Workforce Development for Modern Networking and Cybersecurity Teams
Develop and refine skills for improved organizational resiliency with hands-on training and certifications.
INE offers a continuous
learn by doing training model
Award winning, hands-on and technically challenging training ensures learners have the in-depth knowledge and skill set to master the subject.
Build a Team Training RoadmapPopular Learning Paths & Courses
Made for Organizations
Our full-cycle training methodology was created with organizations in mind. INE provides organizations with what they need to develop, upskill, and retain employees in and across cybersecurity and networking roles.
Enterprise and Business SolutionsIntersection of Cybersecurity and NetworkingDevelop skills with immersive, scenario-based practice labs.
INE understands that teaching “how to” under "ideal" conditions stops short of being work-role ready. We place great emphasis on creating scenarios which are as close to real world circumstances as possible to help create a resilient team.
Top News
Pursuing the Unknown: How to Build a Structured & Repeatable Learning Model
This coming January will mark the 25th anniversary of me obtaining my first Cisco Certified Internetwork Expert (CCIE) in Routing and Switching (now known as Enterprise Infrastructure). Over the course of my career, I’ve seen lots of new technologies and solutions come and go, but one thing has always remained the same: change.The IT industry is constantly changing. To remain relevant, you always need to be learning and expanding your knowledge base. In my case, this meant learning new topics deeply enough that I could turn around and explain them more plainly to students in my courses—from Enterprise Switching, to Service Provider Routing, to Data Center Fabrics. Learning a lot of these new technologies looked like an insurmountable task when I knew very little about them. By the end of my learning process, though, I would often find myself looking back and realizing that the technology wasn't necessarily more difficult than anything else I've learned throughout my career. Instead, it was simply unfamiliar. Over time, I realized I was approaching each new technology in roughly the same way. What started as an informal process eventually developed into a repeatable learning model that I still use today.How Do You Eat an Elephant?There’s an old saying that there is only one way to eat an elephant: one bite at a time. Learning works the same way. Rather than overwhelming myself by reading an entire book end to end, or trying to understand every detail of a new technology all at once, I take a small, modular approach, where each step builds on the one before it. The core of this learning model is a four-step process:Start by understanding why the technology existsBuild something simple Go back and learn the deeper detailsReturn to the lab and explore the advanced implementationThe end result is a repeatable system for approaching subjects that initially seem overwhelming.Step 1: Understand Why the Technology ExistsThe first step is to get a basic understanding of the technology. At this point, I’m not trying to learn how it’s implemented. I’m trying to understand why it exists.What problems was this technology designed to solve? What limitations existed in previous solutions? Why is this a better or different approach?For example, when learning how modern Data Center Fabrics work, I needed to understand why there were limitations in Classical Ethernet Switching. Why did Spanning Tree Protocol (STP) result in active/standby forwarding instead of active/active? It’s because of the inherent problems that Layer 2 bridging loops can create. Once I understood those limitations, I had context for why newer Data Center architectures evolved the way they did.Before I start worrying about all the configuration details, I want to understand the problem we’re trying to solve.Step 2: Build the Simplest Working ImplementationThe second step is to get a basic hands-on understanding of how the technology works.This is where I start experimenting with lab scenarios, looking at the most basic functionality of the technology without any of the advanced features or bells and whistles. I want to know the minimum configuration required to get the technology functional.Along with learning this basic implementation, I want to learn how to verify that it’s actually working the way it’s supposed to. For a network device, this might mean learning the relevant show commands, debug commands, packet captures, or other forms of verification.For Data Center Fabrics, this meant learning how to build a basic VXLAN Flood-and-Learn network before jumping into BGP EVPN. Once I saw this config functioning, it made more sense what the scaling limitations of this design were, and why using BGP for the VXLAN control-plane would be a better solution.By the time I complete the first two steps, I have a basic understanding of the purpose of the technology, the problems it’s designed to solve compared to previous solutions, and how I can implement and verify a basic version of it in a live environment. That foundation makes the next step much easier.Step 3: Go Back and Learn the DetailsNow I go back through the learning process again, but at a much deeper level. This is where I spend more time reading detailed documentation, watching technical presentations, referencing RFCs, and studying how advanced implementations of the technology work.In the case of Data Center Fabrics, this meant moving beyond the basic operation of a single fabric and studying how multi-site designs work, and how to connect multiple data centers over a Data Center Interconnect.The important difference is that I’m no longer reading the material without context. I already understand the basic problem. I’ve already configured the technology, seen it work, and know some of the basic terminology and verification commands.Now I have the foundation I need to build that advanced understanding. Instead of trying to absorb hundreds of pages of documentation at the beginning, I can connect each new detail to something I already understand.Step 4: Learn the Advanced ImplementationThe final step is to return to the hands-on implementation and start exploring the advanced functionality. This is where I want to understand all the different "nerd knobs" I can control when configuring the technology. More importantly, I want to understand why those options exist and what problems they’re designed to solve.For a Data Center Fabric, this could mean understanding how ARP suppression works, or how BUM traffic—Broadcast, Unknown Unicast, and Multicast—needs to be handled differently across a routed fabric as opposed to a classical