Resources

Microsoft Office
Zero-Day Vulnerability, CVE-2026-21509, Under Active Exploitation

Overview On January 26, 2026, Microsoft issued emergency out-of-band security patches for a high-severity security feature bypass vulnerability in Microsoft…
Blog

The Practical Path to Fixing What Matters: XM Cyber’s 2025 Milestones and What They Mean for You

The cybersecurity industry has been driven by volume for years. More alerts, more scanners, and more “critical” vulnerabilities to patch.…
Blog

Four Real-Life Financial Service Attacks Paths and How we Blocked Them

Back in the wild west, there was this guy, Willie Sutton. Willie’s chosen profession wasn’t the town dentist-barber or saloon…
Blog

Double Agent: Service Agent Privilege Escalation in Google Vertex AI

While analyzing Google’s Vertex AI, we discovered two distinct attack vectors, specifically in Ray on Vertex AI and the Vertex…
Blog

Exposure Management in Finance: A Proactive Approach to Cyber Resilience

The financial sector is perhaps the most cyber-targeted industry on the planet. It’s no secret why: financial institutions manage the…
Blog

How Thalia Turned the Page on Threat Exposures

Markus Armsruster, the Director of digitalization and IT at the CTO of Thalia, talks about how using XM Cyber helped…
Case Studies

2026, The Year Validation Wins Over Speculation

Overview As I look back at 2025, one thing that’s clear is that folks are starting to come around to…
Blog

How A Large Italian Financial Institution Prioritizes Risk and Improves Security Posture

The security team at a large Italian financial services firm was overloaded with vulnerability data. Their traditional scanners flagged issue…
Case Studies

How Save the Children Strengthens Security and Prioritizes What Matters

Save the Children operates critical programs across more than twenty countries, managing sensitive donor and beneficiary data globally. This diverse…
Case Studies

MongoBleed (CVE-2025-14847) Information Leak Vulnerability Exploited in the Wild

Overview A critical high-severity vulnerability, tracked as CVE-2025-14847 and nicknamed MongoBleed, has been disclosed in MongoDB Server and is already…
Blog

Vinci Construction Fortifies Global Security Posture and Dramatically Reduces Risk

Vinci Construction manages high-stakes infrastructure projects worldwide, including work on the Paris Metro, major highways, and airports. Operating in over…
Case Studies

Global Retail Giant Secures Rapidly Expanding Infrastructure

As a global luxury goods manufacturer, security was a top priority. But their rapid global growth, fueled by frequent acquisitions,…
Case Studies
1 4 5 6 7 8 50

See XM Cyber In Action