<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>River Security</title><description>Content written by our people for the cyber security community.</description><link>https://riversecurity.eu/</link><item><title>Most Valuable Pentesting (MVP): A Composable, Recursive Way to Test Anything</title><link>https://riversecurity.eu/mvp-a-composable-recursive-way-to-test-anything/</link><guid isPermaLink="true">https://riversecurity.eu/mvp-a-composable-recursive-way-to-test-anything/</guid><description>Editors note and the use of AI I used ChatGPT to assist with formatting, spelling, sentence structure, and the creation of visualizations designed to make the concepts easier to understand. I also used Claude Code to review our existing repository of hundreds of pentesting methodologies and help inform the article’s structure and graphics. The ideas,…</description><pubDate>Mon, 20 Jul 2026 16:26:14 GMT</pubDate></item><item><title>Gitjacking: From an Abandoned Repository to Website Compromise</title><link>https://riversecurity.eu/gitjacking-from-an-abandoned-repository-to-website-compromise/</link><guid isPermaLink="true">https://riversecurity.eu/gitjacking-from-an-abandoned-repository-to-website-compromise/</guid><description>Repository-related risks are not limited to exposed credentials or source code. References to repositories and GitHub identities can also become vulnerable when projects, accounts, or integrations are renamed, transferred, or abandoned. This can create an opportunity for an attack known as gitjacking. In a gitjacking scenario, an attacker claims a repository name, account name, or…</description><pubDate>Mon, 13 Jul 2026 21:10:46 GMT</pubDate></item><item><title>Spot Spoofing Risk Before Attackers Abuse Your Brand</title><link>https://riversecurity.eu/spot-spoofing-risk-before-attackers-abuse-your-brand/</link><guid isPermaLink="true">https://riversecurity.eu/spot-spoofing-risk-before-attackers-abuse-your-brand/</guid><description>Email remains one of the most abused trust channels on the internet. Attackers do not need to compromise your infrastructure to damage your brand, trick your customers, or target your employees. In many cases, they only need to make an email look like it came from you. That is where email domain protection becomes critical.…</description><pubDate>Fri, 19 Jun 2026 12:08:11 GMT</pubDate></item><item><title>Welcoming Lucas Vanaheim – Senior Penetration Tester</title><link>https://riversecurity.eu/welcoming-lucas-vanaheim-senior-penetration-tester/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-lucas-vanaheim-senior-penetration-tester/</guid><description>We’re excited to welcome Lucas Vanaheim to River Security, where he joins us as a Senior Penetration Tester in our Offensive Security Operations Center (OSOC). Lucas brings experience from Norsk Helsenett, where he has worked as a penetration tester for the past year and a half. Prior to that, he spent two years at Advania’s…</description><pubDate>Thu, 09 Apr 2026 05:56:00 GMT</pubDate></item><item><title>Continuous Penetration Testing: Why Fresh Eyes Find Fresh Bugs</title><link>https://riversecurity.eu/why-fresh-eyes-find-fresh-bugs/</link><guid isPermaLink="true">https://riversecurity.eu/why-fresh-eyes-find-fresh-bugs/</guid><description>[Editor’s note: I wrote this short blog post to illustrate the advantages of Continuous Penetration Testing. In this case, a tester discovered a vulnerability triggered by a new event in Active Focus, even though the same issue had been missed during a previous test. It’s a great example of why continuous testing matters. ~Chris Dale]…</description><pubDate>Sat, 07 Mar 2026 14:00:09 GMT</pubDate></item><item><title>Welcoming Tomasz Czyz – Senior Penetration Tester  </title><link>https://riversecurity.eu/welcoming-tomasz-czyz-senior-penetration-tester/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-tomasz-czyz-senior-penetration-tester/</guid><description>We are pleased to announce that Tomasz Czyz is joining River Security as a Senior Penetration Tester. Tomasz joins us from Atea, where he has worked as a Senior Security Consultant in recent years. He brings solid experience in penetration testing, vulnerability assessments, assumed breach engagements, and testing of network and infrastructure environments, as well…</description><pubDate>Mon, 02 Mar 2026 07:25:11 GMT</pubDate></item><item><title>SSL/TLS Management: Reducing Risks and Gaining Visibility</title><link>https://riversecurity.eu/ssl-tls-management-reducing-risks-and-gaining-visibility/</link><guid isPermaLink="true">https://riversecurity.eu/ssl-tls-management-reducing-risks-and-gaining-visibility/</guid><description>Transport Layer Security (TLS) and its predecessor SSL remain cornerstones of modern internet security. They protect confidentiality, integrity, and authentication for data in transit. But while TLS is everywhere, managing it across an organization’s infrastructure is far from straightforward. Poor management introduces hidden risks that attackers are quick to exploit. Why TLS Management Matters For…</description><pubDate>Thu, 05 Feb 2026 15:59:35 GMT</pubDate></item><item><title>Turning Cloudflare Into an SSRF Engine, Reaching What You Were Never Meant to See</title><link>https://riversecurity.eu/turning-cloudflare-into-an-ssrf-engine-reaching-what-you-were-never-meant-to-see/</link><guid isPermaLink="true">https://riversecurity.eu/turning-cloudflare-into-an-ssrf-engine-reaching-what-you-were-never-meant-to-see/</guid><description>[Editor note: Raymond identified a potential SSRF issue within Cloudflare infrastructure. While initially difficult to exploit due to limitations and unexpected behavior, further investigation confirmed real impact. By leveraging Cloudflare’s SSRF, we were able to access internal services otherwise unreachable, including bypassing certificate-based authentication. This post shares Raymond’s insights into using Cloudflare as a proxy…</description><pubDate>Thu, 29 Jan 2026 09:09:46 GMT</pubDate></item><item><title>Welcoming Martin Nyberg – Penetration Tester</title><link>https://riversecurity.eu/welcoming-martin-nyberg-penetration-tester/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-martin-nyberg-penetration-tester/</guid><description>We’re excited to welcome Martin Nyberg to River Security, who joins us as a Penetration Tester in our Offensive Security Operations Center (OSOC). Martin comes from a strong technical background with a Bachelor of Science in Computer Science from Karlstad University and nearly 13 years of experience as a backend developer. Throughout his career, he…</description><pubDate>Thu, 15 Jan 2026 08:32:42 GMT</pubDate></item><item><title>Welcoming Valdemar Andersen – Threat Intelligence Manager</title><link>https://riversecurity.eu/welcoming-valdemar-andersen-threat-intelligence-manager/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-valdemar-andersen-threat-intelligence-manager/</guid><description>We’re excited to welcome Valdemar Andersen to River Security, who joins us today as our new Threat Intelligence Manager. Valdemar comes to us from the role of Senior Cybersecurity Consultant at Experis, where he has worked closely with large and complex organizations to strengthen their security operations, incident response capabilities, and overall security architecture. With…</description><pubDate>Fri, 02 Jan 2026 11:49:27 GMT</pubDate></item><item><title>Like stealing (Cisco) ISE-cream from a kid – Weaponizing a CVE</title><link>https://riversecurity.eu/like-stealing-cisco-ise-cream-from-a-kid-weaponizing-a-cve/</link><guid isPermaLink="true">https://riversecurity.eu/like-stealing-cisco-ise-cream-from-a-kid-weaponizing-a-cve/</guid><description>[Editors Note: Raymond Strandheim is a principal pentester, and I asked him to share with us how he managed to weaponize a new vulnerability from Cisco into a working exploit which grants attackers full access to the device. Enjoy the read, I sure did! ~Chris Dale.] Introduction to the Vulnerability – Unauthenticated Remote Code Execution,…</description><pubDate>Thu, 16 Oct 2025 16:51:07 GMT</pubDate></item><item><title>From Norway to Sweden – with Europe in sight</title><link>https://riversecurity.eu/from-norway-to-sweden-with-europe-in-sight/</link><guid isPermaLink="true">https://riversecurity.eu/from-norway-to-sweden-with-europe-in-sight/</guid><description>With local leadership and senior expertise, we’re ready to meet the Swedish market River Security continues its Nordic growth journey. In September, we established our Swedish subsidiary, River Security AB, headquartered in Stockholm. This marks a significant step in bringing both technical excellence and business risk reduction to a market with enormous potential. To lead…</description><pubDate>Sun, 05 Oct 2025 19:54:31 GMT</pubDate></item><item><title>Sikkerhetsfestivalen 2025: Reflections and the Road Ahead for Cybersecurity </title><link>https://riversecurity.eu/sikkerhetsfestivalen-2025-reflections-and-the-road-ahead-for-cybersecurity/</link><guid isPermaLink="true">https://riversecurity.eu/sikkerhetsfestivalen-2025-reflections-and-the-road-ahead-for-cybersecurity/</guid><description>Introduction What a festival. Sikkerhetsfestivalen 2025 – my first, and definitely not my last. The organizers and the city of Lillehammer brought together some of the sharpest companies and minds in cybersecurity, setting a clear tone that this is one of the most critical focus areas in IT today. I can’t wait for my next…</description><pubDate>Thu, 02 Oct 2025 13:27:55 GMT</pubDate></item><item><title>Welcoming Andreas Claesson – Principal Penetration Tester</title><link>https://riversecurity.eu/welcoming-andreas-claesson-principal-penetration-tester/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-andreas-claesson-principal-penetration-tester/</guid><description>We’re excited to welcome Andreas Claesson as our new