Ethernet network (where a true broadcast domain natively exists).At this point, the goal isn’t to simply know which commands enable a feature. I want to understand exactly what changes when I enable it, why that behavior is desirable, and how I can prove that the technology is actually behaving the way I think it should.Understanding Instead of MemorizingThis repetition – starting with a small piece of the puzzle and slowly expanding the depth of your knowledge – allows you to move beyond memorization and retain information long-term.This is the opposite of what I've seen many people try when learning advanced technologies. They often start by trying to memorize all the configuration steps needed to make the solution work. The problem with that approach becomes apparent when something goes wrong.In the real world, you’ll eventually find yourself in an unfamiliar situation where the behavior you're seeing doesn't match your understanding of how the protocol or solution is supposed to work.You might not remember every config command or every possible option, but a fundamental understanding of why something should work a certain way gives you a structured reasoning process for troubleshooting it. You can determine what should be happening, verify what is actually happening, and focus your troubleshooting efforts on understanding the difference.Can You Explain It to Someone Else?In my experience, the best way I can prove that this process is successful is whether I can explain the technology to someone who’s never used it before, and simplify it to a level where it no longer seems intimidating. That’s ultimately how I got into IT training.When studying for my first CCIE, I found myself helping other students and peers in my class. Being able to explain a difficult concept in a way that helped someone else understand it demonstrated that I truly understood the technology myself. That lesson has stayed with me throughout my career.Building Confidence for What Comes NextThe blessing (or maybe the curse) of working in IT is that things are constantly changing. New technologies are introduced, and old technologies are abandoned in favor of new, bright, shiny solutions.The longer you're in this industry, though, the more you realize that things come in cycles. Today's solutions often turn out to be variations of concepts that aren't entirely new, but instead have been recycled, evolved, and repackaged over the years.The challenge when looking at something new is that the amount of depth and detail can seem overwhelming. From the starting point, it can feel like you'll never truly understand how all of it works. By using this modular learning approach, though, you slowly start to chip away at the problem.Start by understanding why the technology exists. Build something simple. Go back and learn the deeper details, then return to the lab and explore the advanced implementation.A few months later, you’ll look back at where you started, and realize how far you've come. More importantly, having a structured and repeatable learning process gives you confidence. You don't need to know what technologies will emerge five or ten years from now. You just need to know that when something new arrives, you have a process for learning it.The goal isn't to memorize everything. It’s to know that whatever comes next, you can understand it – one bite at a time.Continue learning with Brian McGahan through INE’s training, and follow him on LinkedIn for more insights on networking, Cisco technologies, and professional development.
INE Earns G2 Fall 2026 Recognition for Enterprise Leadership, Momentum and Customer Satisfaction
Fall 2026 badges highlight continued customer momentum across enterprise and small-business training, including Easiest Admin, Momentum Leader, Enterprise Leader, Small-Business Leader and Users Love Us recognition.CARY, N.C. — September 17, 2026 — INE, a global provider of hands-on cybersecurity, networking, and IT training, proudly announced new recognition in the G2 Fall 2026 Reports, underscoring continued customer momentum and satisfaction across organization-focused training categories.The Fall results include G2 badges for Momentum Leader, Enterprise Leader, Small-Business Leader, and Easiest Admin distinctions, alongside broader gains across Cybersecurity Professional Development, Technical Skills Development, Online Course Providers, and eLearning Content.“What I value most about INE is its hands-on, lab-driven training that closely aligns with real-world security work, scales across multiple infosec roles, and delivers measurable skill development without adding operational overhead,” said Aditya Malhotra A., Information Security Leader, in a verified G2 review. “The solution scales well in a high-pressure environment and directly improves how my team performs. Additionally, the initial setup of INE was very easy.”For business and technical leaders, the strongest signal is the breadth of those accolades. INE earned Enterprise Leader distinctions across multiple regional reports, as well as Small-Business Leader recognition across multiple markets. The results reflect growing adoption among organizations using INE to build practical cybersecurity and IT capabilities at scale.Among the Fall 2026 highlights:Momentum Leader across all categories (Cybersecurity Professional Development, Technical Skills Development, eLearning Content, and Online Course Providers)Enterprise Leader across multiple regional markets (Europe, EMEA, Asia, Asia Pacific, and India)Small-Business Leader across multiple regional markets (Europe, EMEA, Asia, Asia Pacific, India, and Middle East & Africa)Easiest Admin distinction, reflecting a strong experience for teams managing and deploying training (Enterprise and Small Business)Users Love Us recognition based on verified customer satisfaction“G2 recognition is especially meaningful because it reflects the experiences of the professionals and organizations using INE every day,” said Lindsey Rinehart, CEO of INE. “The Fall results point to the areas that matter most to business customers: customer satisfaction, continued momentum, and the ability to support technical teams across organizations of different sizes and regions. That is the kind of progress we want to keep building.”G2 calculates rankings using verified customer reviews, market presence, and category-specific performance indicators. INE’s Fall 2026 report highlights the company’s continued strength in delivering practical cybersecurity and IT training across enterprise, small-business, and global markets.Organizations looking to build and measure technical skills across their teams can learn more about INE’s enterprise training solutions at https://ine.com/enterprise.
