
A Fortune 100 retailer found a subdomain they’d forgotten they owned. It wasn’t just exposed. It had already been taken over by an attacker. And their existing attack surface tool had never surfaced it.
That story stuck with me because I hear a version of it constantly. Security teams start with alerts or known vulnerabilities. Attackers start with what’s exposed on the internet.
That asymmetry is the whole problem. You’re triaging findings from scanners, chasing CVEs through ticketing workflows and trying to explain exposure reduction to a board, all while an attacker, increasingly armed with AI that compresses days of reconnaissance into minutes, is quietly mapping your subdomains, flagging misconfigured DNS records and watching for a certificate to expire. The tools most teams use weren’t built to see what the attacker sees. They were built to look inward.
Today we’re changing that: Infoblox Exposure Management now includes External Attack Surface Management (EASM) and Supply Chain Intelligence, giving security teams the same outside-in view of their infrastructure that attackers have always had. In hours, not weeks. No software to deploy across your environment, no scanners to tune, no swivel-chairing between tools to piece the picture together, and all of it in the same portfolio where Digital Risk Protection Services (DRPS) is already disrupting threats.
The View from Outside
Every organization has an internet-facing footprint bigger than anyone realizes.
Domains, subdomains, IP ranges, certificates and cloud assets pile up across teams, projects and acquisitions. Development teams spin up services and forget them. Marketing launches microsites that outlive their campaigns. M&A drags in entire infrastructures nobody fully inventoried. Internal security tools, built to look inward, never see any of it.
Most external attack surface management (EASM) tools make it worse. Weeks of onboarding, credentialed scanning and manual triage before the first meaningful finding shows up, burning analyst hours that should go to actual remediation.
Infoblox’s External Attack Surface Management capability flips both problems at once. Starting from the outside, using passive DNS, certificate transparency logs and agentless data sources, it builds a continuous, authoritative inventory of everything an attacker can observe about your organization. Because discovery is passive, reading DNS rather than probing services, there’s nothing to install, nothing to configure and no running systems to disrupt. That’s why the first prioritized view arrives in hours. Seed a domain. Get a prioritized exposure picture. Nothing to deploy. No active scanning. No weeks-long setup before you see value.
The goal is simple: see what attackers see before they can use what they find.
The Finding Set Most Tools Miss
Many EASM tools stop at assets and Common Vulnerabilities and Exposures (CVEs). We go further.
Because Infoblox is built on decades of DNS expertise, our External Attack Surface Management treats DNS hygiene as a real, exploitable exposure class, not background noise to filter out. Dangling CNAMEs. Open zone transfers. Weak DMARC and SPF records. Lame delegations. Expiring domains. These aren’t flagged for awareness and forgotten. They’re scored and prioritized right alongside CVEs, automatically, on two dimensions: how likely a finding is to be exploited (using EPSS probability, CISA Known Exploited Vulnerabilities status and Infoblox threat intelligence) and how critical the affected asset is to the business (derived from DNS traffic patterns only Infoblox’s position in enterprise DNS can provide). High-exploitability findings on high-impact assets rise to the top. The rest stay visible, but they don’t crowd out what matters.
The data from our early access program makes the point: nearly one in three dangling CNAMEs were easy or trivial for an attacker to take over. Remember that Fortune 100 retailer’s forgotten subdomain? The risk was always there. Nobody could find it in the right place.
We also fixed the prioritization problem that makes most EASM tools operationally frustrating. Findings are grouped by shared root cause, so twenty assets sharing one dangling CNAME show up as one ticket, not 20. Each finding comes with AI-generated, step-by-step guidance for mitigation, remediation and validation. Findings route to the right owners through existing security information and event management (SIEM) and IT service management (ITSM) integrations via API.
Human attention is a finite resource. Discovery without mobilization is just a report. We close the loop.
The Supply Chain Is Part of Your Attack Surface
Here’s a truth most exposure tools aren’t built to handle: your perimeter doesn’t end at your assets. It extends to every vendor, payroll provider and software supplier connected to your business.
