Infoblox is entering the external attack surface management (EASM) market. With a new feature called Supply Chain Intelligence, the company is expanding its Exposure Management portfolio. The goal is to detect vulnerabilities in internet-facing assets before attackers can exploit them.
Whereas reconnaissance, vulnerability identification, and exploit development used to take weeks, cutting-edge AI now accomplishes this in hours or even minutes. This narrows the window between when an exposure arises and when it is exploited. Infoblox is addressing precisely this problem with its new EASM capability.
The feature discovers internet-facing assets without requiring software installation, credentials, or active scanning. The system then prioritizes vulnerabilities based on exploitability and business impact, including DNS hygiene issues that traditional solutions often miss. And that is precisely where Infoblox’s strength lies, as the company has its roots in DNS security.
During a recent early access program, the reality of the risk became clear. At 31 of the approximately 40 participating organizations, Infoblox found so-called dangling CNAME records, orphaned DNS pointers that attackers can hijack to take over a company’s web presence. According to the company, nearly a third of those records were easy or trivial to hijack. Attackers can then host phishing pages or send spoofed emails under a trusted company domain.
Focus on the supply chain
In addition to EASM, Infoblox is also introducing Supply Chain Intelligence. This feature extends the outside-in perspective to the internet-facing assets of critical suppliers. It continuously monitors supplier exposures, leaked credentials, activity on the dark web, and active threat campaigns. Both additions align with Digital Risk Protection Services (DRPS), which Infoblox previously enhanced through its integration with Axur.
“The simple question every security leader should be able to answer is: ‘What can an attacker reach right now?” says Mukesh Gupta, chief product officer at Infoblox. “As AI accelerates attacker reconnaissance, that question has become much harder to answer.”