Resources

Blog

Resource Library

Clear filters

When SaaS Trust Becomes a Threat: Insights from the Salesloft Drift Compromise

September 10, 2025

When SaaS Trust Becomes a Threat: Insights from the Salesloft Drift Compromise
The STRIKE team has been analyzing the Salesloft Drift breach that spread into Salesforce environments. Discover what the breach tells us about supply chain security, how attackers abused OAuth tokens, what data is exposed, and defensive actions to take next.
STRIKE Team
Now You Can See European Union Vulnerability Database (EUVD) IDs in the SecurityScorecard Platform

September 8, 2025

Now You Can See European Union Vulnerability Database (EUVD) IDs in the SecurityScorecard Platform
Third-party risk management is complex as teams often struggle to track vulnerabilities across different data sources and standards. This can be especially challenging when working with vendors in the European Union, who may rely on a different set of databases with naming standards that don’t always align with U.S. standards.
How to Communicate Third-Party Risk to the Board

August 26, 2025

How to Communicate Third-Party Risk to the Board
Learn effective strategies for presenting third-party cyber risks to your board. Expert insights on simplifying complex security data for executive decision-making.
Scorecarder Spotlight: John Gonzalez

August 26, 2025

Scorecarder Spotlight: John Gonzalez
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners.
Scorecarder Spotlight
Red Team Cybersecurity: Complete Guide to Red Team Testing

August 18, 2025

Red Team Cybersecurity: Complete Guide to Red Team Testing
Learn what red teaming is, methodology, process, and importance in cybersecurity. Expert insights on red team testing and exercises.
SQL Injection in Cyber Security Prevention Guide

August 18, 2025

SQL Injection in Cyber Security Prevention Guide
Learn how SQL injection in cyber security threatens your data. Discover prevention strategies, attack types, and best practices to secure web applications.
What is Residual Risk in Cybersecurity?

August 18, 2025

What is Residual Risk in Cybersecurity?
Why perfect security is impossible. Understand residual risk cybersecurity and learn to manage what remains after all controls are in place.
FTP Security Risks, Vulnerabilities & Best Practices Guide

August 18, 2025

FTP Security Risks, Vulnerabilities & Best Practices Guide
Learn about FTP security vulnerabilities, risks of unencrypted file transfers, and best practices for secure data transmission alternatives like SFTP.
From the Depths of the Shadows: IRGC and Hacker Collectives Of The 12-Day War

August 5, 2025

From the Depths of the Shadows: IRGC and Hacker Collectives Of The 12-Day War
From reconnaissance to propaganda to payloads, this is how Iran’s digital foot soldiers mobilized across borders and platforms during the war with Israel in June 2025.
STRIKE Team
SecurityScorecard Discovers new botnet, ‘Zhadnost,’ responsible for Ukraine DDoS attacks

August 1, 2025

SecurityScorecard Discovers new botnet, ‘Zhadnost,’ responsible for Ukraine DDoS attacks
SecurityScorecard (SSC) has identified three separate DDoS attacks which all targeted Ukrainian government and financial websites leading up to and during Russia’s invasion of Ukraine. Details of these DDoS attacks have not yet been publicly identified.
Scorecarder Spotlight: Minh Pham

August 1, 2025

Scorecarder Spotlight: Minh Pham
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners.
Scorecarder Spotlight
Why Continuous Monitoring Is Replacing Point-in-Time Audits for Compliance

July 9, 2025

Why Continuous Monitoring Is Replacing Point-in-Time Audits for Compliance
Keeping pace with cybersecurity regulations in 2025 isn’t just about annual audits. It’s about real-time visibility across your entire supply chain. And that’s not just a fringe expectation for some industries. It’s increasingly a requirement across sectors as compliance frameworks and regulations evolve to meet present-day threats and attackers exploit third-party access.  To meet the
Compliance
SecurityScorecard In The News Q2 2025

July 2, 2025

SecurityScorecard In The News Q2 2025
Catch up on SecurityScorecard press coverage from Q2 2025, including coverage of STRIKE Threat Intelligence team’s LapDogs ORB report, global media coverage, executive commentary, and company news.
Scorecarder Spotlight: Isabella Dorado Burbano

July 1, 2025

Scorecarder Spotlight: Isabella Dorado Burbano
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners.
Scorecarder Spotlight
What is a Cyber Attack? Types and Preventive Measures

June 30, 2025

What is a Cyber Attack? Types and Preventive Measures
Learn what is a cyber attack, explore common types like ransomware and phishing, understand financial impacts, and discover prevention strategies.
What is a Whaling Attack in Cybersecurity?

June 30, 2025

What is a Whaling Attack in Cybersecurity?
What is a whaling attack? See how phishing attacks aimed at executives and whaling attacks work, and how cybercriminals steal sensitive information.
What is DNSSEC and Why Is It Important?

June 30, 2025

What is DNSSEC and Why Is It Important?
Understand how DNSSEC secures the domain name system with cryptographic methods to verify the authenticity of DNS records and boost DNS security.
10 Cybersecurity Criteria for Smarter Vendor Selection

June 27, 2025

10 Cybersecurity Criteria for Smarter Vendor Selection
Learn the 10 most critical cybersecurity criteria to include in your vendor selection process. Make smarter, risk-informed decisions before onboarding third parties.
What Is Residual Risk and How Do You Mitigate It?

June 26, 2025

What Is Residual Risk and How Do You Mitigate It?
Learn what residual risk is in cybersecurity, how to measure and reduce it, and why complete risk elimination is a myth. Understand strategies to manage what remains after controls are applied.
What Does CIRCIA Require—and How Can You Prepare for Reporting Cyber Incidents?

June 25, 2025

What Does CIRCIA Require—and How Can You Prepare for Reporting Cyber Incidents?
Learn what the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires, who it applies to, and how your organization can prepare for faster, smarter breach response.
What is the Difference Between IT Risk Management and Cybersecurity?

June 25, 2025

What is the Difference Between IT Risk Management and Cybersecurity?
Explore how IT risk management and cybersecurity differ—and where they overlap. Learn how to align both for a stronger, more resilient organization.