Threat briefings from the front line
Exploits, engagements and field notes from our operators. Practical intelligence, no fluff.
The 2026 US Threat Landscape
The techniques have not changed much. What changed is the economics: attacks that used to require skill now require a budget, and the targeting reaches much further down.
ReadSOC 2 and Penetration Testing: What Auditors Actually Expect
No SOC 2 criterion says penetration testing. Several say you must identify vulnerabilities and evaluate whether controls operate effectively, which auditors read the obvious way.
ReadPCI DSS Penetration Testing Requirements Explained
PCI DSS is unusually specific about testing, which makes it easier to satisfy and easier to fail. Here is what requirement 11.4 actually asks for.
ReadHIPAA Security Rule and Penetration Testing
HIPAA does not name penetration testing. It requires an accurate and thorough risk analysis and periodic technical evaluation, and OCR has been consistent about what inadequate looks like.
ReadCyber Security for Financial Services in the USA
Financial services carries the most developed regulatory expectations of any US sector and some of the most motivated adversaries. The gap between compliance and resilience is where incidents happen.
ReadField Notes: Phishing That Bypassed MFA
An anonymized red team field note on phishing that bypasses MFA: how an adversary-in-the-middle proxy captured a live session token, what it reached, and the controls that would have stopped it.
ReadISO 27001 and Penetration Testing: What Auditors Expect
ISO 27001 does not mandate penetration testing by name. It requires you to manage technical vulnerabilities and verify controls work, which in practice amounts to the same thing.
ReadCyber Security for Healthcare in the USA
Healthcare combines the most sensitive data, systems that cannot go offline, and an attacker population that understands both. That combination is why the sector is targeted.
ReadField Notes: Domain Admin in a Day
An anonymized field note on reaching domain administrator in under eight hours from an ordinary user account, using four ordinary misconfigurations that nobody had connected.
ReadNIST Cybersecurity Framework 2.0 Explained
CSF 2.0 added a sixth function and dropped the critical infrastructure framing. The change that matters most is that governance is now something you have to evidence.
ReadCyber Security for Federal, State and Local Government
Government environments carry legacy nobody can retire, adversaries with time and funding, and citizen data that cannot be reissued. The combination is difficult and the obligations are specific.
ReadField Notes: SSRF to Cloud Takeover
An anonymized field note on server-side request forgery: how one URL field in an upload feature reached the cloud metadata service and returned credentials for the account behind it.
ReadField Notes: The Air Gap That Was Not
An anonymized field note from an industrial assessment: the control network was described as air-gapped, and four separate connections to the corporate environment said otherwise.
ReadCyber Security for Law Firms in the USA
A firm holds the confidential business of every client it acts for, concentrated in one place, defended by an IT team sized for a mid-market business.
ReadWhat Is Penetration Testing? A Complete 2026 Guide for US Business
Penetration testing is an authorized, simulated cyber attack that finds and safely exploits weaknesses before real attackers do. Here is what it covers, how it works and why US organizations rely on it.
ReadCMMC Level 2: What Defense Contractors Need to Know
CMMC did not create new requirements. It created verification of requirements defense contractors have carried since 2017, which is why so many are behind.
ReadCyber Security for Energy, Utilities and Industrial Operators
The air gap most operators believe they have generally does not exist. Connectivity accumulates for good reasons, and nobody reassesses what it adds up to.
ReadWhat Is Red Teaming? Objective-Based Adversary Emulation Explained
Red teaming emulates a real adversary working toward an objective while your team defends without warning. It measures detection and response, not just whether vulnerabilities exist.
ReadFedRAMP Penetration Testing Requirements
FedRAMP is the most prescriptive testing regime most cloud providers will encounter. It names the attack vectors you must cover, which removes the usual scoping arguments.
ReadCyber Security for Schools, Districts and Universities
Education holds data about children, runs networks that must stay open to be useful, and defends both with a fraction of the resources a comparable business would have.
ReadPenetration Testing vs Vulnerability Scanning: What Is the Difference?
Scanning gives you breadth and currency. Testing gives you depth and proof. Buying one when you needed the other is the most common and most expensive mistake in this decision.
ReadNYDFS Part 500: Penetration Testing and the Amended Rules
Part 500 is among the most specific US cybersecurity regulations, it carries personal certification by a senior officer, and the amendments raised the bar again.
ReadOffensive Security for MSPs and Their Clients
An MSP typically holds more privilege across a client estate than any internal administrator. Attackers worked this out some time ago, and the targeting reflects it.
ReadActive Directory Attack Paths: How Attackers Reach Domain Admin
Domain compromise is almost never one exploit. It is a chain of ordinary misconfigurations nobody connected. Here are the links attackers use most and how to break them.
ReadSEC Cyber Disclosure Rules: What Boards Need to Know
Four business days from determining materiality, not from discovery. The clock starts on a judgment call, which is why the judgment process needs to exist beforehand.
ReadIdentity Attacks: Why MFA Alone Is Not Enough in 2026
Having MFA enabled is not the same as being protected. The method determines whether the control holds, and attackers focus their effort on the weaker end of the range.
ReadHow Much Does Penetration Testing Cost in the USA?
Two proposals for the same environment can differ threefold, and the cheaper one is sometimes right. Here is what actually drives the number and how to compare.
ReadWeb and API Attacks: The OWASP Top 10 in Practice
The OWASP Top 10 is a useful map and a poor checklist. Here is what these categories actually look like when an operator finds them, and why access control dominates.
ReadThe Cloud Misconfigurations That Lead to Breach
Cloud environments rarely become insecure through one decision. They drift, one reasonable permission grant at a time, into an escalation path nobody designed.
ReadSupply Chain and Third-Party Risk in the USA
A completed questionnaire tells you what a vendor says about their controls. It does not tell you what they could reach inside your environment, which is the question.
ReadAssumed Breach: The Evolution of Offensive Security
Perimeter testing answers a question most organizations have already conceded. Assumed breach asks the more useful one: when someone gets in, how much does it cost you?
ReadAI in Penetration Testing: What It Actually Changes in 2026
AI has genuinely changed the economics of reconnaissance and correlation. It has not changed who decides whether a finding is real. Here is where the line actually falls.
ReadContinuous Penetration Testing vs Point-in-Time Testing
An annual test describes an environment that no longer exists by the time the report is read. Continuous testing solves that, and introduces problems of its own.
ReadHow to Run a Successful Red Team Engagement
Most red team engagements fail for organizational reasons, not technical ones: vague objectives, too many people in the know, and no capacity to act on the findings.
ReadRansomware Preparedness: Preventing and Recovering From Attacks
Encryption is the last step, not the attack. By the time files lock, the crew has been in your environment for days or weeks, and that window is where preparedness pays.
ReadResearch FAQs
What does the StrikeCyber research library cover?
Offensive cyber security research, field notes from real engagements, compliance guidance across SOC 2, NIST CSF, PCI DSS, HIPAA and CMMC, and US threat-landscape analysis, written by our operators.
How often is new research published?
We publish regularly as our operators surface new findings and as the threat and compliance landscape shifts. You can follow along through our RSS feed at /feed.xml.
Can I cite or share StrikeCyber research?
Yes. You are welcome to reference and cite our research with attribution. For media or speaking enquiries, get in touch.
Ready to take the offensive?
StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.
No obligation, no sales pressure. A senior operator replies within one business day.
