Red Sentry
Human-led penetration testing that goes beyond compliance and simulates real attacks.
05/28/2026
CMMC requirements are evolving fast, and many organizations are still trying to understand what actually applies to them, especially subcontractors and companies within the Defense Industrial Base.
To help cut through the confusion, Red Sentry is hosting a live AMA alongside Secureframe and Redspin focused on practical conversations around todayโs CMMC landscape, common compliance challenges, and how organizations can realistically prepare.
Joining the discussion:
โข Marc Rubbinaccio from Secureframe, a cybersecurity and compliance leader with extensive experience across CMMC, FedRAMP, SOC 2, PCI-DSS, and ISO 27001.
โข Robert Teague from Redspin, a former U.S. Army leader and CMMC Certified Lead Assessor with more than 30 years of experience supporting federal cybersecurity and Defense Industrial Base initiatives.
No slides. No sales pitch. Just real answers and open discussion.
๐ June 11 at 1 PM EST
Registration link in the first comment.
05/28/2026
๐ช๐ฒ๐ฏ ๐ฎ๐ฝ๐ฝ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ถ๐ ๐ป๐ผ ๐น๐ผ๐ป๐ด๐ฒ๐ฟ ๐ฎ๐ฏ๐ผ๐๐ ๐ณ๐ถ๐
๐ถ๐ป๐ด "๐ฏ๐ฎ๐ฑ ๐ฐ๐ผ๐ฑ๐ฒ." ๐๐โ๐ ๐ฎ๐ฏ๐ผ๐๐ ๐ฑ๐ฒ๐ณ๐ฒ๐ป๐ฑ๐ถ๐ป๐ด ๐ฎ ๐ฏ๐ฟ๐ผ๐ธ๐ฒ๐ป ๐ฒ๐ฐ๐ผ๐๐๐๐๐ฒ๐บ.
In 2026, the threat landscape has fundamentally shifted. Attackers aren't hunting for isolated bugs in your proprietary code; they are exploiting the sheer interconnectedness of your digital supply chain.
Legacy scanners will call your code "clean", but they miss the architectural flaws that modern adversaries target.
๐ง๐ต๐ฒ ๐ฏ ๐ฏ๐ถ๐ด๐ด๐ฒ๐๐ ๐ฏ๐น๐ถ๐ป๐ฑ ๐๐ฝ๐ผ๐๐ ๐ถ๐ป ๐๐ผ๐๐ฟ ๐ฒ๐ฐ๐ผ๐๐๐๐๐ฒ๐บ ๐ฟ๐ถ๐ด๐ต๐ ๐ป๐ผ๐:
- ๐๐ฃ๐ ๐๐ต๐ฎ๐ผ๐: Modern apps are fragments held together by APIs. Attackers skip the front door and exploit weak authentication on minor backend services.
- ๐๐/๐๐ ๐ฃ๐ถ๐ฝ๐ฒ๐น๐ถ๐ป๐ฒ๐: Fast deployment speeds create massive targets. If an attacker compromises a pipeline tool or developer credentials, they compromise your entire build process.
- ๐ง๐ต๐ถ๐ฟ๐ฑ-๐ฃ๐ฎ๐ฟ๐๐ ๐๐ผ๐ฑ๐ฒ: Most of your app wasn't written by your team. Open-source libraries and external scripts create a fragile web where one hijacked package compromises thousands of apps overnight.
Move away from once-a-year compliance checks. To survive, you need continuous, ecosystem-centric pe*******on testing that evaluates your APIs, CI/CD pipelines, and supply chain dependencies as a unified whole.
Read the full article below.
Final part of our RSAC mini mics ๐ค
During the happy hour we co-hosted with Rippling and Johanson Group LLP at RSAC Conference, the conversation somehow turned into:
โ mustaches in IT
โ why โIโm not trying to sell you anythingโ immediately sounds suspicious
โ the importance of keeping humans in the loop in cybersecurity
โ and AI bots intentionally programmed to tell terrible jokes
Honestly, probably the most accurate summary of RSAC possible ๐ญ
One of the best parts of this series was seeing people drop the polished conference mode for a minute and just have real conversations. Thatโs exactly the vibe we wanted.
Huge shoutout to our very own Max Turner for hosting the mini mic chaos all week long.
