Boston, MA, USA
2011
  |  By Emma Stevens
Imagine waking up Monday morning to discover you’ve been breached. The attacker has stolen sensitive financial data, set up persistent access, and then greets you with a lovely ransom note at 8:00 a.m. demanding money in exchange for the encryption key. Immediately, you reach out to your security operations team, and they quickly begin assessing the damage and reviewing the breadcrumbs left behind.
  |  By Naomi Yusupov
A vendor can pass every questionnaire you send it and still be the reason you end up in a breach report. That's the gap most third-party risk programs live in today. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches now involve a third party, up from 30% the year before and 15% the year before that. But most organizations still manage that risk with periodic assessments and separate threat feeds. Those methods can tell you whether a supplier passed a review last quarter.
  |  By Emma Stevens
Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that are already being exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to run commands on an affected appliance, while CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is turned on. Both received a CVSS v4.0 score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog.
  |  By Emma Stevens
It’s not a secret that phishing, stolen credentials, and human error remain some of the easiest ways for attackers to get into an environment. Identity has become one of the biggest attack surfaces for organizations today because sometimes, all an attacker needs to do is log in. That access can come from valid credentials, stolen sessions, exposed tokens, compromised service accounts, or abused application permissions.
  |  By Emma Stevens
When Anthropic introduced Mythos Preview, the story practically wrote itself. Here was a frontier AI model taking work that once required researchers and threat actors a lot of time and compressing it into hours. Mythos demonstrated the ability to find and exploit vulnerabilities across major operating systems and browsers. In controlled testing, it produced a working Firefox code-execution exploit in less than an hour and developed eight in roughly 12 hours.
  |  By Emma Stevens
Cisco has disclosed a critical authentication bypass affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2026-76460, the vulnerability allows an unauthenticated, remote attacker to send a crafted request to an affected API endpoint and bypass the web-based management interface. The vulnerability received the highest possible CVSS v3.1 score of 10.0.
  |  By Greg Keshian
When a new CVE drops, getting notified is the easy part. The real challenge comes right after. Depending on how your organization is set up, different teams have to scramble to figure out if you're actually using the affected product, which specific versions are exposed, whether it's lurking anywhere in your subsidiaries or vendor ecosystem, and how urgently you need to patch it.
  |  By Emma Stevens
Security teams rarely work from a single rulebook. They may use the NIST Cybersecurity Framework to organize the program, ISO/IEC 27001 to build a formal management system, SOC 2 reports to assess vendors, and laws such as HIPAA, GDPR, DORA, or NIS2 to meet legal obligations. Those names are often grouped together, even though they serve different purposes. Some provide guidance. Some can be certified or independently assessed. Others are contractual requirements, laws, or mandatory sector standards.
  |  By Emma Stevens
The tricky thing about AI compliance is that most organizations are going to experience it from both sides. You need to be able to explain how AI is being used inside your own organization, what it can access, and how you're managing the risk. At the same time, you need to understand how your vendors are using AI and whether that introduces new risk into your environment.
  |  By Emma Stevens
In our previous “ABC’s of ‘ishing” posts, we explored how attackers use social media, calendar invites, fake CAPTCHA challenges, and other trusted tools to deceive users. This next installment looks at three phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, and email phishing.
  |  By Bitsight
Frontier AI can shrink weeks of vulnerability research into exploitation in hours. What does that mean for the flaws your team deprioritized years ago? Bitsight’s Emma Stevens, Senior Threat Intelligence Advisor, breaks it down in the first video of our new series.
  |  By Bitsight
  |  By Bitsight
Cyberattacks take shape long before a breach through exposed systems, vulnerable software, stolen credentials, underground tools, and attacker experimentation. In this webinar, Emma Stevens, Threat Intelligence Researcher at Bitsight, and Qionglu Lei, Senior Product Marketing Manager at Bitsight, explore what Bitsight research reveals about AI-enabled attacker behavior and the changing cyber underground.
  |  By Bitsight
When AI can map your attack surface faster than you can, the question shifts from "can we patch everything" to "what do we fix first." Here is how to make that call defensibly, across your own environment and your supply chain.
