
Most Valuable Pentesting (MVP): A Composable, Recursive Way to Test Anything
Editors note and the use of AI I used ChatGPT to assist with formatting, spelling, sentence structure, and the creation of visualizations designed to …
Our Blog Category

Editors note and the use of AI I used ChatGPT to assist with formatting, spelling, sentence structure, and the creation of visualizations designed to …
Email remains one of the most abused trust channels on the internet. Attackers do not need to compromise your infrastructure to damage your brand, tri…
We’re excited to welcome Lucas Vanaheim to River Security, where he joins us as a Senior Penetration Tester in our Offensive Security Operations Cente…
We are pleased to announce that Tomasz Czyz is joining River Security as a Senior Penetration Tester. Tomasz joins us from Atea, where he has worked a…
[Editor note: Raymond identified a potential SSRF issue within Cloudflare infrastructure. While initially difficult to exploit due to limitations and …

We’re excited to welcome Martin Nyberg to River Security, who joins us as a Penetration Tester in our Offensive Security Operations Center (OSOC). Mar…

We’re excited to welcome Valdemar Andersen to River Security, who joins us today as our new Threat Intelligence Manager. Valdemar comes to us from the…
[Editors Note: Raymond Strandheim is a principal pentester, and I asked him to share with us how he managed to weaponize a new vulnerability from Cisc…

With local leadership and senior expertise, we’re ready to meet the Swedish market River Security continues its Nordic growth journey. In September, w…

Introduction What a festival. Sikkerhetsfestivalen 2025 – my first, and definitely not my last. The organizers and the city of Lillehammer brought tog…
We’re excited to welcome Andreas Claesson as our new Principal Penetration Tester at River Security. Andreas joined us on October 1st, bringing with h…

We’re excited to welcome Mats Herman Heggelund as our new Penetration Tester at River Security. Mats joined us in September and is already proving him…

It’s been three years since I jumped head-first into building the backend systems behind River Security’s ActiveFocus platform, the engine our penetra…

At River Security, we believe that pushing boundaries is the only way to stay ahead in cybersecurity. Recently, three of our team members, Markus, Sim…
We’re so excited and extremely happy to welcome Raymond Strandheim as our new Principal Penetration Tester at River Security. With over 18 years of ex…
When I joined River Security in January 2025, I knew I was stepping into something unique. The company wasn’t just doing cyber security. It was challe…

From Junior to Senior: Simen Bai and Richard Beunk Take the Next Step At River Security, one of our guiding principles is investing in people, not jus…
We’re happy to welcome Raza Ansari as our newest Sales Executive at River Security. Raza’s addition marks a significant milestone as he becomes the 20…

We’re excited to welcome Lasse Bogen to River Security as our newest Sales Executive. With over 15 years of experience in IT and telecom sales, produc…

We are proud to announce that Cato Stensland has been promoted to the role of Offensive Security Operation Center (OSOC) Lead at River Security, effec…
River Security on Stage with Norway’s Leaders – A Defining Moment When a growing company like River Security is invited to share the stage with the Pr…

[Editor’s Note: Even Andreassen is one of our talented business developers. He is also an assistant professor at a Norwegian university. In this excel…

Pentesting isn’t what it used to be, folks. Gone are the days of single checklist exercises and surface-level scans. In 2025, we’re transforming the w…

[Editors Note: Eirik Valle Kjellby is an amazing gentleman and the latest, as of October 2024, addition to the ever growing penetration testing team a…

In this comprehensive guide I will go through the most common frameworks and regulations for Cyber Security, as there might be some confusion in how t…

A couple of weeks ago, we packed our things at River Security and headed back to the beautiful Austevoll to participate in our semi-annual Hackathon, …
We are excited to announce that Bjørnar has joined us as a Fullstack Developer, bringing a wealth of experience in programming, devops, and web develo…

This blog post seeks to outline key aspects of the methodology River Security employs to identify vulnerabilities during our penetration testing. Our …
This year’s B-Sides and DEF CON 32 were my first time ever going to the States and a hacking convention as large as DEF CON. Located in the Las Vegas …

We are proud to announce a key addition to our Board of Directors as we continue our journey of scaling and international expansion. Knut Martin Hauge…
We are very happy to announce the newest addition to our River Security team, Eirik, who will hold the position of Offensive Security Engineer! With a…

When I received the job offer to become the COO at River Security, I was thrilled, humbled, and super excited. I was joining a company with unparallel…
We are happy to introduce Christian Engen as the new Chief Operating Officer (COO) at River Security. Christian steps into this pivotal role, succeedi…

