LmCast :: Stay tuned in

SpiderSilk Hunts External Threats With AI-Based Scanner

Recorded: Sept. 14, 2026, 1:09 p.m.

Original Summarized

SpiderSilk Uses AI to Scan for Cyber Threats Informa TechTarget|SearchSecurityCybersecurity DiveInformationWeekChannel DiveExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsSponsored ContentThe Mythos Panic Is Over. The Budget Window Isn't.The Mythos Panic Is Over. The Budget Window Isn't.Sep 14, 20265 Min ReadMobile SecurityIndonesia Hit by Android Banking App-Cloning CampaignIndonesia Hit by Android Banking App-Cloning CampaignbyAlexander CulafiSep 11, 20264 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryEndpoint SecurityCybersecurity OperationsRemote WorkforceСloud SecurityNews, news analysis, and commentary on the latest trends in cybersecurity technology.SpiderSilk Hunts External Threats With AI-Based ScannerThe Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.Agam Shah,Contributing WriterSeptember 11, 20265 Min ReadSource: Luis Moreira via Alamy Stock PhotoDubai-based security firm SpiderSilk puts on an adversarial hat when scanning for Internet-facing threats affecting companies.The company's scanning technologies require only the company's name, not a customer's list of IP addresses and domains. Within a few hours, the tools scan billions of IP addresses and hunt down leaked data, assets, systems, compromised credentials, and other information the organization never meant to expose to the world. The idea is to mimic an outsider's perspective and use artificial intelligence (AI) to contextualize and discover weak spots that could be targeted tomorrow, says Mossab Hussein, SpiderSilk's co-founder and chief security officer.SpiderSilk's tools are like an early warning system that helps companies spot risks on the open Internet before hackers exploit them. Based on SpiderSilk's findings, companies can take corrective action or patch systems to fend off threats.Related:ClickFix Campaigns Abuse Legitimate Services for Persistent Access"Organizations were struggling to understand what's exposed on their digital presence. They didn't know what that looks like, or what kind of harm it could cause, until it was too late," Hussein says.Why CISOs Need to Know Their ExposureManaging external threats isn't new, but AI provides a unique twist by stitching together more data points to identify external attack surfaces, says Pete Shoard, chief of research for cybersecurity at Gartner. Threats happen at machine speed, and companies are slow to respond, Shoard says. CISOs need to be proactive, not reactive, in approaching cybersecurity."The whole AI thing does make the connection of context a lot easier, makes these kinds of things more accessible," Shoard says. "Twelve months ago, we were 90% reactive, 10% proactive. Next year or the year after, we're heading to 70% proactive and 30% reactive."The pursuit of AI has made vibe-coding a major security threat – in the rush to develop apps, employees could unknowingly leak confidential information, such as sensitive files, passwords or API keys, into repositories such as GitHub or GitLab. Enthusiastic business analysts without deep technical understanding may vibe-code a cool corporate dashboard without realizing that sensitive PDFs and company material were uploaded to GitHub or Claude Code.SpiderSilk's flagship product, Resonance, functions as an alert system for enterprises as it can spot exposed assets such as domain names, company information or other details in proprietary data files in coding platforms such as GitHub. Resonance's AI capabilities analyze, filter, and qualify the data, and “once this is confirmed with the evidence, it immediately escalates that to the customer," Hussein says.Related:ClickFix Campaign Compromises 31 Orgs, Abuses Polygon BlockchainPlatform Identifies Exposed SystemsSpiderSilk's approach to scanning for external threats is based on homegrown technology and partnerships with Akamai and other cloud providers. The Internet-wide scan involves sending a probe that pings billions of servers. If an IP address doesn't respond to a ping, it means the associated system is not exposed on the Internet. If the system rejects the connection or the handshake, it cannot be accessed. It still isn't ideal because it reveals the server's existence.The biggest issue is when a system responds to the ping and reveals that it is available to interact with on a specific port. Some servers respond by showing a login page to an internal HR system or displaying database indexes. This is unsafe as private data may be accessible via exposed databases. HR login pages could bring hackers one step closer to stealing data or breaking into systems. The data is open and available to everyone.SpiderSilk's technology assesses a page's content and code, as well as visual elements such as logos and other assets, Hussein explains."You can tell what risk this poses: Is it an internal system? Is it some commercial software they're hosting? That's the threat assessment phase before we alert the customer," Hussein said.Related:'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a MonthOne such threat could be internal servers unknowingly exposed to the Internet. AI can correlate a server back to the company that owns it, triggering an alert. SpiderSilk tools plug into third-party security operations tools, enabling administrators to act.SpiderSilk can initiate fresh internet scans on demand when a zero-day vulnerability drops. A threat report is generated in real time and pushed to customers' internal systems to keep them informed."The question is not just: Am I vulnerable? It's: Do I have a record of all my systems running that software?" Hussain says.Resonance's AI agent platform SilkRunner can establish a workflow for AI agents to apply fixes. Agents can get the ball rolling by verifying vulnerable systems against a list of assets, checking software versions, and reviewing update instructions. Humans are an important part of the process."Somebody has to say: 'go ahead and apply it,' or reject, or go back and refine it," Hussein says.A Global Player in the Middle EastThere are many attack surfaces online, such as social media, cloud or industrial systems. One provider can't be a specialist in all of them, analysts say."Most security vendors now have some flavor of a proactive security platform as part of their offering," says Erik Nost, senior analyst for security and risk at Forrester Research. He cites Palo Alto's Expanse and CrowdStrike's Falcon Surface among the big names monitoring enterprises' internet-facing assets.Hussein says SpiderSilk differentiates from competitors with its AI tooling and own scan infrastructure. It also doesn't buy datasets from providers like Shodan or Censys, which many competitors use. Running its own scans allows SpiderSilk to surface exposed systems and blind spots that others may miss.Compared to behemoths, SpiderSilk can quickly pivot in the fast-changing cybersecurity landscape and adapt to enterprise or vertical needs, says Jack Gold, principal analyst at J. Gold Associates. But he warns enterprises are unlikely to rip out security offerings from the likes of Cisco, CrowdStrike, Wiz, Microsoft and others."SpiderSilk has to prove that they can find things and protect better than the big guys can," Gold says.The Middle East market tends to be insular, and SpiderSilk may have a net advantage of being in the region, Gartner's Shoard says. Finding talent in Dubai is a challenge, but the emirate is emerging as a global tech hub, and things are changing.SpiderSilk was established in 2019 and now has 55 employees and gets about half its revenue from the U.S. It was acquired in May 2025 by CPX Holding, a cybersecurity solutions company backed by G42, an AI development company tied to the government of the United Arab Emirates."If you can show high-quality revenue from an unbiased and competitive market like the U.S., that showcases the product has merit," Hussein says. "We went global from day one."Read more about:DR Global Middle East & AfricaAbout the AuthorAgam ShahContributing WriterAgam Shah has covered enterprise IT for more than a decade. Outside of machine learning, hardware, and chips, he's also interested in martial arts and Russia.See more from Agam ShahWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsCybersecurity Outlook 2027Threat Exposure Analytics: Measuring and Communicating Security RiskBenchmark Scores Are a False FlagBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachMore WebinarsLatest Articles in DR TechnologyICS/OT SecurityHow an Emerging Industrial Protocol Family Could Put OT at RiskAug 21, 2026|6 Min ReadCyber RiskHardware Makers Implement Post-Quantum Cryptography as Security Threats NearAug 21, 2026|3 Min ReadIdentity & Access Management SecurityCyera's Oasis Security Buy Is All About AI Agent ControlAug 14, 2026|4 Min ReadCyber RiskNew Tool Traces AI Videos Back to Their SourceAug 3, 2026|4 Min ReadRead More DR TechnologyDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices

The Dubai-based threat detection startup SpiderSilk leverages artificial intelligence to scan billions of IP addresses, aiming to identify exposed assets, leaked data, and zero-day vulnerabilities across the internet. The company operates by adopting an adversarial perspective, using AI to contextualize vast amounts of data and discover security weaknesses that external attackers might target, effectively functioning as an early warning system for organizations.

SpiderSilk’s core technology involves an internet-wide scan methodology where probes are sent to billions of servers. If a system fails to respond to a ping, it suggests the system is not exposed online. However, the critical challenge arises when a system responds, as it can reveal its availability on specific ports, potentially exposing sensitive data, login pages for internal systems, or database indexes. To mitigate this, the scanning technology incorporates an assessment phase that analyzes a page’s content, code, and visual elements, allowing the system to differentiate between internal systems and exposed commercial software, thereby informing the risk assessment before issuing an alert to the customer.

The platform’s flagship product, Resonance, employs AI capabilities to analyze, filter, and qualify this discovered data, immediately escalating confirmed findings to the customer. This process is further supported by the SilkRunner AI agent platform, which establishes workflows for AI agents to verify vulnerable systems against asset lists, check software versions, and review necessary updates. Although AI agents initiate these actions, the process retains a necessary human element, requiring human intervention to authorize or refine the application of fixes.

The approach to threat intelligence differs from competitors by relying on homegrown scanning infrastructure and partnerships, such as with Akamai, rather than purchasing datasets from sources like Shodan or Censys. This proprietary scanning capability allows SpiderSilk to surface system blind spots that other vendors might miss. This focus on self-developed technology positions SpiderSilk to pivot quickly in the cybersecurity landscape and address specific enterprise or vertical needs, distinguishing itself from larger entities like Cisco or CrowdStrike by emphasizing superior AI tooling.

The advancement of AI in security provides a mechanism to enhance proactive security posture, moving organizations from a reactive stance to a proactive one by correlating disparate data points to identify external attack surfaces. This shift is crucial as threats evolve at machine speed, necessitating a more proactive response strategy. Furthermore, the technology addresses modern threats such as "vibe-coding," where employees might inadvertently leak sensitive information into code repositories like GitHub or GitLab. Resonance specifically monitors coding platforms to detect exposed assets, such as domain names or proprietary details within files, ensuring that sensitive information is not inadvertently exposed to the public. SpiderSilk's ability to correlate server information with owning entities, triggered by AI, allows for immediate alerts, facilitating rapid incident response and system remediation. The company’s global focus, having established itself in the Middle East, provides a strategic advantage in an area where analysts suggest a potential market niche due to regional insularity.