  |  By Bitsight
Advanced AI models are changing the cyber threat landscape by accelerating vulnerability discovery, exploit development, and attacker decision-making. Regulators like the ECB have made clear: action plans are necessary. Financial institutions need to understand whether their existing cyber risk programs can keep pace, not only across their own attack surface, but across the critical third parties and software dependencies they rely on.
  |  By Bitsight
What to expect? This webinar.
  |  By Bitsight
More data does not always mean better decisions. For TPRM teams, the value comes from actionable, correlated intelligence that helps identify which risks need attention first. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi of TPRA and Vanessa Jankowski of Bitsight discuss how threat context can help organizations prioritize third-party risk, strengthen supply chain resilience, and support business continuity under pressure.
  |  By Bitsight
Third-party risk doesn’t wait for annual reviews. Vendor ecosystems change constantly, and risk teams need visibility that keeps pace. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi, CEO and Co-Founder of TPRA, and Vanessa Jankowski, SVP and GM of Bitsight’s TPRM solution, explore why continuous monitoring and real-time visibility are critical for stronger accountability, faster response, and better resilience across the vendor ecosystem.
  |  By Bitsight
Not every vendor risk deserves the same level of attention. The real challenge is knowing which risks matter most to the business. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi of TPRA and Vanessa Jankowski of Bitsight discuss why business context is becoming the new filter for prioritizing third-party risk — helping teams focus on continuity, revenue protection, and the vendors that truly impact operations.
  |  By Bitsight
Third-party risk management can’t stop at static vendor lists. In today’s interconnected business environment, organizations need to understand the dependencies behind their vendors — including subcontractors, fourth parties, and concentration risks that can affect operational resilience. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi, CEO and Co-Founder of TPRA, and Vanessa Jankowski, SVP and GM of Bitsight’s TPRM solution, discuss why stronger Nth-party visibility is essential for modern third-party risk programs.
  |  By BitSight
Cybersecurity ROI isn't about cost savings. It's about how your cybersecurity program helps you achieve your goals while managing risk to a level that your executive team is comfortable with. So if you shouldn't measure success in cost savings, how do you measure it? BitSight is providing five steps that help CISOs and executive teams evaluate their company's cybersecurity performance.
  |  By BitSight
Are you overwhelmed by the intricacies of your attack surface? Concerned about the rising risk of vulnerabilities in your and your partners' digital ecosystems? New BitSight research finds that the average vulnerability remediation rate across organizations is about 5 percent per month, sparking concern that the status quo of exposure and vulnerability management is broken. Moreover, organizations face significant challenges in managing vulnerabilities in their extended, third-party ecosystem, and most security leaders do not have the tools to address these emerging threats.
  |  By BitSight
Traditional vendor risk management programs are not effective at mitigating risk in ever-expanding third-party networks, and yet 69% of businesses still rely on manual processes. It's time to take your program to the next level. How can you centralize, automate, and streamline your process to manage hundreds of vendors as effectively as you manage ten? Scalable VRM continuously detects, monitors, and mitigates risk, going beyond due diligence and initial assessments to constantly reassess and proactively act on vendor risk.
  |  By BitSight
Stop reacting to cyber risk as it comes. BitSight for Security Performance Management empowers security leaders to strengthen cyber resilience over time with objective, meaningful, and evidence-based metrics. Gain insights, drive decisions, and build confidence with our suite of advanced analytics.

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Global enterprises, governments, and organizations rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. When unrelenting market pressure pushes organizations to uncertainty and caution, they turn to Bitsight to confidently navigate cyber risk and grow with confidence.

Bitsight's universally recognized risk standard and market-leading data provides actionable insights into how companies set and manage to standards and report results to internal and external stakeholders. Built on over a decade of technological innovation, Bitsight's integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance, and data analysis.

Bitsight is on a mission to free the global economy from the material impact of cyber incidents.