Principal Penetration Tester at River Security. Andreas joined us on October 1st, bringing with him years of experience in offensive security and application security leadership. Andreas comes to us from Mnemonic, where he served as Application Security Lead. He has extensive experience in penetration testing, application…</description><pubDate>Wed, 01 Oct 2025 10:45:44 GMT</pubDate></item><item><title>Welcoming Mats Herman Heggelund – Penetration Tester</title><link>https://riversecurity.eu/welcoming-mats-herman-heggelund-penetration-tester/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-mats-herman-heggelund-penetration-tester/</guid><description>We’re excited to welcome Mats Herman Heggelund as our new Penetration Tester at River Security. Mats joined us in September and is already proving himself as a strong addition to the offensive security team. Mats is a newly graduated computer engineer but already brings solid experience as a Security Analyst from Mnemonic. On top of…</description><pubDate>Tue, 30 Sep 2025 07:38:09 GMT</pubDate></item><item><title>Three Years of Building the Unbuildable</title><link>https://riversecurity.eu/three-years-of-building-the-unbuildable/</link><guid isPermaLink="true">https://riversecurity.eu/three-years-of-building-the-unbuildable/</guid><description>It’s been three years since I jumped head-first into building the backend systems behind River Security’s ActiveFocus platform, the engine our penetration testers rely on to continuously identify, surface, and eliminate vulnerabilities before cybercriminals can exploit them. Since then, I’ve lived and breathed every backend detail: every query, every endpoint, every collector. And along the…</description><pubDate>Fri, 15 Aug 2025 17:51:49 GMT</pubDate></item><item><title>Mastering the CWEE: How Three River Security Experts Took on One of the Toughest Web Exploitation Challenges</title><link>https://riversecurity.eu/mastering-the-cwee-how-three-river-security-experts-took-on-one-of-the-toughest-web-exploitation-challenges/</link><guid isPermaLink="true">https://riversecurity.eu/mastering-the-cwee-how-three-river-security-experts-took-on-one-of-the-toughest-web-exploitation-challenges/</guid><description>At River Security, we believe that pushing boundaries is the only way to stay ahead in cybersecurity. Recently, three of our team members, Markus, Simen and Eirik, proved this in a big way by earning the HTB Certified Web Exploitation Expert (CWEE) certification from Hack The Box. This is not an ordinary exam. It is a 10 day, hands-on challenge that…</description><pubDate>Wed, 13 Aug 2025 09:48:22 GMT</pubDate></item><item><title>Welcoming Raymond Strandheim – Principal Penetration Tester  </title><link>https://riversecurity.eu/welcoming-raymond-strandheim-principal-penetration-tester/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-raymond-strandheim-principal-penetration-tester/</guid><description>We’re so excited and extremely happy to welcome Raymond Strandheim as our new Principal Penetration Tester at River Security. With over 18 years of experience in cybersecurity consulting and a track record of delivering high-impact penetration tests, he brings both deep technical expertise and sharp strategic insight. We look forward to what we’ll accomplish together.…</description><pubDate>Sun, 03 Aug 2025 17:10:50 GMT</pubDate></item><item><title>Six Months at River Security – Building Something Different, Together</title><link>https://riversecurity.eu/six-months-at-river-security-building-something-different-together/</link><guid isPermaLink="true">https://riversecurity.eu/six-months-at-river-security-building-something-different-together/</guid><description>When I joined River Security in January 2025, I knew I was stepping into something unique. The company wasn’t just doing cyber security. It was challenging it. River had already made a name for itself with its technical edge, brilliant team, and bold approach, but it was clear that the journey had only just begun. I wasn’t…</description><pubDate>Wed, 16 Jul 2025 08:29:57 GMT</pubDate></item><item><title>Built from Within: How Simen and Richard Grew into Senior Roles at River Security</title><link>https://riversecurity.eu/built-from-within-how-simen-and-richard-grew-into-senior-roles-at-river-security/</link><guid isPermaLink="true">https://riversecurity.eu/built-from-within-how-simen-and-richard-grew-into-senior-roles-at-river-security/</guid><description>From Junior to Senior: Simen Bai and Richard Beunk Take the Next Step At River Security, one of our guiding principles is investing in people, not just hiring for skill, but growing potential. That’s why we’re especially proud to celebrate the promotion of two of our colleagues: Simen Bai and Richard Beunk, who have both advanced to…</description><pubDate>Mon, 14 Jul 2025 09:33:23 GMT</pubDate></item><item><title>One massive step closer to assembling the core team of River Security</title><link>https://riversecurity.eu/one-massive-step-closer-to-assembling-the-core-team-of-river-security/</link><guid isPermaLink="true">https://riversecurity.eu/one-massive-step-closer-to-assembling-the-core-team-of-river-security/</guid><description>We’re happy to welcome Raza Ansari as our newest Sales Executive at River Security. Raza’s addition marks a significant milestone as he becomes the 20th member of our team. This aligns with our strategic plan to expand to over 30 team members across all functions, strengthening our presence in the Nordic home market and supporting…</description><pubDate>Thu, 24 Apr 2025 21:58:26 GMT</pubDate></item><item><title>Welcome to the River Security team, Lasse!</title><link>https://riversecurity.eu/welcome-to-the-river-security-team-lasse/</link><guid isPermaLink="true">https://riversecurity.eu/welcome-to-the-river-security-team-lasse/</guid><description>We’re excited to welcome Lasse Bogen to River Security as our newest Sales Executive. With over 15 years of experience in IT and telecom sales, product management, and IT operations, Lasse brings a strong background in delivering IT solutions across the energy and retail sectors. From IT Solutions to Driving Business Growth Lasse’s career has…</description><pubDate>Fri, 07 Feb 2025 08:40:02 GMT</pubDate></item><item><title>Cato Stensland is the new OSOC Lead at River Security.</title><link>https://riversecurity.eu/cato-stensland-is-new-osoc-lead-in-river-security/</link><guid isPermaLink="true">https://riversecurity.eu/cato-stensland-is-new-osoc-lead-in-river-security/</guid><description>We are proud to announce that Cato Stensland has been promoted to the role of Offensive Security Operation Center (OSOC) Lead at River Security, effective January 1, 2025. Over the past 1.5 years, Cato has served as our Threat Intelligence Manager, demonstrating dedication, expertise, and vision that make him the perfect choice to lead our OSOC team.…</description><pubDate>Tue, 07 Jan 2025 11:01:31 GMT</pubDate></item><item><title>A special invite to the Annual conference in Bergen</title><link>https://riversecurity.eu/arskonferansen-i-bergen/</link><guid isPermaLink="true">https://riversecurity.eu/arskonferansen-i-bergen/</guid><description>River Security on Stage with Norway’s Leaders – A Defining Moment When a growing company like River Security is invited to share the stage with the Prime Minister, top leaders from the Norwegian Armed Forces, The Norwegian Police Security Service (PST), Ministry of Justice and Public Security and prominent figures from the business community, it…</description><pubDate>Fri, 06 Dec 2024 11:23:53 GMT</pubDate></item><item><title>Why Cyber Due Diligence is Critical for M&amp;A Success</title><link>https://riversecurity.eu/why-cyber-due-diligence-is-critical-for-ma-success/</link><guid isPermaLink="true">https://riversecurity.eu/why-cyber-due-diligence-is-critical-for-ma-success/</guid><description>[Editor’s Note: Even Andreassen is one of our talented business developers. He is also an assistant professor at a Norwegian university. In this excellent blog post he has given us his take on cyber due diligence and the role of River Security. Enjoy the read!~ Chris Dale] In the modern business landscape, cybersecurity risks can…</description><pubDate>Tue, 05 Nov 2024 13:00:37 GMT</pubDate></item><item><title>Pentesting is Transforming: 8 Steps to a Successful Pentest Operation in 2025!</title><link>https://riversecurity.eu/pentesting-is-transforming-8-steps-to-a-successful-pentest-operation-in-2025/</link><guid isPermaLink="true">https://riversecurity.eu/pentesting-is-transforming-8-steps-to-a-successful-pentest-operation-in-2025/</guid><description>Pentesting isn’t what it used to be, folks. Gone are the days of single checklist exercises and surface-level scans. In 2025, we’re transforming the way we think about pentesting, making it a dynamic, intelligence-driven, and collaborative practice that does more than just “find vulnerabilities.” We’re taking a proactive, adversary-informed approach that considers not only what’s in…</description><pubDate>Sat, 02 Nov 2024 21:21:52 GMT</pubDate></item><item><title>The Art of Discovery: A Penetration Tester’s Journey Through a Django Misconfiguration</title><link>https://riversecurity.eu/the-art-of-discovery-a-penetration-testers-journey-through-a-django-misconfiguration/</link><guid isPermaLink="true">https://riversecurity.eu/the-art-of-discovery-a-penetration-testers-journey-through-a-django-misconfiguration/</guid><description>[Editors Note: Eirik Valle Kjellby is an amazing gentleman and the latest, as of October 2024, addition to the ever growing penetration testing team at River Security. He continues to amaze me in his hunt for vulnerabilities as part of our continuous and always-on penetration testing efforts. In this article, Eirik shares with us one…</description><pubDate>Mon, 28 Oct 2024 22:41:14 GMT</pubDate></item><item><title>Guide to Navigate the Most Common Frameworks and Regulations for Cyber Security </title><link>https://riversecurity.eu/compliance-and-confusion-your-guide-to-navigate-the-most-common-frameworks-and-regulations-for-cyber-security/</link><guid isPermaLink="true">https://riversecurity.eu/compliance-and-confusion-your-guide-to-navigate-the-most-common-frameworks-and-regulations-for-cyber-security/</guid><description>In this comprehensive guide I will go through the most common frameworks and regulations for Cyber Security, as there might be some confusion in how to apply them to the everyday work. The frameworks and regulations we will map out here are in the table of contents below. Use the links to navigate the article.