CRITICALData Breach
Global

Infoblox joins crowded EASM market with DNS-centric approach

·Source: CSO Online

Updated:

Executive Summary

With AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long before an incident happens. Infoblox is the latest to make that move, announcing its entry into the External Attack Surface Management ( EASM ) market alongside a new Supply Chain Intelligence capability that broadens its exposure management portfo

Analysis

With AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long before an incident happens. Infoblox is the latest to make that move, announcing its entry into the External Attack Surface Management ( EASM ) market alongside a new Supply Chain Intelligence capability that broadens its exposure management portfolio. These two additions are designed to give organizations visibility into both their own internet-facing assets and those of their critical vendors. According to Infoblox, the combined offering enables security teams to discover, prioritize, and reduce external exposures before attackers can exploit them. “As attackers automate reconnaissance, organizations need continuous visibility into their external attack surface and better context to prioritize the exposures that pose the greatest business risk,” said Michelle Abraham , research vice president for Security and Trust at IDC. “This is driving growing interest in preemptive approaches to external attack surface management as part of broader exposure management strategies.” The new capabilities join Infoblox’s existing Digital Risk Protection Services ( DPRS ). A DNS-first spin on the crowded EASM market External Attack Surface Management has become one of the fastest-growing segments in cybersecurity, with vendors racing to help enterprises inventory internet-facing assets and identify exploitable weaknesses. Infoblox’s differentiation lies in applying its long-standing DNS expertise to the problem. The company’s new EASM capability discovers internet-facing assets without requiring software agents, credentials or active scanning, the company said in a press statement shared with CSO ahead of the announcement on Tuesday. It also evaluates exposures based on exploitability and business impact while surfacing DNS-specific issues that conventional EASM platforms may overlook, Infoblox claims. Among such issues are “dangling CNAME records,” which refer to the orphaned DNS entries that attackers can hijack to host phishing sites, steal credentials, or impersonate trusted corporate domains. The company said an early access program involving roughly 40 organizations found dangling CNAME records at 31 participants, a third of which were reportedly easy to take over. A support beyond enterprise assets Infoblox also announced a new Supply Chain Intelligence that promises continuous monitoring of the internet-facing assets of critical vendors, tracking exposures, leaked credentials, dark web activity and active threat campaigns that could introduce risk through third-party connections. This capability is positioned as an expansion of its broader Exposure Management strategy rather than a standalone product launch. “The simple question every security leader should be able to answer is: ‘What can an attacker reach right now?’” said Mukesh Gupta, chief product officer at Infoblox . He argued that AI has made answering that question significantly harder by accelerating attacker reconnaissance, making continuous external visibility a key component of modern cybersecurity operations.
Source Attribution

Originally published by CSO Online on Jul 28, 2026.

Related Threats

CRITICALZero DayNEW

How AI is Rewriting the Zero-Day Playbook for Preemptive Security

The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?” Answering questions like these when zero-days drop tends to trigge

Rapid7
HIGHVulnerability

Rapid7 Cyber GRC is now available: Turn security action into compliance proof

Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third parties, and give executives and the board a clearer answer on whether cyber risk is actually going down. Most of that press

Rapid7
CRITICALData Breach

The Next Evolution of MDR: Preemptive Defense and Agentic Investigation

For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating

Rapid7