
Flashpoint’s Return to Office Security Checklist
This checklist, based on Flashpoint intelligence and best practices, helps mitigate physical and digital security threats associated with returning to the workplace.

Flashpoint’s Physical Safety Event Checklist for Executives
This checklist, based on Flashpoint intelligence and best practices, is designed to help keep executives safe when attending political events, sporting events, religious services, holiday celebrations, or other large in-person events.

Flashpoint Named 2024 Product Leader by Frost & Sullivan
Flashpoint is a leader of threat intelligence, enabling global organizations to address current security challenges with CTI, vulnerability intelligence, geopolitical risk, fraud, and brand protection.
Vulnerability Management
FP-2023-03 – ThinManager
Rockwell Automation ThinManager contains a flaw that allows traversing outside of a restricted path and allows a remote attacker to read files on the local file system with SYSTEM-level privileges.
Vulnerability Management
FP-2023-004-Automa Extension for Chrome Message Handling Universal XSS
Exploitation of this issue allows a universal cross-site scripting attack. If a user visits a specially crafted web page, an attacker can inject JavaScript code into web pages that are embedded via an iframe. The script code executes in the context of the user's browser session within the trust relationship between the browser and the server. The attacker can then access any content on that page or disclose e.g. session cookies to gain direct access to a user account.
Vulnerability Management
FP-2023-01 – NETGEAR’s ProSAFE® Network Management System NMS300
Flashpoint disclosed a new vulnerability affecting NETGEAR's ProSAFE® Network Management System NMS300.
Vulnerability Management
RBS-2022-002 – Delta Infrasuite Device Master
A function that handles GET requests does not enforce any authentication and allows to request any file e.g. in the infrasuitemanager/ApRunning/ directory. This allows accessing the UserInfoList.xml or Gateway.xml files, which include user credentials.
Vulnerability Management
RBS-2022-001 – NetModule Router Software (NRSW)
NetModule Router Software (NRSW) contains PHP type juggling flaws. With specially crafted HTTP requests, a remote attacker can bypass authentication and access the configuration file upload functionality and CLI interface.
Vulnerability Management
2021 Year End Report | Vulnerability QuickView
Conducted by Brian Martin, Vice President of Vulnerability Intelligence at Risk Based Security (RBS) and Flashpoint’s Global Threat Intelligence Team
Cyber Threat Intelligence
2021 Year End Report | Data Breach QuickView
In the 2021 Data Breach QuickView report from Risk Based Security, Inga Goddijn, Executive Vice President of Risk Based Security and Ashley Allocca, Cybersecurity Intelligence Analyst of Flashpoint, examine breach activity from several different perspectives, including the types of data that were targeted, who was compromised, and the impact of these events.
Cyber Threat Intelligence
Investigate Hydra: Where Cryptocurrency Cybercrime Goes Dark
Flashpoint and Chainalysis Investigate Cryptocurrency Cybercrime on Russian Dark Market “Hydra”

RBS-2021-003 – Twonky Server
Vulnerabilities allow a remote attacker to gain access to sensitive information, such as the configured ‘accessuser’ and ‘accesspwd’ options (among others).