{"id":24070,"date":"2025-10-30T07:49:18","date_gmt":"2025-10-30T07:49:18","guid":{"rendered":"http:\/\/localhost\/?p=24070"},"modified":"2025-10-30T07:49:18","modified_gmt":"2025-10-30T07:49:18","slug":"the-death-of-the-security-checkbox-bas-is-the-power-behind-real-defense","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=24070","title":{"rendered":"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-30T12:05:15&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)\\n\\n**Security doesn&#8217;t fail at the point of breach. It fails at the point of impact.**\\n\\nThat line set the tone for this year&#8217;s **Picus** **Breach and Simulation (BAS) Summit** , where researchers, practitioners, and CISOs all echoed the same theme: cyber defense is no longer about prediction. It&#8217;s about proof.\\n\\nWhen a new exploit drops, scanners scour the internet in minutes. Once attackers gain a foothold, lateral movement often follows just as fast. If your controls haven&#8217;t been tested against the exact techniques in play, you&#8217;re not defending, you&#8217;re hoping things don&#8217;t go seriously pear-shaped.\\n\\nThat&#8217;s why pressure builds long before an incident report is written. The same hour an exploit hits Twitter, a boardroom wants answers. As one speaker put it, _\\&#8221;You can&#8217;t tell the board, &#8216;I&#8217;ll have an answer next week.&#8217; We have hours, not days.\\&#8221;_\\n\\nBAS has outgrown its compliance roots and become the daily voltage test of cybersecurity, the current you run through your stack to see what actually holds.\\n\\nThis article isn&#8217;t a pitch or a walkthrough. It&#8217;s a **recap of what came up on stage** , in essence, how BAS has evolved from an annual checkbox activity to a simple and effective everyday way of proving that your defenses are actually working.\\n\\n## **Security isn&#8217;t about design, it&#8217;s about reaction**\\n\\nFor decades, security was treated like architecture: **design** , **build** , **inspect** , **certify**. A checklist approach built on plans and paperwork.\\n\\nAttackers never agreed to that plan, however. They treat defense like physics, applying continuous pressure until something bends or breaks. They don&#8217;t care what the blueprint says; they care where the structure fails.\\n\\nPentests still matter, but they&#8217;re snapshots in motion. \\n\\n**BAS changed that equation.** It doesn&#8217;t certify a design; it stress-tests the reaction. It runs safe, controlled adversarial behaviors in live environments to prove whether defenses actually respond as they should or not.\\n\\nAs Chris Dale, Principal Instructor at SANS, explains: The difference is mechanical: BAS measures **reaction** , not **potential**. It doesn&#8217;t ask, _\\&#8221;Where are the vulnerabilities?\\&#8221;_ but _\\&#8221;What happens when we hit them?\\&#8221;_\\n\\nBecause ultimately, you don&#8217;t lose when a breach happens,_you lose when the impact of that breach lands_.\\n\\n## **Real defense starts with knowing yourself**\\n\\nBefore you emulate\/simulate the enemy, you have to understand yourself. You can&#8217;t defend what you don&#8217;t see &#8211; the forgotten assets, the untagged accounts, the legacy script still running with domain admin rights.\\n\\n_s\u0131la-blog-video-1_1920x1080.mp4 _\\n\\nThen assume a breach and work backward from the outcome you fear the most.\\n\\nTake **Akira** , for instance, a ransomware chain that deletes backups, abuses PowerShell, and spreads through shared drives. Replay that behavior safely inside your environment, and you&#8217;ll learn, not guess, whether your defenses can break it midstream.\\n\\nTwo principles separated mature programs from the rest:\\n\\n  * **Outcome first:** start from impact, not inventory.\\n  * **Purple by default:** BAS isn&#8217;t red-versus-blue theater; it&#8217;s how intel, engineering, and operations converge \u2014 simulate \u2192 observe \u2192 tune \u2192 re-simulate.\\n\\n\\n\\nAs John Sapp, CISO at Texas Mutual Insurance noted, \\&#8221;teams that make validation a weekly rhythm start seeing proof where they used to see assumptions.\\&#8221;\\n\\n## **The real work of AI is curation, not creation**\\n\\nAI was everywhere this year, but the most valuable insight wasn&#8217;t about power, it was about restraint. Speed matters, but provenance matters more. **Nobody wants an LLM model improvising payloads** or making assumptions about attack behavior.\\n\\nFor now, at least, the most useful kind of AI isn&#8217;t the one that _creates_ , it&#8217;s the one that _organizes_ , taking messy, unstructured threat intelligence and turning it into something defenders can actually use.\\n\\ns\u0131la-blog-video-2_1920x1080.mp4\\n\\nAI now acts less like a single model and more like a **relay of specialists** , each with a specific job and a checkpoint in between:\\n\\n  * **Planner** \u2014 defines what needs to be collected.