Heroes, late breaking critical news. Here's a detailed look at the current cybersecurity landscape for September 22, 2025.
Critical Threats
High Severity
Executive Briefing
The decision by Microsoft, SentinelOne, and Palo Alto to forgo the next round of MITRE ATT&CK Evaluations presents a strategic challenge for CISOs and security leadership. These evaluations have served as a crucial, independent benchmark for comparing EDR/XDR platform effectiveness. This shift necessitates a re-evaluation of vendor assessment strategies, placing a greater burden on internal teams to conduct rigorous proof-of-concept testing and demanding more transparent, verifiable performance data directly from vendors.
Vendor Spotlight
Spotlight Rationale: Today's intelligence features two separate reports on the critical risks associated with Non-Human Identities (NHIs) and secrets management. As threat actors increasingly target machine identities to bypass traditional security controls, a specialized approach to NHI Detection and Response (NHIDR) is essential. Entro Security is selected for its direct focus on this often-overlooked but critical attack surface.
Threat Context: Budget-Friendly Secrets Management Strategies
Platform Focus: Entro Security Non-Human Identity and Secrets Security Platform
The Entro platform addresses the threats highlighted in today's rundown by providing comprehensive discovery, classification, and management of non-human identities and their associated secrets across multi-cloud and on-premise environments. Unlike traditional IAM tools focused on human users, Entro provides visibility into the sprawling landscape of service accounts, API keys, and tokens. This allows security teams to enforce least-privilege access, detect anomalous behavior, and remediate vulnerabilities like exposed secrets or excessive permissions before they can be exploited by actors like Nimbus Manticore or others.
Actionable Platform Guidance: Based on the platform's core function, initial steps would involve mapping the NHI attack surface and establishing governance. This guidance provides a starting point for internal assurance.
Source: Entro Security ↗, Entro Security ↗