• Introducing AVA Agentic OS: The New AttackIQ

    July 30, 2026

    Today we announced AVA Agentic OS, the operating system for Continuous Threat Exposure Management, and the start of a new era for cyber defensive operations and AttackIQ.

    Read More

    Response to CISA Advisory (AA26-204A): Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

    July 27, 2026
    AttackIQ introduced the following scenarios in response to the recently published CISA Advisory (AA26-204A), which details how the Russian state-sponsored adversary known as Laundry Bear has targeted and compromised government and commercial organizations across Western countries through the exploitation of the Zimbra Collaboration Suite (ZCS) since at least July 2025.
    Read More

    The First AI Insider: Why the Hugging Face Incident Changes Cybersecurity Forever

    July 23, 2026
    The Hugging Face incident reveals the first AI insider. Learn why autonomous AI agents are reshaping cybersecurity and what defenders must do to prepare.
    Read More

    Chaos Ransomware: BlackSuit-Linked RaaS Resurgence and Detection Opportunities

    July 16, 2026
    Chaos is a ransomware family originally introduced in June 2021 by the developer of the Bagli ransomware through the release of the C#-based Chaos ransomware builder. It rapidly gained popularity within the cybercriminal ecosystem, spawning numerous derivative ransomware families.
    Read More

    Response to CISA Advisory (AA26-194A): Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

    July 15, 2026
    AttackIQ recommends CISA AA26-194A emulations to validate defenses against FSB Center 16 targeting exposed devices.
    Read More

    Finding Flaws Got Easy. That Broke How We Measure Exposure.

    July 8, 2026
    Read More

    Inside Everest Ransomware: Dissecting a ConfuserEx-Protected .NET Encryptor with Wake-on-LAN Capabilities

    July 2, 2026
    AttackIQ has created and released a new assessment that emulates the Tactics, Techniques, and Procedures (TTPs) associated with the deployment of Everest ransomware to help customers validate their security controls and their ability to defend against this threat.
    Read More

    Threat Debt: The Unit of Measure Adversaries Already Use Against You

    June 25, 2026
    Threat debt measures the exploitable attack paths adversaries can actually use. Learn how the Threat Debt Index helps security teams prioritize remediation, reduce exposure, and prove risk reduction.
    Read More

    Back to the Prompt: Why AI Is Taking Us Full Circle to the DOS Era

    June 2, 2026
    From clicks back to commands: AI is bringing back the command line, but this time the machine speaks your language. Explore the future of computing.
    Read More

    Emulating the Gentlemen Ransomware

    May 22, 2026
    AttackIQ has released two new assessments that emulate the behaviors of The Gentlemen ransomware, a cross-platform threat that emerged around July 2025. The group employs a double-extortion model, combining file encryption with data exfiltration and leveraging a dedicated leak site to pressure victims into payment.
    Read More

    Build Your Cybersecurity Profile: Introducing the AttackIQ Champions Program

    May 20, 2026
    The AttackIQ Champions Program recognizes practitioners who promote threat-informed defense and the principles behind operationalizing MITRE ATT&CK. Publish content, get early access to courses, and join a growing community. Applications open now.
    Read More

    Threat Debt: From Findings to Adversary Opportunity

    April 30, 2026
    The speed of adversary exploitation has outrun the cycle most security programs were built to run. Defending proactively starts with knowing what an exploit actually enables next: the path it opens, the assets that path reaches, and the defenses that have to hold. The threat environment has changed and we must shift our focus from how fast can we patch to will our defenses stand up to the threats that we face and how effectively can we eliminate adversary attack paths.
    Read More

    The Vulnerability Management Race Is Over. It’s Time to Focus on Exposure.