\\n  * **Researcher** \u2014 verifies and enriches threat data.\\n  * **Builder** \u2014 structures the information into a safe emulation plan.\\n  * **Validator** \u2014 checks fidelity before anything runs.\\n\\n\\n\\nEach agent reviews the last, keeping accuracy high and risk low.\\n\\nOne example summed it up perfectly:\\n\\n_\\&#8221;Give me the link to the Fin8 campaign, and I&#8217;ll show you the MITRE techniques it maps to in hours, not days.\\&#8221;_\\n\\nThat&#8217;s no longer aspirational, it&#8217;s operational. What once took a week of manual cross-referencing, scripting, and validation now fits inside a single workday.\\n\\n**Headline \u2192 Emulation plan \u2192 Safe run.** Not flashy, just faster. Again, _hours, not days._\\n\\n## **Proof from the field shows that BAS works**\\n\\nOne of the most anticipated sessions of the event was a live showcase of BAS in real environments. It wasn&#8217;t theory,**it was operational proof**.\\n\\nA healthcare team ran ransomware chains aligned with sector threat intel, measuring **time-to-detect** and **time-to-respond** , feeding missed detections back into SIEM and EDR rules until the chain broke early.\\n\\nAn insurance provider demonstrated weekend BAS pilots to verify whether endpoint quarantines actually triggered. Those runs exposed silent misconfigurations long before attackers could.\\n\\nThe takeaway was clear: \\n\\nBAS is already part of daily security operations, **not a lab experiment**. When leadership asks, _\\&#8221;Are we protected against this?\\&#8221;_ the answer now comes from evidence, not opinion.\\n\\n## **Validation turns \\&#8221;patch everything\\&#8221; into \\&#8221;patch what matters\\&#8221;**\\n\\nOne of the summit&#8217;s sharpest moments came when the familiar board question surfaced: _\\&#8221;Do we need to patch everything?\\&#8221;_\\n\\nThe answer was unapologetically clear, **no.**\\n\\ns\u0131la-blog-video-3_1920x1080.mp4\\n\\nBAS-driven validation proved that **patching everything isn&#8217;t just unrealistic** ; _it&#8217;s unnecessary_.\\n\\nWhat matters is knowing which vulnerabilities are _actually exploitable_ in your environment. By combining vulnerability data with live control performance, security teams can see where real risk concentrates, not where a scoring system says it should.\\n\\n\\&#8221;_You shouldn&#8217;t patch everything,\\&#8221;_ Volkan Ert\u00fcrk, Picus Co-Founder \\u0026 CTO said. _\\&#8221;Leverage control validation to get a prioritized list of exposures and focus on what&#8217;s truly exploitable for you.\\&#8221;_\\n\\nA CVSS 9.8 shielded by validated prevention and detection may carry little danger, while a medium-severity flaw on an exposed system can open a live attack path.\\n\\nThat shift, **from patching on assumption to patching on evidence** , was one of the event&#8217;s defining moments. BAS doesn&#8217;t tell you _what&#8217;s wrong everywhere_ ; it tells you _what can hurt you here_ , turning Continuous Threat Exposure Management (CTEM) from theory into strategy.\\n\\n**You don&#8217;t need a moonshot to start**\\n\\nAnother key takeaway from Picus security architecture leaders G\u00fcrsel Ar\u0131c\u0131 and Autumn Stambaugh&#8217;s session was that **BAS doesn&#8217;t require a grand rollout; it simply needs to get started.**\\n\\nTeams began without fuss or fanfare, proving value in weeks, not quarters. \\n\\n  * Most picked one or two scopes, finance endpoints, or a production cluster, and mapped the controls protecting them. \\n  * Then they chose a realistic outcome, like data encryption, and built the smallest TTP chain that could make it happen. \\n  * Run it safely, see where prevention or detection fails, fix what matters, and run it again.\\n\\n\\n\\nIn practice, that loop accelerated fast. \\n\\n_By week three_ , AI-assisted workflows were already refreshing threat intel and regenerating safe actions. By week four, validated control data and vulnerability findings merged into exposure scorecards that executives could read at a glance.\\n\\nThe moment a team watched a simulated kill chain stop mid-run **because of a rule shipped the day before** , everything clicked, BAS stopped being a project and became part of their daily security practice.\\n\\n## **BAS works as the verb inside CTEM**\\n\\nGartner&#8217;s Continuous Threat Exposure Management (CTEM) model: \\&#8221;Assess, validate, mobilize\\&#8221; only works when validation is continuous, contextual, and tied to action.\\n\\n**This is where BAS lives now.**\\n\\nIt&#8217;s not a standalone tool; it&#8217;s the engine that keeps CTEM honest, feeding exposure scores, guiding control engineering, and sustaining agility as both your tech stack and the threat surface shift.\\n\\nThe best teams run validation like a heartbeat. Every change, every patch, every new CVE triggers another pulse. _That&#8217;s what continuous validation actually means_.