About INEINE is the premier provider of online networking, cybersecurity, cloud, and IT training and certifications. Through hands-on labs, expert instruction, and enterprise-ready learning solutions, INE helps individuals and organizations develop the technical skills needed to secure today’s increasingly complex digital environments. Serving Fortune 500 companies, government agencies, and IT professionals worldwide, INE is committed to building workforce readiness through practical, real-world training.
They Patched the Door but Left the Window Open: Inside Langflow’s CVE-2026-33017
Imagine you are running an AI workflow builder for your team. It hums along quietly in the background, building flows. One quiet afternoon, somewhere on the internet, an automated scanner finds your Langflow instance. Soon after, someone who has never logged in, never entered a password, and never clicked a single button is reading your .env file, harvesting your OpenAI keys, and locating sensitive configuration files and databases.That is not a hypothetical scenario. That is CVE-2026-33017, and it played out in the wild in almost exactly that sequence. This post walks through what the bug is, why it exists, and how a single unauthenticated HTTP request turns into full control of the host. The interesting part is not just the vulnerability itself. It is that the Langflow team had already fixed this exact class of bug once before, and the attackers simply walked around the fix.Vulnerability OverviewCVE Identifier: The vulnerability is tracked as CVE-2026-33017.Affected Product: It affects Langflow, the open-source tool for building and deploying AI-powered agents and workflows.Affected Versions: It affects all Langflow versions prior to 1.9.0, up to and including 1.8.2.Vulnerability Type: It is an unauthenticated remote code execution (RCE) flaw, a code injection reachable over the network with no login.Severity: It carries a CVSS score of 9.3 Critical.Vulnerable Endpoint: The flaw lives in the public flow-build endpoint, POST /api/v1/build_public_tmp/{flow_id}/flowFirst Exploited in the Wild: The first exploitation was observed on March 18, 2026, roughly 20 hours after the advisory went public, as reported by Sysdig’s Threat Research Team.Let us start with what Langflow is, because the “why” of this bug is baked into what the product is built to do.The Setup: A Tool Built to Run Your CodeLangflow is a popular open-source, visual tool for building and deploying AI-powered agents and workflows. You drag components onto a canvas, wire them together, and Langflow runs the resulting graph. One of its headline features is the “custom component”: you can write a Python class that inherits from Langflow’s Component base class right inside a flow, and Langflow will execute it as part of the pipeline.Read that last sentence again, because it is the whole story. One thing Langflow is built to do is take the code you give it and run it. That is a feature, not a bug. The trouble begins the moment the question “whose code, and are they allowed to run it here?” gets the wrong answer.To run your custom component, Langflow does what a lot of dynamic Python tools do under the hood: it takes the code you wrote and feeds it to Python’s built-in exec(), the function that executes a string of Python as if it were part of the program. There is no sandbox, no restricted namespace, and no separate low-privilege process. Whatever you write runs with the full privileges of the Langflow server. For a trusted, authenticated user building their own flows, that is an acceptable trade. For an anonymous stranger on the internet, it is a catastrophe.So the entire security of this feature rests on one thing: making sure only trusted, authenticated people can reach that exec(). Hold that thought.Act One: The First Fix (CVE-2025-3248)This is not Langflow’s first encounter with this problem. Earlier, CVE-2025-3248 (CVSS 9.8) described an unauthenticated RCE that funneled attacker-supplied code into an unsandboxed exec() through an endpoint called POST /api/v1/validate/code. Anyone could hit it, hand over arbitrary code, and have it run.The fix looked reasonable on the surface. The maintainers added an authentication gate to /api/v1/validate/code. Now you needed to be a logged-in user to reach that endpoint. Problem solved, right?Here is the subtle mistake, and it is one worth internalizing as a defender. The fix protected that one endpoint, but nobody audited the other endpoints that also let user input reach exec(). That exec() sat deep in Langflow’s code, still unsandboxed, still perfectly happy to run anything that reached it, by whatever path. The patch locked one door into the room. It did nothing about the fact that the room still contained a loaded weapon, and a building with a loaded weapon in it needs more than one locked door to be safe. There were other ways in.The official advisory for CVE-2026-33017 is careful to call this a distinct vulnerability rather than a straight patch bypass: the earlier bug was missing auth on a code-validation endpoint, while this one is an endpoint that is unauthenticated by design and mistakenly accepts attacker-controlled executable code through its data parameter. Fair enough. But from a defender’s chair, the shared thread is unmistakable and it is the whole lesson of this CVE: both bugs end with untrusted code hitting an unsandboxed exec(). The two just take different routes to get there, and locking one route left the other wide open.Act Two: Finding the WindowNow think like an attacker. You know Langflow can run arbitrary code somewhere inside itself. You know one route to it got locked. The natural next question is: what other routes touch that same code path?Langflow has an endpoint designed to let anonymous users build “public” flows, the kind you might share with people who do not have accounts. It is called:POST /api/v1/build_public_tmp/{flow_id}/flowThe word “public” is doing a lot of load-bearing work here. This endpoint is unauthenticated on purpose. It was built to be reachable without logging in. And critically, it accepts a data parameter: a full flow definition, supplied by the caller, that Langflow then builds.Do you see it? To build a flow, Langflow turns each component in the graph into a running object, and for a custom component that means compiling and executing the code in its definition. When you send the optional data parameter, Langflow builds your submitted flow instead of the stored one. So an attacker overrides the flow’s contents with a definition full of malicious component code, and Langflow runs it. No account required, because the endpoint never wanted one.The first fix gated /validate/code. Nobody gated build_public_tmp, because on the surface it was just “build a public flow,” an innocent-sounding feature. But it led to an unsandboxed exec() just the same. The attacker did not pick the lock on the patched door. They strolled in through a window that was never locked in the first place.How It Actually Works: Walking the CodeLet us make this concrete and look at the two ends of the chain in the actual source: the endpoint the request hits, and the exec() it eventually reaches. The relevant files are in the Langflow repository, and the line numbers below are against tag 1.7.3, a vulnerable version.Where it starts: the unauthenticated endpointFile: src/backend/base/langflow/api/v1/chat.pyThe route and its handler start at line 581:@router.post("/build_public_tmp/{flow_id}/flow")
async def build_public_tmp(
...
