Infoblox Expands into EASM Market with Attack Surface & Supply Chain Risk Tools
Infoblox launches solutions in the external attack surface management (EASM) sector, introducing tools to address attack surface and supply chain risk.
Expansion of Exposure Management Portfolio
The company expanded its Exposure Management portfolio with Supply Chain Intelligence, enabling organizations to detect, rank, and mitigate vulnerabilities in both their own internet-facing assets and those of critical third-party providers before adversaries exploit them.
Addressing Modern Threats with AI
This development responds to the increasing urgency faced by security teams as threat actors leverage advanced technologies to shorten the timeline between exposure detection and exploitation.
Traditional Methods vs. Modern Techniques
Traditional methods for reconnaissance, vulnerability identification, and exploit development once required weeks, but modern techniques, including frontier AI, now compress this process to hours or minutes.
Importance of Visibility in Hybrid Clouds
As enterprises grow their presence across hybrid and multi-cloud infrastructures, the need for enhanced visibility into internet-facing assets and third-party dependencies has become critical.
External Attack Surface Management (EASM) Solution
Infoblox’s External Attack Surface Management solution autonomously identifies internet-facing assets without requiring software deployment, credentials, or active scanning. It evaluates risks based on exploitability and potential business impact, including overlooked DNS-related issues.
Early Access Program Findings
During an early access program, the tool uncovered dangling CNAME records at 31 of approximately 40 participating organizations. These orphaned DNS entries, which attackers can manipulate to hijack web domains, were found to be easily compromised in nearly one-third of cases.
Risks of Dangling CNAME Records
Such vulnerabilities could allow adversaries to host phishing sites, harvest credentials, or send spoofed emails under legitimate corporate domains.
Need for Continuous External Monitoring
Without continuous external monitoring, organizations may remain unaware of these risks until breaches occur.
Expert Insights on AI and Cybersecurity
Michelle Abraham, Research Vice President at IDC, emphasized the role of AI in reshaping cyber risk management strategies. She noted that attackers’ automation of reconnaissance and reduced time between exposure and exploitation necessitate ongoing visibility into external attack surfaces.
Supply Chain Intelligence
Infoblox also unveiled Supply Chain Intelligence, a component of its Exposure Management suite that extends monitoring to the internet-facing assets of key vendors. This tool tracks vendor vulnerabilities, leaked credentials, dark web activity, and active threat campaigns, integrating third-party risks into existing security workflows.
CPO’s Perspective on External Risks
Mukesh Gupta, CPO at Infoblox, highlighted the importance of answering a critical question for security leaders: “What can an attacker access right now?” He explained that AI-driven reconnaissance has made this query increasingly complex.
Integrated Solutions for Comprehensive Risk Management
By deploying External Attack Surface Management, Infoblox leverages its expertise in DNS to identify high-priority internet-facing exposures before they escalate into incidents. Extending this approach to critical vendors through Supply Chain Intelligence provides a more comprehensive view of external risks.
Conclusion
The External Attack Surface Management and Supply Chain Intelligence tools are now part of the Infoblox Exposure Management portfolio, alongside Digital Risk Protection Services. Together, these solutions empower enterprises to systematically identify, prioritize, and mitigate external risks across their operational and dependent ecosystems.
