Skip to content
StrikeCyberStrikeCyber
Research

Threat briefings from the front line

Exploits, engagements and field notes from our operators. Practical intelligence, no fluff.

Latest
·4 min readThreat Intelligence

The 2026 US Threat Landscape

The techniques have not changed much. What changed is the economics: attacks that used to require skill now require a budget, and the targeting reaches much further down.

Read briefing
Filter by topic
All research35 articles
·4 min

The 2026 US Threat Landscape

The techniques have not changed much. What changed is the economics: attacks that used to require skill now require a budget, and the targeting reaches much further down.

Read
·4 min

SOC 2 and Penetration Testing: What Auditors Actually Expect

No SOC 2 criterion says penetration testing. Several say you must identify vulnerabilities and evaluate whether controls operate effectively, which auditors read the obvious way.

Read
·4 min

PCI DSS Penetration Testing Requirements Explained

PCI DSS is unusually specific about testing, which makes it easier to satisfy and easier to fail. Here is what requirement 11.4 actually asks for.

Read
·4 min

HIPAA Security Rule and Penetration Testing

HIPAA does not name penetration testing. It requires an accurate and thorough risk analysis and periodic technical evaluation, and OCR has been consistent about what inadequate looks like.

Read
·4 min

Cyber Security for Financial Services in the USA

Financial services carries the most developed regulatory expectations of any US sector and some of the most motivated adversaries. The gap between compliance and resilience is where incidents happen.

Read
·3 min

Field Notes: Phishing That Bypassed MFA

An anonymized red team field note on phishing that bypasses MFA: how an adversary-in-the-middle proxy captured a live session token, what it reached, and the controls that would have stopped it.

Read
·4 min

ISO 27001 and Penetration Testing: What Auditors Expect

ISO 27001 does not mandate penetration testing by name. It requires you to manage technical vulnerabilities and verify controls work, which in practice amounts to the same thing.

Read
·4 min

Cyber Security for Healthcare in the USA

Healthcare combines the most sensitive data, systems that cannot go offline, and an attacker population that understands both. That combination is why the sector is targeted.

Read
·3 min

Field Notes: Domain Admin in a Day

An anonymized field note on reaching domain administrator in under eight hours from an ordinary user account, using four ordinary misconfigurations that nobody had connected.

Read
·4 min

NIST Cybersecurity Framework 2.0 Explained

CSF 2.0 added a sixth function and dropped the critical infrastructure framing. The change that matters most is that governance is now something you have to evidence.

Read
·3 min

Cyber Security for Federal, State and Local Government

Government environments carry legacy nobody can retire, adversaries with time and funding, and citizen data that cannot be reissued. The combination is difficult and the obligations are specific.

Read
·3 min

Field Notes: SSRF to Cloud Takeover

An anonymized field note on server-side request forgery: how one URL field in an upload feature reached the cloud metadata service and returned credentials for the account behind it.

Read
·3 min

Field Notes: The Air Gap That Was Not

An anonymized field note from an industrial assessment: the control network was described as air-gapped, and four separate connections to the corporate environment said otherwise.

Read
·4 min

Cyber Security for Law Firms in the USA

A firm holds the confidential business of every client it acts for, concentrated in one place, defended by an IT team sized for a mid-market business.

Read
·5 min

What Is Penetration Testing? A Complete 2026 Guide for US Business

Penetration testing is an authorized, simulated cyber attack that finds and safely exploits weaknesses before real attackers do. Here is what it covers, how it works and why US organizations rely on it.

Read
·4 min

CMMC Level 2: What Defense Contractors Need to Know

CMMC did not create new requirements. It created verification of requirements defense contractors have carried since 2017, which is why so many are behind.

Read
·4 min

Cyber Security for Energy, Utilities and Industrial Operators

The air gap most operators believe they have generally does not exist. Connectivity accumulates for good reasons, and nobody reassesses what it adds up to.

Read
·4 min

What Is Red Teaming? Objective-Based Adversary Emulation Explained

Red teaming emulates a real adversary working toward an objective while your team defends without warning. It measures detection and response, not just whether vulnerabilities exist.