Certificate Transparency (CT) logs are like public records for internet security. When a new TLS certificate is issued, it gets logged in these CT log…

As we celebrate our fourth anniversary, we at River Security are filled with immense pride and gratitude. What started as a small, ambitious venture h…
This is River Security’s ethos: our belief system, motivation, and inspiration. Interested in working with us? Check out our jobs page. As a hacker, I…

A few years back, River Security developed and launched Active Focus, a world-first, disruptive IT security technology and service enabling penetratio…
We are happy to announce that Martin Andreassen has joined River Security as a Business Developer. Martin is an INSEAD MBA with significant internatio…

Ethical considerations in incident response, especially when dealing with sensitive data and disclosing information about security breaches, are param…
We are delighted to introduce William Kristoffersen as our latest team member, stepping into the role of Senior Penetration Tester! Through thorough i…

In the ever-evolving landscape of cybersecurity, staying ahead of potential threats requires a keen understanding of the nuanced differences between v…

There are many “vulnerabilities” that don’t need immediate fixing; best practices, security hygiene and many other priorities risk taking priority ove…

In an era where cybersecurity threats constantly evolve, organizations must stay ahead of malicious actors to safeguard their digital assets. Bug boun…

In today’s interconnected digital landscape, the importance of robust cybersecurity measures cannot be overstated. With the ever-evolving threat lands…

Change is a constant factor within any active organization, and at River Security, we’re glad to share a shift in our board that pushes us toward a fu…

Why SOC Can Give False Confidence Compared to Proactive Offensive Services In the rapidly evolving landscape of cyber security, businesses face an eve…

We are thrilled to announce our newest addition to the team, Cato Stensland, who is joining us as a Threat Intelligence Manager. With a remarkable bac…

In our company, we believe in the importance of continuous learning and staying up to date with the latest trends and developments in our field. We re…

The Importance of Employee Background Checks. Cyber Security is a field where honesty, integrity and security are of paramount importance. Companies o…

We are pleased to announce that Herman Bergsholm has officially joined River Security’s Platform Engineering team! Herman is a highly skilled develope…

Data has become the currency of our time and as such, it is crucial to ensure its security. Hackers can easily gain access to highly sensitive data th…

Social media has emerged as a significant yet often overlooked part of the attack surface for many businesses. Understanding where your brand is expos…

Richard is currently completing his bachelor’s degree in Cyber Security. His thesis focuses on malware analysis. He is an enthusiastic and driven indi…

As we look back on the year 2022, it’s clear that it was a year of significant milestones and achievements. A great deal of progress has been made, an…

“River Security prioritizes protecting customer assets and data from threats by identifying code repositories and searching for secrets. This approach…

At River Security, we understand the importance of monitoring cloud assets in order to protect our customers from potential threats. That’s why we hav…

Mobile applications have become a crucial part of modern business operations, with many companies relying on them to connect with customers, manage in…

As the prevalence of cyber attacks continues to rise, it’s more important than ever for organizations to protect themselves online. One tool that can …

Active Focus is designed to constantly monitor the digital attack surface of a business or organization, looking for signs of malicious activity or at…

Third party vendors and subcontractors can introduce significant risk to a company, particularly if they are not properly monitored and managed. In or…

Co-writer: Vegard Reiersen The world is more digitally connected than ever before. Criminals take advantage of this online transformation to target th…

We are expanding the Offensive Security Operation Center, where Markus Leding will be joining as an Offensive Security Engineer! He studied Cyber Secu…

We are happy to announce two new external members to the Board of Directors, Stine Andreassen and Karsten Duus Wetteland! Stine brings a lot to the ta…

Preben has been working with our Platform Engineering Team during the summer, so we have had the chance to get to know him well. It has been such a pl…

Firewalls are considered to be a blocking control on our networks, but inherently also exists to allow users access to functionality; functionality pr…

Domains represent a crucial and vital part of the attack surface our organizations expose. A DNS (“Domain Name System”) is a central part of every org…

Cyber Criminals Can Do It, So Can We! Is there any new opportunities Cyber Threat Intelligence provide our Offensive Engineers? On a regular basis, or…

A key pillar in every organizationTECHNOLOGY Why and how do we monitor it? What kind of opportunities does it present our Offensive Security Operation…
Are you passionate and experienced in development and architecture? Perhaps have a special thing for Cyber Security too? You might be the person we ar…

