Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Insurance Authority of Hong Kong

Case Studies

Insurance Authority of Hong Kong
How the Insurance Authority of Hong Kong Strengthened Cyber Visibility and Risk Posture with SecurityScorecard
SecurityScorecard Adds Former Maryland Gov. Larry Hogan to Advisory Board

Press

SecurityScorecard Adds Former Maryland Gov. Larry Hogan to Advisory Board
SecurityScorecard, the global leader in threat-informed third-party risk management (TPRM), today announced that Former Maryland Governor Larry Hogan has joined the company’s Advisory Board.
What Are the Real Security Risks of Agentic AI and OpenClaw?

Blog

What Are the Real Security Risks of Agentic AI and OpenClaw?
SecurityScorecard’s STRIKE Threat Intelligence team examines exposed OpenClaw deployments and the broader security risks of agentic AI, including remote code execution vulnerabilities, prompt injection, and the security controls organizations must implement now.
What is a CVE and Why is It Important?

Blog

What is a CVE and Why is It Important?
What is a CVE? This guide explains how security teams use Common Vulnerabilities and Exposures to identify, track, and prioritize the threats that matter most.
How Exposed OpenClaw Deployments Turn Agentic AI Into an Attack Surface

Blog

How Exposed OpenClaw Deployments Turn Agentic AI Into an Attack Surface
SecurityScorecard’s STRIKE Threat Intelligence team details new research on exposed OpenClaw agentic AI deployments, explaining how attackers can abuse them for remote code execution and infrastructure misuse. STRIKE also shared steps organizations can take to reduce exposure.
SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide

Press

SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide
Channel ARR and partner-led pipeline surged in 2025 as service providers rapidly adopted MAX to deliver managed threat-informed TPRM for global supply chain resilience\r\n
Recent Data Breach Examples

Blog

Recent Data Breach Examples
Discover how real data breach examples expose third-party risks. Learn from MOVEit, healthcare breaches, and M365 attacks to protect your business.
Strengthening National Cyber Resilience: Reflections from My Fireside Chat with ONCD Director Sean Cairncross

Blog

Strengthening National Cyber Resilience: Reflections from My Fireside Chat with ONCD Director Sean Cairncross
Mike Centrella, SecurityScorecard Head of Public Policy, shares insights from his fireside chat with the National Cyber Director Sean Cairncross on strengthening U.S. cyber resilience, deterrence, AI security, and workforce strategy.
Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence

Blog

Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence
While the world debates Moltbook’s role in the AI ecosystem, it is just the tip of the iceberg of Titanic risk. SecurityScorecard’s STRIKE team uncovered what lurks beneath: Thousands of exposed OpenClaw (Moltbot) control panels vulnerable to takeover through misconfigured access and known exploits.
STRIKE Team
Why India Is Emerging as a Third-Party Breach Hotspot

Blog

Why India Is Emerging as a Third-Party Breach Hotspot
SecurityScorecard experts analyzed why 52.6% of Indian vendors experienced at least one third-party breach in the past year in a recent webinar. India has become one of the most critical engines of the global digital economy and one of the most targeted.
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability (CVE-2025-6543) Added to CISA KEV

Strike Alert

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability (CVE-2025-6543) Added to CISA KEV
Learn more in this resource.
What is a SOC 2 Compliance Checklist?

Blog

What is a SOC 2 Compliance Checklist?
Use this SOC 2 compliance checklist to prepare for your audit, meet requirements, and maintain continuous compliance. Expert guidance for security leaders.
What Are Moltbot and Moltbook and What Happens When Agentic AI Assistants Scale Without Security

Blog

What Are Moltbot and Moltbook and What Happens When Agentic AI Assistants Scale Without Security
Moltbot AI assistants and their social media platform Moltbook have sparked AGI fears in recent days, but the real risk is access. Learn what Moltbook and Moltbot are (now OpenClaw and formerly known as Clawdbot), why it’s not artificial general intelligence (AGI), and how to reduce security exposure.
What Is Network Cloud Security?

Blog

What Is Network Cloud Security?
Learn what network cloud security is, why traditional approaches fall short, and best practices for protecting your cloud infrastructure from security threats.
Odyssey 2026 Recap: Building Continuous Supply Chain Resilience in an Era of Persistent Threats

Blog

Odyssey 2026 Recap: Building Continuous Supply Chain Resilience in an Era of Persistent Threats
SecurityScorecard’s Odyssey 2026 customer conference in Miami brought CISOs together to examine continuous, threat-informed supply chain security and the shift from periodic assessments to real-time risk operations.
What Is Cyber Incident Response and Why It Matters

Blog

What Is Cyber Incident Response and Why It Matters
Learn what cyber incident response is, the steps in the incident response lifecycle, and how to build effective incident response teams and playbooks.
The Quiet Siege II

STRIKE

The Quiet Siege II
Explore a fictional depiction of a DDoS attack in The Quiet Siege Part II: Life, Interrupted. The scenario described does not represent a real attack, organization, or incident.
The Quiet Siege I

STRIKE

The Quiet Siege I
Explore a fictional depiction of a DDoS attack. The scenario described does not represent a real attack, organization, or incident.
Latin America as a Proving Ground: Cybercriminal Innovation and Escalation

STRIKE

Latin America as a Proving Ground: Cybercriminal Innovation and Escalation
The Conti ransomware group, active since late 2019, quickly became one of the most aggressive forces in the world of cybercrime. Known for “big game hunting” and its double-extortion model: stealing data before encrypting systems, Conti targeted major institutions in healthcare, education, and infrastructure.
Critical Update: What Security Leaders Need to Know Right Now About the Future of CISA and Threat Sharing

Blog

Critical Update: What Security Leaders Need to Know Right Now About the Future of CISA and Threat Sharing
Discover how the expiration of the Cybersecurity Information Sharing Act (CISA 2015) disrupted threat intelligence, weakened national security, and widened AI-driven attack gaps. SecurityScorecard’s Mike Centrella and Dr. Aleksandr Yampolskiy explain what’s at stake as the January 2026 deadline nears amid a potential government shutdown.
What is a Parked Domain?

Blog

What is a Parked Domain?
Learn what is a parked domain, why people park domains, and the security risks they create. Discover how to protect your attack surface from hidden threats.