San Jose, CA, USA
2000
  |  By Massimiliano Mandolini
Here are three examples that are worth your attention. Oh, what could have been avoided.
  |  By Vincent Saporito
Over the past three years, the second Tuesday of each month has turned into a hectic period of planning and remediation, driven by a 25% average annual growth rate in CVEs. Just last Tuesday, Microsoft revealed a critical TCP/IP remote code execution (RCE) vulnerability in the IPv6 stack, which has a CVSS score of 9.8 due to its criticality and ease of exploitation. For a more in-depth look, we recommend these resources.
  |  By Rik Ferguson
In a never-ending effort to do their job and secure their environments, cybersecurity teams often bear the brunt of negative perceptions, labelled as the department of ‘No.’ “No” to admin privileges, “No” to personal devices, and “No” to connecting unapproved technologies. These repeated denials, although done with the best intentions, can stifle innovation and create frustration within organizations. This perception needs to change.
  |  By Don Sears
This week, the National Institute for Standards and Technology (NIST) released “Implementing a Zero Trust Architecture (NIST SP 1800-35)” for public comment. The guide is written by NIST’s National Cybersecurity Center of Excellence (NCCoE) in collaboration with 24 cybersecurity companies. Now in its fourth draft, NCCoE has opened up comments for this Zero Trust Architecture (ZTA) guide through Sept. 30, 2024, as part of a 60-day review cycle.
  |  By Forescout Research - Vedere Labs
The current state of OT/IOT security is being repainted with a new coat of risk. The shade of color? Cellular routers and the vulnerabilities within firmware. In our new report with Finite State, our joint research explores the risks organizations face within the software supply chains of OT/IoT routers. Hardware has firmware – operational software – within its memory components.
  |  By Forescout Research - Vedere Labs
In the last few weeks, there have been a few announcements made about a new malware threat known as FrostyGoop or BUSTLEBERM (as it was originally tracked by Mandiant). It is being recognized as the first custom malware to integrate Modbus for the purpose of causing physical damage. An associated incident has been reported where the malware was used to disrupt heating in Ukrainian homes in the context of a Russian cyberattack.
  |  By Daniel dos Santos
Ransomware risk is top of mind for citizens and CISOs alike. From the board room to the room known as the ‘SOC’, everyone is feeling the pain of disruption. Being locked out of a system and forced back to pen and paper is shocking to our working lives. Too often, it is delaying a much-needed surgery or forcing manual intervention where a digital avenue was easy and efficient. But the effects of ransomware don’t appear to be going anywhere soon.
  |  By Michael Bacon
No one feels the pain of ransomware and other disruptive and costly digital cybersecurity attacks more than the people managing the day-to-day in your SOC (Security Operations Center). At 13 attacks every second in 2023, cybercriminals, fraudsters and nation-state hacktivists are overwhelming SOC analysts. Nearly two-thirds (63%) of SOC analysts report the size of the attack surface has increased. At the same time, CISOs and SOC managers are struggling to handle on-the-job analyst burnout and turnover.
  |  By Forescout Research - Vedere Labs
Wipers are malware that delete data on a device or make it inaccessible. They can be used for sabotage, to destroy evidence of an attack or simply to make a device unusable. IoT wipers often rewrite important parts of the firmware of an IoT device, rendering that device useless, so they are also known as “brickers”. Recent notorious examples of IoT wipers are AcidRain which was used by a Russian APT to brick satellite modems in Europe at the outset of the Russian invasion of Ukraine in 2022.
  |  By Rhonda Holloway
Network Access Control (NAC) has undergone significant advancements since the beginning, continuously adapting for cybersecurity threats and technological innovation. As organizations embrace BYOD (Bring Your Own Device) and IoT/OT (Internet of Things/Operational Technology), vendors have transformed traditional NAC solutions to meet these new demands while maintaining a balance between usability and security.
  |  By Forescout Technologies
How do security leaders separate legitimate AI security concerns from fear, uncertainty, and doubt? In this clip, Rik Ferguson explains why today's warnings about autonomous threats are different from past predictions. The evidence is already being documented, tested, and observed across the cybersecurity industry, making this a present challenge rather than a future possibility.
  |  By Forescout Technologies
For more than a decade, security strategies have been shaped by the principle of "assume breach." But what if the next evolution of cybersecurity requires a different assumption? In this clip, Rik Ferguson discusses why organizations should begin building and testing security architectures based on the expectation that attackers will increasingly be autonomous and non-human, and why defenses must evolve accordingly.
  |  By Forescout Technologies
Organizations have spent years investing in visibility tools. So why do blind spots remain? In this clip, David Clapp explains how unmanaged, unscannable, and sensitive assets can fall outside the reach of traditional security approaches, leaving organizations with an incomplete picture of risk.
  |  By Forescout Technologies
A device appears. It moves. Its behavior changes. If security teams learn about it days later, the opportunity to respond may already be gone. David Clapp explains why instant discovery is critical in today's threat landscape.
  |  By Forescout Technologies