…</description><pubDate>Thu, 26 Sep 2024 07:48:33 GMT</pubDate></item><item><title>Inside River Security’s Hacker Space in Austevoll</title><link>https://riversecurity.eu/back-to-austevoll-hacker-space/</link><guid isPermaLink="true">https://riversecurity.eu/back-to-austevoll-hacker-space/</guid><description>A couple of weeks ago, we packed our things at River Security and headed back to the beautiful Austevoll to participate in our semi-annual Hackathon, which we’ve named “Hacker Space.” This event has become an important tradition in our calendar, and after last year’s success in Austevoll, there was no doubt we wanted to return…</description><pubDate>Thu, 05 Sep 2024 11:44:17 GMT</pubDate></item><item><title>Welcome to the River Security team, Bjørnar!</title><link>https://riversecurity.eu/welcome-to-the-river-security-team-bjornar/</link><guid isPermaLink="true">https://riversecurity.eu/welcome-to-the-river-security-team-bjornar/</guid><description>We are excited to announce that Bjørnar has joined us as a Fullstack Developer, bringing a wealth of experience in programming, devops, and web development. At 27 years old and originally from Larvik, Bjørnar’s journey into technology started early. He studied IKT in Sandefjord and completed his apprenticeship with Optimale Systemer in Larvik. Bjørnar then…</description><pubDate>Mon, 02 Sep 2024 07:05:20 GMT</pubDate></item><item><title>Penetration Testing Methodology – Much More Than Just Checklists</title><link>https://riversecurity.eu/penetration-testing-much-more-than-just-checklists/</link><guid isPermaLink="true">https://riversecurity.eu/penetration-testing-much-more-than-just-checklists/</guid><description>This blog post seeks to outline key aspects of the methodology River Security employs to identify vulnerabilities during our penetration testing. Our approach is continually evolving, designed to adapt to the ever-changing landscape of technology. This community has given so much to us in the past; now, it’s just about giving back by sharing our…</description><pubDate>Fri, 30 Aug 2024 10:12:55 GMT</pubDate></item><item><title>Depiction from B-Sides &amp; DEF CON 32 </title><link>https://riversecurity.eu/depiction-from-b-sides-def-con-32/</link><guid isPermaLink="true">https://riversecurity.eu/depiction-from-b-sides-def-con-32/</guid><description>This year’s B-Sides and DEF CON 32 were my first time ever going to the States and a hacking convention as large as DEF CON. Located in the Las Vegas Convention Center in the scorching heat of 45 degrees Celsius, I was about to experience the biggest hacking convention on the planet. Shout-out to the…</description><pubDate>Fri, 16 Aug 2024 18:49:33 GMT</pubDate></item><item><title>Strategic Expansion: Knut Martin Hauge Joins River Security’s Board of Directors</title><link>https://riversecurity.eu/strategic-expansion-knut-martin-hauge-joins-river-securitys-board-of-directors/</link><guid isPermaLink="true">https://riversecurity.eu/strategic-expansion-knut-martin-hauge-joins-river-securitys-board-of-directors/</guid><description>We are proud to announce a key addition to our Board of Directors as we continue our journey of scaling and international expansion. Knut Martin Hauge joins us, bringing a distinguished background in management consulting, successful tech startup ventures and corporate strategic growth initiatives. His impressive track record and expertise will be invaluable as we…</description><pubDate>Mon, 05 Aug 2024 06:10:25 GMT</pubDate></item><item><title>Welcome to River Security, Eirik!</title><link>https://riversecurity.eu/welcome-to-river-security-eirik/</link><guid isPermaLink="true">https://riversecurity.eu/welcome-to-river-security-eirik/</guid><description>We are very happy to announce the newest addition to our River Security team, Eirik, who will hold the position of Offensive Security Engineer! With a strong passion for cybersecurity and experience from both penetration testing and programming, Eirik brings a perfect skill set that will build the team even further. Eirik’s Journey to River…</description><pubDate>Thu, 01 Aug 2024 06:17:58 GMT</pubDate></item><item><title>My First Weeks as COO at River Security</title><link>https://riversecurity.eu/my-first-weeks-as-coo-at-river-security/</link><guid isPermaLink="true">https://riversecurity.eu/my-first-weeks-as-coo-at-river-security/</guid><description>When I received the job offer to become the COO at River Security, I was thrilled, humbled, and super excited. I was joining a company with unparalleled expertise in cyber security, a team passionate about challenging the norms and building top-tier products and services. Some of our team members are even hackers! 😮 With cyber…</description><pubDate>Mon, 15 Jul 2024 09:37:44 GMT</pubDate></item><item><title>Introducing new COO, Chris Dale Steps into Chief Hacking Officer</title><link>https://riversecurity.eu/introducing-new-coo-chris-dale-steps-into-chief-hacking-officer/</link><guid isPermaLink="true">https://riversecurity.eu/introducing-new-coo-chris-dale-steps-into-chief-hacking-officer/</guid><description>We are happy to introduce Christian Engen as the new Chief Operating Officer (COO) at River Security. Christian steps into this pivotal role, succeeding one of our founders, Chris Dale. With his entrepreneurial spirit and deep expertise, Christian is eager to further River Security’s mission of staying ahead of cyber threats and delivering top-tier protection…</description><pubDate>Mon, 01 Jul 2024 06:01:57 GMT</pubDate></item><item><title>Finding Attack Surface and Other Interesting Domains via Certificate Transparency Logs</title><link>https://riversecurity.eu/finding-attack-surface-and-fraudulent-domains-via-certificate-transparency-logs/</link><guid isPermaLink="true">https://riversecurity.eu/finding-attack-surface-and-fraudulent-domains-via-certificate-transparency-logs/</guid><description>Certificate Transparency (CT) logs are like public records for internet security. When a new TLS certificate is issued, it gets logged in these CT logs. This makes it easier for us to track and monitor all certificates tied to our customers domains, and perhaps more importantely, their brands. By regularly checking these logs, and subscribing…</description><pubDate>Sat, 29 Jun 2024 15:37:50 GMT</pubDate></item><item><title>Celebrating 4 Years of River Security: A Journey of Growth, Success and Stopping the Threat Actors!</title><link>https://riversecurity.eu/celebrating-4-years-of-river-security-a-journey-of-growth-success-and-stopping-the-threat-actors/</link><guid isPermaLink="true">https://riversecurity.eu/celebrating-4-years-of-river-security-a-journey-of-growth-success-and-stopping-the-threat-actors/</guid><description>As we celebrate our fourth anniversary, we at River Security are filled with immense pride and gratitude. What started as a small, ambitious venture has now grown into a robust organization with 16 dedicated employees, and we’re still hiring! Our journey has been marked by remarkable milestones, outstanding achievements, and unwavering commitment to excellence in cybersecurity.…</description><pubDate>Wed, 05 Jun 2024 08:16:06 GMT</pubDate></item><item><title>The Penetration Testers Manifesto</title><link>https://riversecurity.eu/the-penetration-testers-manifesto/</link><guid isPermaLink="true">https://riversecurity.eu/the-penetration-testers-manifesto/</guid><description>This is River Security’s ethos: our belief system, motivation, and inspiration. Interested in working with us? Check out our jobs page. As a hacker, I am driven by a relentless curiosity and a desire to uncover the hidden truths that lie just beyond our reach. I know that there is always a way to penetrate even…</description><pubDate>Thu, 30 May 2024 19:08:31 GMT</pubDate></item><item><title>Continuous Security, Real Risk Insights, and Business Value – Why Our Customers Choose Active Focus</title><link>https://riversecurity.eu/why-our-customers-choose-active-focus/</link><guid isPermaLink="true">https://riversecurity.eu/why-our-customers-choose-active-focus/</guid><description>A few years back, River Security developed and launched Active Focus, a world-first, disruptive IT security technology and service enabling penetration testers to be always-on, properly fighting against the adversary in real-time. We developed Active Focus because of the clear and obvious need for penetration testing to have a stronger real impact on threat actors,…</description><pubDate>Wed, 15 May 2024 09:54:19 GMT</pubDate></item><item><title>Say hi to Martin</title><link>https://riversecurity.eu/say-hi-to-martin/</link><guid isPermaLink="true">https://riversecurity.eu/say-hi-to-martin/</guid><description>We are happy to announce that Martin Andreassen has joined River Security as a Business Developer. Martin is an INSEAD MBA with significant international exposure, having lived and worked in seven countries, with many years of senior experience from Nordea, Northern Europe’s largest financial services group. Martin brings a wealth of knowledge and experience to…</description><pubDate>Mon, 05 Feb 2024 13:41:20 GMT</pubDate></item><item><title>Ethical Considerations in Incident