AI security and agents
MCP, LLM agents in production, model supply-chain risk, GenAI browser extensions. What organisations can actually control today, what depends on the provider, and which controls to require by contract.
Technical breakdowns, practical guides and operational criteria from the Hard2bit team — the same one that runs a 24/7 SOC, handles incident response, executes pentests and supports compliance programmes at mid-market and large organisations.
We publish about the work we run every day. Every article is signed by someone who has been inside the problem, not written by an external copywriter. You'll find technical breakdowns of high-impact CVEs, implementation-focused guides on NIS2, DORA, ENS and ISO 27001, and explanations of which controls actually move maturity forward and which are theatre.
We cover five areas:
When the decision is X or Y: what each option assesses, where they overlap, and when each makes sense. Written to unblock scoping and procurement calls.
Four frameworks, one control map. What each requires and how to prioritise.
Compare →Endpoint detection, cross-domain correlation or 24/7 managed service. When to pick each.
Compare →Real cost, response capability and operational control. When to internalise, when to outsource.
Compare →What each offensive exercise validates and which one the board, auditor or regulator asks for.
Compare →When an in-house CISO makes sense and when a fractional vCISO solves the equation better.
Compare →Four areas where the blog concentrates most material. Each block links to the articles that cover the fundamentals and to the equivalent service at Hard2bit.
MCP, LLM agents in production, model supply-chain risk, GenAI browser extensions. What organisations can actually control today, what depends on the provider, and which controls to require by contract.
What each type of offensive exercise actually assesses, what a useful pentest report should deliver, and how external attack surface work differs from a compliance audit.
Live campaigns and techniques observed in real engagements. ClickFix, C2 over Microsoft Teams, Microsoft 365 account takeover, npm supply-chain attacks. Vector, indicators and the controls that actually block the technique.
Boardroom-facing material: exposure dashboards a board can act on, digital supply-chain lessons for the CISO, and continuous exposure management for regulated environments.
The blog is signed by Hard2bit's founding partners and technical team. Every article carries the byline of someone who has worked the problem in a real engagement — not an external copywriter.
Filter by category
What a modern cybersecurity company should really offer: audit, pen testing, managed SOC, cloud and Microsoft 365, identity, incident response and compliance — with a practical, risk-led approach.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Microsoft has confirmed active exploitation of CVE-2026-42897, an XSS flaw in on-premises Exchange OWA that runs JavaScript the moment a crafted email is opened. What it means and how to contain it.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Passive analysis of 60 EU domains — banking, pharma, telcos, energy, retail and public sector — against the 11 emerging AI Agent Readiness standards. Aggregated data by sector.
By Adrián González · CEO y socio fundador
CISA has replaced flat patching deadlines with a four-variable risk model. What BOD 26-04 demands, and what European organisations can borrow from it.
By Adrián González · CEO y socio fundador
82% of CrowdStrike's 2025 detections brought no malware: the attacker uses the signed programs you already have. Why antivirus misses them and how to hunt them.
By Daniel O'Grady · CIO y socio fundador
Only 24% of breach notices now disclose the attack vector. What that does to supplier assessment in Europe, and what can still be demanded by contract.
By Adrián González · CEO y socio fundador
The TIBER-ES guide dates from January 2022 and never mentions DORA. Since 2025 the same procedure has been mandatory for designated entities, and several of its parts have changed.
By Daniel O'Grady · CIO y socio fundador
MITRE retired ATT&CK's detection fields and replaced them with 697 strategies and 1,758 analytics. That change explains why a coverage percentage measures the map rather than the ground.
By Adrián González · CEO y socio fundador
Production SIEMs ingest enough data to cover 90% of MITRE ATT&CK and detect 22%. Which sources to prioritise, which fields to demand and how long to keep them.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
A macOS Screen Sharing flaw hands root to anyone who can reach port 5900. Exploitation is active with Monero miners, and the usual hardening offers no protection.
By Adrián González · CEO y socio fundador
Lazarus paired fake job offers and DLL side-loading in a PDF viewer with zero-day CVE-2026-68820 in afd.sys to plant the FudModule rootkit inside European defence firms.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Unit 42, SpecterOps and Mollema got past passkey sign-in without breaking the encryption, starting from an already-compromised endpoint. The weakness is in the implementation.
