Executive Blog

Hear from security leaders at NetSPI as they explore the latest cybersecurity strategies and the most impactful trends affecting the industry today.

CISO Perspectives

Beyond the Hype: What Regulated Industries Need to Know Before Trusting AI Security Tooling

AI security tools can build an attack, but enterprise security teams in regulated industries need consistency, auditability, and predictable costs before they can trust one. Learn why the surrounding infrastructure is where most AI security vendors are still falling short.

Learn More
Critical Vulnerability

Splunk Enterprise Unauthenticated Arbitrary File Operations/RCE (CVE-2026-20253): Overview and Takeaways

Splunk disclosed CVE-2026-20253 on June 10, 2026, affecting Splunk Enterprise versions in the 10.0.x and 10.2.x branches. The flaw stems from a PostgreSQL sidecar service endpoint that completely lacks authentication controls (CWE-306), allowing any network-reachable attacker to invoke arbitrary file creation or truncation operations without credentials.

Learn More
Critical Vulnerability

CVE-2026-9082 Drupal Core PostgreSQL SQL Injection Overview and Takeaways

A critical vulnerability in Drupal Core, tracked as CVE-2026-9082, affects Drupal deployments using a PostgreSQL database. The issue allows unauthenticated attackers to perform arbitrary SQL queries via crafted JSON:API or search queries. Successful exploitation may result in full database compromise or remote code execution.

Learn More
Penetration Testing

Scaling Security with Modern PTaaS: Gartner Report Insights

Discover Gartner® 2025 insights on how PTaaS scales security with continuous validation, automation, and real-time remediation, and how NetSPI can help.

Learn More
NetSPI Updates

Why Continuous Testing is the New Standard for Modern Security

NetSPI’s continuous pentesting delivers regular, tailored assessments across critical assets, customized to your organization’s risk profile and operational cadence to ensure coverage where it matters most. These services are delivered through NetSPI’s leading PTaaS platform using existing workflows.

Learn More
Critical Vulnerability

CVE-2026-0300 Palo Alto Networks PAN-OS Buffer Overflow Overview & Takeaways

Palo Alto Networks has disclosed a critical zero-day vulnerability in PAN-OS, tracked as CVE-2026-0300, affecting PA-Series and VM-Series firewalls with the User-ID Authentication Portal (Captive Portal) enabled. The flaw is a pre-authentication buffer overflow that allows an unauthenticated, remote attacker to execute arbitrary code with root privileges on affected devices.

Learn More
Critical Vulnerability

CVE-2026-41940 cPanel & WHM Authentication Bypass Overview and Takeaways

cPanel has disclosed a critical authentication bypass vulnerability affecting cPanel & WHM and WP Squared, tracked as CVE-2026-41940 (CVSS 9.8). The flaw allows a remote, unauthenticated attacker to gain root-level administrative access by injecting arbitrary values into a server-side session file, effectively bypassing all credential checks.

Learn More
Vulnerability Management

Q1 2026 Critical Vulnerability Roundup: Mitigating Risk

Discover the top critical vulnerabilities of 2026 identified by Team NetSPI and learn how proactive security measures can protect your strategic business initiatives.

Learn More
AI/ML Pentesting

Anthropic’s Mythos Announcement: What it Means for Security Teams

Anthropic’s Mythos accelerates automated vulnerability discovery. Read how to mitigate risk with custom benchmarks and human verification in your workflows.

Learn More
Hardware Penetration Testing

Regulatory-Ready Security: Ensuring FCC Compliance for Routers

Last week, the FCC released a major update to the “Covered List”, officially adding foreign-produced consumer-grade routers to the registry of equipment deemed a threat to national security. This declaration was in part due to the discovery of backdoors in select routers that used standard apps in an attack chain to create a backdoor into seemingly protected networks. 

Learn More
Critical Vulnerability

CVE-2026-35616 & CVE-2026-21643 – Fortinet FortiClientEMS: Overview & Takeaways

Fortinet has disclosed two critical vulnerabilities in FortiClient Endpoint Management Server (EMS) that are both under active exploitation in the wild. 

Learn More
AI/ML Pentesting

AI Fools Week: Don’t Let AI Fool Your Pentesting Strategy

AI is transforming penetration testing. It promises speed, scale, and automation. But here is the catch. When used in isolation, AI can create a false sense of security. And that is no joke. A modern approach to pentesting requires balance, combining the efficiency of AI with the expertise of human testers. Without that balance, organizations risk missing what matters most.

Learn More