Response</title><link>https://riversecurity.eu/ethical-considerations-in-incident-response/</link><guid isPermaLink="true">https://riversecurity.eu/ethical-considerations-in-incident-response/</guid><description>Ethical considerations in incident response, especially when dealing with sensitive data and disclosing information about security breaches, are paramount. These situations require a careful balance between transparency, confidentiality, legal obligations, and the protection of all parties involved. Some of the key ethical considerations to keep in mind are discussed below in this post. Privacy and…</description><pubDate>Fri, 02 Feb 2024 23:24:53 GMT</pubDate></item><item><title>Welcome William</title><link>https://riversecurity.eu/welcome-william/</link><guid isPermaLink="true">https://riversecurity.eu/welcome-william/</guid><description>We are delighted to introduce William Kristoffersen as our latest team member, stepping into the role of Senior Penetration Tester! Through thorough interview rounds and his active participation in our hacker-house event, we’ve come to recognize William as an exceptionally talented individual deeply passionate about Cyber Security. His engagement in the community and keen awareness…</description><pubDate>Thu, 01 Feb 2024 06:52:51 GMT</pubDate></item><item><title>Distinguishing Vulnerabilities, Security Hygiene, and Exploitable Issues – Our Approach</title><link>https://riversecurity.eu/navigating-the-currents-of-cybersecurity-river-securitys-approach-to-distinguishing-vulnerabilities-security-hygiene-and-exploitable-issues/</link><guid isPermaLink="true">https://riversecurity.eu/navigating-the-currents-of-cybersecurity-river-securitys-approach-to-distinguishing-vulnerabilities-security-hygiene-and-exploitable-issues/</guid><description>In the ever-evolving landscape of cybersecurity, staying ahead of potential threats requires a keen understanding of the nuanced differences between vulnerabilities, security hygiene, and issues with demonstrable impacts on confidentiality, availability, or integrity. In this blog post, we’ll delve into how River Security sets itself apart by meticulously navigating these waters, offering a comprehensive approach…</description><pubDate>Sat, 18 Nov 2023 10:47:34 GMT</pubDate></item><item><title>Strengthening the Fort: How Attack Surface Management Empowers Companies in Web Security, Mail Security, Credential Management, and Authentication</title><link>https://riversecurity.eu/strengthening-the-fort-how-attack-surface-management-empowers-companies-in-web-security-mail-security-credential-management-and-authentication/</link><guid isPermaLink="true">https://riversecurity.eu/strengthening-the-fort-how-attack-surface-management-empowers-companies-in-web-security-mail-security-credential-management-and-authentication/</guid><description>There are many “vulnerabilities” that don’t need immediate fixing; best practices, security hygiene and many other priorities risk taking priority over other more important security factors. At River Security, we differenciate between actual issues which require prioritization, and other items, often security hygiene issues which are useful to know about, but doesn’t require anyone yelling…</description><pubDate>Fri, 17 Nov 2023 19:49:01 GMT</pubDate></item><item><title>Beyond Bug Bounty – Elevating Security with Attack Surface Management</title><link>https://riversecurity.eu/beyond-bug-bounty-elevating-security-with-attack-surface-management/</link><guid isPermaLink="true">https://riversecurity.eu/beyond-bug-bounty-elevating-security-with-attack-surface-management/</guid><description>In an era where cybersecurity threats constantly evolve, organizations must stay ahead of malicious actors to safeguard their digital assets. Bug bounty programs have surged in popularity recently as a means for companies to crowdsource security testing. However, there exists an alternative approach that offers superior security coverage, higher quality and faster results, along with…</description><pubDate>Fri, 06 Oct 2023 10:10:40 GMT</pubDate></item><item><title>River Security Joins the Norwegian Cybersecurity Cluster</title><link>https://riversecurity.eu/river-security-joins-the-norwegian-cybersecurity-cluster/</link><guid isPermaLink="true">https://riversecurity.eu/river-security-joins-the-norwegian-cybersecurity-cluster/</guid><description>In today’s interconnected digital landscape, the importance of robust cybersecurity measures cannot be overstated. With the ever-evolving threat landscape, collaborative efforts and shared expertise are essential to ensure the safety and security of our digital world. We are thrilled to announce that River Security has become a proud member of the Norwegian Cybersecurity Cluster, a…</description><pubDate>Wed, 30 Aug 2023 08:52:24 GMT</pubDate></item><item><title>Changes to the Board of Directors</title><link>https://riversecurity.eu/changes-to-the-board-of-directors/</link><guid isPermaLink="true">https://riversecurity.eu/changes-to-the-board-of-directors/</guid><description>Change is a constant factor within any active organization, and at River Security, we’re glad to share a shift in our board that pushes us toward a future filled with opportunities. Firstly, we’re happy to introduce Stine Andreassen, our new Chairwoman of the Board, who brings a lot of experience, a good eye for structure,…</description><pubDate>Wed, 23 Aug 2023 08:53:36 GMT</pubDate></item><item><title>The Illusion of Security</title><link>https://riversecurity.eu/the-illusion-of-security/</link><guid isPermaLink="true">https://riversecurity.eu/the-illusion-of-security/</guid><description>Why SOC Can Give False Confidence Compared to Proactive Offensive Services In the rapidly evolving landscape of cyber security, businesses face an ever-increasing number of threats that can compromise their sensitive data and disrupt their operations. In response, companies have traditional established Security Operations Centers (SOC’s) to monitor and help defend against potential cyber-attacks. While…</description><pubDate>Thu, 10 Aug 2023 08:10:47 GMT</pubDate></item><item><title>Introducing Cato Stensland – A Security Maverick with a Vision</title><link>https://riversecurity.eu/introducing-cato-stensland-a-security-maverick-with-a-vision/</link><guid isPermaLink="true">https://riversecurity.eu/introducing-cato-stensland-a-security-maverick-with-a-vision/</guid><description>We are thrilled to announce our newest addition to the team, Cato Stensland, who is joining us as a Threat Intelligence Manager. With a remarkable background in the Intelligence Service and extensive experience across various disciplines, Cato brings a wealth of knowledge and expertise to our organization. As he joins our team, he remarks: As…</description><pubDate>Mon, 31 Jul 2023 23:24:24 GMT</pubDate></item><item><title>Our Top Resources to Stay Up to Date</title><link>https://riversecurity.eu/our-top-resources-to-stay-up-to-date/</link><guid isPermaLink="true">https://riversecurity.eu/our-top-resources-to-stay-up-to-date/</guid><description>In our company, we believe in the importance of continuous learning and staying up to date with the latest trends and developments in our field. We reached out to a few of our team members to find out their go-to resources. Here are the top recommendations from our knowledegable employees: Chris – The Bookworm Chris,…</description><pubDate>Wed, 05 Jul 2023 07:37:17 GMT</pubDate></item><item><title>Ensuring the Security of Client Data</title><link>https://riversecurity.eu/ensuring-the-security-of-client-data/</link><guid isPermaLink="true">https://riversecurity.eu/ensuring-the-security-of-client-data/</guid><description>The Importance of Employee Background Checks. Cyber Security is a field where honesty, integrity and security are of paramount importance. Companies operating in this industry must take rigorous measures to ensure the trustworthiness of their employees. Agenda Risk is a reputable provider of background checks that delivers high-quality services to a variety of industries. Their…</description><pubDate>Thu, 23 Mar 2023 11:16:15 GMT</pubDate></item><item><title>Welcome Herman!</title><link>https://riversecurity.eu/welcome-herman/</link><guid isPermaLink="true">https://riversecurity.eu/welcome-herman/</guid><description>We are pleased to announce that Herman Bergsholm has officially joined River Security’s Platform Engineering team! Herman is a highly skilled developer who has already made a name for himself in the industry. In a recent Kode24 article, he discusses using advanced technologies to efficiently monitor and handle clients’ attack surfaces through continuous data collection…</description><pubDate>Thu, 23 Feb 2023 12:33:59 GMT</pubDate></item><item><title>Protecting Your Data: Techniques for Securing Sensitive Information Online</title><link>https://riversecurity.eu/protecting-your-data-techniques-for-securing-sensitive-information-online/</link><guid isPermaLink="true">https://riversecurity.eu/protecting-your-data-techniques-for-securing-sensitive-information-online/</guid><description>Data has become the currency of our time and as such, it is crucial to ensure its security. Hackers can easily gain access to highly sensitive data through simple Google queries. Oftentimes, employees may inadvertently or unknowingly upload data on various internet solutions, such as a CMS (“Content Management System”) system or SaaS (“Software as…</description><pubDate>Thu, 23 Feb 2023 11:56:46 GMT</pubDate></item><item><title>Don’t Overlook Social Media Security: Protecting Your Brand</title><link>https://riversecurity.eu/dont-overlook-social-media-security-protecting-your-brand/</link><guid isPermaLink="true">https://riversecurity.eu/dont-overlook-social-media-security-protecting-your-brand/</guid><description>Social media has emerged as a significant yet often overlooked part of the attack surface for many businesses. Understanding where your brand is exposed online is crucial to safeguarding these channels effectively. A compromised social media account can severely damage a company’s reputation and trust, opening the door to misinformation, phishing campaigns, propaganda, and other…</description><pubDate>Thu, 23 Feb 2023 11:23:54 GMT</pubDate></item><item><title>Introducing Richard Beunk, the first hire of the year 2023!