are heavily invested in the Microsoft ecosystem (Azure, M365) and need a native, integrated EM solution that leverages your existing tools and Microsoft’s global threat intelligence network.

    Pros & Cons

    • Pros: Unbeatable integration for Microsoft shops; Leverages Microsoft’s massive threat intelligence; Cost-friendly for existing Defender customers; Strong security monitoring and protection.
    • Cons: Initial setup and integration can be complicated for varied IT environments; Limited for non-Microsoft-centric cloud/infrastructure; Features may be more limited than best-of-breed EASM pure-plays.

    ✅ Best For: Organizations that have standardized on the Microsoft Defender suite and utilize Microsoft Azure/Cloud services.

    Official Home Page: Microsoft Defender External Attack Surface Management

    9. Cymulate

    Tenable One exposure platform
    Cymulate

    Why We Picked It

    Cymulate is unique on this list because its core strength is Breach and Attack Simulation (BAS) and Exposure Validation, enabling organizations to continuously test their defenses against the latest adversarial techniques and validate that an exposure is truly a risk.

    Specifications & Features

    • BAS/Exposure Validation Core: Continuously tests security controls across the full kill chain using automated, live, offensive testing.
    • AI-Assisted Custom Testing: Allows users to create realistic, multi-stage attack chains from plain language prompts or threat advisories (Purple Teaming).
    • Optimized Remediation: Provides actionable guidance, including control-ready threat updates and custom detection rules for SIEM/EDR platforms.
    • Cyber Resilience Metrics: Delivers a unified, measurable view of security posture, benchmarked against industry peers.

    Reason to Buy

    You need to move beyond simple vulnerability discovery to empirically validate if your security controls (firewalls, EDR, SIEM rules) are actually working against current threats and prioritize only those exposures that validation proves are exploitable.

    Pros & Cons

    • Pros: Core focus on validation (BAS/CTEM step 4); Automated Purple Teaming capabilities; Provides quantitative, board-ready cyber resilience metrics; Excellent for optimizing and tuning existing security tools.
    • Cons: External Attack Surface Discovery is a supporting feature rather than the core focus; Requires strong integration with other discovery/scanner tools for full EM value; Requires expertise to leverage the full BAS potential.

    ✅ Best For: Security teams that need to validate, optimize, and prove the effectiveness of their existing security controls against real-world threats (CTEM Validation).

    Official Home Page: Cymulate Exposure Validation

    10. Bitsight

    Tenable One exposure platform
    Bitsight

    Why We Picked It

    Bitsight is known for its market-leading Security Ratings and brings that proprietary risk scoring and analytics model to its EASM platform, offering unmatched signal quality and contextual intelligence for external risks and third-party risk management.

    Specifications & Features

    • Unmatched Signal Quality: Leverages behavioral analytics and telemetry from billions of daily events to identify true exposures with high precision.
    • Integrated Third-Party Risk: Extends EASM visibility and risk scoring to third-party vendors and supply chain partners.
    • Daily Discovery Cadence: Automated, daily discovery and classification of new or changed internet-facing assets.
    • Integration with GRC/SOC Workflows: Provides data for rapid response and allows for integration with workflow tools like Jira and ServiceNow.

    Reason to Buy

    Your primary driver is a quantifiable, data-driven security rating for both your own organization and your entire supply chain, driven by high-quality external risk data and analytics.

    Pros & Cons

    • Pros: Industry-leading security ratings and risk quantification; Excellent for third-party risk management; Daily and automated asset discovery; Strong reporting and governance (GRC) focus.
    • Cons: Licensing model can be complex; Historically focused on ratings, the EASM platform is a newer extension; Less of an internal, post-exploitation focus than some other platforms.

    ✅ Best For: Risk and Governance (GRC) teams that need quantitative security ratings and highly accurate, data-driven external exposure management for themselves and their vendors.

    Official Home Page: External Attack Surface Management - BitSight Technologies

    Conclusion

    The evolution from reactive Vulnerability Management to proactive Exposure Management is the defining shift in cybersecurity for 2026.

    The Top 10 Best Exposure Management Tools in 2026 reflect this trend, with leading vendors moving toward unified platforms that integrate discovery, threat intelligence, business context, and attack validation to deliver a prioritized, actionable view of risk.

    When selecting a tool, organizations must align their choice with their primary risk domain whether it’s cloud-native risk (Wiz), the need for real-world threat intelligence (Mandiant), or the necessity of proving control effectiveness (Cymulate).

    All platforms excel in risk prioritization, but the method (threat intelligence vs. attack path analysis vs. security ratings) is what sets them apart.

