Articles

Practical external security, explained.

Comparisons, how-tos and plain-language explainers on attack surface monitoring, TLS, DNS and the other things the outside world can see about your infrastructure. Plus security news: recent incidents, read for what they mean for the domains you run, and vulnerability news: newly exploited flaws in internet-facing products, with affected and fixed versions.

What's New in Attack Surface Scan: Exploited-Vulnerability Matching, Asset Inventory, Compliance Views and More

Everything added to Attack Surface Scan in September 2026: CVE matching ranked by CISA KEV and EPSS, 123-port exposure checks, an asset inventory, domain hygiene, website privacy checks, framework views, Teams, PagerDuty and Jira alerts, and a REST API.

Read article →

Routing Attack Surface Alerts Into Microsoft Teams, PagerDuty, Jira and Your SIEM

How to route external attack surface alerts into Microsoft Teams Workflows, PagerDuty Events API v2, Jira Automation and a SIEM via OCSF webhooks, and which changes deserve a page versus a digest.

Read article →

Website Privacy Checks for GDPR: Forms Over HTTP, Mixed Content, Unchecked Scripts and Cookies Before Consent

Four website privacy problems you can check from outside: personal-data forms over HTTP, mixed content, third-party scripts without SRI (PCI DSS 4.0 6.4.3) and tracking cookies set before consent.

Read article →

Registrar Locks, DNSSEC and security.txt: A Domain Hygiene Checklist

A practical domain security checklist: EPP transfer, update and delete locks, registry lock, DNSSEC that is missing versus broken, RFC 9116 security.txt and its Expires field.

Read article →

Prioritizing Vulnerabilities by Exploitation: CISA KEV and EPSS for Internet-Facing Assets

CVSS says how bad a flaw could be, not whether anyone is exploiting it. How to rank CVEs on internet-facing hosts with CISA KEV and EPSS, and what an external scan can and cannot see.

Read article →

Two NetScaler Zero-Days Were Exploited for Weeks Before Citrix Patched Them

Citrix disclosed eight NetScaler ADC and Gateway flaws on September 27, 2026, including two unauthenticated RCE bugs (CVE-2026-88771, CVE-2026-88772, CVSS 9.5) already exploited as zero-days. CISA added both to KEV the same day. Fixed builds and what to check.

Read article →

UpGuard Found 16,326 Supabase Databases Readable With the Key Their Own Websites Publish

UpGuard's September 25, 2026 study of about 300,000 sites using Supabase found 16,326 databases serving readable tables to anyone with the public key, more than half with signs of personal data. Why an exposure scan of your own hosts will not find this, and what will.

Read article →

Mapping External Scan Findings to OWASP Top 10, PCI DSS 4.0, CIS Controls v8 and CISA KEV

How external scan findings map to OWASP Top 10, PCI DSS 4.0, CIS Controls v8, CWE and CISA KEV, which categories an outside view can never assess, and how to hand auditors CSV and PDF evidence.

Read article →

Shadow IT and External Asset Inventory: Finding Forgotten Hosts Passively

How to find shadow IT and forgotten internet-facing hosts from public data: certificate transparency, DNS, web archives and cloud IP ranges, plus why related domains need verification.

Read article →

third-party.com Looked Like example.com for Years. It Was Never Reserved, and Now It Serves ClickFix.

Manifold Security found that third-party.com, a placeholder hostname in W3C specs, Chromium docs and over 1,700 GitHub repositories, has served a fake Cloudflare check that pushes a PowerShell payload since at least June 2026. Why every domain your code names is part of your attack surface.

Read article →

Choosing a Certificate Authority for 47-Day Certificates: The Most Reliable SSL Providers

Which SSL providers are most reliable as certificates shrink to 47 days? ACME, ARI, EAB and incident history for nine CAs, plus a two-CA fallback using CAA.

Read article →

Attack Surface Management for MSPs: A Practical Guide

Attack surface management for MSPs: onboard client domains, route alerts per client, build a monthly security report, and price it with a worked margin example.

