š„ This Is Fine | The State of Pen Testing
"If you talk to a dozen pen testers and ask them what a pen test is, you're going to get a dozen different answers."
Penetration testing has long been a cornerstone of enterprise security ā but the landscape continues to evolve.
In this episode of the Hunter Strategy podcast, AJ King (@ScrumWhat), Jake Williams (@MalwareJake), and Joshua Marpet (@quadling - Sr. Product Security Consultant at Finite State, Faculty Member at IANS) discuss how penetration testing fits into modern enterprise risk management strategies.
From compliance requirements to real-world security validation, the conversation explores how organizations can approach testing with both technical rigor and business context.
Good security isnāt theoretical.
Itās tested.
Get the full episode ā”ļø f.mtr.cool/qfolyvslhaĀ
#CyberSecurity#PenTesting#SecurityTesting#EnterpriseSecurity
CVE-2020-2033, CVE-2020-2021, CVE-2020-2050, CVE-2026-0257, and now CVE-2026-0265
Authentication bypass, as in direct access to your internal networks over the Internet
This VPN architecture should be dead, get it off the Internet, it's a time bomb waiting to happen
When Your VPN Opens Your Private Network to the Public!
An auth bypass in Palo Alto PAN-OS CAS Auth (CVE-2026-0265) that lets an attacker connect to the company's GlobalProtect VPN.
Blog - hacktron.ai/blog/cve-2026-02ā¦
Entra App Proxy continues to be one of the biggest hidden gems of Entra P1
For over a decade, we've been able to stop exposing risky apps to the Internet by routing through agents with outbound connections to Azure
I don't care what vendor you use, just get it off the Internet
Cloudflare is right about this. You're not going to be able to patch fast enough, but you can build your systems so that the vast majority of vulnerabilities don't matter.
If you've not done that, you're going to have a bad time.
A good primer on reasoning for IaC for all the things, even outside of infrastructure
The one big caveat is, of course, the learning curve involved and the resulting increase in level of skill required for new hires
To add onto what @NathanMcNulty said, Terraform isnāt just for Azure. It can build, release, and scale infra anywhere (Azure, AWS, etc.) and manage it as code. Paired with GitHub/GitLab, Entra becomes IaC too ā more consistent, stable, and minimizing drift.
In 48 hours, weāll show you how to go from āBe Afraidā to āActionable Huntā!
Donāt miss this special webinar with @MalwareJake & Ibrahim Ahmed as they share how to turn scary headlines into focused action.
š Aug 14 ā 2:30 PM ET
Save your spot: hunterstrategy.zoom.us/webinā¦
When you bring an idea to someone, and the only thing they can do is talk about why itās exhausting, hard, or canāt do itā¦just know if youāre that kind of personā¦youāre the worst.
There is a difference between poking holes in an approach for someone to help vs. criticize.
šØ ONLY 3 DAYS LEFT TO REGISTER! šØĀ
Threat headlines are constant. Your hunts should be consistent.
Join @MalwareJake & Ibrahim Ahmed as they reveal the exact process to turn vague alerts into actionable hunts.
š Aug 14 ā 2:30 PM ET
Secure your spot now: hunterstrategy.zoom.us/webinā¦
Man there is zero question in my mind that Miami drivers are by far and away the worst drivers Iāve ever seen. Almost every single morning there is some dumbass wreck on I-95.
OK schools chief Ryan Walters issues a statement tonight where he claims that the board members who said they observed porn playing on his screen during a meeting are lying and they should resign in disgrace.
Someone needs to go tell @Apple that their speech recognition has gone into the garbage can. Itās gotten to the point for me where itās almost unusable.
Anyone else notice this trend?
I mainly use it for speech to text.
In St Louis, one PE firm owns 4 separate brands in the same geography.
Customers search āHVAC contractor near meā and donāt realize that the first 3 paid ads are from 3 companies⦠that are owned by the same parent company.
The āillusionā of getting ācompetitive bidsāā¦
Archaeologists have discovered huge, spiral-shaped cylindrical structures stretching over 600 meters (about 2,000 feet) straight down beneath the Great Pyramid of Giza. These massive findings, located more than 2 kilometers (1.2 miles) below the pyramid's base, hint at enormous hidden constructions deep underground.
1/ An investigation into the alleged identity of the mysterious Hyperliquid whale tied to illicit activity that profited ~$20M via highly leveraged positions over the past couple weeks.