❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayCyberScoop

Why federal cyber defense demands an offense-driven mindset

8 September 2026 at 14:30

Federal agencies are drowning in cybersecurity data. Every day, security operations centers absorb millions of logs, scanner alerts and inventory feeds. But raw, static data isn’t actionable intelligence. Ask a room of federal CISOs to name the three critical weaknesses an adversary could exploit today to compromise their missions, and you’ll likely be met with a mountain of compliance reports.

That disconnect reveals a critical velocity problem in government risk management.      Traditional vulnerability management treats every Common Vulnerabilities and Exposures (CVE) entry and high Common Vulnerability Scoring System (CVSS) score as an equal emergency, regardless of whether it’s actually exploitable. Security teams spend weeks chasing theoretical findings, while adversaries exploit overlooked attack paths in hours. CVSS scores are static abstractions: they cannot reveal whether a flaw is reachable today, chainable with other weaknesses or capable of causing immediate mission damage.

As AI collapses the window between vulnerability disclosure and exploit execution, CISA’s issuance of BOD 26-04 marks a long-overdue pivot. The directive codifies what frontline defenders already know: agencies cannot win 90-day patch races against adversaries moving at machine speed. Federal cyber defense must shift from reactive spreadsheet patching to real-time prioritization based on exploitability, active threats and mission risk.

Vulnerable does not mean exploitable

During 30 years in IT operations and military cyber environments, I lost count of how many times I had to tell an auditor: “That high-severity CVE is a false positive, the vulnerable module isn’t running, or we’ve mitigated it six different ways.”

That gap between vulnerable and exploitable is where federal security teams lose the clock. Vulnerability scanners produce thousand-page laundry lists. Teams work from the top down, spending finite engineering hours patching high-severity “purples.” They often exhaust their time and budget before reaching the medium- and low-severity findings.

Adversaries do not follow a 90-day patch cycle. Attackers rarely burn a valuable zero-day exploit when a misconfiguration, weak trust relationship or stolen credential provides a direct path to their objective. As my colleague Todd Beebe from Freeport LNG has noted, “Credentials are the everyday zero-day.” Attackers don’t hack in when they can simply log in.

Defenders spend months building fortresses around static “crown jewel” systems while adversaries maneuver around those controls by chaining low-severity weaknesses with compromised identities. CVEs are only part of the story: misconfigurations and the tactics, techniques and procedures that live between CVEs matter just as much. We’ve validated thousands of attack paths across thousands of organizations that led to critical impact without leveraging a single CVE, and the only way to understand those paths is through offense-driven defense. Closing a vulnerability ticket on schedule doesn’t mean you have stopped an attacker. Untested assumptions are what get organizations in the news.

The cyber version of the McNamara Fallacy

Federal leaders risk falling victim to a modern cyber version of the McNamara Fallacy. Named for Defense Secretary Robert McNamara’s reliance on quantifiable metrics during the Vietnam War, it describes managing by what is easiest to count (e.g., patches applied, tickets closed and average CVSS scores) while overlooking operational reality.

I learned this lesson firsthand while leading IT and cybersecurity operations for a specialized defense unit. Our team was compliant. We checked every DISA STIG box, passed every audit and maintained immaculate documentation. Then a red team assessed our environment. Across people, process and technology, our organization performed well, but the assessment still found things a threat actor could immediately take advantage of.

When I asked whether they could return in three months to verify our fixes, they laughed. “No way,” they said. “You don’t have the budget, and we don’t have the resources.”

That experience fundamentally shifted my mindset: it is much easier to be compliant than secure.

Human-led penetration testing remains valuable, but small-scoped, point-in-time assessments cannot match today’s threat velocity. A manual test conducted annually gives you 24 hours of confidence and 364 days of guesswork. In an AI-accelerated environment, the report may be stale before the ink dries.

Proving defenses work in real time

Across modern framework developments, from NIST SP 800-53 Rev. 5 and NIST CSF 2.0 to federal zero trust mandates, FedRAMP, and Continuous Threat Exposure Management (CTEM), the market is shifting from static attestation toward validation and verification:

  • Compliance asks if a control is present and documented.
  • Validation asks if that control stops realistic attacker behavior now.
  • Verification asks if remediation eliminated the attack path in production.

To outpace adversaries, agencies must augment human expertise with autonomous penetration testing capabilities. We know this works in high-assurance public-sector environments. Under the NSA’s Continuous Autonomous Penetration Testing (CAPT) program, autonomous testing has logged 223,833 hours of operations across 28,282 completed pentests, spanning more than 3.7 million endpoints across 822 Defense Industrial Base organizations.

More importantly, the program accelerated remediation, saving more than 340,000 labor hours and enabling lean security teams to verify and close 71% of critical findings within 30 days. That is the difference between an annual-audit mindset and real-time operational defense.

Three action steps for federal leaders

Federal leaders should take three steps to operate at the speed of the threat:

  1.   Define risk through exploitability and impact. Risk is the product of likelihood and impact. But legacy vulnerability management accepts theoretical guessing of likelihood and fails to account for the consequences of the exploitation. Remediation should prioritize validated attack paths posing immediate mission risk.
  1. Move to continuous verification. In the military, we said, “Trust but verify.” In modern cyber defense, it is simply “verify.” Agencies must safely and continuously test controls, architectures, and identity permissions in production from multiple perspectives, including outside-in, assumed-breach, identity-based, and cloud-native.
  2. Verify the fix, not the activity. A ticket should not close merely because someone deployed a patch or changed a configuration. It should close only after a targeted retest confirms the exploitable attack path is gone.

As Corey Brunkow, Horizon3’s Director of Federal Operations, puts it: “Compliance is the baseline, not the finish line. In the new era of AI-enabled attacks, government and supply chain partners cannot afford to mistake a documented security control for an effective one.” The only way to know whether defenses can withstand an adversary is to send an attacker at them. Federal leaders must turn the map around, view their networks through the eyes of the adversary and continuously validate their security posture before an opponent does.

Learn how Horizon3 can help organizations move from point-in-time compliance to continuous, autonomous penetration testing.

The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.

U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang

10 August 2026 at 15:13

U.S. and South Korean cyber agencies warned Monday about a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers’ tools to target government and critical infrastructure organizations.

Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and construction, media, retail, transportation and utilities. Its global scope is far-ranging, according to Monday’s alert: Africa, the Americas, the Asia-Pacific, Europe and the Middle East.

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, which produced the advisory with the Department of Defense’s Cyber Crime Center, FBI, National Security Agency, Secret Service and Republic of Korea’s National Police Agency.

The alert is part of the #StopRansomware series, a joint FBI-CISA project aimed at network defenders.

The FBI first took notice of Gunra in April of last year. The double-extortion group established a data leak site on Tor to list victims and publish purloined data. By January of this year, Gunra had launched a formal ransomware-as-a-service affiliate and was growing in its ambition, Monday’s alert states.

“The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion,” it reads. “Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access.”

Gunra seeks initial access with known vulnerabilities in internet-facing devices like firewalls or virtual private networks, and is based on or influenced by the Conti ransomware code leaked in 2022, according to the agencies.

Research published in July by a South Korean cybersecurity firm took note of Gunra overlap with Lazarus Group, although it doesn’t explicitly mention the latter group’s name.

“These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks,” AhnLab wrote in its report.

That kind of North Korean government-ransomware gang collaboration dates back to at least 2024. Nor is Gunra alone among ransomware-as-a-service outfits recruiting penetration testers.

The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop.

❌
❌