Read
·4 min

FedRAMP Penetration Testing Requirements

FedRAMP is the most prescriptive testing regime most cloud providers will encounter. It names the attack vectors you must cover, which removes the usual scoping arguments.

Read
·4 min

Cyber Security for Schools, Districts and Universities

Education holds data about children, runs networks that must stay open to be useful, and defends both with a fraction of the resources a comparable business would have.

Read
·4 min

Penetration Testing vs Vulnerability Scanning: What Is the Difference?

Scanning gives you breadth and currency. Testing gives you depth and proof. Buying one when you needed the other is the most common and most expensive mistake in this decision.

Read
·4 min

NYDFS Part 500: Penetration Testing and the Amended Rules

Part 500 is among the most specific US cybersecurity regulations, it carries personal certification by a senior officer, and the amendments raised the bar again.

Read
·4 min

Offensive Security for MSPs and Their Clients

An MSP typically holds more privilege across a client estate than any internal administrator. Attackers worked this out some time ago, and the targeting reflects it.

Read
·4 min

Active Directory Attack Paths: How Attackers Reach Domain Admin

Domain compromise is almost never one exploit. It is a chain of ordinary misconfigurations nobody connected. Here are the links attackers use most and how to break them.

Read
·4 min

SEC Cyber Disclosure Rules: What Boards Need to Know

Four business days from determining materiality, not from discovery. The clock starts on a judgment call, which is why the judgment process needs to exist beforehand.

Read
·4 min

Identity Attacks: Why MFA Alone Is Not Enough in 2026

Having MFA enabled is not the same as being protected. The method determines whether the control holds, and attackers focus their effort on the weaker end of the range.

Read
·4 min

How Much Does Penetration Testing Cost in the USA?

Two proposals for the same environment can differ threefold, and the cheaper one is sometimes right. Here is what actually drives the number and how to compare.

Read
·4 min

Web and API Attacks: The OWASP Top 10 in Practice

The OWASP Top 10 is a useful map and a poor checklist. Here is what these categories actually look like when an operator finds them, and why access control dominates.

Read
·4 min

The Cloud Misconfigurations That Lead to Breach

Cloud environments rarely become insecure through one decision. They drift, one reasonable permission grant at a time, into an escalation path nobody designed.

Read
·4 min

Supply Chain and Third-Party Risk in the USA

A completed questionnaire tells you what a vendor says about their controls. It does not tell you what they could reach inside your environment, which is the question.

Read
·4 min

Assumed Breach: The Evolution of Offensive Security

Perimeter testing answers a question most organizations have already conceded. Assumed breach asks the more useful one: when someone gets in, how much does it cost you?

Read
·4 min

AI in Penetration Testing: What It Actually Changes in 2026

AI has genuinely changed the economics of reconnaissance and correlation. It has not changed who decides whether a finding is real. Here is where the line actually falls.

Read
·4 min

Continuous Penetration Testing vs Point-in-Time Testing

An annual test describes an environment that no longer exists by the time the report is read. Continuous testing solves that, and introduces problems of its own.

Read
·4 min

How to Run a Successful Red Team Engagement

Most red team engagements fail for organizational reasons, not technical ones: vague objectives, too many people in the know, and no capacity to act on the findings.

Read
·4 min

Ransomware Preparedness: Preventing and Recovering From Attacks

Encryption is the last step, not the attack. By the time files lock, the crew has been in your environment for days or weeks, and that window is where preparedness pays.

Read
FAQ

Research FAQs

What does the StrikeCyber research library cover?

Offensive cyber security research, field notes from real engagements, compliance guidance across SOC 2, NIST CSF, PCI DSS, HIPAA and CMMC, and US threat-landscape analysis, written by our operators.

How often is new research published?

We publish regularly as our operators surface new findings and as the threat and compliance landscape shifts. You can follow along through our RSS feed at /feed.xml.

Can I cite or share StrikeCyber research?

Yes. You are welcome to reference and cite our research with attribution. For media or speaking enquiries, get in touch.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation