Exposure Management & CTEM

The market is shifting from finding issues to proving exposure has actually fallen. These articles cover what CTEM asks of a security program, why EDR and XDR leave a correction gap, how to measure exposure rather than activity, and where continuous validation earns its place.

Anthropic’s AI Warning: Pacing the Frontier Is Not a Security Control

Anthropic’s AI Warning: Pacing the Frontier Is Not a Security Control

Dario Amodei just made the most consequential call yet for slowing AI down. Buried in it were security concerns every CISO should know. The exploits weren't new: unauthenticated service, leaked tokens, unsafe file parsing, secrets on a production worker.

Learn more

Topic

Author

A folder with a document labeled “Visual Studio Code Vulnerability” prominently displayed, featuring the “Remedio Research” logo on a blue gradient background.

Bypassing VS Code Workspace Trust with a Single Link

Remedio Research uncovered a critical flaw in Microsoft VS Code: a simple link click bypasses Workspace Trust to silently install persistent extensions and compromise developer workstations. Learn how the exploit works and how to harden your editor today.

Omri Dar
Omri Dar
Sep 17, 2026 | 9 min read
A digital graphic with charts, a cracked clock showing 22 seconds, and the text: “What Is Risk-Aware Trust And How Can It Be Operationalized?” and “Threat actor initial access.” This visual highlights the importance of risk-aware operational trust in addressing threat actors’ initial access.

The Shift to Risk-Aware Operational Trust

Autonomous remediation will succeed or fail on more than model capability. It will depend on whether security teams can prove that a proposed change is safe, bounded, reversible, and durable in production.

Ilan Mintz
Ilan Mintz
Sep 15, 2026 | 9 min read

Want updates?

Capture the noteworthy, cut the noise!

Get Remedio’s monthly endpoint security briefing on emerging risks, hardening strategies, and what’s new in enterprise security.

Subscribe to our newsletter to stay up-to-date and in the loop.

One email a month. Unsubscribe anytime.

A computer screen displays “Eliminate the exposed state before a threat actor sees it,” with automated vulnerability remediation keywords above and digital graphics in the background.

Automated Vulnerability Remediation

Finding vulnerabilities is not the security outcome. Learn how automated remediation turns vulnerability management into preemptive action by safely eliminating exposed states before attackers can exploit them.

Ilan Mintz
Ilan Mintz
Sep 10, 2026 | 9 min read
A digital illustration showing a security alert, a 76-day vulnerability mark, and the text “Haywire Hygiene? Here’s What You Need to Know About Security Drift.” This striking visual highlights the importance of configuration-drift-management in maintaining strong cyber hygiene.

Change Control and Configuration Drift Management

Configuration drift management should not be treated as a checklist exercise, but as a change-control discipline for security teams that need their hardening, policies, and protections to actually hold over time.

Ilan Mintz
Ilan Mintz
Sep 9, 2026 | 9 min read
A digital illustration shows a laptop with overlaid text: “Blind spots to you, mined spots to attackers. Automate fixes without operational risk.” The header reads “Endpoint Remediation Is A Change-Control Problem,” highlighting how effective endpoint remediation is essential for minimizing threats while maintaining operational stability.

Automating Endpoint Remediation Without Operational Risk

From patches and configuration changes to software removal, the devil is in the details when it comes to remediating endpoints. Here we look at the role played by impact analysis, controlled execution, verification, and rollback in preventing operation disruption.

Ilan Mintz
Ilan Mintz
Sep 3, 2026 | 9 min read
A laptop displays a projection with digital graphics and text saying, “MOVE FROM STATIC POSTURE SCANS,” under a heading, “Higher Education. Higher Security?”—highlighting the growing importance of higher education cyber security.

Back to School, Back to Exposure? Higher Education Cybersecurity

Higher education security fails when detection doesn't lead to correction. Learn how unified device and identity governance tames the September surge.

Ilan Mintz
Ilan Mintz
Aug 30, 2026 | 10 min read
Diagram showing a laptop with patching and hardening alongside Vulnerability and Configuration Management tools, a magnifier on risk found, and a shield labeled blind spot under the text “Embracing Comprehensive Coverage and Integrated Insights.”.

The Value of Unified Vulnerability and Configuration Management

Separating vulnerability patching from configuration hardening creates a widening exposure gap and severe operational drag. Learn how borrowing principles from DevOps allows security teams to unify exposure intelligence and enforce continuous, safe remediation.

Yaron Bialik
Yaron Bialik
Aug 30, 2026 | 8 min read
A laptop displays a cybersecurity graphic showing a network diagram and red nodes, with blue and red digital cubes beside it. Text above asks about defense speed against machine-speed attacks, highlighting the importance of effective cyber exposure management.

The Robot Uprising Was Just Bad Cyber Exposure Management

The Hugging Face incident shows that, as AI changes the economics of the vulnerability backlog, security teams must shift from managing risk on paper to safely eliminating it at scale.

Matt Rowe
Matt Rowe
Aug 20, 2026 | 6 min read
A digital graphic shows a handshake between two glowing hands, connecting “Safe Fixes” and “Business Aware,” with the phrase “At the Intersection of Understanding & Action, There’s Progress.” Subtly woven into the imagery is the concept of autonomous remediation, highlighting how seamless collaboration can drive proactive solutions.

Autonomous Remediation Is Coming Fast. Trust Will Decide Who Wins.

The next battleground isn’t speed alone, but an embrace of business-aware control that allow operators to reduce exposure decisively, safely, and at scale through autonomous remediation.

Mor Bikovsky
Mor Bikovsky
Aug 5, 2026 | 5 min read
configuration-and-edr-data-integration

Integrating Configuration Security with EDR Protection

EDR tells you what happened. Configuration security tells you why it was possible. Learn how integrating both helps teams reduce exposure, prioritize faster, and drive safe remediation.

Mor Bikovsky
Mor Bikovsky
Jul 27, 2026 | 8 min read

For Continuous Risk Reduction, Start With 3 Cyber Problems

Most cyber risk isn’t unknown, it’s unresolved. Identity drift, exposed remote access, and shadow AI keep known exposures alive. Here's how continuous risk reduction can close the gap.

Ilan Mintz
Ilan Mintz
Jul 22, 2026 | 7 min read