[{"data":1,"prerenderedAt":429},["ShallowReactive",2],{"\u002Fblog\u002Fbeware-the-ulp":3,"blog-all-posts":314},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"bodyLeadTitle":10,"publishedAt":11,"updatedAt":11,"tags":12,"coverImage":16,"coverAlt":17,"heroLayout":18,"heroTitleSize":19,"featured":6,"draft":6,"body":20,"_type":308,"_id":309,"_source":310,"_file":311,"_stem":312,"_extension":313},"\u002Fblog\u002Fbeware-the-ulp","blog",false,"","Beware the ULP","Something Wicked Logged In","The Credentials Attackers Are Waiting For","2026-09-30",[13,14,15],"dark web intelligence","identity security","infostealer malware","\u002Fblog\u002Fbeware-the-ulp\u002Fcover.jpg","Hooded attacker at a computer representing the threat of stolen URL, login, and password records","overlay","compact",{"type":21,"children":22,"toc":299},"root",[23,45,55,67,79,84,91,96,101,106,116,121,126,164,170,175,180,185,191,196,201,229,234,240,245,250,256,261,273,278,284,289,294],{"type":24,"tag":25,"props":26,"children":27},"element","ul",{},[28,35,40],{"type":24,"tag":29,"props":30,"children":31},"li",{},[32],{"type":33,"value":34},"text","Your principal cloud engineer works remotely and is an avid gamer who installs cheat-code software on a work desktop.",{"type":24,"tag":29,"props":36,"children":37},{},[38],{"type":33,"value":39},"Your top sales representative visits sketchy lottery sites on an aging laptop.",{"type":24,"tag":29,"props":41,"children":42},{},[43],{"type":33,"value":44},"Your director of enterprise architecture lets their children install a cracked copy of Photoshop on a family-used device.",{"type":24,"tag":46,"props":47,"children":48},"p",{},[49],{"type":24,"tag":50,"props":51,"children":52},"strong",{},[53],{"type":33,"value":54},"Congratulations: your organization might be visited by the ULP.",{"type":24,"tag":46,"props":56,"children":57},{},[58,60,65],{"type":33,"value":59},"When organizations think about stolen credentials on the dark web, they often picture a massive database breach: millions of email addresses and password hashes dumped into a forum and traded among criminals. Another form of credential exposure can be more immediately damaging: ",{"type":24,"tag":50,"props":61,"children":62},{},[63],{"type":33,"value":64},"URL, Login, Password",{"type":33,"value":66}," records.",{"type":24,"tag":46,"props":68,"children":69},{},[70,72,77],{"type":33,"value":71},"Called simply: ",{"type":24,"tag":50,"props":73,"children":74},{},[75],{"type":33,"value":76},"ULP",{"type":33,"value":78},".",{"type":24,"tag":46,"props":80,"children":81},{},[82],{"type":33,"value":83},"An employee infected with an infostealer may have turned their endpoint into a surveillance platform that captures authentication data and other sensitive information. The result can be a set of credentials with the context attackers need to use them.",{"type":24,"tag":85,"props":86,"children":88},"h2",{"id":87},"ulp-data-in-detail",[89],{"type":33,"value":90},"ULP Data in Detail",{"type":24,"tag":46,"props":92,"children":93},{},[94],{"type":33,"value":95},"ULP datasets are commonly associated with information-stealing malware and credential theft from compromised endpoints. Infostealers can harvest information stored or entered through browsers and applications, including credentials, cookies, authentication artifacts, cryptocurrency-related data, system information, and other sensitive material.",{"type":24,"tag":46,"props":97,"children":98},{},[99],{"type":33,"value":100},"ULPs have appeared with greater frequency in breach data over the last several years. A ULP record contains three pieces of information attackers value: the URL, username, and password.",{"type":24,"tag":46,"props":102,"children":103},{},[104],{"type":33,"value":105},"A typical record conceptually looks like this:",{"type":24,"tag":46,"props":107,"children":108},{},[109],{"type":24,"tag":110,"props":111,"children":113},"code",{"className":112},[],[114],{"type":33,"value":115},"https:\u002F\u002Fportal.example.com : employee@example.com : Password123",{"type":24,"tag":46,"props":117,"children":118},{},[119],{"type":33,"value":120},"The important distinction is the URL. It gives a credential context, and that context makes stolen credentials substantially more useful. A ULP dataset can represent recently captured, highly actionable credential intelligence.",{"type":24,"tag":46,"props":122,"children":123},{},[124],{"type":33,"value":125},"ULPs may point attackers toward critical assets, including:",{"type":24,"tag":25,"props":127,"children":128},{},[129,134,139,144,149,154,159],{"type":24,"tag":29,"props":130,"children":131},{},[132],{"type":33,"value":133},"VPN and remote-access