data: Annotated[FlowDataRequest | None, Body(embed=True)] = None, # attacker-controlled flow definition
...
):Start with the fact that this endpoint takes no authenticated user. That is not the bug. It is intentional, and the docstring says so outright: “This endpoint is specifically for public flows that don’t require authentication.” A public endpoint that anyone can reach is a perfectly reasonable thing to have. The catch is what such an endpoint is allowed to do, and this is where the design goes wrong.Look at the data parameter. Its type is FlowDataRequest, the caller’s full flow definition, which per the advisory can carry “arbitrary Python code in node definitions.” The endpoint was meant to serve an existing flow that has been marked public in the database. Instead it happily accepts and builds a flow body handed to it by whoever is calling. So an unauthenticated, public endpoint, exactly as designed, ends up building and running a flow that the caller supplied. Public access was fine. Public access to arbitrary submitted code is the vulnerability.Where it ends: the exec() sinkFile: src/lfx/src/lfx/custom/validate.pyDeep in the custom-component machinery, in the function prepare_global_scope() (defined at line 323, with its exec() at line 397), sits the sink:...
exec(compiled_code, exec_globals) # attacker's code runs here, no sandbox
...That is the loaded weapon from Act One. This file is the code-execution heart of Langflow’s custom components. It does not run in a sandbox, a restricted namespace, or a separate low-privilege process. Whatever code reaches it runs with the full authority of the Langflow process.And here is the detail that makes it worse than it first looks. When Langflow builds the graph, it calls prepare_global_scope(), which uses exec() to compile and run module-level code from the component definitions. Module-level Assign statements in the supplied code execute immediately at build time, before the flow even runs. Simply getting Langflow to build the graph is enough to run their code.Put the whole attack in a sentence: an attacker embeds a component whose code runs a shell command (through subprocess, os.system, or similar) inside the data they submit, and POSTs it to the public endpoint. Langflow builds the graph, hits exec(), and the attacker’s command runs on the server.The Lab: Exploiting It YourselfReading about a vulnerability is one thing. Popping a shell with it is another. Here is a walkthrough of exploiting CVE-2026-33017 end-to-end in a lab environment, from a Kali box to code execution on the target.The EnvironmentThe lab target runs the vulnerable Langflow release, version 1.7.3, reachable from a Kali attack box at:http://demo.ine.local:7860Step 1: Confirm the target is aliveping -c 4 demo.ine.localStep 2: Confirm the relevant port is opennmap -p- demo.ine.localPort 7860 is the default port used by Langflow.Step 3: Load the dashboardhttp://demo.ine.local:7860The dashboard loads straight in, no login screen, confirming LANGFLOW_AUTO_LOGIN is active on this target (which is the default).Step 4: Preparing the exploitThere are multiple exploit scripts available publicly for this CVE by now; disclosure was followed quickly by several independent proof-of-concept releases. For this lab, we will use the PoC available here.Strictly speaking, the only thing an attacker needs going in is the UUID of a flow on the target that is already marked public. In the real world, those are not hard to come by; public flow links get shared around exactly like any other shareable chatbot link. And on a target where AUTO_LOGIN is left at its default of true, as it is here, an attacker does not even need that: they can hit /api/v1/auto_login, get a token, and mint their own public flow on the spot. No prerequisite survives that setting.Here is what the script actually does, and notice it needs nothing handed to it up front. Given just a target URL, it:Calls /api/v1/auto_login itself and pulls an access token straight out of the response. No credentials, because LANGFLOW_AUTO_LOGIN hands one to anybody who asks.Looks for an existing flow with access_type set to PUBLIC. If it finds one, it reuses it. If not, it creates one itself and marks it public, no --flow-id argument required unless you want to target a specific one.Builds the malicious payload: a CustomComponent node whose code field is ordinary-looking Python, ending in one line that matters, a module-level assignment: _r = __import__('os').system(
Cisco FMC Vulnerabilities Highlight the Risk of Exposed Network Management Access
Cisco Talos recently disclosed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC), including one flaw carrying the maximum CVSS score of 10.0.The technical details deserve immediate attention from organizations running affected systems, but the broader lesson extends beyond Cisco FMC: obtaining access to the management-plane of network infrastructure is itself a high-value security bounty.Management platforms for routers, switches, and firewalls often have visibility into – and authority over – large portions of an enterprise environment. When attackers compromise the management-plane, they will likely gain access to more than one device. They can gain a position from which to enumerate systems, capture credentials, establish persistent access, and move deeper into the network.The ongoing Cisco FMC exploitation offers a timely example of why securing these management systems must be treated as a core part of network defense.What Are CVE-2026-20079 and CVE-2026-20316?The more severe vulnerability, CVE-2026-20079, affects the web interface of Cisco Secure Firewall Management Center (FMC) Software, the platform used to control Cisco’s Firepower Threat Defense (FTD) next-generation firewalls.Cisco describes it as an authentication bypass vulnerability caused by an improper system process created during boot. A remote, unauthenticated attacker can send specially crafted HTTP requests to a vulnerable device, bypass authentication, and execute scripts or commands that can ultimately provide root access to the underlying operating system.Cisco assigned the vulnerability a CVSS score of 10.0 – the highest possible. The company has also confirmed active exploitation and states that no workaround fully addresses the vulnerability; affected customers should apply the available software fixes.The second vulnerability, CVE-2026-20316, involves static credentials associated with a low-privileged account in Cisco FMC. An unauthenticated remote attacker can use those credentials to log into an affected system and access sensitive information.Its CVSS score is lower at 5.3, but severity scores do not tell the entire operational story. Cisco rated the advisory High because the vulnerability can be combined with other FMC weaknesses to escalate an attacker’s privileges. This distinction matters, as vulnerabilities rarely exist in isolation