Articles


Article
Out of band, out of mind: DEF CON research calls IPMI a ‘sanctioned backdoor’ into enterprise networks
Alongside the disclosure, runZero released OOBscan, an open-source tool that scans for vulnerable BMCs and other out-of-band management devices.
Article
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Baseboard management controllers from the world’s biggest manufacturers are a security mess.
Article
Legacy Systems, Real-World Impacts: The Reality of OT Security
Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity’s most challenging...
Article
No Exploits Required
Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.
Article
Segmentation Works for OT If Operators Are Paying Attention
Even the best segmentation strategy will fall apart without constant oversight and disciplined operations.
Article
20 Leaders Who Built the CISO Era: 2 Decades of Change
HD Moore, Founder and CEO of runZero, was selected as one of 20 industry figures who rewrote the enterprise risk playbook.
Article
The CVE Program, a bedrock of global cyber defense, is teetering on the brink
A funding scare, AI and similar international initiatives are raising existential questions about the program’s future.
Article
Q&A: Tod Beardsley on how to use CISA’s KEV catalog
Without context, the KEV catalog is just a very large collection of data. Tod Beardsley is the former CISA KEV section chief, and he recently...
Article
Don’t panic over CISA’s KEV list, use it smarter
Tod Beardsley, VP of Security Research at runZero, explains what CISA’s Known Exploited Vulnerabilities (KEV) Catalog is and how security teams...
Article
Trend analysis: intelligent vulnerability triage
The relentless deluge of digital threats has transformed the cybersecurity landscape into a constant battle of prioritization.
Article
New paper and tool help security teams move beyond blind reliance on CISA’s KEV catalog
The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it.