Dubai-based security firm SpiderSilk puts on an adversarial hat when scanning for Internet-facing threats affecting companies.

SpiderSilk’s scanning technologies require only a company’s name, not a customer’s list of IP addresses and domains. Within a few hours, the tools scan billions of IP addresses and hunt down leaked data, assets, systems, compromised credentials, and information the organization never meant to expose to the world. The idea is to mimic an outsider’s perspective and use artificial intelligence (AI) to contextualize and discover weak spots that could be targeted tomorrow, says Mossab Hussein, SpiderSilk’s co-founder and chief security officer.

SpiderSilk’s tools are like an early warning system that helps companies spot risks on the open Internet before hackers exploit them. Based on SpiderSilk’s findings, companies can take corrective action or patch systems to fend off threats.

Related:BragJack Attack Can Turn a Browser’s Agentic AI Against It

“Organizations were struggling to understand what’s exposed on their digital presence,” Hussein says. “They didn’t know what that looks like or what kind of harm it could cause until it was too late.”

Why CISOs Need to Know Their Exposure

Managing external threats isn’t new, but AI provides a unique twist by stitching together more data points to identify external attack surfaces, says Pete Shoard, chief of research for cybersecurity at Gartner. Threats happen at machine speed, and companies are slow to respond, Shoard says. CISOs need to be proactive about cybersecurity.

“The whole AI thing does make the connection of context a lot easier [and] makes these kinds of things more accessible,” Shoard says. “Twelve months ago, we were 90% reactive, 10% proactive. Next year or the year after, we’re heading to 70% proactive and 30% reactive.”

The pursuit of AI has made vibe-coding a major security threat; in the rush to develop apps, employees could unknowingly leak confidential information, such as sensitive files, passwords, or API keys, into GitHub, GitLab, and other repositories. Enthusiastic business analysts without deep technical understanding may vibe-code a cool corporate dashboard without realizing that sensitive PDFs and company material were uploaded to GitHub or Claude Code.

SpiderSilk’s flagship product, Resonance, functions as an alert system for enterprises, spotting exposed assets, such as domain names, company information, and other details in proprietary data files in coding platforms such as GitHub. Resonance’s AI capabilities analyze, filter, and qualify the data, and “once this is confirmed with the evidence, it immediately escalates that to the customer,” Hussein says.

Related:VectraRAT Can Hack Windows Enterprises for $250 per Month

Platform Identifies Exposed Systems

SpiderSilk’s approach to scanning for external threats is based on homegrown technology and partnerships with Akamai and other cloud providers. The Internet-wide scan involves sending a probe that pings billions of servers. If an IP address doesn’t respond, it means the associated system is not exposed on the Internet. If the system rejects the connection or the handshake, it cannot be accessed. It still isn’t ideal because it reveals the server’s existence.

The biggest issue is when a system responds to the ping and reveals that it is available to interact with on a specific port. Some servers respond by showing a login page to an internal HR system or displaying database indexes. This is unsafe because private data may be accessible via exposed databases. HR login pages could bring hackers one step closer to stealing data or breaking into systems. The data is open and available to everyone.

SpiderSilk’s technology assesses a page’s content, code,and visual elements, such as logos and other assets, Hussein explains.

“You can tell what risk this poses: Is it an internal system? Is it some commercial software they’re hosting? That’s the threat assessment phase before we alert the customer,” Hussein said.

Related:ClickFix Campaigns Abuse Legitimate Services for Persistent Access

One such threat could be internal servers unknowingly exposed to the Internet. AI can correlate a server back to the company that owns it, triggering an alert. SpiderSilk tools plug into third-party security operations tools, enabling administrators to act.

SpiderSilk can initiate fresh Internet scans on demand when a zero-day vulnerability drops. A threat report is generated in real time and pushed to customers’ internal systems to keep them informed.

“The question is not just ‘Am I vulnerable?’ It’s ‘Do I have a record of all my systems running that software?'” Hussain says.

Resonance’s AI agent platform SilkRunner can establish a workflow for AI agents to apply fixes. Agents can get the ball rolling by verifying vulnerable systems against a list of assets, checking software versions, and reviewing update instructions. Humans are an important part of the process.

“Somebody has to say ‘Go ahead and apply it’ or ‘Reject’ or ‘Go back and refine it,'” Hussein says.

A Global Player in the Middle East

There are many attack surfaces online, such as social media, cloud, or industrial systems. One provider can’t be a specialist in all of them, analysts say.

“Most security vendors now have some flavor of a proactive security platform as part of their offering,” says Erik Nost, senior analyst for security and risk at Forrester Research. He cites Palo Alto’s Expanse and CrowdStrike’s Falcon Surface among the big names monitoring enterprises’ Internet-facing assets.

Hussein says SpiderSilk differentiates from competitors with its AI tooling and own scan infrastructure. It also doesn’t buy datasets from providers like Shodan or Censys, which many competitors use. Running its own scans allows SpiderSilk to surface exposed systems and blind spots that others may miss.

Compared to behemoths, SpiderSilk can quickly pivot in the fast-changing cybersecurity landscape and adapt to enterprise or vertical needs, says Jack Gold, principal analyst at J. Gold Associates. But enterprises are unlikely to rip out security offerings from the likes of Cisco, CrowdStrike, Wiz, and Microsoft, he warns.

“SpiderSilk has to prove that they can find things and protect better than the big guys can,” Gold says.

The Middle East market tends to be insular, and SpiderSilk may have a net advantage of being in the region, Gartner’s Shoard says. Finding talent in Dubai is a challenge, but the emirate is emerging as a global tech hub, and things are changing.

SpiderSilk was established in 2019. It now has 55 employees and gets about half its revenue from the US. It was acquired in May 2025 by CPX Holding, a cybersecurity solutions company backed by G42, an AI development company tied to the government of the United Arab Emirates.

“If you can show high-quality revenue from an unbiased and competitive market like the US, that showcases the product has merit,” Hussein says. “We went global from day one.”





Source link

#

Comments are closed