By Adrián González · CEO y socio fundador
Hundreds of organisations targeted in July 2026: Payroll Pirates steals Microsoft 365 sessions with AiTM phishing, maps HR staff via Microsoft Graph and reroutes salaries.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Six US and South Korean agencies detail how Gunra operates: in through firewalls and VPNs, a back door planted inside MFA, and backups wiped before encryption.
By Adrián González · CEO y socio fundador
An attacker pivoted from a wind farm to a heating plant through a private APN assumed to be isolated, stopped a turbine and wiped its tracks — no malware.
By Daniel O'Grady · CIO y socio fundador
A deserialization flaw (CWE-502) in JetBrains TeamCity On-Premises allows unauthenticated remote code execution (CVSS 9.8). Now on CISA's KEV: timeline, detection and CI/CD hardening.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
UNC6671 calls employees on their personal phones, steals the MFA token with AiTM infrastructure and negotiates under four separate brands. What it reveals about defending financial firms.
By Daniel O'Grady · CIO y socio fundador
Progress patched the flaw on 4 June and attacks began on the 29th, the day the analysis went public. CISA added it to KEV on 7 August. What that timeline teaches about your patching deadlines.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Two suppliers can both claim ENS and cover very different things. What the boundary, the category and the audit result actually tell a buying committee.
By Adrián González · CEO y socio fundador
The ENS reaches far beyond Spanish public bodies. When a contract, a system and administrative powers line up, private suppliers' systems fall inside it too.
By Adrián González · CEO y socio fundador
For a SaaS provider selling to Spanish public bodies, ENS arrives as a tender clause with a deadline. Boundary and category decide the cost. How to get both right.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
An unauthenticated CVSS 10.0 flaw in Metabase, exploited since 3 August, handed attackers the credentials for connected databases. What to check, how to detect it and who to notify.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Edge devices went from 3% to 22% of exploitation breaches in a year. Why EDR cannot reach firewalls, VPNs and routers, and how to regain visibility without an agent.
By Adrián González · CEO y socio fundador
Verizon cut US$350m from the Yahoo price over two breaches; Marriott inherited Starwood's penalty. What to assess, how to price it and how to get it into the agreement.
By Adrián González · CEO y socio fundador
At Black Hat 2026 an AI system found attack techniques no human had catalogued first. Signature and known-TTP defence now has a much shorter shelf life.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
What does cybersecurity really do for a business? In 2026 it has stopped being an IT cost and become a key to winning contracts, a shield against losses and an engine of trust.
By Adrián González · CEO y socio fundador
Two North Korea-linked npm packages resolve their command server by reading a blank Ethereum transfer. NullReceiver defeats domain takedown — here is what changes for defenders.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
How we publish, who writes, what we cover and how to cite the material.
Several articles a month. We refresh the pillar posts (NIS2, DORA, ENS, ISO 27001, pentesting, SOC, AI security) whenever the technique or the regulatory interpretation shifts.
The Hard2bit team: SOC analysts, pentesters, compliance leads and security architects. Every article is signed by someone who has worked the problem in a real engagement, not by an external copywriter.
Offensive security (pentesting, red team, external attack surface), compliance and GRC (NIS2, DORA, ENS, ISO 27001, ISO 42001, EU AI Act), AI security (agents, MCP, LLMs), defensive operations (managed SOC, MDR, threat hunting, incident response) and analysis of live cyber threats.
The technical ones are: CVE analyses, security architecture, AI, threat hunting or pentesting content is transnational. Compliance material focuses on the European regulatory frame (NIS2, DORA, EU AI Act) and on Spanish specifics (ENS). The English edition covers the same topics adapted to the UK/EU context.
Yes, with attribution to Hard2bit and a link to the original URL. For partial reproduction or translation, get in touch and we'll coordinate.
Before you leave…
Quick 15-minute assessment and we'll tell you what to prioritise first: Microsoft 365, pentesting, vulnerability management, SOC, DORA, NIS2, ENS or ISO 27001.
No spam. Reply within 24h.