    To begin building a comprehensive EM program, security teams should focus on the initial step of Continuous Threat Exposure Management (CTEM) by establishing a complete inventory of all internet-facing assets.

    The post Top 10 Best Exposure Management Tools In 2026 appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new wave of ClickFix attacks is abusing highly realistic fake Windows Update screens and PNG image steganography to secretly deploy infostealing malware such as LummaC2 and Rhadamanthys on victim systems.

    The campaigns rely on tricking users into manually running a pre-staged command, turning simple social engineering into a multi-stage, file-light infection chain that is hard for traditional defenses to spot.​

    ClickFix is a social engineering technique in which a web page convinces users to press Win+R, then paste and run a command that has been silently copied to the clipboard.

    Earlier lures posed as “Human Verification” or robot-check pages, but newer activity observed by Huntress swaps this for a full-screen, blue Windows Update-style splash screen with convincing progress messages.

    Fake Windows Update

    Once the fake update “completes,” the page instructs users to follow the familiar pattern and execute the malicious Run-box command.​

    That command typically launches mshta.exe with a URL whose second IP octet is hex-encoded, kicking off a staged chain that downloads obfuscated PowerShell and reflective .NET loaders. This approach leans heavily on trusted “living off the land” binaries, making the activity blend in with legitimate Windows behavior.​

    Malware hidden in PNG pixels

    The most distinctive feature of this campaign is its use of a .NET steganographic loader that hides shellcode inside the pixel data of a PNG image.

    Instead of appending data, the loader AES-decrypts an embedded PNG resource, reads the raw bitmap bytes, and reconstructs shellcode from a specific color channel, using a custom XOR-based routine to recover the payload in memory.​

    The recovered shellcode is Donut-packed and then injected into a target process such as explorer.exe via dynamically compiled C# code that calls standard Windows APIs like VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.

    In analyzed cases, this final stage has delivered LummaC2 and, in a separate Windows Update cluster, the Rhadamanthys information stealer.​

    Huntress has tracked ClickFix Windows Update clusters since early October, noting repeated use of the IP address 141.98.80[.]175 and rotating paths such as /tick.odd, /gpsc.dat, and /one.dat for the first mshta.exe stage.

    Subsequent PowerShell stages have been hosted on domains like securitysettings[.]live and xoiiasdpsdoasdpojas[.]com, pointing back to the same backend infrastructure.​

    These campaigns continued to appear around the time of Operation Endgame 3.0, which targeted Rhadamanthys’ infrastructure in mid-November, disrupting servers and seizing domains linked to the stealer.

    Even after the takedown announcement, researchers observed multiple active domains still serving the Windows Update ClickFix lure, though the Rhadamanthys payload itself appeared to be unavailable.​

    Because the attack hinges on user interaction with the Run dialog, one strong control is to disable the Windows Run box via Group Policy or registry settings (for example, configuring the NoRun policy under the Explorer key).

    Security teams should also use EDR telemetry to watch for explorer.exe spawning mshta.exe, powershell.exe, or other scripting binaries with suspicious command lines.​

    User awareness remains critical: employees should be trained that neither CAPTCHA checks nor Windows Update processes will ever require pasting commands into the Run prompt from a web page.

    During investigations, analysts can further validate potential ClickFix abuse by reviewing the RunMRU registry key, which records recent commands executed via the Run dialog.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • TRUPPENÜBUNGSPLATZ PUTLOS TRAINING GROUND, Germany—In a grassy field near the Baltic Sea, U.S. soldiers used net-shooting hunter drones, specially outfitted 557 rifles, and .50-caliber machine guns to drop dozens of drones, large and small, into the cold mud.

    For the U.S. Army, the daylong event marked the beginning of the end of firing $4-million missiles at $20,000 drones; for its European counterparts, it showed off options to counter Russia’s accelerating threat.

    The event was part of Project Flytrap, a U.S. Army effort to advance the state of counter-drone art. More than 200 vendors applied to participate in the November iteration; 20 were chosen by the Global Tactical Edge Acquisition Directorate, a new procurement office the service set up to get such gear to the field quickly.

    On Nov. 21, media and foreign militaries watched a series of demonstrations that showed off not just individual products, but how they could be made to work together in just days.

    Brig. Gen. Curtis King of the 10th Army Air and Missile Defense Command told Defense One that Ukrainian descriptions of battlefield conditions have helped the U.S. Army develop new tactics, gear, and weapons.

    Because supply lines are vulnerable, it’s useful to be able to make drones at, or near, the front lines. In a tent on the field, a soldier with the 10th AAMDC showed off the results of some experimentation: a 3D printer that can print a drone frame in a few hours. With pre-ordered electronic components, it could serve as an interceptor or as part of a sensor mesh to locate enemy drones and their launching points.

