惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
GbyAI
GbyAI
S
SegmentFault 最新的问题
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
Visual Studio Blog
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
B
Blog
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
雷峰网
雷峰网
爱范儿
爱范儿
Vercel News
Vercel News
人人都是产品经理
人人都是产品经理
U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
P
Proofpoint News Feed
A
About on SuperTechFans
I
InfoQ
F
Fortinet All Blogs
L
LangChain Blog
T
Tailwind CSS Blog

Cyble

Cyble's Executive Monitoring Module Gets An Upgrade Boost Infostealer Malware To Marketplace: The Credential Pipeline Qatar's Digital Boom Has A Blind Spot: What The Data Says AI-Powered Threat Intelligence For GCC Cyber Compliance Supply Chain Attacks In 2026: Risks And Defenses Financial Exposure: From Cyber Risk To Business Impact Ransomware Attack Vectors: 5 Endpoint Blind Spots Brand Impersonation: Detect & Take Down Threats At AI Speed Brand Impersonation Takedown: Why Manual Response Fails Ransomware Threats In The Americas H1 2026: Deep Dive Ransomware Incident Response Plan: 2025-2026 Threat Guide Ransomware Threats In Europe H1 2026: A Deep Dive Decoding The 72-hour Timeline Of A Credential-Based Attack APTs Lead The List Of Most Active Threat Actors In H1 2026 Dark Web Trends 2026: Ransomware, AI And Cyber Threats 2026 Threat Intelligence Trends, Cyber And Ransomware Report Glitch SPY RAT Distributed Via Fake Polish Rental App Operation FanTrap: FIFA 2026 Fraud Ecosystem Exposed Borrowed Trust: Cloud DNS Hijack Fuels Gambling SEO Attack FIFA World Cup 2026 Scams Surge As Fake Sites Target Fans CEO Fraud And Executive Impersonation Threats In The Gulf How AI-Powered Brand Impersonation Works — And Why Traditional Security Misses It Entirely OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign - Cyble Cyble: Challenger In 2026 Gartner® Magic Quadrant™ For CTI GCC Digital Banking Attack Surface Risks In 2026 Australian Dark Web Data Breaches Surge In 2025-2026 Gartner® Magic Quadrant™ 2026 | Cyberthreat Intelligence Operation HumanitarianBait: An Infostealer Campaign Weekly Vulnerability Report: Azure AI, Spring AI, Fortinet Bugs
Attack Surface Discovery: Why Asset Visibility Matters Most
Ashish Khaitan · 2026-08-03 · via Cyble

Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, third-party integrations, and rapid digital expansion have made the boundary between “inside” and “outside” for the enterprise increasingly difficult to define. 

Attackers exploit this ambiguity by scanning continuously for weaknesses across an organization’s hardware, software, cloud, and internet-facing assets. The uncomfortable truth security leaders must confront is simple: an organization cannot secure what it does not know it has. 

Attack surface expansion is frequently framed as a tooling gap, but the evidence points elsewhere — toward a persistent, structural failure in attack surface discovery, asset discovery, and visibility. 

Why Attack Surface Sprawl Happens 

Attack surfaces expand for several identifiable and recurring reasons. Cloud adoption introduces new workloads, storage resources, and services that may be provisioned outside formal IT review processes, creating visibility gaps.  

Effective cloud asset discovery has become important as organizations struggle to maintain awareness of resources created across distributed cloud environments. Shadow IT further increases complexity when business units deploy applications, platforms, or services without security teams being aware of their existence, creating additional shadow IT risk. 

Multi-cloud environments can fragment visibility across different providers, each with varying configuration standards and security controls. During mergers and acquisitions, organizations often inherit unknown infrastructure and assets from newly integrated entities, making it difficult to establish complete visibility. Forgotten infrastructure, including systems that were intended to be decommissioned but remain accessible online, can continue to create exposure risks. 

Third-party services also expand the attack surface by introducing dependencies on vendors, suppliers, and partners whose security weaknesses may impact the organization. In addition, temporary development environments are frequently left active, misconfigured, or unmonitored after their original purpose has ended. As organizations continue adding internet-facing assets at a rapid pace, traditional manual inventory processes struggle to maintain an accurate and complete view of the modern attack surface. 

Discovery Is the Real Challenge 

Security tools, firewalls, endpoint detection, vulnerability scanners, and vulnerability management tools can only act on assets that are already registered in an inventory. They cannot protect what has never been identified. This is why NIST’s Cybersecurity Framework places asset understanding at the very foundation of its Identify function: organizations must understand their data, hardware, software, systems, facilities, services, people, and supplier relationships before they can prioritize risk. 

Traditional asset inventories, built on periodic audits and manual record-keeping, cannot keep pace with environments that change hourly. CISA’s own directive on federal network visibility frames this directly, stating that its core focus areas, asset discovery and vulnerability enumeration, are essential building blocks of operational visibility that many organizations still lack. 

