Resources

The Identity Attack Surface: A Practical Security Checklist

Audit configuration drift, manage non-human identities, and close hidden lateral movement paths.
Checklists

7 Mistakes to Avoid With Identity and Access Security

Identity and access security is a complex landscape that is a vital part of every organization’s security program. Here are…
Checklists

The VM Category Shift: XM Cyber Wins SC Awards Europe 2026 Best Vulnerability Management Solution

The vulnerability management category has shifted. For three consecutive years, Qualys won SC Awards Europe Best Vulnerability Management Solution. This…
Blog

Identity Is the Highway. Here’s How Attackers Use It.

In the modern enterprise, the perimeter hasn’t just shifted, it has dissolved. As organizations accelerate their digital transformation, traditional boundaries…
Blog

Initial Reactions and Key Takeaways from the 2026 Gartner Security and Risk Summit

Last week, the XM Cyber team had the pleasure of attending the annual Gartner Security and Risk Summit at the…
Blog

The Identity Conundrum: Enforcing Least Privilege Access At Scale

Overview In the modern cybersecurity landscape identity isn’t a perimeter, it’s a highway. As organizations scale, that highway gets longer,…
Blog

Your CVE Count Is a Meaningless Metric

Overview I’ve sat in a lot of vulnerability reviews where the team felt good about the numbers. Closed tickets for…
Blog

NGINX Rift Chain (CVE-2026-42945): Remote Code Execution (RCE) Discovered Leveraging 18-Year-Old Vulnerabilities

Overview On May 13, 2026, researchers disclosed “NGINX Rift,” a critical vulnerability chain discovered by DepthFirst AI. The chain consists…
Blog

Contextualizing SOC Alerts with Exposure Intelligence

Overview Security Operations Centers (SOCs) are on the front lines of a lopsided battle. They are navigating an overwhelming volume…
Blog

Digital Risk Assessment for Your M&A Growth Strategy

Continuous Exposure Management for Mergers and Acquisitions.
Solution Briefs

From Hunting Context to Hunting Threats: Using Exposure Intelligence to Accelerate SOC Investigations

Overview In many organizations, SOC teams spend more time digging for context than actually hunting for or responding to threats.…
Blog

Linux Kernel “Dirty Frag” Local Privilege Escalation (LPE), CVE-2026-43284 & CVE-2026-43500

Overview On May 8, 2026, cybersecurity researchers disclosed a critical vulnerability chain in the Linux kernel, nicknamed “Dirty Frag.” Tracked…
Blog
1 2 3 4 50

See XM Cyber In Action