Opens in a new tab
The Attack Path Tour

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-20079

CVE-2026-20079 is a critical Cisco FMC authentication bypass vulnerability enabling remote attackers to gain root access. Learn how to validate and remediate exposure.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-20127

CVE-2026-20127 is a critical authentication bypass in Cisco Catalyst SD-WAN that allows remote attackers to gain administrative access to network infrastructure. Learn how to detect exposure and validate remediation using NodeZero Rapid Response.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

Filter - Checkbox

TAGS

Filter - Checkbox

SEARCH

Filter - Checkbox
Filter - Checkbox

    From Noise to Proof: Reinventing Vulnerability Management with NodeZero®

    Vulnerability management wasn’t designed to deal with real attackers. That’s the problem. Most programs drown in scan data, chase vulnerabilities with high CVSS scores with no context, and still can't answer a simple question: Are we exposed? This isn’t just another dashboard. You’ll see how NodeZero: If you're tired of measuring risk with guesswork, this…

    How to Run NodeZero® vs. GOAD

    GOAD (Game Of Active Directory) is an intentionally vulnerable cyber range used by pentesters and defenders to explore common attack techniques in a Windows Active Directory environment. It's chock full of real-world misconfigurations and vulnerabilites, the type we see all the time in client environments. As such, it's a great way to understand the capabilities…

    Lessons Learned from 100k Pentests with Carahsoft

    Combating Modern Cybersecurity Challenges with Offensive Security Principles Despite global cybersecurity spending projected to reach $212 billion in 2025, 84% of organizations still experienced breaches in the past year. This disconnect between investment and outcomes reveals fundamental flaws in traditional defensive approaches. Drawing from insights gained through over 100,000 autonomous penetration tests conducted across diverse…

    From Support Ticket to Zero Day

    August 13, 2025
    Examining a Critical Vulnerability in Xerox FreeFlow Core

    CVE-2025-8356

    August 11, 2025
    Xerox FreeFlow Core Remote Code Execution Vulnerability

    Supercharge Enterprise AI with the Attacker’s Perspective: Introducing the NodeZero® MCP Server

    Enterprises are racing to harness AI to automate workflows, secure infrastructure, and accelerate decision-making. But here’s the uncomfortable truth: AI that doesn’t see your environment through an attacker’s eyes is operating blind.

    Securing the NodeZero® MCP Server: Building a Safe, Agent-Ready Runtime for Enterprises

    When we set out to build the first version of the NodeZero MCP Server, we had two guiding principles: Most Model Context Protocol (MCP) servers today are overpowered and underdefended. They often: We didn’t build ours that way. The NodeZero MCP Server is a constrained, API-native runtime designed to give agents safe, structured access to…

    Fix What Matters Most: Six New NodeZero® Capabilities That Redefine Risk-Based Vulnerability Management

    Vulnerability management started with scanning — identify assets, fingerprint software, and match scan findings to known CVEs. Then came “risk-based” approaches that promised smarter prioritization. But in practice, most programs still just patch what scores the highest. Risk is inferred, not proven. Fixes are assumed to work. And security teams are left guessing what actually…

    Proof, Not Promises: Redefining Cybersecurity for the Defense Industrial Base

    The Defense Industrial Base (DIB) is the backbone of national security—and is a high-value target for advanced cyber adversaries exploiting weaknesses across the supply chain. In this joint keynote, Snehal Antani, CEO of Horizon3 and special guest Bailey Bickley, Chief of DIB Defense at the NSA Cybersecurity Collaboration Center reveal how the NSA’s Continuous Autonomous…

    CVE-2025-54309

    August 1, 2025
    CrushFTP Authentication Bypass Vulnerability