And big thanks to everyone who stopped by to share a thought, a hot take, or just a laugh with us โค๏ธ
05/20/2026
"๐๐๐ ๐ผ๐๐ฟ ๐ฐ๐น๐ถ๐ฒ๐ป๐ ๐ฝ๐ผ๐ฟ๐๐ฎ๐น ๐ถ๐ ๐ฒ๐ป๐ฐ๐ฟ๐๐ฝ๐๐ฒ๐ฑ!"
Relying solely on encryption (HTTPS) is like locking your front door but leaving the back window wide open. Encryption creates a secure tunnel to stop eavesdroppers, but it ๐ฑ๐ผ๐ฒ๐ ๐ป๐ผ๐ ๐๐ฒ๐ฟ๐ถ๐ณ๐ ๐๐ต๐ฒ ๐๐ฎ๐ณ๐ฒ๐๐ ๐ผ๐ณ ๐๐ต๐ฒ ๐ณ๐ถ๐น๐ฒ๐ ๐ฝ๐ฎ๐๐๐ถ๐ป๐ด ๐๐ต๐ฟ๐ผ๐๐ด๐ต ๐ถ๐. In fact, it actually hides malicious traffic from basic security tools.
For law firms managing digital paperwork, this blind spot is a goldmine for hackers.
Without strict validation, a client portal is vulnerable to ๐จ๐ป๐ฟ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐๐ฒ๐ฑ ๐๐ถ๐น๐ฒ ๐จ๐ฝ๐น๐ผ๐ฎ๐ฑ, allowing cybercriminals to disguise malicious scripts as PDFs.
Once inside your server, attackers can:
- ๐๐ฒ๐ฝ๐น๐ผ๐ ๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐ฎ๐ฟ๐ฒ: Freeze your operations entirely.
- ๐๐
๐ณ๐ถ๐น๐๐ฟ๐ฎ๐๐ฒ ๐๐ฎ๐๐ฎ: Steal M&A plans, IP, and privileged communications.
- ๐๐ป๐ณ๐ถ๐น๐๐ฟ๐ฎ๐๐ฒ ๐ก๐ฒ๐๐๐ผ๐ฟ๐ธ๐: Gain a permanent backdoor into your billing and email systems.
Law firms hold the "keys to the kingdom." To protect your reputation and your clients, you must move beyond the basic padlock icon.
๐ฏ ๐ฆ๐๐ฒ๐ฝ๐ ๐๐ผ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ฌ๐ผ๐๐ฟ ๐๐ถ๐ฟ๐บ:
- ๐ฆ๐๐ฟ๐ถ๐ฐ๐ ๐๐ถ๐น๐ฒ ๐ฉ๐ฎ๐น๐ถ๐ฑ๐ฎ๐๐ถ๐ผ๐ป: Scan and verify files before they hit your server.
- ๐๐ฒ๐ฎ๐๐ ๐ฃ๐ฟ๐ถ๐๐ถ๐น๐ฒ๐ด๐ฒ ๐ฃ๐ฒ๐ฟ๐บ๐ถ๐๐๐ถ๐ผ๐ป๐: Restrict web app capabilities to stop unauthorized code ex*****on.
- ๐๐ผ๐ป๐๐ถ๐ป๐๐ผ๐๐ ๐ฃ๐ฒ๐ป๐ฒ๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป ๐ง๐ฒ๐๐๐ถ๐ป๐ด: Find the flaws before a hacker does.
Stop guessing if your legal tech is secure.
Read our full breakdown below.
Most companies treat SOC 2 like a stressful annual scavenger hunt.
But what happens when compliance becomes operational instead of manual?
Tomorrow, weโre dropping a new episode of Ctrl-Alt-Secure with Emma Lawler and AJ Yawn from Rippling, where we dive into:
โข Why traditional compliance drains teams
โข How automation changes the audit experience
โข The role of first-party data in modern GRC
โข Why auditor independence still matters
โข What it looks like to engineer compliance instead of chasing screenshots
A really interesting conversation on where compliance and security operations are headed next.
Full episode drops tomorrow. Stay tuned!
05/15/2026
At some point, every founder hears:
โYou need SOC 2 before we can move forward.โ
And suddenly, youโre spending more time screenshotting compliance than actually building.
