Resources
Blog
Resource Library
August 7, 2026
What Is Internet-Wide Scanning, and How Attackers Use It
Internet-wide scanning lets attackers find exposed hosts fast. See how it works and how to spot your exposure before they do.
August 7, 2026
How SOC Automation Improves Threat Response
SOC automation helps security teams respond faster, cut false positives, and scale operations. Learn the top use cases, benefits, and challenges.
August 5, 2026
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
STRIKE Team
August 4, 2026
How to Make the Most of Your SecurityScorecard Free Trial
Most free trial users only check their score once. Here’s how to use every feature available — from self-monitoring and vendor checks to ASI searches — to get real value from day one.
August 3, 2026
How to Manage AI Vendor Risk
Manage AI vendor risk with a framework for vetting AI capabilities, auditing data flows, and bringing AI tools into continuous monitoring.
August 3, 2026
Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains
This month, the Administration signed an executive order that will force primes and subcontractors in the Defense Industrial Base to answer a question they have spent years avoiding: where does this actually come from? That’s the right question. It’s just not the whole question.
July 27, 2026
How to Identify a Critical Vendor
Identifying a critical vendor is a CISO’s discipline. Learn how to build a defensible list, run a bankruptcy stress test, and monitor continuously.
July 20, 2026
How to Secure Your SaaS Supply Chain
Most SaaS supply chain attacks start at a forgotten vendor. Learn how to map, monitor, and secure every third-party app touching your data.
July 13, 2026
What Is Cybersecurity M&A and Why It Matters
Cybersecurity M&A turns every deal into a cyber risk question. See what cybersecurity M&A is, why it matters, and the role of cyber due diligence.
July 9, 2026
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
July 6, 2026
What Is the Third-Party Risk Management Maturity Model
The third-party risk management maturity model turns vague TPRM goals into measurable stages. See the levels and how to move yours forward.
June 29, 2026
How to Secure Your CI/CD Pipeline
Your CI/CD pipeline can ship a breach as fast as a feature. Learn the CI/CD pipeline security threats, controls, and practices that close the gap.
June 22, 2026
How Open Source Risk Threatens Your Vendors
Open source risk follows every vendor into your supply chain. See where it hides, how attackers exploit it, and what continuous monitoring solves.
June 22, 2026
How State-Sponsored Cyber Attacks Use Third Parties
State-sponsored cyber attacks increasingly target vendors to reach high-value organizations. Learn how nation-state actors exploit third parties and how to defend.
June 15, 2026
Identity-Based Attacks and Third-Party Risk
Identity attacks now account for 59% of breaches, and vendors are the fastest-growing entry point. Learn how to protect your supply chain.
June 15, 2026
The World Cup Has 48 Teams. Adversaries Are Playing Too.
During the 2020 Tokyo Olympics, held in 2021 after a pandemic-forced delay, NTT Corporation recorded approximately 450 million cyberattack attempts targeting Olympic systems. The 2022 FIFA World Cup in Qatar drew similar attention from state-aligned threat actors and opportunistic criminals. The 2026 tournament, spanning three nations, 16 cities, and several million projected visitors, will be
June 12, 2026
Compliance vs Security: What Passing an Audit Misses
Compliance vs security explained. A passed audit proves controls existed on one day, not that you are secure. Close the gap.
June 8, 2026
What Secure by Design Means for Vendor Vetting
Secure by design means building security in from the start. Learn what it means for vendor vetting and how to assess whether your vendors actually follow it.
June 5, 2026
Vendor Offboarding: The Step TPRM Teams Forget
Vendor offboarding is the stage most teams skip. See why lingering vendor access turns into breach risk, and how to close the gap.
June 1, 2026
Living Off the Land Attacks Explained
Living off the land attacks use legitimate system tools to evade detection. Learn how LOTL techniques work, who uses them, and how to reduce your exposure.
June 1, 2026
How Ransomware as a Service Has Changed
Ransomware-as-a-service has transformed who can launch a ransomware attack and how. Learn how the RaaS model works and how to defend your supply chain.