Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

How SOC Automation Improves Threat Response

Blog

How SOC Automation Improves Threat Response
SOC automation helps security teams respond faster, cut false positives, and scale operations. Learn the top use cases, benefits, and challenges.
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity

Blog

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
STRIKE Team
Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire

Research

Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire
Blocklists, geolocation, and ASN reputation all share one assumption: that an IP tells you who’s behind it. CanOworms is built to break that assumption. STRIKE identified 633 confirmed member servers operating as a shared Squid/SOCKS/OpenVPN/IPsec relay fleet — not a command-and-control panel, but the disposable front in front of one. Dozens of tenants, from Remcos and Quasar operators to suspected APT41 and APT43/APT37 infrastructure, have used these same relays. The operator is unattributed by design. Many tenants, one set of relays. What you’ll learn: How the mesh was found. A shared self-signed TLS certificate (O=kickass), corroborated by JARM and JA4X fingerprints, exposed 633 confirmed nodes out of 748 candidate IPs across a dozen dense /24 blocks, six-plus hosting providers, and more than a dozen countries. How it’s run. Five Czech Republic control-plane hosts manage the fleet in a centralized “star” topology, with one node alone touching roughly 256 others and a fleet-wide ~35-second heartbeat back to a single collector — a pressure point defenders can watch. Who’s renting it, and who isn’t. A reseller called “PrivacyFirst” (MAXKO d.o.o., AS214366) surfaces in the paper trail, but only a fraction of its address space actually carries the mesh certificate — a case study in why reseller identity isn’t operator identity isn’t tenant identity. Where the attack traffic lands. Suspected credential-spray traffic exits the fleet toward MikroTik routers, TR-069 CPE, and Hikvision cameras — concentrated in South Africa, India, the U.S., Brazil, and Bangladesh. Commodity-crime geography, not espionage-target geography. Why IP-based defense fails here, and what to fingerprint instead. The report lays out why durable detection means tracking how the infrastructure was built (certificate thumbprints, JARM, JA4X, service-stack signature) rather than chasing IPs that get burned and replaced faster than blocklists can keep up. Full IOCs and MITRE ATT&CK mapping. Appendix A publishes the complete fingerprint set — ready to drop into detection tooling — mapped to ATT&CK Resource Development and C2 techniques (T1583.003, T1090.002, T1571). Download “Catch Me If You Can” for the complete CanOworms research, including the fingerprint methodology, control-plane analysis, and the full IOC appendix.
Use the TITAN AI MCP connector in Claude

Video

Use the TITAN AI MCP connector in Claude
Our customers can now build powerful TPRM workflows directly in Claude using SecurityScorecard data and the Titan AI MCP connector. An MCP connector for SSC has been one of our most requested asks and it’s a huge milestone for the platform.
Demo Tuesdays
How to Manage AI Vendor Risk

Blog

How to Manage AI Vendor Risk
Manage AI vendor risk with a framework for vetting AI capabilities, auditing data flows, and bringing AI tools into continuous monitoring.
Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains

Blog

Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains
This month, the Administration signed an executive order that will force primes and subcontractors in the Defense Industrial Base to answer a question they have spent years avoiding: where does this actually come from? That’s the right question. It’s just not the whole question.
MAX: Behind the scenes – How Max Delivers Accountability

Video

MAX: Behind the scenes – How Max Delivers Accountability
See how requests, updates, and escalations flow through a managed task backlog, where TITAN AI agents analyze data and propose actions for human review to ensure total accountability.
Demo Tuesdays
MAX: How MAX detects and responds to zero-days

Video

MAX: How MAX detects and responds to zero-days
See how MAX monitors vendor ecosystems for emerging threats and zero-day vulnerabilities, identifying exposed vendors and driving remediation to closure within tight SLAs.
Demo Tuesdays
MAX: What a Mature TPRM Program Looks Like

Video

MAX: What a Mature TPRM Program Looks Like
See how MAX streamlines vendor assessments, cuts cycle times, and achieves a 70% engagement rate through managed vendor outreach—empowering our customers to focus on decision-making instead of chasing follow-ups.
Demo Tuesdays
How to Identify a Critical Vendor

