NetSPI researcher reveals NAA flow abuse.
The technique bypasses Microsoft Entra Conditional Access Policies by exploiting authentication flows as intended.
See the latest news and media coverage for NetSPI. We track all announcements, press releases, and industry mentions in real time, all in one place.
Proactive cybersecurity testing and attack surface management
netspi.comLast updated
In short: NetSPI launched an AI-powered continuous penetration testing platform and released ForceHound, an open-source tool for Salesforce security auditing.
The technique bypasses Microsoft Entra Conditional Access Policies by exploiting authentication flows as intended.
The flaw allows unauthenticated arbitrary file operations and remote code execution. Patching is urgent as a proof-of-concept is public.
The vulnerability (CVE-2026-45585) allows physical attackers to bypass BitLocker; Microsoft offers a temporary fix.
The company offers on-site engagements to test physical security against real threat actor tactics.
MINNEAPOLIS, May 12, 2026 (GLOBE NEWSWIRE) -- NetSPI ®, the global leader in modern penetration testing, today announced the launch of its AI-powered Continuous Pentesting...
To continue reading this content, please enable JavaScript in your browser settings and refresh this page. This week in Minne Inno, a Minneapolis cybersecurity firm...
NetSPI®, the global leader in modern penetration testing, today announced a new, modern user experience for the NetSPI platform, reimagining what penetration testing should feel...
NetSPI ®, the global leader in modern penetration testing, today announced it has been recognized in the 2026 GigaOm Radar Report for Attack Surface Management...
Track NetSPI and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to NetSPI and other trending companies.