Weโll be talking about exactly that with Rippling and Johanson Group LLP at Salesforce Tower on June 3: How startups can become enterprise-ready without slowing everything down.
And since weโll already be in SFโฆ weโre also co-hosting a happy hour that same week ๐ธ
Matias Donnet and Michael Shelton from our team will be there - come say hi!
๐ SF | June 2 & 3
๐ Links in the first comment.
Part 2 of our RSAC mini mics ๐ค
Back at RSAC Conference during the happy hour we co-hosted with Rippling and Johanson Group LLP, we kept asking people whatโs actually happening in cybersecurity right now.
Some of the takes this round:
โ Computer science students are getting more into writing
โ Mostly because everyoneโs trying to get better at AI prompting
โ AI is powerful, but definitely comes with risks
โ And apparently, a โfree tripโ email is still a pretty convincing phishing lure ๐
Honestly, these were some of our favorite moments from RSAC. Just real conversations, real opinions, and people having fun with it.
Big thanks to everyone who jumped in to share thoughts and laughs with us!
Last part coming soon ๐
05/12/2026
๐ฌ๐ผ๐๐ฟ ๐ ๐๐ ๐ถ๐๐ปโ๐ ๐๐ต๐ฒ "๐ฆ๐ถ๐น๐๐ฒ๐ฟ ๐๐๐น๐น๐ฒ๐" ๐๐ผ๐ ๐๐ต๐ถ๐ป๐ธ ๐ถ๐ ๐ถ๐.
The old "castle and moat" strategy is dead. Today, ๐๐ฑ๐ฒ๐ป๐๐ถ๐๐ ๐ถ๐ ๐๐ต๐ฒ ๐ป๐ฒ๐ ๐ฝ๐ฒ๐ฟ๐ถ๐บ๐ฒ๐๐ฒ๐ฟโand the wall is cracking.
While MFA blocks 99% of bulk attacks, sophisticated attackers aren't "breaking" your security anymore. Theyโre simply riding the wave of your successful login.
๐๐ผ๐ ๐๐ต๐ฒ๐ ๐ฏ๐๐ฝ๐ฎ๐๐ ๐๐ต๐ฒ ๐๐ต๐ถ๐ฒ๐น๐ฑ:
- ๐๐ถ๐ง๐ ๐๐๐๐ฎ๐ฐ๐ธ๐: Intercepting session tokens in real-time to "clone" your authenticated state.
- ๐ ๐๐ ๐๐ฎ๐๐ถ๐ด๐๐ฒ: Weaponizing human psychology through push-notification spam until a user hits "Approve."
- ๐ฆ๐ฒ๐๐๐ถ๐ผ๐ป ๐๐ถ๐ท๐ฎ๐ฐ๐ธ๐ถ๐ป๐ด: Using malware or XSS to steal cookies, bypassing the login process entirely.
๐ง๐ต๐ฒ ๐ ๐ผ๐๐ฒ ๐๐ผ ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด-๐ฅ๐ฒ๐๐ถ๐๐๐ฎ๐ป๐ฐ๐ฒ
If identity is where attacks start and end, we need stronger materials:
- ๐๐๐๐ข๐ฎ/๐ช๐ฒ๐ฏ๐๐๐๐ต๐ป: Hardware keys that make interception impossible.
- ๐๐ผ๐ป๐ฑ๐ถ๐๐ถ๐ผ๐ป๐ฎ๐น ๐๐ฐ๐ฐ๐ฒ๐๐: Evaluating device health and context, not just a password.
- ๐๐ผ๐ป๐๐ถ๐ป๐๐ผ๐๐ ๐ ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด: Because security shouldn't end once the "Login" button is clicked.
๐ฆ๐๐ผ๐ฝ ๐๐ผ๐ป๐ฑ๐ฒ๐ฟ๐ถ๐ป๐ด ๐ถ๐ณ ๐๐ผ๐๐ฟ ๐ ๐๐ ๐ถ๐ ๐ฒ๐ป๐ผ๐๐ด๐ต. ๐ฆ๐๐ฎ๐ฟ๐ ๐ธ๐ป๐ผ๐๐ถ๐ป๐ด.
