Unrestricted local administrator rights represent a critical vulnerability, granting users dangerous control that threat actors frequently exploit to bypass security and move laterally across networks. This whitepaper details a strategic path to eliminating these excessive privileges without creating user friction or stalling productivity.
By l...
Sidewinder represents a significant redesign of Assail's Ares platform, moving from a script-following scanner to a system that plans its own security engagements.
Interview with Adriel Desautels - the pentest is broken. Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: https://hbr.org/2026/04/boards-are-falling-short-on-cybersecurity , https://www.scworld.com/perspective/how...
Modern enterprises face expanding digital footprints and unseen risk. This session explores how CISOs are operationalizing attack surface management to stay ahead of exposure through discovery, validation, and prioritization.
Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the vulnerabilities that matter, the ones that are actually exploitable in production. This conversation explores why automated testin...
Your attack surface is bigger, and more unknown than you think. Learn how modern environments (cloud, SaaS, identity) are reshaping risk, and how to prioritize what actually matters. Thank you to our sponsor for this webcast, Axonius! If you don’t know what assets you have, you don’t know your risk. Learn how to fix it at https://scworld.com/webcas...
Red team exercises set goals to see if a particular outcome can be accomplished through a simulated attack, but the ultimate outcome should be educating the org about how to improve tools and processes that make attacks more difficult to succeed. Gwyddon "Data" Owen shares his experience building a red team, creating an exercise, and leveraging the...
In this segment, we will explore some pretty awesome tools for scanning the Internet, with a focus on network edge devices. We'll bring it all together with Claude Code and look at some sample results. Tools include: Shodan | Passive recon — query existing scan data for exposed devices, services, and vulns | Passive (API) | Instant (no packets sent...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.