</title><link>https://riversecurity.eu/introducing-richard-beunk-the-first-hire-of-the-year-2023/</link><guid isPermaLink="true">https://riversecurity.eu/introducing-richard-beunk-the-first-hire-of-the-year-2023/</guid><description>Richard is currently completing his bachelor’s degree in Cyber Security. His thesis focuses on malware analysis. He is an enthusiastic and driven individual who is eager to bring his passion for cyber security to the team. As a Security Researcher, Richard will join our team of experts, taking on new challenges and utilizing his expertise…</description><pubDate>Tue, 31 Jan 2023 09:02:03 GMT</pubDate></item><item><title>The milestones of 2022</title><link>https://riversecurity.eu/the-milestones-of-2022/</link><guid isPermaLink="true">https://riversecurity.eu/the-milestones-of-2022/</guid><description>As we look back on the year 2022, it’s clear that it was a year of significant milestones and achievements. A great deal of progress has been made, and we have seen a wide range of advancements that will shape the future. New Team Members We are truly happy that we got to welcome new…</description><pubDate>Thu, 12 Jan 2023 10:26:14 GMT</pubDate></item><item><title>Code Repositories: A Wealth of Information and Potential Threats. How River Security Protects Your Assets</title><link>https://riversecurity.eu/code-repositories-a-wealth-of-information-and-potential-threats-how-river-security-protects-your-assets/</link><guid isPermaLink="true">https://riversecurity.eu/code-repositories-a-wealth-of-information-and-potential-threats-how-river-security-protects-your-assets/</guid><description>“River Security prioritizes protecting customer assets and data from threats by identifying code repositories and searching for secrets. This approach allows for identification of vulnerabilities and potential for improvement in customers’ security posture, ultimately enhancing protection for assets, brand, and data.”</description><pubDate>Wed, 28 Dec 2022 23:44:39 GMT</pubDate></item><item><title>Cheating the Threat Actors: How River Security Monitors Cloud Assets to Stay Ahead</title><link>https://riversecurity.eu/cheating-the-threat-actors-how-river-security-monitors-cloud-assets-to-stay-ahead/</link><guid isPermaLink="true">https://riversecurity.eu/cheating-the-threat-actors-how-river-security-monitors-cloud-assets-to-stay-ahead/</guid><description>At River Security, we understand the importance of monitoring cloud assets in order to protect our customers from potential threats. That’s why we have developed a unique approach to monitoring these assets that involves not only scanning for them, but also using small pieces of code deployed inside customers cloud environments, fully controlled and operated…</description><pubDate>Wed, 28 Dec 2022 23:36:59 GMT</pubDate></item><item><title>Mobile Apps Can Reveal Valuable Information for Attackers</title><link>https://riversecurity.eu/mobile-apps-can-reveal-valuable-information-for-attackers/</link><guid isPermaLink="true">https://riversecurity.eu/mobile-apps-can-reveal-valuable-information-for-attackers/</guid><description>Mobile applications have become a crucial part of modern business operations, with many companies relying on them to connect with customers, manage internal processes, and handle sensitive information. However, the convenience and functionality of these apps also make them a potential target for attackers looking to gain unauthorized access to an organizations systems and data.…</description><pubDate>Wed, 28 Dec 2022 23:25:20 GMT</pubDate></item><item><title>Active Trace – Adding Deception to Aid Detection and Attack Surface Management</title><link>https://riversecurity.eu/active-trace-adding-deception-to-aid-detection-and-attack-surface-management/</link><guid isPermaLink="true">https://riversecurity.eu/active-trace-adding-deception-to-aid-detection-and-attack-surface-management/</guid><description>As the prevalence of cyber attacks continues to rise, it’s more important than ever for organizations to protect themselves online. One tool that can help with this is Active Trace, a service that detects attackers cloning websites by planting traps that are difficult for the attackers to detect. When it comes to website cloning, the…</description><pubDate>Wed, 28 Dec 2022 22:43:36 GMT</pubDate></item><item><title>Combating Digital Threats with Active Focus – Your Brand</title><link>https://riversecurity.eu/combating-digital-threats-with-active-focus-your-brand/</link><guid isPermaLink="true">https://riversecurity.eu/combating-digital-threats-with-active-focus-your-brand/</guid><description>Active Focus is designed to constantly monitor the digital attack surface of a business or organization, looking for signs of malicious activity or attempts to fraudulently use the company’s brand. This can include things like the use of the company’s name, logos, or other identifying features on fake websites or other digital assets. By keeping…</description><pubDate>Thu, 15 Dec 2022 13:04:40 GMT</pubDate></item><item><title>The Key to Successful Third-Party Management in the SaaS Space</title><link>https://riversecurity.eu/the-key-to-successful-third-party-management-in-the-saas-space/</link><guid isPermaLink="true">https://riversecurity.eu/the-key-to-successful-third-party-management-in-the-saas-space/</guid><description>Third party vendors and subcontractors can introduce significant risk to a company, particularly if they are not properly monitored and managed. In order to help mitigate these risks, companies can take a number of steps to monitor and maintain an overview of their third party vendors. A major concern for many companies is that sensitive…</description><pubDate>Thu, 08 Dec 2022 16:57:40 GMT</pubDate></item><item><title>5 reasons why you should explore Attack Surface Management</title><link>https://riversecurity.eu/5-reasons-why-you-should-explore-attack-surface-management-now/</link><guid isPermaLink="true">https://riversecurity.eu/5-reasons-why-you-should-explore-attack-surface-management-now/</guid><description>Co-writer: Vegard Reiersen The world is more digitally connected than ever before. Criminals take advantage of this online transformation to target the ever-changing digital attack surface and weaknesses in online systems, networks, and infrastructure. Does Attack Surface Management offer solutions to these complex challenges? What is Attack Surface Management? If you are remotely interested in…</description><pubDate>Fri, 28 Oct 2022 07:21:34 GMT</pubDate></item><item><title>Welcome Markus!</title><link>https://riversecurity.eu/welcome-markus/</link><guid isPermaLink="true">https://riversecurity.eu/welcome-markus/</guid><description>We are expanding the Offensive Security Operation Center, where Markus Leding will be joining as an Offensive Security Engineer! He studied Cyber Security in Florida at the Valencia College. Since his return to Norway, he has been working as a Cyber Security Analyst at Advania, where he has gained considerable experience. He has completed relevant…</description><pubDate>Mon, 03 Oct 2022 09:31:25 GMT</pubDate></item><item><title>New external members to our Board of Directors!</title><link>https://riversecurity.eu/new-external-members-to-our-board-of-directors/</link><guid isPermaLink="true">https://riversecurity.eu/new-external-members-to-our-board-of-directors/</guid><description>We are happy to announce two new external members to the Board of Directors, Stine Andreassen and Karsten Duus Wetteland! Stine brings a lot to the table when it comes to innovation and business development. Her infectious passion for strategy and marketing are truly inspiring and will be extremely valuable as we keep growing. She…</description><pubDate>Thu, 29 Sep 2022 13:10:15 GMT</pubDate></item><item><title>We’re officially welcoming Preben to the team!</title><link>https://riversecurity.eu/were-officially-welcoming-preben-to-the-team/</link><guid isPermaLink="true">https://riversecurity.eu/were-officially-welcoming-preben-to-the-team/</guid><description>Preben has been working with our Platform Engineering Team during the summer, so we have had the chance to get to know him well. It has been such a pleasure having him with us during these few months, and we are thrilled that he is eager to continue working with us. He has had a…</description><pubDate>Mon, 26 Sep 2022 15:24:03 GMT</pubDate></item><item><title>Where Applications Reside, Vulnerabilities Arise – Network Services</title><link>https://riversecurity.eu/where-applications-reside-vulnerabilities-arise-network-services/</link><guid isPermaLink="true">https://riversecurity.eu/where-applications-reside-vulnerabilities-arise-network-services/</guid><description>Firewalls are considered to be a blocking control on our networks, but inherently also exists to allow users access to functionality; functionality provided by applications. Applications unfortunately regularly contain vulnerabilities, and it’s our duty to help close such vulnerabilities before attackers can take advantage of them. Active Focus and the team at the Offensive Security…</description><pubDate>Thu, 15 Sep 2022 20:57:05 GMT</pubDate></item><item><title>Why Do We Monitor for Domains? Finding Keys to the Kingdom!