In an Infoblox survey of 550 security professionals, 88 percent report exposure concerns beyond what they can manage, with third-party dependencies among the most cited gaps. The World Economic Forum’s Global Cybersecurity Outlook 2026 reinforces why: 78 percent of CEOs at highly resilient organizations name supply chain and third-party dependencies as the single most significant challenge to cyber resilience.1 When a vendor gets breached, the attacker doesn’t knock on your front door. They walk in through a trusted connection you already authorized.
Supply Chain Intelligence extends the same outside-in discovery that powers External Attack Surface Management to your named vendors, and it also connects directly to Digital Risk Protection Services when external threats tied to those vendors or your brand need to be disrupted. It’s purpose-built for your security operations team, not procurement. That distinction matters.
Third-party risk management tools generate risk ratings for vendor onboarding decisions. That’s a procurement question. Supply Chain Intelligence answers a defender’s question: is this vendor being used against us right now? It surfaces exposed CVEs and misconfigurations on vendor infrastructure, leaked corporate and customer credentials from dark-web forums, active threat campaigns targeting each vendor and CTI bulletins with IoCs, so analysts can pivot from a vendor exposure straight into threat hunting and incident response without a separate tool.
The speed difference is real. When a widely reported third-party incident broke involving a critical software vendor, one early-access customer triaged the relevant credentials and quantified the risk in minutes, work that used to take hours pivoting across separate CTI, threat-hunting and credential-monitoring tools.
Same security-operations lens. Applied to your vendor ecosystem. Connected to both External Attack Surface Management for outside-in visibility and Digital Risk Protection Services for disruption. In the same Infoblox Exposure Management console. No additional tool, no integration project.
What This Means for Security Teams
With External Attack Surface Management and Supply Chain Intelligence, the teams that have to act on exposure can finally do it with confidence:
- CISOs and security operations leaders get a continuous, quantified view of external risk across their own estate and their vendor ecosystem, with the evidence to show the board measurable reduction over time. Not a point-in-time assessment. A program.
- SOC leaders and vulnerability management teams get hours-to-value: seed a domain, get a prioritized exposure picture, route findings straight to SIEM or ITSM without deploying software or standing up new infrastructure. Findings grouped by root cause mean analyst time goes to remediation, not deduplication.
- CTI analysts and CSIRT leads get the vendor coverage they’ve been assembling by hand from fragmented sources, consolidated into one workspace, updated continuously and connected to the same threat intelligence that drives everything Infoblox does.
The Connected Loop
What makes this launch matter isn’t any single capability. It’s how they connect.
When External Attack Surface Management surfaces a high-risk exposed asset, teams can connect that context to Infoblox Threat Defenseâ„¢ for DNS-layer blocking, on average 68 days before traditional defenses recognize the threat. When Supply Chain Intelligence detects a vendor credential leak or active campaign, it surfaces alongside your own exposure data in the same console. And when Supply Chain Intelligence surfaces threat infrastructure targeting your brand, including impersonating domains, lookalike campaigns and attacker infrastructure tied to a vendor breach, Digital Risk Protection Services can take it down, including infrastructure outside your own perimeter.
That’s what a real exposure management portfolio does. It doesn’t generate findings in silos. It runs a continuous loop: discover, prioritize, mobilize, disrupt.
Infoblox is building toward the unified Exposure Management portfolio the market is moving to. We launched Digital Risk Protection Services earlier this year as the first capability in Infoblox Exposure Management. External Attack Surface Management and Supply Chain Intelligence are the next step, adding outside-in visibility for your own estate and your most critical vendors. More will follow.
To the retailer who found their subdomain already taken over, to the analyst who triaged a vendor breach in minutes instead of hours and to every security leader who’s been asked to reduce exposure they can’t fully see: the outside-in view has always been the attacker’s advantage.
Today, it’s yours.
Footnotes
- Global Cybersecurity Outlook 2026. World Economic Forum. January 12, 2026.