www.globenewswire.com Holm Security Launches Active Directory Security Amid Regulatory Pressure
Article Content
- •Holm Security's Active Directory Security continuously assesses vulnerabilities in AD.
- •22% of breaches start with stolen credentials, often linked to Active Directory.
- •The platform includes 187 checks mapped to nine MITRE ATT&CK tactics.
Holm Security has introduced Active Directory Security, enhancing its platform to continuously assess on-premises Active Directory for vulnerabilities. This launch coincides with increasing regulatory demands in Europe, particularly under directives like NIS2 and DORA. Active Directory remains a critical component for identity management in organizations, with 22% of breaches starting from stolen credentials, as noted in the Verizon 2025 Data Breach Investigations Report. The new capability replaces traditional point-in-time audits with continuous visibility, addressing common attack vectors such as Kerberos abuse and credential dumping. Holm Security's platform now includes 187 checks across nine MITRE ATT&CK tactics, focusing on credential access, privilege escalation, and lateral movement. The service is available to all Holm Security customers as of today, June 9, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…