AI security and agents
MCP, LLM agents in production, model supply-chain risk, GenAI browser extensions. What organisations can actually control today, what depends on the provider, and which controls to require by contract.
Technical breakdowns, practical guides and operational criteria from the Hard2bit team — the same one that runs a 24/7 SOC, handles incident response, executes pentests and supports compliance programmes at mid-market and large organisations.
We publish about the work we run every day. Every article is signed by someone who has been inside the problem, not written by an external copywriter. You'll find technical breakdowns of high-impact CVEs, implementation-focused guides on NIS2, DORA, ENS and ISO 27001, and explanations of which controls actually move maturity forward and which are theatre.
We cover five areas:
When the decision is X or Y: what each option assesses, where they overlap, and when each makes sense. Written to unblock scoping and procurement calls.
Four frameworks, one control map. What each requires and how to prioritise.
Compare →Endpoint detection, cross-domain correlation or 24/7 managed service. When to pick each.
Compare →Real cost, response capability and operational control. When to internalise, when to outsource.
Compare →What each offensive exercise validates and which one the board, auditor or regulator asks for.
Compare →When an in-house CISO makes sense and when a fractional vCISO solves the equation better.
Compare →Four areas where the blog concentrates most material. Each block links to the articles that cover the fundamentals and to the equivalent service at Hard2bit.
MCP, LLM agents in production, model supply-chain risk, GenAI browser extensions. What organisations can actually control today, what depends on the provider, and which controls to require by contract.
What each type of offensive exercise actually assesses, what a useful pentest report should deliver, and how external attack surface work differs from a compliance audit.
Live campaigns and techniques observed in real engagements. ClickFix, C2 over Microsoft Teams, Microsoft 365 account takeover, npm supply-chain attacks. Vector, indicators and the controls that actually block the technique.
Boardroom-facing material: exposure dashboards a board can act on, digital supply-chain lessons for the CISO, and continuous exposure management for regulated environments.
The blog is signed by Hard2bit's founding partners and technical team. Every article carries the byline of someone who has worked the problem in a real engagement — not an external copywriter.
Filter by category
What a modern cybersecurity company should really offer: audit, pen testing, managed SOC, cloud and Microsoft 365, identity, incident response and compliance — with a practical, risk-led approach.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Microsoft has confirmed active exploitation of CVE-2026-42897, an XSS flaw in on-premises Exchange OWA that runs JavaScript the moment a crafted email is opened. What it means and how to contain it.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Passive analysis of 60 EU domains — banking, pharma, telcos, energy, retail and public sector — against the 11 emerging AI Agent Readiness standards. Aggregated data by sector.
By Adrián González · CEO y socio fundador
What tiered administration is, what belongs in Tier 0, why so many organisations skip it, and which controls and evidence prove the model exists.
By Adrián González · CEO y socio fundador
Proofpoint and Volexity separately document Chinese groups exploiting three Chrome and Windows zero-days in the gap between the Chromium fix and the browser release.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
On 29 September we will have a stand at Digitaliza Madrid and Thilina Manana joins the panel on the human factor and the supply chain.
By Adrián González · CEO y socio fundador
By leaving the SMTP envelope sender empty, an attacker sidesteps the RejectDirectSend control and slips external mail into Microsoft 365 as if it were internal. Detection and defence.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
We scanned SPF and DMARC across 219 large companies in 8 sectors: 73% block, 38% at reject, 22% with SPF at the edge of the limit. What RFC 9989 requires and how to reach p=reject.
By Adrián González · CEO y socio fundador
PostGREShell (CVE-2026-6471) lets a REPLICATION account load code on the PostgreSQL server. Conditions, trail, detection, and how to patch without breaking logical replication.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
CVE-2026-48710, a CVSS 6.5 Starlette flaw, joins the KEV catalogue after being used to break into AI gateways without credentials. Who is exposed, how to detect it and how to patch.
By Daniel O'Grady · CIO y socio fundador
Microsoft will block NTLM by default in the next Windows release and tightens NTLMv1 in October 2026. Why it persists on your network, which events to audit and how to remove it in phases.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
US and Canadian courts handed database copies to their case management vendor to debug faults, and an intruder had them for four months. What EU rules require and what to check in your contracts.