    April 17, 2026
    With Anthropic’s Mythos Preview announcement, the race to patch all vulnerabilities is over. As defenders, we must move on.
    Read More

    Emulating the Persuasive NightSpire Ransomware

    April 14, 2026
    AttackIQ has released a new attack graph that emulates the behaviors of NightSpire Ransomware, a financially motivated ransomware and data extortion group that emerged in early 2025 and quickly evolved into a full double-extortion operation.
    Read More

    Emulating the Multi-Stage RoningLoader Malware

    April 7, 2026
    AttackIQ has released a new assessment template that emulates the behaviors of RoningLoader, a multi-stage loader observed in recent intrusion campaigns. RoningLoader operates through a layered execution chain, enabling stealthy delivery and execution of follow-on payloads while evading traditional detection mechanisms.
    Read More

    Emulating the Concealed Sinobi Ransomware

    April 2, 2026
    AttackIQ has released a new attack graph that emulates the behaviors of Sinobi ransomware, a ransomware strain that has been active since mid 2025. Sinobi is suspected to be a rebrand of Lynx, a Ransomware-as-a-Service (RaaS) group that first emerged in 2024.
    Read More

    Defenseless Defenders: Exploring Endpoint Detection and Response (EDR) Inhibitors

    March 23, 2026
    Learn how adversaries are shifting from evasion to systematically dismantling endpoint defenses to eliminate visibility, enforcement, and response. Explore how modern EDR inhibition techniques abuse legitimate system features and vulnerable drivers to quietly degrade protections with minimal detection. Understand why this once-advanced tradecraft is now standard practice—and how it creates a critical blind spot for defenders.
    Read More

    What Does MITRE ATT&CK Coverage Really Mean?

    March 10, 2026
    Coverage claims without context are one of the most persistent sources of confusion in security tooling. This post breaks down four myths behind ATT&CK coverage claims and offers a more useful framework for thinking about ATT&CK coverage in practice.
    Read More

    Defending Against Iranian Cyber Threats in the Wake of Operation Epic Fury 

    March 5, 2026
    On February 28, 2026, the United States and Israel launched Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel), a coordinated military and cyber campaign targeting Iranian military installations, IRGC leadership, and government infrastructure. U.S. Cyber Command was designated the “first mover,” with cyber operations beginning before any kinetic weapons were deployed. In the first 48 hours, U.S. and allied forces struck more than 1,250 targets across Iran, while Israel conducted what has been described as the largest cyberattack in history, collapsing Iran’s internet connectivity to 1-4% of normal levels through multi-layered attacks on BGP routing, DNS infrastructure, and SCADA/ICS systems.
    Read More
    CTEM + MITRE INFORM

    Finally, CTEM and MITRE INFORM Without the Jargon

    March 3, 2026
    Drowning in security data? This practical guide shows how CTEM and MITRE INFORM cut noise, validate defenses, and prove what matters.
    Read More

    Emulating the Systematic LokiLocker Ransomware

    February 26, 2026
    AttackIQ has released a new attack graph that emulates the behaviors of LokiLocker ransomware, a .NET based strain active since at least mid-August 2021. The malware combines defense evasion and impact techniques, including disabling Task Manager and Windows Firewall, as well as deleting Volume Shadow Copies to hinder detection and prevent restoration.
    Read More

    The “Analog Panic Button”: What The Pitt Gets Right (and Wrong) About Hospital Cyber Resilience

    February 26, 2026
    When ransomware hits a hospital, shutting everything down isn’t resilience. Learn how healthcare CISOs prevent hospital-wide outages with identity security, network segmentation validation, and CTEM.
    Read More

    Emulating the Mutative BlackByte Ransomware

    February 25, 2026
    AttackIQ has released a new attack graph that emulates the behaviors exhibited by BlackByte ransomware, a strain operated under the Ransomware-as-a-Service (RaaS) model that emerged in July 2021. Since its emergence, BlackByte has targeted organizations worldwide, including entities within U.S. critical infrastructure sectors such as Government, Financial Services, Manufacturing, and Energy.
    Read More

    From Exposure to Assurance: How CTEM and MITRE INFORM Enable Modern Cyber Defense

    February 24, 2026
    What if you could prove—right now—that your defenses actually work? See how CTEM and MITRE INFORM turn exposure data into real, board-level confidence.
    Read More

    Why I Chose to Join AttackIQ as a Senior Advisor

    February 18, 2026
    After 30 years in cyber defense and research, I joined AttackIQ to bring clarity and prioritize what truly matters in security.
    Read More