during a real intrusion.What Attackers Are Doing After Compromising Cisco FMCTalos identified three clusters of malicious activity associated with the vulnerabilities, including activity linked to both advanced threat actors and ransomware operations.In one intrusion cluster, attackers exploited CVE-2026-20079 and deployed a web shell with Java-based command-execution tooling. That access was then used to query internal databases and obtain authentication information.Another cluster involved exploitation of the FMC vulnerabilities followed by a Netcat reverse shell, configuration theft, credential harvesting, network discovery, and deployment of a variant of Cyclops Blink, malware previously associated with the Sandworm threat actor. A third cluster shows perhaps the clearest example of why network management infrastructure is such a valuable target.According to Talos, a ransomware operator accessed an FMC device, conducted extensive reconnaissance, harvested credentials, enumerated systems in the victim environment, deployed tunneling tools, and assembled a list of systems for eventual encryption. The activity was consistent with tactics used by Qilin ransomware affiliates.The compromised management platform became more than just the initial target – it became a bridge into the organization.The Bigger Lesson: Protect the Management-PlaneNetwork teams naturally spend significant effort securing traffic that moves through infrastructure devices, known as the data-plane. Firewall rules, access-control lists, segmentation, intrusion prevention, and VPN policies all work together to limit what traffic is allowed to forward in the data-plane; however, security teams also need to protect the systems used to manage that infrastructure.The management-plane represents a fundamentally different level of trust. Administrators use it to alter configurations, retrieve operational information, manage connected devices, and interact with services that have extensive visibility into the environment. This makes vulnerabilities in management access very attractive to attackers.Cisco specifically notes that organizations can reduce the attack surface for these vulnerabilities by ensuring that the FMC management interfaces do not directly have public internet access. This principle applies far more broadly to secure infrastructure design.Beyond applying software fixes, organizations should be asking:Is management access exposed beyond the networks and users that actually require it?Are management interfaces segmented from end-users and production networks?Are administrative connections restricted through dedicated management networks, VPNs, jump hosts, or equivalent controls?Are privileged accounts strongly authenticated and monitored?Can administrators detect unusual management-plane activity?Are infrastructure management systems included in vulnerability and patch-management programs?Does the incident response team know what evidence to collect if a network management system is compromised?The goal is not to put another firewall around the firewall, but instead to be able to recognize that administrative access paths deserve stricter controls because of the authority they provide.Patching Is Essential, but Architecture Determines ExposureOrganizations operating affected Cisco FMC versions should follow Cisco's security guidance and apply the available hotfixes or fixed software as quickly as operationally feasible.Cisco also provides indicators that administrators can use to investigate potential exploitation. Importantly, Cisco warns that applying a hotfix prevents future exploitation, but does not resolve an existing compromise. Organizations that identify indicators of exploitation should treat the situation as an incident rather than assuming patching alone has restored trust.Applying software updates is the immediate response, but the longer-term solution is architectural. Organizations should minimize unnecessary exposure of device-management interfaces, isolate administrative paths with VPNs and management jump-boxes, enforce least privilege, monitor management activity, and regularly evaluate who and what can reach both the infrastructure management and control-planes.The lesson here is that network security is not only about defending workloads and endpoints, but also that the infrastructure controlling those defenses must also be defended.Network Engineers Are Part of the Security TeamIncidents like the Cisco FMC exploitation also illustrate why modern network engineering and cybersecurity increasingly overlap.A network engineer may not have “security analyst” in their job title, but decisions about management-plane design, segmentation, device access, authentication, logging, and infrastructure hardening directly affect an organization's ability to withstand an intrusion.Developing these skills requires more than just memorizing configuration commands. Engineers need to understand how infrastructure behaves during an attack, how adversaries abuse legitimate administrative functionality, and how architectural decisions can either constrain or expand an attacker’s options.INE’s CCIE Security learning path focuses on these practical skills across enterprise security architecture, firewall technologies, identity and access control, secure connectivity, threat detection, and mitigation. For broader development, INE also provides hands-on networking and cybersecurity training for teams designed around real-world technical skills.The lesson from these vulnerabilities is straightforward: the devices that protect the network can become some of its most valuable attack paths when their own management access is not sufficiently protected. CVE-2026-20079 and CVE-2026-20316 will eventually become two entries in a vulnerability database, while the architectural lesson should last much longer.FAQWhat is CVE-2026-20079?CVE-2026-20079 is a critical authentication bypass vulnerability affecting Cisco Secure Firewall Management Center Software. A remote, unauthenticated attacker may be able to exploit the FMC web interface and execute commands that result in root-level access. Cisco assigned it a CVSS score of 10.0 and has confirmed active exploitation.What is CVE-2026-20316?CVE-2026-20316 is a Cisco FMC vulnerability involving static credentials for a low-privileged account. Although its CVSS score is 5.3, Cisco warns that it can be combined with other FMC vulnerabilities to elevate privileges.Why is securing network management access important?Management platforms can provide extensive visibility and control over network infrastructure. If attackers compromise them, they may be able to collect credentials, perform reconnaissance, alter configurations, create persistent access, or pivot toward other systems. Restricting and monitoring management-plane access can therefore reduce both initial attack surface and post-compromise opportunities.
