XM Cyber Attack Path Management
- It took $58 to break Microsoft’s SCCM, but a patch made it harderby keren.farin@xmcyber.com on August 18, 2026 at 8:10 am
One of the vulnerabilities in a newly disclosed SCCM exploit chain was patched by Microsoft but the fix, allegedly, does not close the path… The post It took $58 to break Microsoft’s SCCM, but a patch made it harder appeared first on XM Cyber.
- The Brain Behind the Muscle: Why AI Automation Fails Without Unified Exposure Contextby keren.farin@xmcyber.com on August 17, 2026 at 11:34 am
The problem with traditional vulnerability and risk management programs hasn’t been discovery, and that’s to take nothing away from the groundbreaking frontier models that… The post The Brain Behind the Muscle: Why AI Automation Fails Without Unified Exposure Context appeared first on XM Cyber.
- How Hamburg Port Authority Secures its Vast IT Infrastructureby keren.farin@xmcyber.com on August 17, 2026 at 9:54 am
Hamburg Port Authority‘s its existing security controls were lacking. XM Cyber’s initial scan turned up unsecured databases on developer machines, write access to shared… The post How Hamburg Port Authority Secures its Vast IT Infrastructure appeared first on XM Cyber.
- How Bizerba Strengthens Digital Sovereignty with Continuous Exposure Managementby keren.farin@xmcyber.com on August 17, 2026 at 9:52 am
Bizerba is a global German technology company known for its weighing and production systems. After a cyberattack brought production to a halt worldwide, Bizerba… The post How Bizerba Strengthens Digital Sovereignty with Continuous Exposure Management appeared first on XM Cyber.
- How Sana Kliniken Protects Patient Trust with Continuous Exposure Managementby keren.farin@xmcyber.com on August 17, 2026 at 9:49 am
Sana Kliniken is one of Germany’s largest healthcare providers, with a nationwide network of clinics, outpatient facilities, and health services. XM Cyber runs around… The post How Sana Kliniken Protects Patient Trust with Continuous Exposure Management appeared first on XM Cyber.
- How Jeremias Strengthens Security and Focuses Remediation Across Global Operationsby keren.farin@xmcyber.com on August 17, 2026 at 9:47 am
Jeremias is a leading German manufacturer of flue, exhaust, and chimney systems, with production facilities and sales operations across Europe and the US. XM… The post How Jeremias Strengthens Security and Focuses Remediation Across Global Operations appeared first on XM Cyber.
- Potential for Remote Code Execution in Microsoft SCCM via Newly-Discovered Exploit Chainby keren.farin@xmcyber.com on August 13, 2026 at 12:01 pm
Security researchers from XM Cyber have recently discovered a series of vulnerabilities in Microsoft System Center Configuration Management (SCCM) that could be chained together… The post Potential for Remote Code Execution in Microsoft SCCM via Newly-Discovered Exploit Chain appeared first on XM Cyber.
- The Mobilization Trap: Why Remediation Stalls and How to Fix Itby keren.farin@xmcyber.com on August 13, 2026 at 11:11 am
Most exposure management programs have no problem discovering and prioritizing findings. Where they consistently break down is at the mobilization stage – getting validated… The post The Mobilization Trap: Why Remediation Stalls and How to Fix It appeared first on XM Cyber.
- Shift Left and Hunt Deep: Announcing Automated Exposure Discovery Engines for macOS XPC and Oracle Cloud IAMby abi.gittler@xmcyber.com on July 30, 2026 at 12:51 pm
As enterprise infrastructure expands across hybrid environments—ranging from the local macOS endpoints used by developers to massive distributed environments in the cloud—the attack surface… The post Shift Left and Hunt Deep: Announcing Automated Exposure Discovery Engines for macOS XPC and Oracle Cloud IAM appeared first on XM Cyber.
- OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentialsby keren.farin@xmcyber.com on July 16, 2026 at 9:42 am
At least two threat actors have weaponized a novel evasion technique called OAuth client ID spoofing in multiple cloud campaigns. The post OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentials appeared first on XM Cyber.








