Webinar: Navigate the ASM Landscape with KuppingerCole’s Leadership Compass. Register now Webinar: Navigate the ASM Landscape

CyCognito Blog

Your source for exposure management research, product news, and security insights.

Search the Blog

By Jason Pappalexis

Exposure Management (EM), introduced by Gartner in 2022, represents the evolution or vulnerability management. With EM, security teams can address visibility and testing gaps, and stay ahead of threats. This blog includes six signs that your organization needs EM, and five essential requirements to implement it.

Read more about Six Signs that Exposure Management is Right for Your Organization
By Tim Matthews

With EASM becoming essential to security operations, many vendors are jumping on board, but not all solutions are enterprise-grade. Basic EASM products can waste time, undermine security teams, and offer a false sense of protection. To avoid these pitfalls, ask your vendor these five critical questions—if they can’t answer, it’s a red flag.

Read more about Five Questions Your EASM Vendor Doesn’t Want You to Ask
By Emma Zaballos

CVE-2024-7594 is a severe unrestricted authentication issue affecting HashiCorp’s Vault’s SSH secrets engine, specifically Vault Community Edition versions 1.7.7-1.17.5 and Vault Enterprise versions 1.7.7-1.17.5, as well as 1.16.9 and 1.15.14. HashiCorp has released patches for CVE-2024-7594 and organizations can mitigate vulnerable instances by setting the SSH secrets engine valid_principals field to a non-empty value. CyCognito is investigating methods to deploy to actively detect this vulnerability, but more information about this issue is available to users in the CyCognito platform.

Read more about Emerging Security Issue: HashiCorp Vault SSH CVE-2024-7594
By Emma Zaballos

CVE-2024-28987 is a critical (CVSS v3 score: 9.1) hardcoded credential vulnerability in SolarWinds Web Help Desk (WHD) software. Organizations can patch this vulnerability by upgrading to version 12.8.3 HF2. CyCognito discovery and testing engines actively detect CVE-2024-28987 and customers have access to an in-platform emerging security issue announcement as of September 29th, 2024.

Read more about Emerging Security Issue: SolarWinds Web Help Desk CVE-2024-28987
By Jason Pappalexis

Many organizations believe their security testing is robust, but common tools like vulnerability scanning and penetration testing often leave surprising gaps. Infrequent tests, limited asset coverage and inaccurate results leave exposure and risk. Achieving ideal security goals requires full coverage, high accuracy, and frequent testing—criteria most approaches struggle to deliver. CyCognito bridges these gaps with automated testing for network systems and web applications, helping organizations strengthen their security, continuously.

Read more about Think your attack surface is covered? Let’s look at the math.
By Emma Zaballos

CVE-2024-6670 is an actively exploited critical (CVSS v3 score: 9.8) SQL injection vulnerability affecting Progress Software’s WhatsUp Gold network monitoring tool. CyCognito discovery and testing engines actively detect vulnerable versions of Progress Software WhatsUp Gold and all customers have access to an in-platform emerging security issue announcement as of September 27th, 2024.

Read more about Emerging Security Issue: Progress Software WhatsUp Gold (CVE-2024-6670)
By Emma Zaballos

CyCognito just published our 2024 State of External Exposure Management Report. In this report, we looked at where serious issues hide on the average attack surface, how basic protections can help (or fail to) protect critical assets, and the ways that deprioritizing issues can help security teams spend their time on the right vulnerabilities.

Read more about Defensive Playbook: Understanding New Trends in External Risk with CyCognito’s State of External Exposure Management Report
By Jason Pappalexis

Gaps in security testing involve more than missed assets – infrequent and inaccurate security testing can be just as big. This blog provides a five-step plan to help you find testing gaps and tighten your testing program, improving risk management, decision-making, and cost efficiency. A must-read for anyone looking to strengthen their security across their external attack surface.

Read more about Common security testing approaches leave gaps. Here’s how to find them.
By Emma Zaballos

CVE-2024-40766 is a critical (CVSS v3 score: 9.3) access control flaw affecting SonicWall firewall devices that attackers are actively exploiting to deliver ransomware. CyCognito discovery and testing engines detect all assets running SonicWall SonicOS products and leverage multiple tests to services of the vulnerable product and versions. All customers have access to an in-platform emerging security issue announcement as of September 10th, 2024.

Read more about Emerging Security Issue: SonicWall SSLVPN (CVE-2024-40766)
By Ansh Patnaik

CyCognito’s new certified integration with ServiceNow’s Configuration Management Database (CMDB) enhances asset visibility and streamlines management to bolster cybersecurity defenses. By synchronizing CyCognito assets with ServiceNow Configuration Items (CIs), the integration ensures that the CMDB remains current, enabling quicker assessment and response to potential threats. This integration is particularly valuable for organizations aiming to standardize asset management and security operations on the ServiceNow platform.

Read more about Optimizing Asset Management and Incident Response: CyCognito’s New Integration with ServiceNow CMDB