River Security has experienced substantial growth over the past two years. Our services are gaining increasing international attention and demand, and…
Combating Adversaries, The Way We Know Best “I do not believe in luck. Coincidence can happen, but I believe in well-preparedness, and proactive measu…
We want to congratulate our colleague, Simen Bai, who together with Ruben Christoffer Hegland-Antonsen and Even Bøe completed their Bachelor of Engine…
Penetration Testing exercises has for a long time has several flaws in its execution. For example: What is the scope of the penetration test? Who is b…

We are happy to announce yet an expansion of the team! It is no secret that there is a global shortage in Cyber Security competence. It has been predi…

We are thrilled to welcome a full-stack developer to the team! Our company and services are continuously expanding and evolving, and our service Activ…
A month into 2022, it’s finally time to take a look back at 2021. This was our first full year in business, and it has been beyond anything we could h…

The deadline, which was a short one, was set to the 27th of December, meaning only the most diligent and hard-working 🤶Santa’s little elves🎅 hackers…
Christmas is approaching, and here at River Security, “Santa’s helpful elves” have produced 24 challenges, one for each day in December leading up to …

Want to join an innovative start-up within the cyber security industry? Employer: River Security AS Job title: Senior Penetration Tester Deadline: App…
Join us in welcoming our future rockstar, Simen Bai to the position as Security Researcher! Throughout interview-rounds and his participation in our h…

This is a continuation of Part 1 – Acquiring Talent In Information Security. Assessing New Prospects Being able to discern the ones who “can talk the …

Hiring Great Fantastic Penetration Testers What does it take to become a successful penetration tester? How do you identify, hire and stimulate your s…
We are incredibly happy to announce our latest member to the team, Karina Årland, joining us from Beerenberg! We welcome her to the position as Accoun…

I recently published a video on YouTube on the aspect of practicing Incident Response scenarios, applying elements of gamification and planning out ho…

At the time of writing, River Security has turned one year old and looking back, we realize what a fantastic year it has been! As most one-year-olds a…

To beat attackers at their own game, it is imperative River Security is able to more rapidly detect, uncover and find flaws in our customers environme…

River Security follow closely the attackers’ behaviors and attack techniques. In studying attackers Tactics, Techniques and Procedures (TTP’s), our to…
The current threat landscape, where the number of cyberattacks are rapidly increasing, sets requirements for cybersecurity companies to always be on t…

As we all know, at least to some extent, cryptocurrency solved the main problem (if we ask threat actors, that is) in ransomware and extortion attacks…

Introduction Breaking news within our Cyber Security domain has become almost an everyday business; Cyber-Warfare and crime has become an everyday thr…
We are extremely happy to welcome Jan Petter Dale (https://www.linkedin.com/in/jan-petter-dale-6794a0174/) to our team. Jan Petter will join the team …

The Norwegian cruise company Hurtigruten was recently targeted with a successful attack directed towards large portions of their IT infrastructure. Ju…

In River, we always seek to challenge the norm and the methodology set. This also involves our way of recruiting. This topic, of finding new ethical h…

As part of our on-going strategy to only employ the best and most qualified people, we held a quite difficult (and complex) hacking competition during…

Krister will have his first day with us today. “Coming from Bouvet, having great and competent colleagues, expectations are high. I have had a conside…
People have continually been contacting me for mentorship, positions in their company or in general about how to get started in the Information Securi…

We frequently help customers deal with data-breaches and compromise, both organization-wide and incidents limited to a handful of devices. When the br…

NRK, the biggest Norwegian television broadcaster and news medium called us last week and asked, “how does actually email accounts get hacked (so easi…

Several companies have been hacked in Norway the past few weeks (Intersport, NHH), and internationally we’ve seen the same (Intel, Canon, Garmin). Riv…

Today the podcast Infosec & OSINT show was released, and our Founder and Principal Consultant Chris Dale participated on the show. He explains why bre…

Chris Dale was invited to do a webcast with XSS Rat, and why not give back to the community and say yes? The webcast discussed the following topics: H…

15 minutes for a podcast is perfect! It’s not too long, not too short and we got to share the most important things. Last month we did an in studio re…
This post will assist you in how to best start engaging a company in offensive services, because you want to understand the running risks of your comp…

We’ve contributed with a blog post at www.sans.org to shed light on smarter, more efficient and convenient ways of providing offensive services. We di…

Today we had an article featured online in the magazine “Advokatbladet”, which in English is translated into “Lawyer Magazine”. We discuss how multi-f…

This week we guest blogged to our friends over at InfoSec-Magazine. The article discusses how Cybercrime is Winning and how we can change our stories …