Read article →

Microsoft Defender EASM Pricing: What It Really Costs in 2026

Microsoft Defender EASM pricing is $0.011 per billable asset per day. What counts as billable, worked costs for small to large estates, and how to cut the bill.

Read article →

Arista VeloCloud Orchestrator Zero-Day (CVSS 10.0) Exploited, and Two Release Trains Have No Fix Yet

CVE-2026-93952 in on-premises Arista VeloCloud Orchestrator (CVSS 3.1 10.0) is exploited and on CISA KEV since September 22, 2026. Fixes exist for 5.2.3 and 6.4.2 only. Affected versions, indicators and what to check.

Read article →

F5 BIG-IP APM and Check Point VPN Gateways Hit by Pre-Auth Exploits in the Same Week

On September 22, 2026 CISA added an exploited F5 BIG-IP APM zero-day (CVE-2026-94127, CVSS 9.8) and two exploited Check Point flaws (CVE-2026-85102, CVE-2026-93616) to its KEV catalog. Affected versions, fixes and what to check.

Read article →

Elsevier's Domains Pointed at a LAPSUS$ Page for Over an Hour. The Servers Were Never the Target.

On September 21, 2026 www.elsevier.com, evolve.elsevier.com and submit.elsevier.com redirected visitors to a LAPSUS$-branded extortion page for at least 78 minutes. The mechanism is unconfirmed, but it points at the DNS or CDN edge. What that means for your own domains.

Read article →

Nearly 1,000 Zyxel GS1900 Switches Hacked Through a Bug Rated "LAN Only"

CVE-2026-7273, a pre-auth stack overflow in Zyxel GS1900 switches patched in June 2026, was used to compromise 996 switches in 48 countries. CISA added it to the KEV on September 21. Affected firmware, fixes and what to check.

Read article →

A Leaked Cloudflare Key Turned Brevo's Embedded Scripts Into Malware on 100,000 Sites

On September 14, 2026 an attacker used a hardcoded Cloudflare API key to put a Worker in front of Brevo's forms, chat and SDK scripts, serving ClickFix malware to visitors of Brevo customers' websites for hours. What happened and what to check on your own pages.

Read article →

GitLab's CVSS 10 File-Read Bug Was Exploited a Day After the Patch

CVE-2026-85706 lets an unauthenticated attacker read arbitrary files from a self-managed GitLab server. GitLab patched it on September 10, 2026; CISA listed it as exploited on September 11. Versions, fixes and what to check.

Read article →

Cisco Firewall Management Center and FortiGate Firewalls Exploited: Two Old Patches Become Three-Day Deadlines

On September 9, 2026 CISA added Cisco Secure FMC CVE-2026-20079 (CVSS 10.0) and Fortinet FortiOS CVE-2025-25249 to its KEV catalog. Both were patched months ago and are now exploited. Affected and fixed versions, and what to check.

Read article →

Citrix NetScaler Auth Bypass CVE-2026-19490 Is Now Exploited. CISA Gave Agencies Three Days.

CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway, was added to CISA's KEV catalog on September 9, 2026 after exploitation attempts began. Affected builds, fixed builds and how to check your exposure.

Read article →

N-able N-central Pre-Auth RCE Exploited on Fully Patched Servers. Hotfix 3 Is Not Enough.

CVE-2026-86218 is an exploited pre-authentication RCE in N-able N-central before 2026.3.1.14 (CVSS 4.0 10.0). CISA added it to the KEV on September 8, 2026. What happened, which hotfix you need, and how to check exposure.

Read article →

StyleSmuggler: Unauthenticated RCE in Magento and Adobe Commerce Was Exploited Three Days Before the Patch

CVE-2026-75650 (StyleSmuggler, CVSS 10.0) gives unauthenticated remote code execution on Adobe Commerce and Magento Open Source 2.4.4 to 2.4.9. Exploited from September 4, patched September 7, added to CISA KEV September 8. Versions, hotfix and what to check.