    More sensing is key to effective, affordable counter-drone efforts. King said one of the most important aspects of the event was integrating data from active radar systems with that of passive radar, a novel form that deduces a drone’s location from perturbations in FM radio signals. And he said the event showed off a real breakthrough: integrating all that sensor data so it could be used at all levels, from anti-drone snipers to the operators of first-person-view drones to unit commanders.

    “We were able to send that to the units that were working on classified systems, and we were able to send that information to units who were working on sensitive but unclassified information. We've been demonstrating that for a while, but what was so significant this time is the number of sensors that we did and we did that with no latency, meaning we got real-time data,” he said.

    Soldier feedback led to a top prize for Armaments Research Company, whose portable drone-tracing gear could turn “every soldier into a sensor,” said CEO Mike Canty, an Iraq War veteran.

    An “aim assistant” from Zeromark helps soldiers shoot down drones with bullets—rather than with lasers that are still under development or jammers that don’t work against autonomous drones.

    Then there’s Fortem's net-shooting drone, useful in cities or around civilian populations.

    Besides helping the U.S. Army, the show aimed to help European officials learn to defend themselves against Russian drones, even if the U.S. backs out of its security guarantees. 

    “What you saw today … are effectors that cost much less, sometimes a tenth of the cost of that drone. So not only are we still achieving the lethality we need, but we're doing it on the right side of the cost curve,” King told reporters. 

    Journalists from Europe wanted to know: will the tech on display really stop Russian drone incursions

    King and other Army officials didn’t have a simple answer. They noted that the United States remains part of NATO, that the event aimed to inform European decision-making, and that future FlyTrap events will incorporate ground robotics and air-launched effects.

    Col. Chris Hill, project manager for integrated fires mission command, noted, “The real goal is to have soldiers from other countries that are part of the assessment, because you want skin in the game early. You want your soldiers to take a look at their own commands, to say, ‘Yes, this capability works.’ You see a lot of non-U.S. flags out there because if you look at the eastern flank, those are NATO countries. So every country along that plane who's in closest proximity to the threat from Russia needs to know that the kit actually works.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • NVIDIA has disclosed two critical code injection vulnerabilities affecting its Isaac-GR00T robotics platform.

    The vulnerabilities, tracked as CVE-2025-33183 and CVE-2025-33184, exist within Python components and could allow authenticated attackers to execute arbitrary code, escalate privileges, and alter system data.

    The flaws pose a significant threat to organizations deploying NVIDIA’s robotics solutions across industrial automation, research facilities, and autonomous systems.

    Both vulnerabilities carry a high CVSS score of 7.8, indicating serious security risks that require immediate remediation.

    Vulnerability Details

    The code injection issues affect all versions of NVIDIA Isaac-GR00T N1.5 across all platforms.

    An attacker with local access and low-level privileges could exploit these vulnerabilities without user interaction, potentially gaining complete system control.

    CVE IDDescriptionCVSS ScoreCWEAttack Vector
    CVE-2025-33183Code injection in Python component allowing arbitrary code execution7.8CWE-94Local/Low Privilege
    CVE-2025-33184Code injection in Python component allowing arbitrary code execution7.8CWE-94Local/Low Privilege

    Successful exploitation could result in unauthorized code execution, privilege escalation, information disclosure, and data modification, compromising the integrity of critical robotic operations.

    Both vulnerabilities stem from improper handling of user-supplied input in Python components, classified under CWE-94 (Improper Control of Generation of Code).

    This weakness has been historically exploited in numerous attacks targeting interpreted code environments.

    NVIDIA has released a software update addressing both vulnerabilities. The patch is available through GitHub commit 7f53666 of the Isaac-GR00T repository.

    Organizations running Isaac-GR00T should immediately update to any code branch incorporating this specific commit to eliminate the attack surface.

    System administrators should prioritize deploying the security update across all Isaac-GR00T deployments.

    Given the high severity rating and the potential for critical system compromise, NVIDIA recommends treating this as an urgent priority.

    Organizations unable to patch immediately should restrict local access to affected systems and monitor for suspicious activity.

    NVIDIA’s Product Security Incident Response Team (PSIRT) continues monitoring for exploitation attempts.

    The vulnerabilities were responsibly disclosed by Peter Girnus of Trend Micro Zero Day Initiative, highlighting the importance of coordinated vulnerability research.

    For comprehensive information, visit NVIDIA’s Product Security page to access complete Security alerts and subscribe to future vulnerability notifications.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post NVIDIA’s Isaac-GROOT Robotics Platform Vulnerability Let Attackers Inject Malicious Codes appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