Blog

How to Identify a Critical Vendor
Identifying a critical vendor is a CISO’s discipline. Learn how to build a defensible list, run a bankruptcy stress test, and monitor continuously.
TITAN SECURE: Identifying a Cybersecurity Event

Video

TITAN SECURE: Identifying a Cybersecurity Event
In this installment of SecurityScorecard’s Demo Tuesday series, see how TITAN Secure’s built-in investigation workspaces, response tracking, and clear vendor-impact tables help teams move from reactive noise sifting to proactive, evidence-backed decision-making.
Demo Tuesdays
How to Secure Your SaaS Supply Chain

Blog

How to Secure Your SaaS Supply Chain
Most SaaS supply chain attacks start at a forgotten vendor. Learn how to map, monitor, and secure every third-party app touching your data.
Preparing for the Post-Mythos Era: When AI Finds Vulnerabilities Faster Than Humans

Webinars

Preparing for the Post-Mythos Era: When AI Finds Vulnerabilities Faster Than Humans
Learn more in this resource.
Mythos
Supply Chain Cyber Risk
CEDIA

Case Studies

CEDIA
Cómo CEDIA transformó la ciberresiliencia del ecosistema académico ecuatoriano con SecurityScorecard
MRS Brazil

Case Studies

MRS Brazil
Depoimento da MRS sobre como a SecurityScorecard trouxe visibilidade independente à postura de segurança externa da empresa, elevando o score a 100% e tornando a gestão de risco cibernético um indicador estratégico acompanhado por executivos e áreas técnicas.
MAX Managed Questionnaires

Video

MAX Managed Questionnaires
In this installment of SecurityScorecard’s Demo Tuesday series, see MAX Managed Questionnaires in action and what your security program looks like when your team is free to focus on risk strategy instead of assessment admin.
Demo Tuesdays
What Is Cybersecurity M&A and Why It Matters

Blog

What Is Cybersecurity M&A and Why It Matters
Cybersecurity M&A turns every deal into a cyber risk question. See what cybersecurity M&A is, why it matters, and the role of cyber due diligence.
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers

Blog

LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
Meeting BNM RMiT 2025: A Guide to Third-Party & Supply Chain Cyber Risk Requirements

White Papers

Meeting BNM RMiT 2025: A Guide to Third-Party & Supply Chain Cyber Risk Requirements
On 28 November 2025, Bank Negara Malaysia issued one of the most significant overhauls to Malaysian financial sector cybersecurity regulation in recent years. The revised Risk Management in Technology (RMiT) policy expands who’s in scope, mandates continuous monitoring of third-party vendors, introduces SBOM requirements, and enforces stricter SLAs for incident disclosure and remediation. This white paper breaks down what changed, what it means for your third-party risk program, and how to operationalise and evidence the new obligations at scale. 28 Nov 2025 — the date RMiT was revised and reissued by BNM New entities in scope — including certain non-bank merchant acquirers and intermediary remittance institutions Continuous monitoring now mandatory — periodic, questionnaire-based assessment is explicitly no longer sufficient 12M+ entities rated across SecurityScorecard’s global intelligence network RMiT 2025 isn’t a checkbox exercise. It’s a shift in how cyber risk is governed.
TITAN ASSESS: Send questionnaires

Video

TITAN ASSESS: Send questionnaires
In Episode 5 of SecurityScorecard’s Demo Tuesday series, see how TITAN Assess streamlines the entire questionnaire outreach process — so your team spends less time on admin and more time acting on what vendors actually tell you.
Demo Tuesdays
TITAN ASSESS: Building an Assessment Template with Titan Agent

Video

TITAN ASSESS: Building an Assessment Template with Titan Agent
In this installment of SecurityScorecard’s TITAN demo series, see how TITAN Agent uses AI to build customized, comprehensive assessment templates — so your team gets to evaluation faster and with more consistency across every vendor engagement.
Demo Tuesdays