
Most Valuable Pentesting (MVP): A Composable, Recursive Way to Test Anything
Editors note and the use of AI I used ChatGPT to assist with formatting, spelling, sentence structure, and the creation of visualizations designed to …
Our Blog Category

Editors note and the use of AI I used ChatGPT to assist with formatting, spelling, sentence structure, and the creation of visualizations designed to …

Repository-related risks are not limited to exposed credentials or source code. References to repositories and GitHub identities can also become vulne…
Email remains one of the most abused trust channels on the internet. Attackers do not need to compromise your infrastructure to damage your brand, tri…

[Editor’s note: I wrote this short blog post to illustrate the advantages of Continuous Penetration Testing. In this case, a tester discovered a vulne…

[Editor’s Note: Even Andreassen is one of our talented business developers. He is also an assistant professor at a Norwegian university. In this excel…

Pentesting isn’t what it used to be, folks. Gone are the days of single checklist exercises and surface-level scans. In 2025, we’re transforming the w…

This blog post seeks to outline key aspects of the methodology River Security employs to identify vulnerabilities during our penetration testing. Our …

Certificate Transparency (CT) logs are like public records for internet security. When a new TLS certificate is issued, it gets logged in these CT log…

“River Security prioritizes protecting customer assets and data from threats by identifying code repositories and searching for secrets. This approach…

At River Security, we understand the importance of monitoring cloud assets in order to protect our customers from potential threats. That’s why we hav…

Mobile applications have become a crucial part of modern business operations, with many companies relying on them to connect with customers, manage in…

As the prevalence of cyber attacks continues to rise, it’s more important than ever for organizations to protect themselves online. One tool that can …

Active Focus is designed to constantly monitor the digital attack surface of a business or organization, looking for signs of malicious activity or at…

Third party vendors and subcontractors can introduce significant risk to a company, particularly if they are not properly monitored and managed. In or…

Co-writer: Vegard Reiersen The world is more digitally connected than ever before. Criminals take advantage of this online transformation to target th…

Firewalls are considered to be a blocking control on our networks, but inherently also exists to allow users access to functionality; functionality pr…

Domains represent a crucial and vital part of the attack surface our organizations expose. A DNS (“Domain Name System”) is a central part of every org…

Cyber Criminals Can Do It, So Can We! Is there any new opportunities Cyber Threat Intelligence provide our Offensive Engineers? On a regular basis, or…

A key pillar in every organizationTECHNOLOGY Why and how do we monitor it? What kind of opportunities does it present our Offensive Security Operation…

To beat attackers at their own game, it is imperative River Security is able to more rapidly detect, uncover and find flaws in our customers environme…

River Security follow closely the attackers’ behaviors and attack techniques. In studying attackers Tactics, Techniques and Procedures (TTP’s), our to…

As we all know, at least to some extent, cryptocurrency solved the main problem (if we ask threat actors, that is) in ransomware and extortion attacks…