Infoblox joins crowded EASM market with DNS-centric approach Infoblox entered the External Attack Surface Management market with a DNS-centric approach, announcing new EASM and Supply Chain Intelligence capabilities to give organizations continuous visibility into internet-facing assets and vendor exposures. The company claims its agentless, credential-free discovery method surfaces DNS-specific issues like dangling CNAME records, which an early access program found at 31 of 40 participants, a third of which were easy to hijack. IDC research vice president Michelle Abraham said growing interest in preemptive exposure management is driving the market. With AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long before an incident happens. Infoblox is the latest to make that move, announcing its entry into the External Attack Surface Management EASM https://www.csoonline.com/article/574797/9-attack-surface-discovery-and-management-tools.html market alongside a new Supply Chain Intelligence capability that broadens its exposure management portfolio. These two additions are designed to give organizations visibility into both their own internet-facing assets and those of their critical vendors. According to Infoblox, the combined offering enables security teams to discover, prioritize, and reduce external exposures before attackers can exploit them. “As attackers automate reconnaissance, organizations need continuous visibility into their external attack surface and better context to prioritize the exposures that pose the greatest business risk,” said Michelle Abraham https://my.idc.com/getdoc.jsp?containerId=PRF005492 , research vice president for Security and Trust at IDC. “This is driving growing interest in preemptive approaches to external attack surface management as part of broader exposure management strategies.” The new capabilities join Infoblox’s existing Digital Risk Protection Services DPRS https://www.infoblox.com/resources/faqs/infoblox-exposure-management-digital-risk-protection-services/ . External Attack Surface Management has become one of the fastest-growing segments https://www.csoonline.com/article/4090333/5-key-ways-attack-surface-management-will-evolve-in-2026.html in cybersecurity, with vendors racing to help enterprises inventory internet-facing assets and identify exploitable weaknesses. Infoblox’s differentiation lies in applying its long-standing DNS expertise https://www.csoonline.com/article/3991070/poor-dns-hygiene-is-leading-to-domain-hijacking-report.html to the problem. The company’s new EASM capability discovers internet-facing assets without requiring software agents, credentials or active scanning, the company said in a press statement shared with CSO ahead of the announcement on Tuesday. It also evaluates exposures based on exploitability and business impact while surfacing DNS-specific issues that conventional EASM platforms may overlook, Infoblox claims. Among such issues are “dangling CNAME records,” which refer to the orphaned DNS entries that attackers can hijack to host phishing sites, steal credentials, or impersonate trusted corporate domains. The company said an early access program involving roughly 40 organizations found dangling CNAME records at 31 participants, a third of which were reportedly easy to take over. Infoblox also announced a new Supply Chain Intelligence that promises continuous monitoring of the internet-facing assets of critical vendors, tracking exposures, leaked credentials, dark web activity and active threat campaigns that could introduce risk through third-party connections. This capability is positioned as an expansion of its broader Exposure Management strategy rather than a standalone product launch. “The simple question every security leader should be able to answer is: ‘What can an attacker reach right now?’” said Mukesh Gupta, chief product officer at Infoblox https://www.linkedin.com/in/mukesh77/ . He argued that AI has made answering that question significantly harder by accelerating attacker reconnaissance, making continuous external visibility a key component of modern cybersecurity operations.