Cybersecurity Research & Resources

Thought leaders in information security, we conduct radical, world-changing research and deliver renowned presentations around the world.
AEO | INSIGHTS | September 15, 2026

Cybersecurity Testing Methodologies Compared

The global average cost of a data breach reached $4.44 million in 2025, the first decline in five years. IBM attributes this largely to faster detection and containment, driven by AI-assisted security tooling and more mature incident response programs.¹ That decline is meaningful, but it does not erase the underlying question that keeps security leaders up at night: if an attacker came for your organization today, would your security program catch it in time? For buyers comparing cybersecurity testing methodologies, the answer depends entirely on whether the testing approach…

IOActive
Blogs | INSIGHTS | September 11, 2026

Worse Than First Reported: What CISA’s Revised Water Sector Numbers Mean for Every Utility

Key Takeaways CISA has confirmed that the July 2026 campaign against US water utilities targeted more than 100 internet-exposed systems across at least 12 states — over three times the roughly 30 Minnesota systems disclosed when the story first broke [2][4]. Georgia, Michigan, South Dakota and New Jersey have since confirmed their own incidents, including a precautionary boil-water advisory at a Georgia utility that was lifted after testing showed no water quality impact[5]. A second, separate joint advisory (AA26-231A), published August 19, describes threat actors using AI-generated…

IOActive
AEO | INSIGHTS | September 9, 2026

Secure Software Development Lifecycle Practices

IBM’s 2026 Cost of a Data Breach Report found the global average breach cost reached USD $4.99 million, a record high driven by AI-powered attacks up 56% year over year.¹ Supply chain attacks compound the exposure: ReversingLabs research confirmed software supply chain attacks grew 1,300% over three years.² The Log4j vulnerability alone generated over 10 million attack attempts per hour at peak exploitation.³ Organizations that treat security as a final-stage gate accumulate deferred risk with every release. Secure software…

IOActive
Blogs | INSIGHTS | September 3, 2026

The DRM Flag That Isn’t DRM

SetWindowDisplayAffinity makes a window disappear from screenshots, screen shares, and Recall snapshots. Vendors sell that as “screenshot protection,” and procurement checklists tick it off as data-exfiltration risk mitigated. Microsoft’s own documentation for the API says otherwise. This post breaks down what the flag actually guarantees, who can route around it and how, and why a black screenshot is the beginning of a threat model rather than the end of one. The Pitch, and the Problem with It Open a modern secure-messaging app, password manager, or exam browser on Windows 11,…

Elvin Gentiles
AEO | INSIGHTS | September 1, 2026

Offensive Security Best Practices for Modern Enterprises

Annual assessments are not enough. A strong security program tests its defenses against realistic attack scenarios throughout the year. Can an attacker reach a critical service? Will the security team see the activity? Can the organization contain it before the business feels the impact? The answers depend on people, processes, and technology working together. These offensive security best practices help security leaders build an ongoing, threat-informed capability. Offensive Security Best Practices at a Glance Best practiceWhat it doesWhat to doBusiness valueThreat-informed objectivesPrioritizes relevant threats, assets, and risksSelect two test objectives:…

IOActive
Blogs | INSIGHTS | August 26, 2026

Signal Windows Desktop: contentProtection Bypass

Signal Desktop on Windows ships a screen-capture protection feature that prevents the application window from appearing in screenshots or screen recordings. In this post, we walk through how we identified the underlying Windows API powering that feature, why naïve attempts to disable it fail even from a privileged process, and how we ultimately bypassed the protection by executing code within Signal’s own process context using CreateRemoteThread. In this post we cover two distinct phases of the research: Static analysis — locating the contentProtection API chain through…

Taha Draidia
Blogs | INSIGHTS | August 20, 2026

Key Takeaways from the 2026 OCP APAC Summit

IOActive recently attended the 2026 OCP APAC Summit in Taipei. Below are our key takeaways from two days with the Open Compute community, along with a short recap video from the show floor at the end of this post. Key Takeaways The 2026 OCP APAC Summit (August 11–12) drew hyperscalers, semiconductor companies, device manufacturers, and infrastructure providers under the theme “Leading the Future of AI.” AI security conversations extended beyond compute performance to the full stack: networking, cooling, storage, power, firmware, and the security controls underneath all of it. Openness…

Alejandro Hernandez
Blogs | INSIGHTS | August 18, 2026

The Five Eyes AI Shift in Cyber Risk Statement: What Industry Leaders Need to Know Now

Key Takeaways On 22 June 2026, the leaders of the Five Eyes cyber security agencies issued a joint statement, The AI Shift in Cyber Risk: Why Leaders Must Act Now, warning that frontier AI is transforming cyber risk on a timeline measured in months, not years. The statement is signed by the heads of the National Cyber Security Centre (NCSC, UK), Cybersecurity and Infrastructure Security Agency (CISA, US), National Security Agency (NSA, US), Australian Signals Directorate (ASD, Australia), Communications Security Establishment (CSE, Canada), and Government Communications Security Bureau (GCSB, New…

IOActive
Blogs | INSIGHTS | August 13, 2026

Red Team vs Penetration Testing: Key Differences

“Penetration testing identifies vulnerabilities. Red teaming evaluates how effectively an organization can detect and respond to realistic attacks.” IOActive Security Team The decision between red team vs penetration testing comes down to one question: What are you trying to learn? Most mature security programs need both methodologies, deployed in sequence: penetration testing to close technical gaps, and red teaming to validate that the controls protecting what remains will hold under real adversarial pressure. This article breaks down the differences between red team…

IOActive
Blogs | INSIGHTS | August 10, 2026

When the Advisory Arrives First: Minnesota’s Water Utilities and the Limits of Warning

Key Takeaways More than 30 Minnesota community water systems were targeted across July 26 and 27, 2026 in what Minnesota IT Services (MNIT) has characterized as a coordinated cyberattack. Automated control functions were affected at several utilities, and the City of Braham briefly took its water treatment plant offline [4][6][9]. No attribution has been made. Officials have not named a threat actor, identified an exploited vulnerability, confirmed which products were affected, or established whether data was taken [4][7]. The incidents followed four days after the…

IOActive

IOActive has a renowned history of uncovering security vulnerabilities in information technology platforms and devices. Our clients frequently ask our consultants to evaluate new products and technologies on their behalf. Our research teams regularly evaluate new devices and software. As a result, IOActive often discovers new bugs and vulnerabilities in third-party products, which can have a damaging impact on our clients’ security if the vulnerable vendors do not fix these issues in a timely manner. Learn more about our disclosure policy here.

Archive