Blog

Chaining together Active Directory attack techniques to give your organization the edge against attackers
Michael Greenberg | May 30, 2022

Debuting at RSA 2022 we will show the industry how we can link the use of Active Directory (AD) into the entire attack path,…

Decrypting VMware Workstation Passwords for Fun
David Azria & Zur Ulianitzky | May 23, 2022

Overview At XM Cyber, we have been hard at work on the techniques that attackers use against your VMware environments. What you’re about to…

Our security is only as strong as our ability to manage it: The necessity of Attack Path Management for the Hybrid Cloud
Michael Greenberg | May 12, 2022

Now it’s no secret businesses have ramped up and driven the adoption of the cloud faster than any period previously. One of the key…

The XM Cyber 2022 Attack Path Management Impact Report
Michael Greenberg | April 26, 2022

The industry’s first annual attack path management research report is here! The XM Cyber research team analyzed nearly 2 million entities to bring insights…

5 Ways to Make Attack Path Management More Manageable
Shay Siksik | April 20, 2022

Effective cybersecurity can be distilled to a single idea: Protect your most business critical assets. Protecting your most critical assets, in turn, can be…

XM Cyber Advisory – Spring4Shell, Zero Day
Zur Ulianitzky; Ilay Grossman | March 31, 2022

Overview On March 30, A new zero day critical vulnerability was leaked in another open source software library. The vulnerability affects Spring Framework which…

New Privilege Escalation Techniques are Compromising your Google Cloud Platform
Idan Strovinsky, Zur Ulianitzky | March 27, 2022

In this research you’ll discover some of the common attack techniques used in Google Cloud Platform (GCP) to better understand how an attacker exploits…

See All Ways: How to Overcome the Big Disconnect in Cybersecurity
Sharron Malaver | March 14, 2022

Today’s reality in cybersecurity is that, with the right combination of tools, you may be able to see all kinds of misconfigurations … and…

10 ways to gain control over Azure function app sites
Zur Ulianitzky and Bill Ben Haim | March 06, 2022

  Pen-testers! Red-teamers! We’ve prepared a bucket of new Azure techniques, specifically about Azure function app sites. In this blog, we’ll show you new…

Choosing Attack Path Management Over Security Control Validation When Shopping for Breach & Attack Simulation
Menachem Shafran | March 06, 2022

Breach and Attack Simulation is gaining lots of hype today. Yet simulating attacks can mean many different things and serve many different use cases….

Go Beyond Log4Shell and See the Entire Attack Path
March 01, 2022

We understand the facts: The most common open-source library (Java) has already been identified with 3 CVEs and counting, with over 3 million attacks…

Attack Path vs Attack Vector: Important Differences You Need To Know
Rinat Villeval | January 04, 2022

If you want to solve a problem, defining your terms is essential — and there are few more pressing problems than safeguarding critical assets…

1 10 11 12 13 14 29

See what attackers see, so you can stop them from doing what attackers do.