Welcome to the ExtraHop Blog

FEATURED BLOG
The Dwell Time Dilemma: How Dwell Time Fuels Network Sprawl
November 25, 2025
Threat actors remain undetected for months or years, fueling network sprawl and devastating breaches. Learn about how to drive dwell time to zero.

Anatomy of an Attack
Anthropic AI Attack: How NDR Detects GTG-1002 Cyber Espionage
November 24, 2025
The GTG-1002 Campaign: Anthropic Reveals the First AI-Orchestrated Cyber Espionage Attack

Anatomy of the Attack
Healthcare Ransomware Defense: How NDR Stops Attacks Like Tufts & Eurofins
November 13, 2025
Deconstruct the Tufts Medicine & Eurofins ransomware attacks. Learn how NDR detects the advanced TTPs and lateral movement that perimeter security misses.

New in RevealX – From Blind Spots to Breakthroughs: Fulfilling on the Vision of the Modern SOC.
November 5, 2025
This release adds integration with Zscaler Private Access (ZPA) to unify visibility into user identity and device behavior across the SSE environment, and enhances our customers’ ability to detect adversaries who utilize LOLBAS techniques
Anatomy of an Attack

Anthropic AI Attack: How NDR Detects GTG-1002 Cyber Espionage
November 24, 2025
The GTG-1002 Campaign: Anthropic Reveals the First AI-Orchestrated Cyber Espionage Attack

Healthcare Ransomware Defense: How NDR Stops Attacks Like Tufts & Eurofins
November 13, 2025
Deconstruct the Tufts Medicine & Eurofins ransomware attacks. Learn how NDR detects the advanced TTPs and lateral movement that perimeter security misses.

Flax Typhoon's ArcGIS Backdoor: Why EDR Failed and How NDR Finds the Webshell
October 30, 2025
Anatomy of an Attack: Flax Typhoon’s ArcGIS Backdoor & NDR Detection

F5 Discloses Nation-State Attack on Cybersecurity Firm, Prompting CISA Emergency Order to Patch BIG-IP
October 20, 2025
Beyond the Patch: Why NDR is Essential for Hunting the Nation-State Actor Inside Compromised F5 Networks

Ransomware Hits JLR Supply Chain, Results in Five Week Disruption
October 17, 2025
The JLR Ransomware Attack: A Supply Chain Under Siege

Iranian Cyber Actors Target U.S. Interests: A Heightened Alert for Critical Infrastructure
September 15, 2025
An urgent alert warns of escalating Iranian cyberattacks targeting U.S. critical infrastructure, leveraging disinformation, phishing, and DDoS. Proactive measures, including NDR solutions like ExtraHop RevealX, are crucial for defense against these evolving threats.

Healthcare Data Breach Exposes 5.4 Million Patient Records
September 8, 2025
A ransomware attack at the healthcare data analytics provider Episource has resulted in a data breach exposing the protected health information (PHI) of more than 5.4 million patients.

Major International Airline Cyber Incident
August 29, 2025
Learn about how 6 million customer records were compromised by this cyber attack and how ExtraHop can help

CISA Alert on Salt Typhoon
August 29, 2025
Learn about the cybersecurity critical joint advisory released on August 27, 2025 by CISA, NSA, and the FBI on Salt Typhoon







