Ai

Infoblox Enters the External Attack Surface Management Market as AI Shortens the Path from Exposure to Exploit

Zaara Abbas

By: Zaara Abbas

4 min read

External attack surface management has become one of enterprise security’s most crowded categories, with platform vendors folding outside-in discovery into suites customers already own. Infoblox is entering it with a bet that its DNS heritage surfaces a class of internet-facing exposure that scanning-based competitors routinely miss.

When Infoblox ran an early access program for its new external attack surface management capability, it found dangling CNAME records at 31 of roughly 40 participating organizations. These are orphaned DNS pointers, left behind when a cloud service or marketing microsite is decommissioned but the record directing traffic to it is not. Nearly one third of the records identified were easy or trivial to take over, which would let an attacker host phishing pages, harvest credentials or send spoofed email from a trusted corporate domain.

That figure is the argument behind the company’s entry into the external attack surface management market, or EASM, announced last week alongside a second capability, Supply Chain Intelligence. Both join Digital Risk Protection Services inside the Infoblox Exposure Management portfolio, launched earlier this year. The EASM capability discovers internet-facing assets without software installation, credentialed access or active scanning, and ranks findings by exploitability and business impact rather than raw vulnerability count.

Why the Timing Favors Outside-In Visibility

The commercial logic rests on time compression. Reconnaissance, vulnerability identification and exploit creation once took attackers weeks; with frontier AI models, the same sequence can run in hours. Verizon’s 2026 Data Breach Investigations Report recorded the consequence: exploitation of software flaws overtook stolen credentials as the leading initial access vector for the first time, accounting for 31 percent of breaches.

“AI is forcing organizations to rethink how they manage cyber risk,” said Michelle Abraham, Research Vice President, Security and Trust, IDC. “As attackers automate reconnaissance and compress the time between exposure and exploitation, organizations need continuous visibility into their external attack surface and better context to prioritize the exposures that pose the greatest business risk. This is driving growing interest in pre-emptive approaches to external attack surface management as part of broader exposure management strategies.”

The Vendor Perimeter is Now the Perimeter

Supply Chain Intelligence extends the same outside-in view to the internet-facing assets of an organization’s critical vendors, monitoring exposures, leaked credentials, dark web activity and active threat campaigns. The market case here is arguably stronger than for EASM itself. Third-party involvement appeared in 48 percent of confirmed breaches in the 2026 DBIR, up 60 percent year over year after doubling the year before. Security teams are being held accountable for infrastructure they neither own nor can scan.

“The simple question every security leader should be able to answer is: ‘What can an attacker reach right now?’” said Mukesh Gupta, chief product officer at Infoblox. “As AI accelerates attacker reconnaissance, that question has become much harder to answer. With External Attack Surface Management, we’re applying Infoblox’s deep DNS expertise to help customers discover the internet-facing exposures that matter most before they become incidents. By extending that same outside-in approach to critical vendors through Supply Chain Intelligence, we’re helping organizations gain a more complete view of external risk. Combined with Digital Risk Protection Services, customers can not only identify emerging threats across their own environments and third-party ecosystem, but also take action to disrupt them before they become incidents. That’s what a more pre-emptive approach to cybersecurity looks like.”

Entering a Category the Platforms Already Claim

Infoblox arrives late to a category with entrenched incumbents. Palo Alto Networks sells Cortex Xpanse, Microsoft ships Defender EASM, CrowdStrike offers Falcon Surface, and Tenable, Qualys, Rapid7, Censys and Bitsight all compete for the same budget line. Most bundle external discovery into platforms customers already license, setting a high bar for any entrant asking a security team to adopt another console.

The company’s answer is distribution and data. Infoblox reports more than 5,700 customers, including the majority of the Fortune 100, most already running its DNS, DHCP and IP address management software. DNS hygiene is also a real blind spot in tools built around port scanning and certificate enumeration; a dangling CNAME is a configuration artifact rather than a vulnerability, and rarely registers as a finding until someone claims the abandoned resource. Whether that is a product or a feature is what buyers will press hardest.

The early access sample is small, and 40 organizations willing to test an unreleased discovery tool are not a representative cross-section of enterprise IT. The unified exposure portfolio also remains partly forward-looking, with further capabilities still to come. For US enterprises consolidating security spending, the practical test is narrower than the positioning: whether DNS-native discovery finds exposures the incumbent platform missed, and whether vendor telemetry arrives with enough context to be actioned rather than filed.

 

Share this article

Related Articles