The Pentesting Skills AI Can’t Replace - and the Ones It Will Change
INE Security Ambassador Mohammad Anas Nirban explains where AI makes penetration testers faster, where it creates false confidence, and why context, verification, and hands-on fundamentals are becoming more valuable.AI is becoming another tool in the pentester’s arsenal—but like any tool, its value depends on the person using it. The more convincing AI-generated output becomes, the more important it is to understand the technical fundamentals well enough to validate what the tool gets right, catch what it gets wrong, and know when context changes the answer. INE spoke with Mohammad Anas Nirban, a Security Analyst, INE Security Ambassador, and active bug bounty hunter, about where AI is changing penetration testing today, which skills remain fundamentally human, and what learners and hiring managers should value as AI becomes a standard part of the pentester’s toolkit.His central argument is simple: AI can accelerate the work, but it cannot take responsibility for the judgment behind it.
Where AI Helps and Where Human Expertise Takes OverAI can generate scripts, payloads, and exploit ideas in seconds. In a live engagement, what separates a capable penetration tester from someone who can only produce plausible-looking output with a prompt?Judgment, honestly. AI can hand you a payload in two seconds, but it has no idea if that payload makes sense for the app sitting in front of you. A capable tester looks at the output and asks "does this actually fit the context I'm in, the framework, the WAF, the auth flow, the business logic" before ever firing it off. Someone who's only prompting will run what they're given, get a weird response, and not know if that's a false positive, a WAF block, or an actual lead worth chasing. The gap shows up the moment something doesn't go according to script literally. That's when you need to understand what's happening under the hood, not just what the tool told you to type next.
Where does AI already make pentesters meaningfully faster, and where does relying on it create the greatest risk of false confidence?It's genuinely great at grunt work like writing boilerplate scripts, summarizing a huge Nmap or Burp output, drafting the first version of a report section and explaining an unfamiliar piece of code quickly. That stuff used to eat hours; now it eats minutes. Where it gets risky is when people let it make the call on severity or exploitability. I've seen AI confidently say a finding is "critical" or "not exploitable" based purely on pattern matching against similar-looking issues it's seen before, without actually understanding the specific business context. In BFSI environments especially, a low-looking issue can be catastrophic because of what data or transaction flow sits behind it and that's exactly the kind of nuance AI glosses over. If you let it triage for you, you either miss something serious or waste the client's time chasing a non-issue.Can you describe an engagement in which a scanner, automated tool, or initial hypothesis pointed in the wrong direction? What did the human tester notice that the tool missed?I had a case where an automated scan flagged a set of endpoints as vulnerable to IDOR based purely on sequential numeric IDs in the URL; classic scanner logic. But when I actually walked through the flow manually, I noticed the app was checking ownership server-side through a separate session token, just not in the way the scanner expected to see it validated. The scanner couldn't reason about that; it just saw "predictable ID, no obvious check in the response" and flagged it as a finding. What actually mattered was digging into a completely different part of the same flow, a related endpoint that skipped that ownership check entirely because a developer had "temporarily" bypassed it during testing and never fixed it. No tool was going to connect those dots. That only came from manually mapping the whole user journey and treating the scanner's flag as a starting point, not a conclusion.
How do scope, safety, ethics, and business context influence what a pentester tests, how far they go, and when they stop—and why are those decisions difficult to automate?Every engagement I've worked on has its own unwritten rules layered on top of the written scope. What's actually acceptable to touch in a live BFSI environment is very different from a staging environment for a SaaS startup. Knowing when to stop poking at something because it risks taking down a production transaction system, or when a "vulnerability" is actually intended business behavior, comes from context you build over time, not from a rules file. AI doesn't know that the client's finance team is running month-end close this week, or that a particular legacy system is held together with duct tape and one wrong request could cause an outage. Those calls need a human who understands the business, not just the technical surface, because the cost of getting it wrong isn't a bad finding, it's real damage to a real system people depend on.