The visibility gap is not a failure of detection technology; it is a failure to first establish a complete, current record of what exists. Strong IT asset inventory security practices require organizations to continuously identify, classify, and monitor assets across their environments. 

 Why Organizations Lose Sight of Their Digital Assets 

Government agencies and independent research organizations consistently point to the same conclusion: unknown and unmanaged assets represent a significant source of organizational risk. Without a complete understanding of what exists across an environment, security teams cannot accurately assess exposure, prioritize vulnerabilities, or reduce potential attack paths. 

This challenge is reflected in CISA’s approach to asset visibility. CISA’s Binding Operational Directive 23-01 requires federal civilian agencies to maintain continuously updated asset inventories and identify vulnerabilities across discovered systems, emphasizing that comprehensive asset visibility is a necessary foundation for effective vulnerability management.  

Similarly, CISA’s Cyber Asset Attack Surface Management (CAASM) resources highlight the importance of understanding and reducing exposure across software, hardware, and network environments, reinforcing the idea that organizations must first identify their assets before they can effectively protect them. 

The UK’s National Cyber Security Centre (NCSC) has also emphasized the importance of visibility into modern attack surfaces. NCSC notes that threat actors continuously scan organizations’ hardware, software, services, and cloud assets to identify weaknesses. External attack surface management (EASM) approaches are designed to help defenders achieve comparable visibility into their exposed digital footprint.  

NCSC’s Active Cyber Defence trials further demonstrated that organizations gained security benefits from EASM capabilities beyond vulnerability identification alone, largely because these tools improved awareness of externally exposed assets. 

Cyble Research and Intelligence Labs (CRIL) has similarly documented how misconfigured and outdated internet-facing assets continue to expand opportunities for threat actors. Cyble’s research highlights sustained targeting of public-facing infrastructure, including exploitation patterns associated with campaigns such as the MOVEit-linked Clop ransomware attacks, demonstrating how exposed systems can become entry points for large-scale compromises. 

The scale of exposed infrastructure further illustrates the challenge organizations face in maintaining visibility. Cyble’s ODIN platform identified more than 660,000 exposed cloud storage buckets and over 91 million exposed hosts, with more than 200 billion files accessible due to cloud misconfigurations. These findings demonstrate the extent to which digital assets can exist outside formal security oversight and create unknown exposure risks. 

Cyble’s analysis of the attack surface management landscape also highlights that the discipline emerged in response to the growing need for organizations to discover unknown technology assets. The approach has evolved into complementary areas, including External Attack Surface Management (EASM), which focuses on internet-facing assets, and Cyber Asset Attack Surface Management (CAASM), which provides broader visibility into internal environments.  

Together, these capabilities address the central challenge facing modern security teams: gaining an accurate understanding of the assets they need to protect. 

Best Practices 

Guidance from these sources converges on a consistent set of practices: 

  • Continuous asset discovery rather than periodic, point-in-time audits. 
  • External attack surface management to maintain an attacker’s-eye view of internet-facing infrastructure. 
  • Asset inventory validation against NIST’s Identify function categories, including supplier and third-party systems. 
  • Continuous monitoring for newly exposed services, certificate issues, and configuration drift. 
  • Risk prioritization is based on exploitability and business impact once assets are known. 
  • Third-party exposure management, since vendor and supplier assets extend the organizational attack surface. 

Conclusion 

The recurring theme across CISA, NIST, NCSC, and Cyble research is not a shortage of security tools; it is a shortage of visibility. Vulnerability scanners, firewalls, and detection platforms are only as effective as the asset inventory feeding them.  

Organizations that treat discovery as a one-time or occasional exercise will continue to carry unknown, unmanaged, and forgotten assets into every future incident. Reducing organizational risk begins with a foundational discipline: knowing, continuously and comprehensively, what exists. 

Know what’s exposed before an attacker finds it first. Get a Free External Threat Profile →

References

  1. https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks 
  2. https://www.cisa.gov/resources-tools/services/cyber-asset-attack-surface-management-caasm 
  3. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf 
  4. https://www.ncsc.gov.uk/guidance/external-attack-surface-management-buyers-guide 
  5. https://www.ncsc.gov.uk/blog-post/active-cyber-defence-2-insights-easm-trials 
  6. https://cyble.com/knowledge-hub/what-is-external-attack-surface-management/
  7. https://cyble.com/knowledge-hub/third-party-risk-management-attack-surface/ 
  8. https://cyble.com/blog/unmasking-the-critical-risk-of-internet-exposed-assets-to-public-and-private-organizations/ 
  9. https://cyble.com/blog/detects-200-billion-files-exposed-in-cloud-buckets/ 
  10. https://cyble.com/blog/cyble-recognized-in-forresters-attack-surface-management-solutions-landscape-q2-2024-report/