\\n\\n## **The future lies in proof**\\n\\nSecurity used to run on belief. BAS replaces belief with proof, running electrical current through your defenses to see where the circuit fails.\\n\\nAI brings speed. Automation brings scale. Validation brings truth. BAS isn&#8217;t how you talk about security anymore. It&#8217;s how you prove it.\\n\\nBe among the first to experience AI-powered threat intelligence. **Get your early access now!**\\n\\n**Note:** _This article was expertly written and contributed bySila Ozeren Hacioglu, Security Research Engineer at Picus Security._\\n\\nFound this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.\\n&#8221;,&#8221;published&#8221;:&#8221;2025-10-30T11:55:00&#8243;,&#8221;modified&#8221;:&#8221;2025-10-30T11:55:00&#8243;,&#8221;type&#8221;:&#8221;thn&#8221;,&#8221;title&#8221;:&#8221;The Death of the Security Checkbox: BAS Is the Power Behind Real Defense&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;THN:D7010D608BB37ECF6532BF2D74AEB918&#8243;,&#8221;bulletinFamily&#8221;:&#8221;info&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/thehackernews.com\/2025\/10\/the-death-of-security-checkbox-bas-is.html&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-30T12:05:15&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)\\n\\n**Security doesn&#8217;t fail at the point of breach. It fails at the point of impact.**\\n\\nThat line set the tone for this year&#8217;s **Picus** **Breach and&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,13,33,7,11,43,5],"class_list":["post-24070","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-security","tag-tapic","tag-thn","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=24070\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-10-30T12:05:15&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)nn**Security doesn&#8217;t fail at the point of breach. It fails at the point of impact.**nnThat line set the tone for this year&#8217;s **Picus** **Breach and...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=24070\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-30T07:49:18+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24070#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24070\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918\",\"datePublished\":\"2025-10-30T07:49:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24070\"},\"wordCount\":1683,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"Security\",\"tapic\",\"thn\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=24070#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24070\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24070\",\"name\":\"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-10-30T07:49:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24070#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=24070\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24070#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=24070","og_locale":"en_US","og_type":"article","og_title":"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-10-30T12:05:15&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)nn**Security doesn&#8217;t fail at the point of breach. It fails at the point of impact.**nnThat line set the tone for this year&#8217;s **Picus** **Breach and...","og_url":"https:\/\/zero.redgem.net\/?p=24070","og_site_name":"zero redgem","article_published_time":"2025-10-30T07:49:18+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=24070#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=24070"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918","datePublished":"2025-10-30T07:49:18+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=24070"},"wordCount":1683,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","Security","tapic","thn","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=24070#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=24070","url":"https:\/\/zero.redgem.net\/?p=24070","name":"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-10-30T07:49:18+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=24070#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=24070"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=24070#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"The Death of the Security Checkbox: BAS Is the Power Behind Real Defense_THN:D7010D608BB37ECF6532BF2D74AEB918"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/24070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=24070"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/24070\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=24070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=24070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=24070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}