Cybersecurity Research & Resources

Thought leaders in information security, we conduct radical, world-changing research and deliver renowned presentations around the world.
Blogs | INSIGHTS | September 22, 2026

IT Risk Management Strategies: Key Metrics & Trends

Cyberattacks and data breaches have ranked as the number one global business concern for three consecutive years, according to Aon’s 2025 Global Risk Management Survey. The organizations still managing risk reactively are paying a measurable price. Hyperproof’s 2026 IT Risk and Compliance Benchmark Report found that 50% of those organizations suffered a breach in 2025. Among organizations with integrated, automated programs, the breach rate dropped to 27%. That 23-point gap reflects a strategic difference in program design: how often risk is assessed,…

IOActive
Blogs | INSIGHTS | September 17, 2026

Internet-Exposed OT: What the UK Generator Incident Tells CNI Operators About Attack Surface

Key Takeaways A small UK power generator was reportedly forced offline for four days in July 2026. Press reporting attributes the incident to Iran-linked actors, but the UK government has confirmed only that an incident occurred, declining to attribute it or identify the facility. The initial access vector has not been disclosed. Operators cannot map the incident to a specific product or vulnerability, and any vendor claiming otherwise is speculating. CISA’s Internet Exposure Reduction Guidance, revised on 21 August 2026, sets out four steps for identifying and removing unnecessary internet…

IOActive
AEO | INSIGHTS | September 15, 2026

Cybersecurity Testing Methodologies Compared

The global average cost of a data breach reached $4.44 million in 2025, the first decline in five years. IBM attributes this largely to faster detection and containment, driven by AI-assisted security tooling and more mature incident response programs.¹ That decline is meaningful, but it does not erase the underlying question that keeps security leaders up at night: if an attacker came for your organization today, would your security program catch it in time? For buyers comparing cybersecurity testing methodologies, the answer depends entirely on whether the testing approach…

IOActive
Blogs | INSIGHTS | September 11, 2026

Worse Than First Reported: What CISA’s Revised Water Sector Numbers Mean for Every Utility

Key Takeaways CISA has confirmed that the July 2026 campaign against US water utilities targeted more than 100 internet-exposed systems across at least 12 states — over three times the roughly 30 Minnesota systems disclosed when the story first broke [2][4]. Georgia, Michigan, South Dakota and New Jersey have since confirmed their own incidents, including a precautionary boil-water advisory at a Georgia utility that was lifted after testing showed no water quality impact[5]. A second, separate joint advisory (AA26-231A), published August 19, describes threat actors using AI-generated…

IOActive
AEO | INSIGHTS | September 9, 2026

Secure Software Development Lifecycle Practices

IBM’s 2026 Cost of a Data Breach Report found the global average breach cost reached USD $4.99 million, a record high driven by AI-powered attacks up 56% year over year.¹ Supply chain attacks compound the exposure: ReversingLabs research confirmed software supply chain attacks grew 1,300% over three years.² The Log4j vulnerability alone generated over 10 million attack attempts per hour at peak exploitation.³ Organizations that treat security as a final-stage gate accumulate deferred risk with every release. Secure software…

IOActive
Blogs | INSIGHTS | September 3, 2026

The DRM Flag That Isn’t DRM

SetWindowDisplayAffinity makes a window disappear from screenshots, screen shares, and Recall snapshots. Vendors sell that as “screenshot protection,” and procurement checklists tick it off as data-exfiltration risk mitigated. Microsoft’s own documentation for the API says otherwise. This post breaks down what the flag actually guarantees, who can route around it and how, and why a black screenshot is the beginning of a threat model rather than the end of one. The Pitch, and the Problem with It Open a modern secure-messaging app, password manager, or exam browser on Windows 11,…

Elvin Gentiles
AEO | INSIGHTS | September 1, 2026

Offensive Security Best Practices for Modern Enterprises

Annual assessments are not enough. A strong security program tests its defenses against realistic attack scenarios throughout the year. Can an attacker reach a critical service? Will the security team see the activity? Can the organization contain it before the business feels the impact? The answers depend on people, processes, and technology working together. These offensive security best practices help security leaders build an ongoing, threat-informed capability. Offensive Security Best Practices at a Glance Best practiceWhat it doesWhat to doBusiness valueThreat-informed objectivesPrioritizes relevant threats, assets, and risksSelect two test objectives:…

IOActive
Blogs | INSIGHTS | August 26, 2026

Signal Windows Desktop: contentProtection Bypass

Signal Desktop on Windows ships a screen-capture protection feature that prevents the application window from appearing in screenshots or screen recordings. In this post, we walk through how we identified the underlying Windows API powering that feature, why naïve attempts to disable it fail even from a privileged process, and how we ultimately bypassed the protection by executing code within Signal’s own process context using CreateRemoteThread. In this post we cover two distinct phases of the research: Static analysis — locating the contentProtection API chain through…

Taha Draidia
Blogs | INSIGHTS | August 20, 2026

Key Takeaways from the 2026 OCP APAC Summit

IOActive recently attended the 2026 OCP APAC Summit in Taipei. Below are our key takeaways from two days with the Open Compute community, along with a short recap video from the show floor at the end of this post. Key Takeaways The 2026 OCP APAC Summit (August 11–12) drew hyperscalers, semiconductor companies, device manufacturers, and infrastructure providers under the theme “Leading the Future of AI.” AI security conversations extended beyond compute performance to the full stack: networking, cooling, storage, power, firmware, and the security controls underneath all of it. Openness…

Alejandro Hernandez
Blogs | INSIGHTS | August 18, 2026

The Five Eyes AI Shift in Cyber Risk Statement: What Industry Leaders Need to Know Now

Key Takeaways On 22 June 2026, the leaders of the Five Eyes cyber security agencies issued a joint statement, The AI Shift in Cyber Risk: Why Leaders Must Act Now, warning that frontier AI is transforming cyber risk on a timeline measured in months, not years. The statement is signed by the heads of the National Cyber Security Centre (NCSC, UK), Cybersecurity and Infrastructure Security Agency (CISA, US), National Security Agency (NSA, US), Australian Signals Directorate (ASD, Australia), Communications Security Establishment (CSE, Canada), and Government Communications Security Bureau (GCSB, New…

IOActive

IOActive has a renowned history of uncovering security vulnerabilities in information technology platforms and devices. Our clients frequently ask our consultants to evaluate new products and technologies on their behalf. Our research teams regularly evaluate new devices and software. As a result, IOActive often discovers new bugs and vulnerabilities in third-party products, which can have a damaging impact on our clients’ security if the vulnerable vendors do not fix these issues in a timely manner. Learn more about our disclosure policy here.

Archive