</title><link>https://riversecurity.eu/how-do-we-monitor-for-domains/</link><guid isPermaLink="true">https://riversecurity.eu/how-do-we-monitor-for-domains/</guid><description>Domains represent a crucial and vital part of the attack surface our organizations expose. A DNS (“Domain Name System”) is a central part of every organization and can essentially be considered as a directory of all things accessible, pointing our computer systems to which IP address responsible for serving up functionality, applications and support to…</description><pubDate>Sat, 10 Sep 2022 17:20:37 GMT</pubDate></item><item><title>Identity and Cyber Threat Intelligence</title><link>https://riversecurity.eu/identity-and-cyber-threat-intelligence/</link><guid isPermaLink="true">https://riversecurity.eu/identity-and-cyber-threat-intelligence/</guid><description>Cyber Criminals Can Do It, So Can We! Is there any new opportunities Cyber Threat Intelligence provide our Offensive Engineers? On a regular basis, organizations are compromised because of credentials of their users allow attackers an easy way into the organization, often via techniques such as Credential Stuffing and Password Spraying. It is imperative that,…</description><pubDate>Thu, 01 Sep 2022 16:07:17 GMT</pubDate></item><item><title>Why We Monitor Technology</title><link>https://riversecurity.eu/why-we-monitor-technology/</link><guid isPermaLink="true">https://riversecurity.eu/why-we-monitor-technology/</guid><description>A key pillar in every organizationTECHNOLOGY Why and how do we monitor it? What kind of opportunities does it present our Offensive Security Operations Center? With aged technology comes vulnerabilities. These can in some cases, but far from every case, be exploited by attackers. Identifying technology as it dates, but also verifying if conditions are…</description><pubDate>Tue, 23 Aug 2022 12:52:38 GMT</pubDate></item><item><title>We are looking for Senior Developers!</title><link>https://riversecurity.eu/we-are-looking-for-senior-developers/</link><guid isPermaLink="true">https://riversecurity.eu/we-are-looking-for-senior-developers/</guid><description>Are you passionate and experienced in development and architecture? Perhaps have a special thing for Cyber Security too? You might be the person we are looking for! To support our fully remote workforce we are now looking for a senior developer to help lead and build our development team. Cyber Security is an indispensable part…</description><pubDate>Tue, 09 Aug 2022 14:17:19 GMT</pubDate></item><item><title>Meet our Head of International Sales, Vegard Reiersen!</title><link>https://riversecurity.eu/meet-our-head-of-international-sales-vegard-reiersen/</link><guid isPermaLink="true">https://riversecurity.eu/meet-our-head-of-international-sales-vegard-reiersen/</guid><description>River Security has experienced substantial growth over the past two years. Our services are gaining increasing international attention and demand, and we are super happy to finally announce Vegard as our newly appointed Head of International Sales. Vegard will be responsible for growing and developing new international business while maintaining key customer and partner relationships. …</description><pubDate>Thu, 30 Jun 2022 08:33:56 GMT</pubDate></item><item><title>Two years in business</title><link>https://riversecurity.eu/two-years-in-business/</link><guid isPermaLink="true">https://riversecurity.eu/two-years-in-business/</guid><description>Combating Adversaries, The Way We Know Best “I do not believe in luck. Coincidence can happen, but I believe in well-preparedness, and proactive measures.” A little more than two years have passed since I founded this company along with Chris Dale, and I am taking a moment to dwell on the past, present and future…</description><pubDate>Mon, 27 Jun 2022 09:05:37 GMT</pubDate></item><item><title>Efficiently Weaponizing Vulnerabilities and Automating Vulnerability Hunting</title><link>https://riversecurity.eu/efficiently-weaponizing-vulnerabilities-and-automating-vulnerability-hunting/</link><guid isPermaLink="true">https://riversecurity.eu/efficiently-weaponizing-vulnerabilities-and-automating-vulnerability-hunting/</guid><description>We want to congratulate our colleague, Simen Bai, who together with Ruben Christoffer Hegland-Antonsen and Even Bøe completed their Bachelor of Engineering in Computer Science at NTNU! The bachelor thesis was written about “Efficiently Weaponizing Vulnerabilities and Automating Vulnerability Hunting”. They wanted to develop a working methodology for efficiently going from a published security vulnerability,…</description><pubDate>Fri, 10 Jun 2022 10:54:52 GMT</pubDate></item><item><title>What is an Offensive Security Operations Center?</title><link>https://riversecurity.eu/what-is-an-offensive-security-operations-center/</link><guid isPermaLink="true">https://riversecurity.eu/what-is-an-offensive-security-operations-center/</guid><description>Penetration Testing exercises has for a long time has several flaws in its execution. For example: What is the scope of the penetration test? Who is best capable of setting the scope? Clients are often not the best to answer the question regarding what the scope is. If they were, we would not have the…</description><pubDate>Thu, 12 May 2022 20:49:53 GMT</pubDate></item><item><title>A warm welcome to Robert!</title><link>https://riversecurity.eu/a-warm-welcome-to-robert/</link><guid isPermaLink="true">https://riversecurity.eu/a-warm-welcome-to-robert/</guid><description>We are happy to announce yet an expansion of the team! It is no secret that there is a global shortage in Cyber Security competence. It has been predicted that in the near future, the gap between skilled workers and the demand will increase significantly. We are therefore humbled and proud that we are in…</description><pubDate>Mon, 04 Apr 2022 06:59:57 GMT</pubDate></item><item><title>Welcome Oscar W. Halland, full-stack developer!</title><link>https://riversecurity.eu/we-are-thrilled-to-welcome-a-full-stack-developer-to-the-team/</link><guid isPermaLink="true">https://riversecurity.eu/we-are-thrilled-to-welcome-a-full-stack-developer-to-the-team/</guid><description>We are thrilled to welcome a full-stack developer to the team! Our company and services are continuously expanding and evolving, and our service Active Focus has matured significantly over the past year and a half. To help us facilitate further growth, and to maintain a user-friendly interface both in the back- and frontend, we have…</description><pubDate>Tue, 01 Mar 2022 11:21:48 GMT</pubDate></item><item><title>2021 – The Comic</title><link>https://riversecurity.eu/2021-the-comic/</link><guid isPermaLink="true">https://riversecurity.eu/2021-the-comic/</guid><description>A month into 2022, it’s finally time to take a look back at 2021. This was our first full year in business, and it has been beyond anything we could have hoped for! We are sincerely grateful for the opportunity to welcome new highly skilled team members to our River Security family. Every day we…</description><pubDate>Wed, 02 Feb 2022 08:06:02 GMT</pubDate></item><item><title>❄River Security XMAS Advent Challenge ❄</title><link>https://riversecurity.eu/river-security-xmas-advent-challenge/</link><guid isPermaLink="true">https://riversecurity.eu/river-security-xmas-advent-challenge/</guid><description>The deadline, which was a short one, was set to the 27th of December, meaning only the most diligent and hard-working 🤶Santa’s little elves🎅 hackers would be able to participate in the competition part of the challenge. The challenge was to solve as many doors/windows/hatches from the https://rsxc.no/ advent calendar as possible, and submit a…</description><pubDate>Tue, 28 Dec 2021 14:16:59 GMT</pubDate></item><item><title>Countdown to Christmas!</title><link>https://riversecurity.eu/countdown-to-christmas-with-us/</link><guid isPermaLink="true">https://riversecurity.eu/countdown-to-christmas-with-us/</guid><description>Christmas is approaching, and here at River Security, “Santa’s helpful elves” have produced 24 challenges, one for each day in December leading up to Christmas. We’ve got awesome stickers and unique coins for the hackers who provide a write-up in solving the challenges. For the top 3 best write-ups for the challenge, we have the…</description><pubDate>Fri, 19 Nov 2021 13:53:07 GMT</pubDate></item><item><title>We are hiring!</title><link>https://riversecurity.eu/we-are-hiring/</link><guid isPermaLink="true">https://riversecurity.eu/we-are-hiring/</guid><description>Want to join an innovative start-up within the cyber security industry? Employer: River Security AS Job title: Senior Penetration Tester Deadline: Apply! For the right person, there is always an opening. Form of employment: 100% Get to know River Security: https://riversecurity.eu Cyber Security is an indispensable part of all services, especially on the Internet. River Security prides ourselves in tackling Cyber Security…</description><pubDate>Mon, 15 Nov 2021 16:09:24 GMT</pubDate></item><item><title>Welcome Simen Bai!</title><link>https://riversecurity.eu/welcome-simen-bai/</link><guid isPermaLink="true">https://riversecurity.eu/welcome-simen-bai/</guid><description>Join us in welcoming our future rockstar, Simen Bai to the position as Security Researcher! Throughout interview-rounds and his participation in our hacker-house event early this fall, we have gotten to know Simen Bai to be extremely talented and passionate about Cyber Security. He is currently finishing his Bachelor of Engineering in Computer Science at…</description><pubDate>Mon, 01 Nov 2021 08:42:02 GMT</pubDate></item><item><title>Part 2 – Acquiring Talent in Information Security</title><link>https://riversecurity.eu/part-2-acquiring-talent-in-information-security/</link><guid isPermaLink="true">https://riversecurity.eu/part-2-acquiring-talent-in-information-security/</guid><description>This is a continuation of Part 1 – Acquiring Talent In Information Security. Assessing New Prospects Being able to discern the ones who “can talk the talk” from who can “walk the walk” is a challenge, but with the right tools we can greatly speed up the interview process and find high quality prospects. Within…</description><pubDate>Wed, 01 Sep 2021 10:58:02 GMT</pubDate></item><item><title>Part 1 – Acquiring Talent In Information Security</title><link>https://riversecurity.eu/acquiring-talent-in-information-security/</link><guid isPermaLink="true">https://riversecurity.eu/acquiring-talent-in-information-security/</guid><description>Hiring Great Fantastic Penetration Testers What does it take to become a successful penetration tester? How do you identify, hire and stimulate your staff? Did you know, some of the best penetration testers I know have origins from system administration and networking? Let’s discuss some different points to keep in mind when assessing current and…</description><pubDate>Tue, 24 Aug 2021 06:37:00 GMT</pubDate></item><item><title>Karina Årland – Account Executive – Welcome!