July 27, 2026
AttackIQ introduced the following scenarios in response to the recently published CISA Advisory (AA26-204A), which details how the Russian state-sponsored adversary known as Laundry Bear has targeted and compromised government and commercial organizations across Western countries through the exploitation of the Zimbra Collaboration Suite (ZCS) since at least July 2025.
July 23, 2026
The Hugging Face incident reveals the first AI insider. Learn why autonomous AI agents are reshaping cybersecurity and what defenders must do to prepare.
July 16, 2026
Chaos is a ransomware family originally introduced in June 2021 by the developer of the Bagli ransomware through the release of the C#-based Chaos ransomware builder. It rapidly gained popularity within the cybercriminal ecosystem, spawning numerous derivative ransomware families.
July 15, 2026
AttackIQ recommends CISA AA26-194A emulations to validate defenses against FSB Center 16 targeting exposed devices.
July 2, 2026
AttackIQ has created and released a new assessment that emulates the Tactics, Techniques, and Procedures (TTPs) associated with the deployment of Everest ransomware to help customers validate their security controls and their ability to defend against this threat.
June 25, 2026
Threat debt measures the exploitable attack paths adversaries can actually use. Learn how the Threat Debt Index helps security teams prioritize remediation, reduce exposure, and prove risk reduction.
June 2, 2026
From clicks back to commands: AI is bringing back the command line, but this time the machine speaks your language. Explore the future of computing.
May 22, 2026
AttackIQ has released two new assessments that emulate the behaviors of The Gentlemen ransomware, a cross-platform threat that emerged around July 2025. The group employs a double-extortion model, combining file encryption with data exfiltration and leveraging a dedicated leak site to pressure victims into payment.
May 20, 2026
The AttackIQ Champions Program recognizes practitioners who promote threat-informed defense and the principles behind operationalizing MITRE ATT&CK. Publish content, get early access to courses, and join a growing community. Applications open now.
April 30, 2026
The speed of adversary exploitation has outrun the cycle most security programs were built to run. Defending proactively starts with knowing what an exploit actually enables next: the path it opens, the assets that path reaches, and the defenses that have to hold. The threat environment has changed and we must shift our focus from how fast can we patch to will our defenses stand up to the threats that we face and how effectively can we eliminate adversary attack paths.
April 17, 2026
With Anthropic’s Mythos Preview announcement, the race to patch all vulnerabilities is over. As defenders, we must move on.
April 14, 2026
AttackIQ has released a new attack graph that emulates the behaviors of NightSpire Ransomware, a financially motivated ransomware and data extortion group that emerged in early 2025 and quickly evolved into a full double-extortion operation.
April 7, 2026
AttackIQ has released a new assessment template that emulates the behaviors of RoningLoader, a multi-stage loader observed in recent intrusion campaigns. RoningLoader operates through a layered execution chain, enabling stealthy delivery and execution of follow-on payloads while evading traditional detection mechanisms.
April 2, 2026
AttackIQ has released a new attack graph that emulates the behaviors of Sinobi ransomware, a ransomware strain that has been active since mid 2025. Sinobi is suspected to be a rebrand of Lynx, a Ransomware-as-a-Service (RaaS) group that first emerged in 2024.
March 23, 2026
Learn how adversaries are shifting from evasion to systematically dismantling endpoint defenses to eliminate visibility, enforcement, and response. Explore how modern EDR inhibition techniques abuse legitimate system features and vulnerable drivers to quietly degrade protections with minimal detection. Understand why this once-advanced tradecraft is now standard practice—and how it creates a critical blind spot for defenders.
March 10, 2026
Coverage claims without context are one of the most persistent sources of confusion in security tooling. This post breaks down four myths behind ATT&CK coverage claims and offers a more useful framework for thinking about ATT&CK coverage in practice.
March 5, 2026
On February 28, 2026, the United States and Israel launched Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel), a coordinated military and cyber campaign targeting Iranian military installations, IRGC leadership, and government infrastructure. U.S. Cyber Command was designated the “first mover,” with cyber operations beginning before any kinetic weapons were deployed. In the first 48 hours, U.S. and allied forces struck more than 1,250 targets across Iran, while Israel conducted what has been described as the largest cyberattack in history, collapsing Iran’s internet connectivity to 1-4% of normal levels through multi-layered attacks on BGP routing, DNS infrastructure, and SCADA/ICS systems.
March 3, 2026
Drowning in security data? This practical guide shows how CTEM and MITRE INFORM cut noise, validate defenses, and prove what matters.
February 26, 2026
AttackIQ has released a new attack graph that emulates the behaviors of LokiLocker ransomware, a .NET based strain active since at least mid-August 2021. The malware combines defense evasion and impact techniques, including disabling Task Manager and Windows Firewall, as well as deleting Volume Shadow Copies to hinder detection and prevent restoration.
February 26, 2026
When ransomware hits a hospital, shutting everything down isn’t resilience. Learn how healthcare CISOs prevent hospital-wide outages with identity security, network segmentation validation, and CTEM.
February 25, 2026
AttackIQ has released a new attack graph that emulates the behaviors exhibited by BlackByte ransomware, a strain operated under the Ransomware-as-a-Service (RaaS) model that emerged in July 2021. Since its emergence, BlackByte has targeted organizations worldwide, including entities within U.S. critical infrastructure sectors such as Government, Financial Services, Manufacturing, and Energy.
February 24, 2026
What if you could prove—right now—that your defenses actually work? See how CTEM and MITRE INFORM turn exposure data into real, board-level confidence.
February 18, 2026
After 30 years in cyber defense and research, I joined AttackIQ to bring clarity and prioritize what truly matters in security.

