Our Web App pentesting services expose the logic flaws and authentication gaps that automated tools miss. Letโs stress-test your perimeter before an attacker does.
Read the full article below.
Everyone says they want to โstreamline SOC 2.โ
But most teams are still doing this:
- screenshot by screenshot
- spreadsheet by spreadsheet
- audit panic once a year
At some point, compliance became more about proving systems work than actually making them better.
In our upcoming ๐๐๐ฟ๐น-๐๐น๐-๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ episode with AJ Yawn and Emma Lawler from Rippling, weโre talking about why GRC needs a mindset shift:
What if SOC 2 wasnโt treated like a painful annual projectโฆ but like a living product that continuously evolves?
We get into:
โ Why the 1st and 5th SOC 2 are both painful
โ Why audits shouldnโt define your year
โ How to move evidence collection to where the evidence already lives
โ And why itโs time to stop screenshotting compliance
Hereโs a little sneak peek ๐ฅ
Full episode dropping soon - release date announcement coming shortly.
05/08/2026
๐๐ ๐๐ผ๐๐ฟ ๐๐ ๐ฐ๐ต๐ฎ๐๐ฏ๐ผ๐ ๐ฎ "๐ต๐ถ๐ด๐ต-๐๐ฝ๐ฒ๐ฒ๐ฑ ๐ต๐ถ๐ด๐ต๐๐ฎ๐" ๐ณ๐ผ๐ฟ ๐ต๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐?
Organizations are racing to "bolt on" LLMs, but weโre repeating the mistakes of the SQL injection era. The new threat is ๐ฃ๐ฟ๐ผ๐บ๐ฝ๐ ๐๐ป๐ท๐ฒ๐ฐ๐๐ถ๐ผ๐ป, where hackers use simple prose to hijack your system.
๐ช๐ต๐ ๐ฑ๐ผ๐ฒ๐ ๐ถ๐ ๐ต๐ฎ๐ฝ๐ฝ๐ฒ๐ป:
- ๐ฃ๐ฟ๐ผ๐๐ฒ ๐ฎ๐ ๐๐ผ๐ฑ๐ฒ: Attackers use "polite" requests to trick AI into leaking data or bypassing auth.
- ๐ช๐๐๐ ๐ฎ๐ฟ๐ฒ ๐๐น๐ถ๐ป๐ฑ: Traditional firewalls look for code, not natural language.
- ๐ง๐ต๐ฒ "๐๐ผ๐ป๐ณ๐๐๐ฒ๐ฑ ๐๐ฒ๐ฝ๐๐๐": If your AI has API access, a hijacked prompt can trigger unauthorized actions.
๐ง๐ต๐ฒ ๐ฆ๐๐ฟ๐ฎ๐๐ฒ๐ด๐:
- ๐ ๐ถ๐ป๐ถ๐บ๐ถ๐๐ฒ ๐ฃ๐ฟ๐ถ๐๐ถ๐น๐ฒ๐ด๐ฒ: Don't give an LLM "write" access it doesn't need.
- ๐๐๐บ๐ฎ๐ป-๐ถ๐ป-๐๐ต๐ฒ-๐๐ผ๐ผ๐ฝ: Confirm sensitive actions outside the AI interface.
- ๐๐น๐๐ฎ๐๐-๐ผ๐ป ๐ฃ๐ฒ๐ป๐๐ฒ๐๐๐ถ๐ป๐ด: AI bypasses evolve daily; your testing must too.
๐๐ป๐ป๐ผ๐๐ฎ๐๐ถ๐ผ๐ป ๐๐ต๐ผ๐๐น๐ฑ๐ปโ๐ ๐บ๐ฒ๐ฎ๐ป ๐ฐ๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ.
Secure your web apps and shut down vulnerabilities before theyโre exploited.
Check the full article here: https://dub.sh/WXUdSab
Click here to claim your Sponsored Listing.
Category
Contact the business
Website
Address
3490 Piedmont Road NE
Atlanta, GA
30305
Opening Hours
| Monday | 8am - 6pm |
| Tuesday | 8am - 6pm |
| Wednesday | 8am - 6pm |
| Thursday | 8am - 6pm |
| Friday | 8am - 6pm |
| Saturday | 8am - 12pm |
| Sunday | 8am - 12pm |