portals",{"type":24,"tag":29,"props":135,"children":136},{},[137],{"type":33,"value":138},"Microsoft 365 and other cloud services",{"type":24,"tag":29,"props":140,"children":141},{},[142],{"type":33,"value":143},"SaaS applications and webmail",{"type":24,"tag":29,"props":145,"children":146},{},[147],{"type":33,"value":148},"Administrative interfaces and developer platforms",{"type":24,"tag":29,"props":150,"children":151},{},[152],{"type":33,"value":153},"Customer portals and financial applications",{"type":24,"tag":29,"props":155,"children":156},{},[157],{"type":33,"value":158},"Internal or externally exposed business systems",{"type":24,"tag":29,"props":160,"children":161},{},[162],{"type":33,"value":163},"Third-party services used by employees",{"type":24,"tag":85,"props":165,"children":167},{"id":166},"ulps-are-more-than-passwords",[168],{"type":33,"value":169},"ULPs Are More Than Passwords",{"type":24,"tag":46,"props":171,"children":172},{},[173],{"type":33,"value":174},"Organizations should avoid treating ULP exposure solely as a password-reset problem. Depending on how the information was stolen, the surrounding compromise may include far more than a username and password.",{"type":24,"tag":46,"props":176,"children":177},{},[178],{"type":33,"value":179},"An infostealer infection can potentially expose browser cookies, session information, autofill data, browser history, host information, and other authentication-related artifacts. The broader lesson is that defenders must consider whether the endpoint and authenticated session were compromised, not merely the password.",{"type":24,"tag":46,"props":181,"children":182},{},[183],{"type":33,"value":184},"Changing an exposed password is essential, but incident response should also consider what else may have been taken from the affected system.",{"type":24,"tag":85,"props":186,"children":188},{"id":187},"the-third-party-and-customer-problem",[189],{"type":33,"value":190},"The Third-Party and Customer Problem",{"type":24,"tag":46,"props":192,"children":193},{},[194],{"type":33,"value":195},"ULP data exposes a weakness conventional vulnerability scanning and risk management may never see: an organization's dependence on external services, the security of employees' home systems, and the security practices of customers and vendors.",{"type":24,"tag":46,"props":197,"children":198},{},[199],{"type":33,"value":200},"Vendors, employees, and customers authenticate to hundreds of systems the company does not own, such as:",{"type":24,"tag":25,"props":202,"children":203},{},[204,209,214,219,224],{"type":24,"tag":29,"props":205,"children":206},{},[207],{"type":33,"value":208},"Payroll and benefits platforms",{"type":24,"tag":29,"props":210,"children":211},{},[212],{"type":33,"value":213},"CRM and marketing applications",{"type":24,"tag":29,"props":215,"children":216},{},[217],{"type":33,"value":218},"Cloud consoles and code repositories",{"type":24,"tag":29,"props":220,"children":221},{},[222],{"type":33,"value":223},"Accounting and file-sharing services",{"type":24,"tag":29,"props":225,"children":226},{},[227],{"type":33,"value":228},"Managed service providers and industry-specific applications",{"type":24,"tag":46,"props":230,"children":231},{},[232],{"type":33,"value":233},"A traditional external vulnerability scan of corporate IP addresses may reveal none of these relationships. That makes Dark Web Breach Data useful not only for detecting compromised accounts, but also for discovering portions of an organization's identity and third-party attack surface that may already be exposed.",{"type":24,"tag":85,"props":235,"children":237},{"id":236},"executives-are-particularly-interesting",[238],{"type":33,"value":239},"Executives Are Particularly Interesting",{"type":24,"tag":46,"props":241,"children":242},{},[243],{"type":33,"value":244},"Executives are especially valuable targets because their digital identities often extend far beyond a single corporate account. A CEO, CFO, CIO, or CISO may interact with financial institutions, board portals, cloud services, travel systems, professional networks, personal email accounts, and numerous third-party platforms.",{"type":24,"tag":46,"props":246,"children":247},{},[248],{"type":33,"value":249},"Attackers do not respect the artificial boundary between corporate and personal identity. An infection on a personal or home-used device can create risk well beyond that device.",{"type":24,"tag":85,"props":251,"children":253},{"id":252},"a-ulp-record-is-a-lead-not-proof-of-access",[254],{"type":33,"value":255},"A ULP Record Is a Lead, Not Proof of Access",{"type":24,"tag":46,"props":257,"children":258},{},[259],{"type":33,"value":260},"Finding a ULP