Threat Advisory: DPRK Social Engineering Attacks
APT37 has deployed NarwhalRAT, a fileless Python RAT using pCloud for C2. Read the TIDE Team's full analysis and response guidance for Microsoft 365 environments.
Benchmarks your AI security practices against peer data.
Find flaws in AI Systems
Find flaws in web, mobile, and IoT applications.
Live-fire exercises to sharpen detection and response.
Time-boxed security assessments across networks, apps, and infrastructure.
Simulated attacks to test detection and incident response.
Named security experts integrated seamlessly into your team.
Real-time detection and automated threat response.
24x7 monitoring and response by expert analysts.
Detection-focused SIEM migration without visibility gaps.
UltraViolet's proprietary AI platform powering all application penetration testing.
Unified security platform powering all UV services.
Automated detection engineering across your security platforms.
Cross-platform toolkit for advanced red team ops.
UltraViolet Cyber provides security services across the AI lifecycle, combining strategy, threat modeling, adversarial testing, monitoring, and training to support secure AI adoption.
How a Fortune 100 technology company extends its offensive security team with UltraViolet Cyber, testing web, ...
Secure your code, infrastructure, and deployment pipelines before attackers exploit them.
Before you trust a MITRE ATT&CK coverage number, run it through three questions. Here's what to ask, and why each one ...
UltraViolet's AISec Study uses an interview-based methodology to score AI security maturity across 10 organizations. Read ...
UltraViolet Cyber is a practitioner-led MSSP delivering offensive and defensive security to Global 2000 and Federal clients. Built by former intelligence operators, we unify application security, red teaming, detection, and engineering under one roof. Our UV Lens platform replaces silos with integrated, outcome-driven operations.
This in-depth quarterly report uncovers how the convergence of operational technology and IT networks is exposing critical infrastructure systems—like access control, fire safety, HVAC, and UPS—to sophisticated cyber threats, and outlines actionable strategies for resilience.
As physical systems like access control, fire alarms, HVAC, and UPS equipment become increasingly integrated into enterprise networks and cloud platforms, they introduce new and often overlooked cybersecurity risks. The Q3 2025 OT/ICS Threat Report from UltraViolet Cyber reveals how attackers are exploiting vulnerabilities in these systems—ranging from hardcoded credentials and unencrypted communications to insecure APIs and firmware flaws—to bypass traditional defenses and disrupt operations.
Real-world incidents in 2025 have shown how these threats can lead to physical damage, safety hazards, and systemic outages. The report emphasizes the urgent need for organizations to treat facilities management technologies as critical components of their cybersecurity strategy. Key recommendations include asset inventories, network segmentation, encrypted protocols, strong authentication, and centralized monitoring.
Read the full report to explore detailed threat analyses, CVEs, and actionable protective measures:
We’re here to help. Get in touch for an initial conversation with one of our security experts and learn more about how UltraViolet Cyber can help you take cyber readiness and resilience to new levels.