-

Cymulate Ups the Game on Exposure Management

Company closes risky gaps between Vulnerability Scanning and Attack Surface Management across hybrid infrastructure

NEW YORK--(BUSINESS WIRE)--Cymulate, the leader in cybersecurity risk validation and exposure management, today announced the expansion of its Attack Surface Management (ASM) solution to close gaps between traditional vulnerability management and ASM. Organizations will now have advanced capabilities to easily visualize risky exposures across hybrid environments. The company achieves this by extending its coverage to include more attack surface discovery and added misconfiguration detection, Cloud-specific analysis, and vulnerability discovery. Previously only for external attack surface management, the new enhancements will analyze Active Directory, Azure, GCP, and AWS Cloud footprints for misconfigurations and remediable security concerns.

“Customers will immediately benefit from seeing gaps in their public-facing infrastructure and through attack path mapping to see how an attacker can traverse the network from on-premises to cloud and cloud to on-premises,” said Avihai Ben-Yossef, CTO and Co-founder. “This will significantly aid organizations in assessing how at risk their organization’s assets are.”

Vulnerability scanners are designed to identify, classify, prioritize, and remediate vulnerabilities that could be exploited – primarily from within the environment. Conversely, attack surface management has mainly focused on discovery of vulnerabilities from an external perspective. This Cymulate solution now closes the visibility gap needed to understand if an exposure has a viable attack path, if security controls detect and alert effectively, and validating that remediations achieve the desired risk mitigation. This brings exposure management to a new level that is more continuous and efficient for classifying and prioritizing the remediation of vulnerabilities.

The ASM solution expansion provides four new tool capabilities: Active Directory Misconfiguration Scanning, Cloud Misconfiguration Scanning, Vulnerability Scanning, and Unified Attack Path Mapping and Analysis (UAPMA). This provides more information than just what needs to be patched, and the ability to leverage information from more sources to determine the priority of each remediation action.

The Unified Attack Path Mapping and Analysis (UAPMA) will

  • Support attack pathing and security validation across networks, Clouds, and identity systems, including Active Directory services
  • Deliver a significantly more complete and detailed picture of viable attack paths and techniques than can be discovered when compared to performing such scanning operations only in one infrastructure or the other
  • Factor in that interconnections, trusts, permissions, and other variables can change the path of an attacker in unexpected ways
  • Provide the ability to clearly identify and see attack paths (displayed as graphs and detailed information), which delivers a quicker way to identify and close gaps without disrupting business operations

When paired with Cymulate Breach and Attack Simulation (BAS) technology, security teams can also validate whether controls that sit in the attack path successfully detect and alert on threat activity; and where remediation is required, knowing where that remediation can best be performed to reduce any business disruptions. This combination further refines which vulnerabilities to prioritize and at what level of urgency.

The driving factors for these enhancements center on the growing use of cloud computing, remote workforce, and third-party services; which are expanding organizations' attack surface and creating numerous challenges in identifying and tracking assets across on-premises, hybrid, and cloud infrastructure; and in managing and securing all exposed assets. Additionally, the inability to evaluate risk posed by each asset, the proliferation of unmonitored assets such as legacy infrastructure and shadow IT add to the complexity of controlling networks; compounding risk, especially when scaling operations.

Resources:

About Cymulate

The Cymulate cybersecurity risk validation and exposure management solution provides security professionals with the ability to continuously challenge, validate and optimize their on-premises and Cloud cyber-security posture with end-to-end visualization across the MITRE ATT&CK® framework. The platform provides automated, expert, and threat intelligence-led risk assessments that are simple to deploy, and easy for organizations of all cybersecurity maturity levels to use. It also provides an open framework for creating and automating red and purple teaming exercises by generating tailored penetration scenarios and advanced attack campaigns for their unique environments and security policies. For more information, visit www.cymulate.com.

Contacts

Media Contact
Katrina Porter, Sr. Manager,
Marketing Communications at Cymulate
katrinap@cymulate.com
1-831-227-0776

Cymulate


Release Versions

Contacts

Media Contact
Katrina Porter, Sr. Manager,
Marketing Communications at Cymulate
katrinap@cymulate.com
1-831-227-0776

More News From Cymulate

Cymulate Announces AI Innovations to Deliver Agentic Cyber Defense Engineering Built for Speed, Scale and Accessibility

TEL AVIV, Israel--(BUSINESS WIRE)--Black Hat USA 2026, Las Vegas -- Cymulate, the leader in exposure validation and cyber defense engineering, today announced a major expansion of its AI innovation strategy with the introduction of Cymulate Cowork, the Cymulate Claude Plugin and the Cymulate Model Context Protocol (MCP) Server. Launched at Black Hat, this Cymulate innovation is the next step in the evolution of Cymulate Vero AI and the Cymulate vision for agentic cyber defense engineering. As a...

Cymulate Joins the Wiz Integration Network (WIN)

NEW YORK & TEL AVIV, Israel--(BUSINESS WIRE)--Cymulate, a leader in threat exposure management, today announces its partnership with cloud security leader Wiz by joining the Wiz Integration Network (WIN). Through this partnership, Cymulate brings the power of its Continuous Threat Exposure Management Platform to WIN, enabling customers to seamlessly integrate Wiz into their existing workflows. Now, joint customers will benefit from pre- and post-exploitation simulation assessments to test and v...

Cymulate Reveals New Exposure Management Platform

NEW YORK & TEL AVIV, Israel--(BUSINESS WIRE)--Cymulate, a champion in exposure management, today announced the new Cymulate Exposure Management Platform, which validates, prioritizes and optimizes the entire security ecosystem – continuously. The new Cymulate platform uniquely unifies exposure data and integrates threat validation results to accelerate existing SecOps, detection engineering and exposure management workflows. Now, security teams can easily prioritize the threats proven to be exp...
Back to Newsroom