Read article →

Microsoft 365 Was Down for 67 Hours. Admins Traced It to an Expired Certificate.

From August 31 to September 3, 2026, Exchange Online, Teams and SharePoint failed worldwide. Microsoft blamed a core authentication configuration; admins saw an expired certificate thumbprint in the errors. What to check on your own domains.

Read article →

Attack Surface Scan vs. Cert Spotter: Certificate Monitoring Compared

Cert Spotter and Attack Surface Scan both watch certificate transparency and the certificate each host serves. Where they match, where Cert Spotter is ahead, where Attack Surface Scan goes further, and how the two price.

Read article →

CISA Adds Seven Exploited Flaws in One Day. Two Score a Perfect 10, All Sit on Internet-Facing Software.

On September 2, 2026 CISA added seven actively exploited CVEs to its KEV catalog, including a CVSS 10 SonicWall SMA 1000 flaw and a CVSS 10 Kestra bug. Under BOD 26-04, publicly exposed assets get three days. How to know what you expose.

Read article →

One in Five New Domain Registrations Is Someone's Expired Domain, and Criminals Are Paying Millions for Them

Infoblox Threat Intel found about 65,000 expired domains re-registered every day in the first half of 2026, and one actor, Sable Squirrel, holding 10,000 of them for malware C2, gambling and piracy. Why your lapsed domains are an attack surface.

Read article →

AWS Defaults Leave Your Attack Surface Exposed: What CloudFront + S3 Ships Without

A default CloudFront + S3 deployment ships with no HSTS, no CSP, no clickjacking protection and a Server header that names your stack. What an external scan finds, and the one policy that fixes most of it.

Read article →

The Best DMARC Monitoring Tools in 2026 (Free and Paid)

The best DMARC monitoring tools compared: free analyzers from Postmark and Cloudflare, paid platforms like dmarcian and EasyDMARC, and open source parsedmarc.

Read article →

The Best SSL Certificate Monitoring Tools in 2026

The best SSL certificate monitoring tools compared: free options, open source (Zabbix, blackbox_exporter), dedicated monitors and enterprise CLM platforms.

Read article →

Open Source Attack Surface Management: The 9 Best Tools in 2026

Open source attack surface management in 2026: the 9 best free EASM tools (Amass, Subfinder, httpx, nuclei, OpenVAS and more), what each does and how to chain them.

Read article →

What Does Attack Surface Management Actually Cost in 2026?

Attack surface management pricing in 2026: the four models, real ranges from $25/month to six figures, the costs vendors leave out, and how to size a budget.

Read article →

47-Day TLS Certificates: The Schedule, and How to Be Ready

TLS certificate lifetimes drop to 100 days in 2027 and 47 in 2029. The CA/Browser Forum schedule, why it is happening, and what breaks if you renew by hand.

Read article →

EASM vs. CAASM vs. CSPM: The Acronyms, Untangled

EASM looks inward from the internet, CAASM aggregates the tools you already run, and CSPM audits cloud config. What each acronym means and which one you need.

Read article →

The Gap in Your Compliance Stack Is the Part the Internet Can See

MDM, CSPM and vulnerability scanners only watch assets someone enrolled. Breaches start at the ones nobody did. Why the stack is inside-out, and what fixes it.

Read article →

Attack Surface Scan vs. OpenVAS: Vulnerability Scanner or External Monitor?

OpenVAS is a free self-hosted vulnerability scanner; Attack Surface Scan is a hosted external monitor. What each does, the real cost of self-hosting, and when to run both.

Read article →

Hand Your Security Findings to a Coding Agent: Claude Code, Codex and opencode

Most scan findings are config changes in a repo, exactly what coding agents do well. How to hand a security report to Claude Code, Codex or opencode.

