NetSPI details Azure VM command execution via Salt Minion extension
The attack exploits third-party extensions to deploy a rogue Salt master and push malicious states for code execution as root.
See the latest news and media coverage for NetSPI. We track all announcements, press releases, and industry mentions in real time, all in one place.
Proactive cybersecurity testing and attack surface management
netspi.comLast updated
In short: NetSPI launched AI-powered continuous pentesting services and a new platform to accelerate threat validation and risk reduction.
The attack exploits third-party extensions to deploy a rogue Salt master and push malicious states for code execution as root.
Research shows a rogue Chef server with write permission can execute code and steal Managed Identity tokens.
Attackers are actively exploiting CVE-2026-63030 and CVE-2026-60137 chain, affecting multiple WordPress versions.
The tool maps privilege escalation paths across AD, ADCS, MSSQL, and SCCM using BloodHound graph data and includes password auditing.
MINNEAPOLIS, May 12, 2026 (GLOBE NEWSWIRE) -- NetSPI ®, the global leader in modern penetration testing, today announced the launch of its AI-powered Continuous Pentesting...
To continue reading this content, please enable JavaScript in your browser settings and refresh this page. This week in Minne Inno, a Minneapolis cybersecurity firm...
NetSPI®, the global leader in modern penetration testing, today announced a new, modern user experience for the NetSPI platform, reimagining what penetration testing should feel...
NetSPI ®, the global leader in modern penetration testing, today announced it has been recognized in the 2026 GigaOm Radar Report for Attack Surface Management...
Track NetSPI and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to NetSPI and other trending companies.