record does not automatically mean the stolen credentials still work. The password may have changed, the account may be disabled, MFA may prevent authentication, the URL may no longer exist, or the data may be old, duplicated, malformed, or incorrectly attributed.",{"type":24,"tag":46,"props":262,"children":263},{},[264,266,271],{"type":33,"value":265},"Dark Web datasets are messy. ULP data should therefore be treated as ",{"type":24,"tag":50,"props":267,"children":268},{},[269],{"type":33,"value":270},"security intelligence requiring validation and investigation",{"type":33,"value":272},", not automatic proof that an account is currently compromised.",{"type":24,"tag":46,"props":274,"children":275},{},[276],{"type":33,"value":277},"But defenders should not confuse uncertainty with irrelevance. From an attacker's perspective, trying a known authentication path can be dramatically easier than discovering one from scratch.",{"type":24,"tag":85,"props":279,"children":281},{"id":280},"what-organizations-should-do",[282],{"type":33,"value":283},"What Organizations Should Do",{"type":24,"tag":46,"props":285,"children":286},{},[287],{"type":33,"value":288},"Organizations should incorporate a Dark Web Breach Data assessment into their penetration-testing and risk-management schedules. Those that identify relevant ULP exposure need a defined response process; for privileged accounts and critical systems, the response should be correspondingly aggressive.",{"type":24,"tag":46,"props":290,"children":291},{},[292],{"type":33,"value":293},"Repeated ULP exposure can reveal weaknesses in endpoint security, credential management, MFA coverage, third-party access, employee security practices, and identity architecture. The objective is not simply to remove individual exposed passwords. It is to understand why usable authentication information is escaping the organization and what an attacker could do with it.",{"type":24,"tag":46,"props":295,"children":296},{},[297],{"type":33,"value":298},"Cybersecurity is a process, not a destination. Incorporating Dark Web ULP intelligence into risk management is one practical way to make that process stronger.",{"title":7,"searchDepth":300,"depth":300,"links":301},2,[302,303,304,305,306,307],{"id":87,"depth":300,"text":90},{"id":166,"depth":300,"text":169},{"id":187,"depth":300,"text":190},{"id":236,"depth":300,"text":239},{"id":252,"depth":300,"text":255},{"id":280,"depth":300,"text":283},"markdown","content:blog:beware-the-ulp.md","content","blog\u002Fbeware-the-ulp.md","blog\u002Fbeware-the-ulp","md",[315,317,328,339,351,362,372,381,391,399,409,419],{"_path":4,"title":8,"description":9,"publishedAt":11,"tags":316,"coverImage":16,"coverAlt":17,"featured":6},[13,14,15],{"_path":318,"title":319,"description":320,"publishedAt":321,"tags":322,"coverImage":326,"coverAlt":327,"featured":6},"\u002Fblog\u002Fbuilding-an-ai-hacker-lab","Building an AI Hacker Lab","Build a contained, observable, and reversible environment for developing and testing autonomous AI and cybersecurity agents.","2026-08-26",[323,324,325],"artificial intelligence","cybersecurity strategy","AI safety","\u002Fblog\u002Fbuilding-an-ai-hacker-lab\u002Fcover.jpg","Illustrated AI hacker lab showing the autonomous-agent development lifecycle, isolated infrastructure, source control, local and frontier models, and security monitoring",{"_path":329,"title":330,"description":331,"cardTitle":330,"publishedAt":332,"tags":333,"coverImage":337,"coverAlt":338,"featured":6},"\u002Fblog\u002Fwhite-glove-cybersecurity-risk-assessments-penetration-tests","White Glove Cybersecurity","Combining enterprise risk assessments with hands-on penetration testing reveals how secure an organization really is.","2026-08-13",[334,335,336],"cybersecurity assessments","risk assessments","penetration testing","\u002Fblog\u002Fwhite-glove-cybersecurity-risk-assessments-penetration-tests\u002Fcover.jpg","White-glove professional presenting an integrated cybersecurity risk assessment and penetration testing environment",{"_path":340,"title":341,"description":342,"cardTitle":343,"publishedAt":344,"tags":345,"coverImage":349,"coverAlt":350,"featured":6},"\u002Fblog\u002Fexecutive-operational-security-opsec-part-two-osint-attack-surface","Executive Operational Security (OPSEC) Part Two: OSINT Attack Surface","Publicly available information expands an executive's attack surface and gives cybercriminals the intelligence needed for targeted attacks.","Executive Operational Security Part Two","2026-08-06",[346,347,348],"executive security","OPSEC","OSINT","\u002Fblog\u002Fexecutive-operational-security-opsec-part-two-osint-attack-surface\u002Fcover.jpg","Executive