Read article →

Turning External Monitoring Into SOC 2 and ISO 27001 Evidence

SOC 2 CC7.1 and ISO 27001 Annex A 8.8 expect monitoring you can prove. What scan history maps to which control, what auditors sample, and what it misses.

Read article →

The Best Attack Surface Management Tools in 2026, Compared

Attack surface management tools compared for 2026: Attack Surface Scan, Detectify, Intruder, Censys and Microsoft Defender EASM, ranked by team size and budget.

Read article →

Attack Surface Scan vs. Detectify: Which External Security Monitor Fits Your Team?

Attack Surface Scan vs. Detectify for external attack surface monitoring: what each product checks, how the two price, and which kind of team each one actually fits.

Read article →

Attack Surface Scan vs. Intruder: Vulnerability Scanning or Attack Surface Monitoring?

Intruder is a vulnerability scanner with attack surface features; Attack Surface Scan is a passive external monitor with change detection. How to decide which one you need.

Read article →

Attack Surface Scan vs. Shodan and Censys: Search Engines Aren't Monitoring

Shodan and Censys index the whole internet; Attack Surface Scan monitors the domains you own. Where they overlap, and why searching yourself is not monitoring.

Read article →

Which HTTP Security Headers Actually Matter in 2026 (and How to Set Them)

The HTTP security headers worth setting in 2026: HSTS, Content-Security-Policy, nosniff, Referrer-Policy and cookie flags, with copy-paste starting values.

Read article →

SSL Labs vs. SecurityHeaders.com vs. Mozilla Observatory: Free Scanners Compared

The best free website security scanners compared: SSL Labs, securityheaders.com, Mozilla Observatory, MXToolbox and Hardenize. What each grades and misses.

Read article →

As of June 15, Every Public TLS Certificate Goes Into a Transparency Log. Your Hostnames Are Now Public.

Chrome Root Program Policy v1.8 requires every CA to log every TLS precertificate and certificate to Certificate Transparency from June 15, 2026. DigiCert enforced it June 1. The opt-out is gone: what that exposes, and how to use it.

Read article →

What Is a Subdomain Takeover? How a Dangling CNAME Becomes Someone Else's Website

What is a subdomain takeover? A dangling CNAME points at a service anyone can claim. How the attack works, how to check for it, and how to stop it.

Read article →

How to Monitor SSL/TLS Certificate Expiry (Before Your Users Do)

SSL certificate expiration monitoring explained: how expiry outages happen, how to monitor certificate expiry for free, and what a good setup should alert on.

Read article →

SPF, DKIM and DMARC Explained: Stop Other People Sending Email as You

What SPF, DKIM and DMARC each do, how the three records fit together, the mistakes that silently break them, and how to reach a DMARC reject policy safely.

Read article →

Let's Encrypt Stopped Issuing for Two and a Half Hours. Did Your Renewals Notice?

On May 8, 2026 Let's Encrypt halted all issuance for about 2.5 hours after its new Generation Y cross-signed intermediates shipped without the serverAuth EKU. Renewals failed with serverInternal. What a quiet renewal failure looks like on your side.

Read article →

What Is External Attack Surface Management (EASM)? A Plain-English Guide

External attack surface management (EASM) is the continuous discovery of everything you expose to the internet. What it covers and how it differs from scanning.

Read article →

CoW Swap Lost $1.2 Million to a Domain Hijack That Never Touched Its Servers

On April 14, 2026 attackers took over cow.fi through the .fi registration process using forged identity documents, pointed swap.cow.fi at a wallet-draining clone and stole about $1.2M. Backend untouched. What the DNS and certificate signals looked like.

Read article →

Microsoft: Phishing Crews Are Spoofing Domains That Have DMARC, Through Gaps in Mail Routing

Microsoft's January 6, 2026 report shows Tycoon2FA phishing campaigns sending mail as an organization's own domain and getting through despite SPF and DMARC, because third-party routing broke enforcement. Microsoft blocked 13M such emails in one month.

Read article →