By Adrián González · CEO y socio fundador
An unauthorised BGP announcement diverted Softaculous traffic for 33 hours, handed the attacker a valid certificate and served a Virtualizor update with root. What failed and what to check.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
CVE-2026-82329 lets attackers mint Artifactory admin tokens with no credentials. Patched 28 August, exploited by 1 September, now on CISA's KEV catalogue.
By Adrián González · CEO y socio fundador
Three DDoS attacks in three months struck ID-porten, Norway's digital identity gateway. What the campaign reveals, and what any organisation that depends on a shared layer should take from it.
By Daniel O'Grady · CIO y socio fundador
A business guide to DDoS protection: what to contract upstream, what your architecture must do, how to rehearse the response and what NIS2 demands. With 2026 data: 5,343 attacks mitigated every hour.
By Adrián González · CEO y socio fundador
In 2025 NIST withdrew the incident response model much Spanish-language guidance still copies. What a plan needs today, the deadlines NIS2, DORA and Spain's ENS impose, and how to test it.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
The firewall blocked the request and that log entry carried the order in: how GhostJacking hijacks AI agents through the data they trust most.
By Daniel O'Grady · CIO y socio fundador
CISA has replaced flat patching deadlines with a four-variable risk model. What BOD 26-04 demands, and what European organisations can borrow from it.
By Adrián González · CEO y socio fundador
82% of CrowdStrike's 2025 detections brought no malware: the attacker uses the signed programs you already have. Why antivirus misses them and how to hunt them.
By Daniel O'Grady · CIO y socio fundador
Only 24% of breach notices now disclose the attack vector. What that does to supplier assessment in Europe, and what can still be demanded by contract.
By Adrián González · CEO y socio fundador
The TIBER-ES guide dates from January 2022 and never mentions DORA. Since 2025 the same procedure has been mandatory for designated entities, and several of its parts have changed.
By Daniel O'Grady · CIO y socio fundador
MITRE retired ATT&CK's detection fields and replaced them with 697 strategies and 1,758 analytics. That change explains why a coverage percentage measures the map rather than the ground.
By Adrián González · CEO y socio fundador
Production SIEMs ingest enough data to cover 90% of MITRE ATT&CK and detect 22%. Which sources to prioritise, which fields to demand and how long to keep them.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
A macOS Screen Sharing flaw hands root to anyone who can reach port 5900. Exploitation is active with Monero miners, and the usual hardening offers no protection.
By Adrián González · CEO y socio fundador
Lazarus paired fake job offers and DLL side-loading in a PDF viewer with zero-day CVE-2026-68820 in afd.sys to plant the FudModule rootkit inside European defence firms.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Unit 42, SpecterOps and Mollema got past passkey sign-in without breaking the encryption, starting from an already-compromised endpoint. The weakness is in the implementation.
By Adrián González · CEO y socio fundador
How we publish, who writes, what we cover and how to cite the material.
Several articles a month. We refresh the pillar posts (NIS2, DORA, ENS, ISO 27001, pentesting, SOC, AI security) whenever the technique or the regulatory interpretation shifts.
The Hard2bit team: SOC analysts, pentesters, compliance leads and security architects. Every article is signed by someone who has worked the problem in a real engagement, not by an external copywriter.
Offensive security (pentesting, red team, external attack surface), compliance and GRC (NIS2, DORA, ENS, ISO 27001, ISO 42001, EU AI Act), AI security (agents, MCP, LLMs), defensive operations (managed SOC, MDR, threat hunting, incident response) and analysis of live cyber threats.
The technical ones are: CVE analyses, security architecture, AI, threat hunting or pentesting content is transnational. Compliance material focuses on the European regulatory frame (NIS2, DORA, EU AI Act) and on Spanish specifics (ENS). The English edition covers the same topics adapted to the UK/EU context.
Yes, with attribution to Hard2bit and a link to the original URL. For partial reproduction or translation, get in touch and we'll coordinate.
Before you leave…
Quick 15-minute assessment and we'll tell you what to prioritise first: Microsoft 365, pentesting, vulnerability management, SOC, DORA, NIS2, ENS or ISO 27001.
No spam. Reply within 24h.