What Pentesters Still Need to Know Without AIHow should learners use AI without allowing it to short-circuit the learning process? Which fundamentals should every pentester be able to perform and explain without AI assistance?My rule for myself has always been: use AI to speed up practice, not replace it. On TryHackMe or in a CTF, I'll only ask AI for help after I've genuinely tried and gotten stuck, and even then I ask it to explain the concept, not hand me the exact command to paste in. If you skip straight to the answer, you get the flag but none of the understanding, and that gap catches up with you the first time you're on a real engagement without a hint button. Fundamentals every pentester should be able to do and explain without help: manual enumeration (not just running a tool and reading output), understanding how HTTP requests actually work, being able to read and modify a script rather than just run one, and explaining why a vulnerability exists; the actual mechanism; not just that it exists.
Before you would trust someone on a real client engagement, what hands-on abilities would you expect them to demonstrate in an unfamiliar environment and without a walkthrough?I'd want to see them enumerate a target from scratch, not run one scanner and call it done, but actually build a picture of the attack surface manually and know what to prioritize and why. I'd want to see them read source code or app behavior and form a hypothesis before touching a tool, rather than throwing tools at it until something sticks. And I'd want to see them handle a dead end gracefully, pivot to a different approach instead of getting stuck repeating the same failed technique. That combination tells you someone actually understands the systems they're testing, rather than having memorized a checklist.
What AI Changes About Hiring and Senior-Level SkillAs AI capabilities improve, what skills—and what evidence of competence—should hiring managers value most when evaluating a pentester?I'd look past the flashy AI-assisted findings and pay attention to how someone explains their process. Can they walk you through why they chose a particular attack path? not just what the outcome was. Real bug bounty submissions or CTF writeups are far more telling than a resume line, because they show actual reasoning under uncertainty, not a curated success story. I'd also weigh communication skills more than people expect the ability to explain a technical risk to a non-technical stakeholder is becoming more valuable, not less, because AI is compressing the technical grunt work but doing nothing for the human translation layer that clients actually pay for.
What pentesting skill will become more important because of AI, rather than less important?Verification. As AI-generated findings and reports become more common from tools, from junior testers leaning on AI, even from clients running their own AI-assisted scans, someone needs to be the person who can look at a claimed vulnerability and say with confidence "yes this is real" or "no this is a false positive, here's why." That validation skill, the ability to manually confirm or kill a finding, becomes the actual bottleneck and the actual value a senior tester provides once the volume of AI-generated "maybe-findings" goes up.
The Bottom LineNone of this is an argument against using AI; it’s an argument for making sure the fundamentals come first. That’s the same philosophy behind practical pentesting certifications like the eJPT and eCPPT: not simply producing an exploit or finding a vulnerability, but understanding the environment, choosing an appropriate methodology, validating what is actually exploitable, and communicating the result clearly. AI can compress the technical grunt work, but it can’t build judgment for you. The testers who will matter most are the ones who can use AI effectively while still understanding what’s happening underneath—and connect the dots when the tools can’t.About Mohammad Anas Nirban Mohammad Anas Nirban is a Security Analyst and INE Security Ambassador who ranks in the top 1% globally on TryHackMe. He holds the eJPT certification and is currently working toward eCPPT. He is also an active HackerOne bug bounty hunter, with a particular interest in authentication, authorization, and IDOR vulnerabilities.
ISMG Acquires INE to Advance Global Cyber Readiness Across Every Discipline and Role
ISMG Unites Intelligence, Community, Live Events and Now Certification Into One Education Ecosystem Spanning Networking, Cybersecurity, Identity, AI and OT Security — Serving Engineers, Practitioners, Security Leaders and Boards AlikePRINCETON, NJ – ISMG, the leading intelligence and education firm dedicated exclusively to cybersecurity and information technology, today announced the acquisition of INE, the premier provider of hands-on networking and cybersecurity training and certification, trusted by Fortune 500 enterprises and practitioners in more than 190 countries.Coming weeks after ISMG's 20th anniversary, the acquisition is the company's most ambitious commitment in two decades: to raise readiness across the full breadth of the field — networking, cybersecurity, identity, AI and OT security — and across every role that carries risk, from the engineer who builds the foundation to the executive in the boardroom."Twenty years ago, we built ISMG to give defenders the intelligence to see a threat before it reached them," said Sanjay Kalra, chief executive officer, ISMG. "The lesson of the AI era is that intelligence is only as strong as the infrastructure beneath it: every AI system, every transaction, every connected operation depends on networks that must be engineered and identities that must be secured, and on trained people to do that work. INE has proven that capability can be taught, measured and certified at scale, and now, as one organization, we can raise readiness across the entire stack, from the engineer who runs the network to the board that answers for the risk."For two decades, ISMG has kept the community ahead of emerging threats and convened the leaders who must answer for it. INE turns that awareness into demonstrated skill, through hands-on labs and certification programs used across enterprises of every size."INE's heritage in networking and cybersecurity runs deep," said Lindsey Rinehart, chief executive officer, INE. "For years we have carried