Dubai-based security firm SpiderSilk puts on an adversarial hat when scanning for Internet-facing threats affecting companies.
The company's scanning technologies require only the company's name, not a customer's list of IP addresses and domains. Within a few hours, the tools scan billions of IP addresses and hunt down leaked data, assets, systems, compromised credentials, and other information the organization never meant to expose to the world. The idea is to mimic an outsider's perspective and use artificial intelligence (AI) to contextualize and discover weak spots that could be targeted tomorrow, says Mossab Hussein, SpiderSilk's co-founder and chief security officer.
SpiderSilk's tools are like an early warning system that helps companies spot risks on the open Internet before hackers exploit them. Based on SpiderSilk's findings, companies can take corrective action or patch systems to fend off threats.
Related:ClickFix Campaigns Abuse Legitimate Services for Persistent Access
"Organizations were struggling to understand what's exposed on their digital presence. They didn't know what that looks like, or what kind of harm it could cause, until it was too late," Hussein says.
Why CISOs Need to Know Their Exposure
Managing external threats isn't new, but AI provides a unique twist by stitching together more data points to identify external attack surfaces, says Pete Shoard, chief of research for cybersecurity at Gartner. Threats happen at machine speed, and companies are slow to respond, Shoard says. CISOs need to be proactive, not reactive, in approaching cybersecurity.
"The whole AI thing does make the connection of context a lot easier, makes these kinds of things more accessible," Shoard says. "Twelve months ago, we were 90% reactive, 10% proactive. Next year or the year after, we're heading to 70% proactive and 30% reactive."
The pursuit of AI has made vibe-coding a major security threat — in the rush to develop apps, employees could unknowingly leak confidential information, such as sensitive files, passwords or API keys, into repositories such as GitHub or GitLab. Enthusiastic business analysts without deep technical understanding may vibe-code a cool corporate dashboard without realizing that sensitive PDFs and company material were uploaded to GitHub or Claude Code.
SpiderSilk's flagship product, Resonance, functions as an alert system for enterprises as it can spot exposed assets such as domain names, company information or other details in proprietary data files in coding platforms such as GitHub. Resonance's AI capabilities analyze, filter, and qualify the data, and “once this is confirmed with the evidence, it immediately escalates that to the customer," Hussein says.
... continue reading