standing beside a digital OSINT profile mapping public and professional information",{"_path":352,"title":353,"description":354,"cardTitle":355,"publishedAt":356,"tags":357,"coverImage":360,"coverAlt":361,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two","Understanding Your True Attack Surface: Part Two","Few companies understand how they look to an attacker. Your Internet attack surface is exactly what attackers see first.","Understanding Your True Attack Surface Part Two","2026-07-28",[358,359,324],"attack surface","internet security","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two\u002Fcover.jpg","Cyber operations control tower monitoring a connected city and its Internet-facing attack surface",{"_path":363,"title":364,"description":365,"publishedAt":366,"tags":367,"coverImage":370,"coverAlt":371,"featured":6},"\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026","Top Cyber Threats Facing Businesses in 2026","Businesses face AI-assisted hacking, interception-proxy phishing, dark web breach data, and API attacks in 2026.","2026-06-26",[368,369,324],"cyber threats","business security","\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026\u002Fcover.jpg","A city skyline beneath a massive storm cloud embedded with cybersecurity symbols and lightning",{"_path":373,"title":374,"description":375,"publishedAt":376,"tags":377,"coverImage":379,"coverAlt":380,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two","Challenges Facing AI Frontier Models Part Two","Frontier AI models must overcome constraints in context, agent design, data quality, energy, and open-source competition.","2026-06-25",[323,378,325],"frontier models","\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two\u002Fcover.jpg","A humanoid robot ascending a snowy mountain ridge toward the sunset",{"_path":382,"title":383,"description":384,"cardTitle":385,"publishedAt":386,"tags":387,"coverImage":389,"coverAlt":390,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one","Understanding Your True Attack Surface: Part One","The modern attack surface extends far beyond the corporate firewall.","Understanding Your True Attack Surface Part One","2026-06-21",[358,388,324],"network security","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one\u002Fcover.jpg","Security leader reviewing an enterprise attack surface dashboard spanning cloud, applications, remote offices, devices, patching, identities, and internet exposure",{"_path":392,"title":393,"description":394,"publishedAt":395,"tags":396,"coverImage":397,"coverAlt":398,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models","Challenges Facing AI Frontier Models Part One","Frontier AI models face a series of challenges that threaten their viability","2026-06-12",[323,378,325],"\u002Fblog\u002Fchallenges-facing-ai-frontier-models\u002Fcover.jpg","A humanoid robot standing among clouds beneath a blue sky",{"_path":400,"title":401,"description":402,"cardTitle":403,"publishedAt":404,"tags":405,"coverImage":407,"coverAlt":408,"featured":6},"\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation","Executive Operational Security Part One: Setting the Foundation","Executive OPSEC protects senior leaders, privileged access, sensitive information, communications, travel, and personal activity from targeted threats.","Executive Operational Security Part One","2026-06-10",[346,347,406],"risk management","\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation\u002Fcover.jpg","Executive reviewing his phone beside a laptop in a private office",{"_path":410,"title":411,"description":412,"publishedAt":413,"tags":414,"coverImage":417,"coverAlt":418,"featured":6},"\u002Fblog\u002Fevaluating-identity-before-attackers-do","Evaluating Identity Before Attackers Do","An IAM assessment evaluates authentication, access controls, user behavior, and identity resilience before attackers can exploit them.","2026-06-07",[14,415,416],"IAM assessment","access management","\u002Fblog\u002Fevaluating-identity-before-attackers-do\u002Fcover.jpg","Open cyber vault displaying identity security controls and authentication monitoring",{"_path":420,"title":421,"description":422,"publishedAt":423,"tags":424,"coverImage":427,"coverAlt":428,"featured":6},"\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment","The Necessity of an Enterprise Risk Assessment","Effective Cybersecurity is both a Technical and Procedural Endeavor","2026-05-26",[425,406,426],"enterprise risk assessment","cybersecurity governance","\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment\u002Fcover.jpg","CISO in an aircraft cockpit overlooking clouds with technical and procedural cybersecurity displays",1790813428791]