Picus Security

2.9K posts

Picus Security banner
Picus Security

Picus Security

@PicusSecurity

Picus Security, the leading security validation company, gives organizations a clear picture of their cyber risk based on business context.

Katılım Ocak 2013
50 Takip Edilen2.9K Takipçiler
Picus Security
Picus Security@PicusSecurity·
A signed driver from a video game was used to kill enterprise antivirus at the kernel level. That's not theoretical. That's BYOVD in the wild. Attackers load a legit, signed, vulnerable driver. Windows trusts it. They exploit it for kernel access. Your EDR goes dark. We break down the full attack chain 👇 Read more: hubs.li/Q046GpYZ0
Picus Security tweet media
English
0
3
3
266
Picus Security
Picus Security@PicusSecurity·
Healthcare has the highest prevention score of any industry at 83%. But only 13% of simulated attacks triggered an alert. And credential-based attacks succeeded 98% of the time. Strong walls. Blind interior. That's the real risk in healthcare security right now. Read the full analysis: hubs.ly/Q046GdXs0
Picus Security tweet media
English
0
0
0
45
Picus Security
Picus Security@PicusSecurity·
G2 Leader in Breach and Attack Simulation, Winter 2026. What our customers value most: Picus replicates real cyberattacks in a safe setting. No guesswork. No assumptions. Just validated defense. Thank you to everyone who reviewed us.
Picus Security tweet media
English
1
0
1
57
Picus Security
Picus Security@PicusSecurity·
Pen tests once or twice a year. Attackers every day. Automated penetration testing runs continuously, maps real attack paths, and shows which vulnerabilities actually lead to compromise. Not just what's wrong. What's exploitable. See the full use case: hubs.li/Q046Gdg-0
Picus Security tweet media
English
0
1
0
72
Picus Security
Picus Security@PicusSecurity·
RSAC 2026. Booth #N-4405. March 23-26. We're showing Picus Agentic Exposure Validation live. AI agents that continuously find gaps and validate your controls before attackers do. Stop by for a demo. Or book time with our team ahead of the event.
Picus Security tweet media
English
1
0
0
68
Picus Security
Picus Security@PicusSecurity·
Some of the biggest findings from this year's data: ↳ Ransomware encryption down 38%. ↳ Malware now uses trigonometry to detect if it's in a sandbox. ↳ C2 traffic running through OpenAI and AWS APIs. Full report: picussecurity.com/red-report
English
1
0
1
245
Picus Security
Picus Security@PicusSecurity·
The Red Report 2026 is here. 1.1M+ malicious files. 15.5M+ adversary actions. One clear shift: 80% of the top techniques are now about staying hidden, not causing damage. Attackers aren't breaking down doors anymore. They're logging in and living inside your systems.
Picus Security tweet media
English
1
0
1
67
Picus Security
Picus Security@PicusSecurity·
Sutter Health's red team was spending weeks on manual validation cycles. Now they get full simulation reports in under an hour. Here's how their Red Team Manager, Jaime Rodriguez, and team made the shift 👇 [link in reply]
Picus Security tweet media
English
1
0
0
74
Picus Security
Picus Security@PicusSecurity·
New from Hong Kong: the Code of Practice for Critical Infrastructure operators doesn't just ask "do you have security controls?" It asks "can you prove they work?" Our compliance guide breaks down every major CoP section and how to meet it with continuous validation. Read more: hubs.ly/Q046Gd780
Picus Security tweet media
English
0
0
0
78
Picus Security
Picus Security@PicusSecurity·
CVE-2025-66516 in Apache Tika. CVSS 8.4. The root cause is in tika-core, not the PDF parser. Upgrading the wrong module won't fix it. Attack path: malicious XFA in a PDF → XXE → local file disclosure. Fix: tika-core 3.2.2+ Simulate it in Picus with Threat ID 74403. Full breakdown: hubs.li/Q046G6SK0 #CVE202566516 #XXE
Picus Security tweet media
English
0
0
1
286
Picus Security
Picus Security@PicusSecurity·
Wrapped up two sessions at #eCrime2026 in London. AI adversaries on the main stage. True cyber exposure validation in the breakout. Full rooms both times. Good conversations with the people doing the real work. See you at the next one
Picus Security tweet mediaPicus Security tweet mediaPicus Security tweet mediaPicus Security tweet media
English
0
0
0
59
Picus Security
Picus Security@PicusSecurity·
Gartner core argument: → Fragmented tools = blind spots, slow response, and unvalidated risk → The fix: platforms that unify the full CTEM lifecycle with automation → 8+ major acquisitions in the last 2 years — all moving toward unification This isn't a forecast. It's already happening.
English
1
0
0
67
Picus Security
Picus Security@PicusSecurity·
New @Gartner_inc prediction: By 2028, unified exposure management platforms (UEMPs) will capture 60% of the exposure management market — up from less than 5% in 2025 — driven by the need to consolidate fragmented security data and unify siloed exposure management processes. Point solutions are getting displaced. The consolidation is already underway. Here's what the research says 🧵
English
1
0
0
98