Knowing a device exists is only the first step. In this clip, David Clapp explains why effective risk management requires more than asset inventory. Factors like device type, ownership, business role, network location, communication patterns, and reachability all contribute to understanding risk and making informed security decisions.
  |  By Forescout Technologies
Security teams often invest in more dashboards, more alerts, and more visibility. But when does visibility become noise? In this clip, David Clapp explains why security improvements come from actionability, not just awareness, and how organizations can close the gap between findings and decisions.
  |  By Forescout Technologies
Cyber threats continue to evolve, and the first half of 2026 delivered no shortage of new challenges. Forescout Research – Vedere Labs' 2026 H1 Threat Review examines the latest trends in vulnerabilities, ransomware, threat actor activity, supply chain security, and AI-driven attacks. Discover the key findings, emerging attack patterns, and practical recommendations security teams can use to better understand and reduce risk.
  |  By Forescout Technologies
Visibility tells you an asset exists. Security requires knowing what it is, what it can reach, how it behaves, and what controls can be applied. In this clip, David Clapp explains why the gap between visibility and action remains one of cybersecurity's biggest challenges.
  |  By Forescout Technologies
How do you get users access to critical systems without exposing your network? Secure remote access. In this episode of Forefront, Todd Berthcume, senior manager of technical marketing engineering, shows how to use an SRA Manager.
  |  By Forescout Technologies
Cybersecurity teams have faced major shifts before—from advanced persistent threats to ransomware. Now, Frontier AI is accelerating vulnerability discovery and creating new challenges for defenders. In this episode of Let's Talk Security, Forescout CEO Barry Mainz sits down with cybersecurity evangelist and former practitioner Karsten Abata to discuss the concept of the "Control Gap"—the time between identifying a risk and having the controls in place to effectively contain it.
  |  By Forescout
The IT landscape is rapidly evolving to meet the demands of our digitally transforming world and a radically changed business environment that calls for always-on performance and agility at scale. As a result, client-server computing has given way to disruptive IT architectures that reshape business and ownership models. These include private and public cloud services, 'bring your own device' (BYOD), mobility and the Internet of Things (IoT).
  |  By Forescout
They are designed to secure the assets of these essential services. There are 11 standards in total, covering everything from the protection of critical cyber assets to security management, personnel & training, incident reporting, and recovery planning. In this free eBook we explore how the continuous network monitoring capabilities of eyeInspect can streamline your compliance with these NERC CIP standards, saving you considerable time and money.
  |  By Forescout
That's because perimeter-focused security architectures that default to high trust levels on the internal network are ill-suited for an edgeless enterprise that increasingly supports mobile and remote workers as well as vast numbers of IoT devices. This Forescout white paper explains why visibility is essential for effective Zero Trust architecture and how continuous visibility can help you identify, segment and enforce compliance using Zero Trust principles. It also addresses foundational capabilities Forrester Research requires to designate solutions as a Zero Trust platform.
  |  By Forescout
With a staggering majority of devices - expected to reach more than 75 billion by 2025 - connected to vast networks and the internet, reducing cyber risk becomes a critical focal point for the age of IoT.
  |  By Forescout
The drive to increase productivity and reduce costs in manufacturing environments has led to an exponential increase in the adoption of automation on plant floors, also known as Industry 4.0. If your organization has integrated its computation, networking and physical processes, this whitepaper will explain how deploying network monitoring technology will bring tremendous value to both your IT and OT teams.
  |  By Forescout
The diverse and complex nature of IIoT and OT security use cases can make the technology selection difficult, and unfortunately, copying IT security practices and technology will not result in a secure OT environment. To achieve lasting success with OT cybersecurity investments, managers must ask prescriptive questions during the technology procurement process. In this eBook, we discuss the seven questions recommended by Gartner for SRM leaders to ask during their OT security technology selection and how Forescout answers them.

With so many agentless devices being deployed every day, it’s never been harder to protect your network from threats. Forescout delivers actionable information so you can see the devices on your network and take action to prevent them from compromising your enterprise.

Forescout Technologies, Inc. actively defends the Enterprise of Things by identifying, segmenting and enforcing compliance of every connected thing. Fortune 1000 companies trust Forescout as it provides the most widely deployed, enterprise-class platform at scale across IT, IoT, and OT managed and unmanaged devices.

Forescout arms customers with more device intelligence than any other company in the world, allowing organizations across every industry to accurately classify risk, detect anomalies and quickly remediate cyberthreats without disruption of critical business assets. Don’t just see it. Secure it.

See Every Device. Defend Your Entire Network.