Blog

Decrypting VMware Workstation Passwords for Fun

Overview At XM Cyber, we have been hard at work on the techniques that attackers use against your VMware environments.…
Blog

Our security is only as strong as our ability to manage it: The necessity of Attack Path Management for the Hybrid Cloud

Now it’s no secret businesses have ramped up and driven the adoption of the cloud faster than any period previously.…
Blog

The XM Cyber 2022 Attack Path Management Impact Report

The industry’s first annual attack path management research report is here! The XM Cyber research team analyzed nearly 2 million…
Blog
5 Ways to Make Attack Path Management More Manageable

5 Ways to Make Attack Path Management More Manageable

Effective cybersecurity can be distilled to a single idea: Protect your most business critical assets. Protecting your most critical assets,…
Blog

XM Cyber Advisory – Spring4Shell, Zero Day

Overview On March 30, A new zero day critical vulnerability was leaked in another open source software library. The vulnerability…
Blog

New Privilege Escalation Techniques are Compromising your Google Cloud Platform

In this research you’ll discover some of the common attack techniques used in Google Cloud Platform (GCP) to better understand…
Blog
See All Ways3 (1)

See All Ways: How to Overcome the Big Disconnect in Cybersecurity

Today’s reality in cybersecurity is that, with the right combination of tools, you may be able to see all kinds…
Blog

10 ways to gain control over Azure function app sites

  Pen-testers! Red-teamers! We’ve prepared a bucket of new Azure techniques, specifically about Azure function app sites. In this blog,…
Blog

Choosing Attack Path Management Over Security Control Validation When Shopping for Breach & Attack Simulation

Breach and Attack Simulation is gaining lots of hype today. Yet simulating attacks can mean many different things and serve…
Blog

Go Beyond Log4Shell and See the Entire Attack Path

We understand the facts: The most common open-source library (Java) has already been identified with 3 CVEs and counting, with…
Blog

Attack Path vs Attack Vector: Important Differences You Need To Know

If you want to solve a problem, defining your terms is essential — and there are few more pressing problems…
Blog
Top 3 Benefits of Ransomware Readiness Assessment

Top 3 Benefits of Ransomware Readiness Assessment

After so many recent high-profile ransomware attacks, CISOs, SOC Managers and other cybersecurity leaders are certainly aware of the risks…
Blog
1 11 12 13 14 15 30

Request a demo

See what attackers see, so you can stop them from doing what attackers do.