"Most attacks still come back to the same basic entry points: stolen credentials and software or scripts that never should have been allowed to run in the first place. Before organizations start asking what new AI-powered detection tool they need, they should first be asking whether Zero Trust basics are in place. Detection still matters, but it cannot be the whole strategy. Once an attack is detected, the breach has happened." - Danny Jenkins
From the ThreatLocker blog
Demonstrating resilience through segmentation and containment
What's happening: As AI enables attackers to move faster, cyber insurance providers are raising the bar. Controls like antivirus and MFA are no longer enough on their own. Insurers increasingly want evidence that organizations continuously enforce security policies, patch vulnerabilities promptly, and can contain attacks before they spread.
Why it matters: AI isn't inventing new attacks, but it is accelerating current ones, making prevention a business requirement. As attacks become faster and more frequent, organizations need to demonstrate resilience, not just document policies.
The big picture: Insurance providers are adding to the impact of a breach. Weak security can now affect insurance premiums, coverage eligibility, and even whether a claim is paid after an incident.
What's happening: Attackers increasingly rely on lateral movement after an initial compromise. While traditional segmentation uses VLANs, internal firewalls, and access control lists (ACLs), modern network segmentation uses a Zero Trust, default-deny approach to limit unnecessary communication between systems. This ensures compromised devices cannot be used as stepping stones to critical assets, and granular policies based on identity, context, and business need help contain attacks before they spread.
Why it matters:Preventing every breach isn't realistic, but preventing attackers from reaching identity systems, backups, administrative tools, or payment infrastructure is. Effective segmentation limits the blast radius of an attack and gives security teams a far better chance of containing incidents before they become organization-wide compromises.
The big picture: Continuous enforcement provides control and visibility, but network segmentation isn't a "set it and forget it" practice. Regular testing is equally important, especially as attack methods and exploits are evolving so rapidly. Simulated attack scenarios help confirm that segmentation is actively preventing lateral movement.
What's happening: Even if network segmentation limits lateral movement, attackers will still find ways to evade detection and wreak havoc. One of the most dangerous and frequent ways they attempt this is with a LOTL attack that abuses legitimate tools already in the environment. In a high-profile event from October 2025, threat actors compromised Ukrainian organizations in a LOTL attack and were able to steal data, maintain access for months, and evade detection while deploying very little malware.
Why it matters:Preventing LOTL attacks isn't as simple as blocking untrusted software by default. In this case, the tools being abused are integral to daily operations, and because the tools are legitimate and digitally signed, distinguishing between normal and malicious use is difficult.
The big picture: Like network segmentation, defending against LOTL attacks requires combining prevention with containment. By controlling both what applications can run and how trusted tools are allowed to behave, organizations build layered defenses that improve containment, resilience, and their overall security posture.
August webinar: Recognize the techniques attackers use to gain elevated privileges and see where traditional security tools leave dangerous gaps.
Tuesday, August 11 | 11 a.m. EDT
Hosted by ThreatLocker CEO Danny Jenkins and CPO Rob Allen
Old vulnerabilities are still a threat and reconnaissance that evades detection
18-year-old Cisco flaw exploited in the wild
Old vulnerabilities don't disappear—they're rediscovered
What's happening: CISA has confirmed active exploitation of CVE-2008-4128, a vulnerability affecting Cisco IOS 12.4 first discovered in 2008. The flaw allows attackers to gain full administrative control of vulnerable devices without stealing credentials, making legacy infrastructure a prime target for exploitation.
Why it matters: Legacy network devices are often considered stable or too critical to disrupt, so they are not prioritized in patching. This makes them attractive targets for attackers who routinely scan for vulnerable systems.
The big picture: Security demands more than responding to the latest CVEs. Maintaining visibility into every device and prioritizing patch management are essential to preventing both new and old vulnerabilities from becoming entry points.
New Microsoft Entra technique evades detection
How attackers are quietly mapping your environment
What's happening: Attackers are spoofing OAuth client IDs in Microsoft Entra ID authentication requests in order to identify valid accounts without completing authentication. Multiple large-scale campaigns using the technique have already been observed. The method enables attackers to identify valid accounts while generating little of the telemetry security teams typically rely on to detect reconnaissance.
Why it matters: This technique bypasses multiple defensive measures. The spoofed client IDs generate blank entries in the application field, making trend-based monitoring less effective, and they also won't trigger conditional access policies for highly targeted applications. This means better reconnaissance with fewer opportunities to be spotted.
The big picture: Identity is becoming a primary target. Organizations should continuously monitor Entra sign-in logs for unusual authentication activity—particularly requests with missing application names—and pair identity monitoring with Zero Trust controls that limit what attackers can do even if they go undetected.
ThreatLocker events
Meet the Cyber Hero Team in person at these upcoming events
Watch now: AI tools should increase productivity, not risk or IT workload. Watch this week's webinar to discover how to embrace AI without sacrificing control, compliance, or security.