</title><link>https://riversecurity.eu/karina-arland-account-executive-welcome/</link><guid isPermaLink="true">https://riversecurity.eu/karina-arland-account-executive-welcome/</guid><description>We are incredibly happy to announce our latest member to the team, Karina Årland, joining us from Beerenberg! We welcome her to the position as Account Executive. The continuous growth in our customer base and service portfolio requires us to focus on shaping the long-term customer experience beyond what is of technical relevance to our…</description><pubDate>Mon, 02 Aug 2021 06:55:29 GMT</pubDate></item><item><title>Incident Response – Practicing and Gamification</title><link>https://riversecurity.eu/incident-response-practicing-and-gamification/</link><guid isPermaLink="true">https://riversecurity.eu/incident-response-practicing-and-gamification/</guid><description>I recently published a video on YouTube on the aspect of practicing Incident Response scenarios, applying elements of gamification and planning out how we can plan to prepare against dealing with the different scenarios. The video can be found here: The lists of scenarios are included for your convenience in this post: Large number of…</description><pubDate>Thu, 01 Jul 2021 17:48:57 GMT</pubDate></item><item><title>Happy Birthday to River Security</title><link>https://riversecurity.eu/happy-birthday-to-river-security/</link><guid isPermaLink="true">https://riversecurity.eu/happy-birthday-to-river-security/</guid><description>At the time of writing, River Security has turned one year old and looking back, we realize what a fantastic year it has been! As most one-year-olds are busy learning to walk, we find ourselves running, jumping, and climbing. While constantly in the zone, either developing our service or concluding a project delivery, we rarely…</description><pubDate>Mon, 07 Jun 2021 10:22:59 GMT</pubDate></item><item><title>OODA Loops, Speed and Agility</title><link>https://riversecurity.eu/ooda-loops-speed-and-agility/</link><guid isPermaLink="true">https://riversecurity.eu/ooda-loops-speed-and-agility/</guid><description>To beat attackers at their own game, it is imperative River Security is able to more rapidly detect, uncover and find flaws in our customers environments than the threat actors. This process boils down to a process known as a OODA Loop. The OODA loops is a concept we have borrowed from the military. It…</description><pubDate>Thu, 20 May 2021 08:30:00 GMT</pubDate></item><item><title>Know Your Enemy</title><link>https://riversecurity.eu/know-your-enemy/</link><guid isPermaLink="true">https://riversecurity.eu/know-your-enemy/</guid><description>River Security follow closely the attackers’ behaviors and attack techniques. In studying attackers Tactics, Techniques and Procedures (TTP’s), our tools are sharpened and tailored to discover weaknesses in organizations defenses so we can better defend ourselves. Our Red Team uses the same attacks and techniques of attackers, and those we use in penetration tests, to…</description><pubDate>Tue, 18 May 2021 09:04:00 GMT</pubDate></item><item><title>New employee!</title><link>https://riversecurity.eu/new-employee/</link><guid isPermaLink="true">https://riversecurity.eu/new-employee/</guid><description>The current threat landscape, where the number of cyberattacks are rapidly increasing, sets requirements for cybersecurity companies to always be on the constant lookout for more skilled talent in this on-going fight on cybercrime. As the market on global scale lacks enough competent resources, we are truly happy to announce Vegar Linge Haaland as the…</description><pubDate>Mon, 03 May 2021 08:46:47 GMT</pubDate></item><item><title>Ransomware Roulette – Level up or pay up</title><link>https://riversecurity.eu/ransomware-roulette-level-up-or-pay-up/</link><guid isPermaLink="true">https://riversecurity.eu/ransomware-roulette-level-up-or-pay-up/</guid><description>As we all know, at least to some extent, cryptocurrency solved the main problem (if we ask threat actors, that is) in ransomware and extortion attacks – getting away with the money. It became so easy to monetize the criminal act of breaking into organizations and encrypt their data that RAAS was born. What is…</description><pubDate>Thu, 29 Apr 2021 10:42:18 GMT</pubDate></item><item><title>Cyber Warfare – The threat of the 0-day – Is there nothing we can do?</title><link>https://riversecurity.eu/cyber-warfare-the-threat-of-the-0-day-is-there-nothing-we-can-do/</link><guid isPermaLink="true">https://riversecurity.eu/cyber-warfare-the-threat-of-the-0-day-is-there-nothing-we-can-do/</guid><description>Introduction Breaking news within our Cyber Security domain has become almost an everyday business; Cyber-Warfare and crime has become an everyday threat against democratic values, privacy and the livelihood of most organizations are threatened. Our online and interconnected networks, ranging of hundreds of systems and hundreds of thousands of lines of code are putting us…</description><pubDate>Thu, 11 Mar 2021 20:07:39 GMT</pubDate></item><item><title>Welcoming Jan Petter Dale to the team as Technical Account Manager &amp; Security Analyst</title><link>https://riversecurity.eu/welcoming-jan-petter-dale-to-the-team-as-technical-account-manager-security-analyst/</link><guid isPermaLink="true">https://riversecurity.eu/welcoming-jan-petter-dale-to-the-team-as-technical-account-manager-security-analyst/</guid><description>We are extremely happy to welcome Jan Petter Dale (https://www.linkedin.com/in/jan-petter-dale-6794a0174/) to our team. Jan Petter will join the team as a Technical Account Manager &amp; Security Analyst. This effectively bridges the gap between our Active Focus customers and our specialists. During his 4 years at his latest employer Atea, he had amongst others, the position…</description><pubDate>Mon, 01 Feb 2021 07:41:01 GMT</pubDate></item><item><title>Will your backup save you?</title><link>https://riversecurity.eu/will-your-backup-save-you/</link><guid isPermaLink="true">https://riversecurity.eu/will-your-backup-save-you/</guid><description>The Norwegian cruise company Hurtigruten was recently targeted with a successful attack directed towards large portions of their IT infrastructure. Judging from Hurtigrutens own announcement, it appears their entire IT operations are down. We were asked by the Norway’s leading business newspaper, Dagens Næringsliv, to give our perspective on what seems to be an organized…</description><pubDate>Tue, 15 Dec 2020 07:47:39 GMT</pubDate></item><item><title>In search of ethical hackers</title><link>https://riversecurity.eu/in-search-of-ethical-hackers/</link><guid isPermaLink="true">https://riversecurity.eu/in-search-of-ethical-hackers/</guid><description>In River, we always seek to challenge the norm and the methodology set. This also involves our way of recruiting. This topic, of finding new ethical hackers through technical challenges and competitions, even caught the interest from NRK (Norway’s biggest TV broadcaster) and they invited us to explain in detail how and why this is…</description><pubDate>Mon, 16 Nov 2020 11:39:03 GMT</pubDate></item><item><title>Do you want to join us? – See what our latest hire says about the process joining River Security</title><link>https://riversecurity.eu/do-you-want-to-join-us-see-what-our-latest-hire-says-about-the-process-joining-river-security/</link><guid isPermaLink="true">https://riversecurity.eu/do-you-want-to-join-us-see-what-our-latest-hire-says-about-the-process-joining-river-security/</guid><description>As part of our on-going strategy to only employ the best and most qualified people, we held a quite difficult (and complex) hacking competition during the summer months, and Krister Kvaavik were one out of four resources/candidates to fully solve the tasks. When looking at the logs covering weeks of competition, we could see traces…</description><pubDate>Mon, 09 Nov 2020 10:29:18 GMT</pubDate></item><item><title>Say welcome to our latest hire – Krister Kvaavik!</title><link>https://riversecurity.eu/say-welcome-to-our-latest-hire-krister-kvaavik/</link><guid isPermaLink="true">https://riversecurity.eu/say-welcome-to-our-latest-hire-krister-kvaavik/</guid><description>Krister will have his first day with us today. “Coming from Bouvet, having great and competent colleagues, expectations are high. I have had a considerable career so far and I am excited for my next chapter now with River Security. When I solved the hacking challenge during summer, they contacted me for an interview and…</description><pubDate>Mon, 02 Nov 2020 08:16:30 GMT</pubDate></item><item><title>Breaking Into Information Security</title><link>https://riversecurity.eu/breaking-into-information-security/</link><guid isPermaLink="true">https://riversecurity.eu/breaking-into-information-security/</guid><description>People have continually been contacting me for mentorship, positions in their company or in general about how to get started in the Information Security industry. Thank you, I am honored. In my humble attempt to satisfy the latter, I have compiled a list of resources and some tips and tricks I often recommend to people…</description><pubDate>Mon, 19 Oct 2020 08:25:33 GMT</pubDate></item><item><title>Share and prepare</title><link>https://riversecurity.eu/share-and-prepare/</link><guid isPermaLink="true">https://riversecurity.eu/share-and-prepare/</guid><description>We frequently help customers deal with data-breaches and compromise, both organization-wide and incidents limited to a handful of devices. When the breach has been contained and the organization recovered, we always ask our customers to help us give back to the community by sharing their story. Not only is this a great learning process for all parties involved within the compromised…</description><pubDate>Thu, 17 Sep 2020 07:23:10 GMT</pubDate></item><item><title>Wake up. Don’t get your email compromised</title><link>https://riversecurity.eu/wake-up-dont-get-your-email-compromised/</link><guid isPermaLink="true">https://riversecurity.eu/wake-up-dont-get-your-email-compromised/</guid><description>NRK, the biggest Norwegian television broadcaster and news medium called us last week and asked, “how does actually email accounts get hacked (so easily)?” The reason for asking is closely linked with the recent and critical events both in Stortinget (the supreme legislature of Norway) and in various public sector organizations here in Norway. This…</description><pubDate>Tue, 08 Sep 2020 08:03:53 GMT</pubDate></item><item><title>Leaked Credentials and Vulnerabilities Lead to Compromise</title><link>https://riversecurity.eu/leaked-credentials-and-vulnerabilities-lead-to-compromise/</link><guid isPermaLink="true">https://riversecurity.eu/leaked-credentials-and-vulnerabilities-lead-to-compromise/</guid><description>Several companies have been hacked in Norway the past few weeks (Intersport, NHH), and internationally we’ve seen the same (Intel, Canon, Garmin). River Security commented in the Norwegian news magazine Dagens Næringsliv regarding this. Norwegian article: https://www.dn.no/teknologi/river-security/chris-dale/nhh/chris-dale-hjelper-bedrifter-rammet-av-losepengevirus-vi-betaler-ut-sa-mye-at-vi-sliter-med-a-skaffe-nok-bitcoin-pa-det-apne-markedet/2-1-854498 Google Translate in English: https://translate.google.com/translate?hl=&amp;sl=no&amp;tl=en&amp;u=https%3A%2F%2Fwww.dn.no%2Fteknologi%2Friver-security%2Fchris-dale%2Fnhh%2Fchris-dale-hjelper-bedrifter-rammet-av-losepengevirus-vi-betaler-ut-sa-mye-at-vi-sliter-med-a-skaffe-nok-bitcoin-pa-det-apne-markedet%2F2-1-854498 Do we really pay criminals #ransom? Ideally, we would not, and we will…</description><pubDate>Mon, 10 Aug 2020 08:08:03 GMT</pubDate></item><item><title>The Infosec &amp; OSINT Show – Breaking up the recon and pentest produces better results</title><link>https://riversecurity.eu/the-infosec-osint-show-breaking-up-the-recon-and-pentest-produces-better-results/</link><guid isPermaLink="true">https://riversecurity.eu/the-infosec-osint-show-breaking-up-the-recon-and-pentest-produces-better-results/</guid><description>Today the podcast Infosec &amp; OSINT show was released, and our Founder and Principal Consultant Chris Dale participated on the show. He explains why breaking up recon and pentest produces better results. He also explains his recon process as well as the tools he uses to map out the target’s attack surface. The 20/80 rule…</description><pubDate>Fri, 10 Jul 2020 08:46:44 GMT</pubDate></item><item><title>Interview: XSS Rat &amp; Chris Dale</title><link>https://riversecurity.eu/interview-xss-rat-chris-dale/</link><guid isPermaLink="true">https://riversecurity.eu/interview-xss-rat-chris-dale/</guid><description>Chris Dale was invited to do a webcast with XSS Rat, and why not give back to the community and say yes? The webcast discussed the following topics: How to become a certified SANS instructor. What makes you want to teach for other people. Advice on how to get into the hacking scene. How do…</description><pubDate>Tue, 07 Jul 2020 14:23:09 GMT</pubDate></item><item><title>15 minute podcast – We share our passion on cyber security</title><link>https://riversecurity.eu/15-minute-podcast-we-share-our-passion-on-cyber-security/</link><guid isPermaLink="true">https://riversecurity.eu/15-minute-podcast-we-share-our-passion-on-cyber-security/</guid><description>15 minutes for a podcast is perfect! It’s not too long, not too short and we got to share the most important things. Last month we did an in studio recording with Teknisk Ukeblad , a popular Norwegian magazine. The podcast is in Norwegian and can be listened to here: Spotify: https://open.spotify.com/episode/1rZKcADrFWjIZ3pQVyakIL?si=nyCw6PwRSmazXjux4gVScw Website player: https://www.tu.no/artikler/mot-chris-som-brenner-for-datasikkerhet-det-er-altfor-lett-a-vaere-hacker-i-norge/494506…</description><pubDate>Fri, 03 Jul 2020 10:41:39 GMT</pubDate></item><item><title>How to engage a company in Offensive Services</title><link>https://riversecurity.eu/how-to-engage-a-company-in-offensive-services/</link><guid isPermaLink="true">https://riversecurity.eu/how-to-engage-a-company-in-offensive-services/</guid><description>This post will assist you in how to best start engaging a company in offensive services, because you want to understand the running risks of your company. It highlights how you can start by assessing your own digital footprint, then move into having penetration testing services on the assets identified as most critical. Don’t start…</description><pubDate>Thu, 02 Jul 2020 08:59:41 GMT</pubDate></item><item><title>“Everybody will be hacked, it’s just a matter of when, not if” – Interview Digi.no</title><link>https://riversecurity.eu/interview-digi-no-everybody-will-be-hacked-its-just-a-matter-of-when-not-if/</link><guid isPermaLink="true">https://riversecurity.eu/interview-digi-no-everybody-will-be-hacked-its-just-a-matter-of-when-not-if/</guid><description>Today we were featured in an article on a Norwegian online magazine called Digi.no. The article discusses our company launch and some important distinctions that makes us different from many others. Following are some of the conclusions the article makes. Link to both Norwegian and translated article at the bottom. The article shares our long-term…</description><pubDate>Wed, 24 Jun 2020 10:45:31 GMT</pubDate></item><item><title>Digital Footprint – The first step in most offensive services – Guest Blog Post</title><link>https://riversecurity.eu/digital-footprint-the-first-step-in-most-offensive-services-guest-blog-post/</link><guid isPermaLink="true">https://riversecurity.eu/digital-footprint-the-first-step-in-most-offensive-services-guest-blog-post/</guid><description>We’ve contributed with a blog post at www.sans.org to shed light on smarter, more efficient and convenient ways of providing offensive services. We discuss the mutual benefits of mapping the digital footprint as a first step in the engagement, and we discuss elements of what such a digital footprint report could contain. “Organizations change continuously…</description><pubDate>Tue, 23 Jun 2020 19:56:26 GMT</pubDate></item><item><title>Weaknesses introduced due to Covid-19 and work-from-home</title><link>https://riversecurity.eu/weaknesses-related-to-work-from-home-related-to-covid-19/</link><guid isPermaLink="true">https://riversecurity.eu/weaknesses-related-to-work-from-home-related-to-covid-19/</guid><description>Today we had an article featured online in the magazine “Advokatbladet”, which in English is translated into “Lawyer Magazine”. We discuss how multi-factor authentication promises great returns for information security vs. the impact on usability. Cyber criminals are using leaked credentials from other sites, to try re-use the credentials to see if they work at…</description><pubDate>Mon, 15 Jun 2020 13:57:52 GMT</pubDate></item><item><title>Hiring – Senior Consultant</title><link>https://riversecurity.eu/hiring-senior-consultant/</link><guid isPermaLink="true">https://riversecurity.eu/hiring-senior-consultant/</guid><description>After a buzzing first couple of weeks, we’re pleased to say that there is high demands for offensive services and projects within cyber consulting. There as been high tempo and great momentum throughout partnerships and prospects in EMEA. This requires us to look at hiring more technicians to join the team. We are searching for…</description><pubDate>Mon, 15 Jun 2020 08:52:08 GMT</pubDate></item><item><title>Cybercrime is Winning – What are you going to do about it?</title><link>https://riversecurity.eu/guest-blog-post-cybercrime-is-winning-what-are-you-going-to-do-about-it/</link><guid isPermaLink="true">https://riversecurity.eu/guest-blog-post-cybercrime-is-winning-what-are-you-going-to-do-about-it/</guid><description>This week we guest blogged to our friends over at InfoSec-Magazine. The article discusses how Cybercrime is Winning and how we can change our stories and objectives to help secure ourselves better. The post discusses how we’re really in the same neighborhood as some of the worst criminals we can imagine, when we’re online. We…</description><pubDate>Thu, 11 Jun 2020 10:00:02 GMT</pubDate></item><item><title>Fraud and scam during Covid-19</title><link>https://riversecurity.eu/fraud-scam-covid19/</link><guid isPermaLink="true">https://riversecurity.eu/fraud-scam-covid19/</guid><description>Principal Consultant, Chris Dale, was yesterday at 11.30 CEST live on national TV commenting on the wide-spread and influx of scammers and fraudsters during the pandemic by news-anchor Sturla Dyregrov. See interview here (Norwegian): https://www.tv2.no/v/1570659/ Telenor had blocked more than 200.000 fraud attempts every day, and tens of thousands of fraud domains are generated every…</description><pubDate>Wed, 10 Jun 2020 08:06:02 GMT</pubDate></item></channel></rss>