practitioners from their first commands to expert-level certification, and proven that genuine skill can be measured and validated, not just claimed. Joining ISMG enhances that standard on the global stage and extends it to the disciplines defining the next decade: identity, AI and operational technology, and to the leaders and boards who now answer for them."Readiness Is the New ConstraintFor most of the past decade, the cybersecurity conversation was about hiring more people. That framing is now too narrow. In its 2025 Cybersecurity Workforce Study, ISC2 found that 88% of organizations suffered at least one significant cybersecurity event tied to skills shortages, a sign that readiness, not headcount, is now the binding constraint, and one that reaches well beyond the security team as AI adoption and IT/OT convergence pull new roles into the blast radius of cyber risk.A Global Mandate for Cyber ReadinessWith this acquisition, ISMG is launching the Global Cyber Readiness Initiative, a long-term commitment to raise competence across the disciplines that define digital risk: networking, cybersecurity, identity management, AI security and OT security, and across the roles that own them, from engineers to CISOs to the boards accountable for all of it. INE brings the depth: CCNA-, CCNP- and CCIE-level networking training, identity-management courses for zero-trust and access security, the eAIS credential for AI security, and hands-on OT training.No company is better positioned to take this on. ISMG already reaches this audience through 38 media properties, more than 400 annual events, and technical gatherings including Nullcon, Hardwear.io, OTSec and ManuSec. Two decades of standing with the global security community give ISMG the credibility to raise the bar for what training and certification should mean, and the reach to make that standard global.ISMG plans to enrich INE's course and certification content, extend its reach into new markets and customer segments, and build an active peer community around the products its clients already rely on."When ISMG started, the community needed trusted reporting on a threat most boardrooms had never discussed," said Mike D'Agostino, general manager, ISMG. "Today it needs something different in scale and kind: readiness for teams and leaders who cannot simply hire their way out of the problem. Reporting a problem and solving it are different jobs, and with INE, we can do both."Community Is Part of the CurriculumNot all learning happens in a lab. For senior leaders, the most valuable education is often peer to peer, comparing decisions with counterparts who face the same threats, regulators and board questions. Through CyberEdBoard, ISMG's invitation-only community for CISOs and CIOs, and its broader CXO advisory programs, members exchange playbooks, pressure-test strategy, and shape the agenda that training and intelligence then serve.Why NowCybersecurity is now foundational to economic stability, as commerce, energy, healthcare, finance and government run on software and, increasingly, on AI. New threats drive demand for training, new regulations for certification, new technologies for continuous upskilling. By adding INE’s industry-leading training infrastructure, ISMG's expanded platform meets all three. INE also widens the ISMG global footprint, adding presence in Salt Lake City, Raleigh and La Plata, Argentina, deepening its reach across India, alongside established hubs in the U.S., U.K. and Israel.Macquarie Capital served as financial advisor to INE, previously a portfolio company of PSG Equity.About ISMGISMG is the world’s largest media organization devoted solely to cybersecurity, information technology, artificial intelligence and operational technology. Each of our 38 media properties provides education, research and news that is specifically tailored to key vertical sectors including banking, healthcare and the public sector; geographies from North America to Southeast Asia; and topics such as data breach prevention, cyber risk assessment, OT security, AI and fraud. Our annual global summit series connects senior security professionals with industry thought leaders to find actionable solutions for pressing cybersecurity challenges.About INEINE is the premier provider of online technical training for the IT industry. Harnessing the world’s most powerful hands-on lab platform, cutting-edge technology, a global video distribution network, and world-class instructors, INE is the top training choice for Fortune 500 companies worldwide and for IT professionals looking to advance their careers. INE’s suite of learning paths offers an incomparable depth of expertise across networking, cybersecurity, cloud and data science.
INE Launches Hands-On SRv6 Course for Next-Generation Service Provider Networks
Implementing Segment Routing v6 (SRv6) gives network professionals practical experience with IPv6-based VPN services, Traffic Engineering with IS-IS Flex-Algo, uSID Compression, and MPLS-to-SRv6 InterworkingCARY, N.C., Sept. 3, 2026 — INE, an industry leader in advanced hands-on networking and cybersecurity training, today announced Implementing Segment Routing v6 (SRv6), a new course built to help network professionals implement and operate SRv6 in modern Service Provider environments.As Service Providers modernize their MPLS networks, SRv6 is emerging as an important architecture for delivering VPN services and programmable Traffic Engineering over an IPv6-based infrastructure. Rather than focusing solely on theory, INE’s course is designed to give engineers practical, hands-on experience implementing the technologies and workflows used to deploy SRv6 in real-world network environments.Led by Brian McGahan, co-founder of INE and Director of Networking Content, the course provides practical training for experienced network professionals looking to build hands-on skills with SRv6.“SRv6 is the kind of technology engineers need to experience first-hand to really understand,” said McGahan. “This course helps learners move beyond just the theory, and directly into implementing SRv6 routing, VPN services, Traffic Engineering, and MPLS-to-SRv6 interworking they’re likely to see in modern Service Provider environments.”The course gives learners experience with technologies and workflows including:Advertising SRv6 Locators with IS-ISImplementing Layer 3 VPNs over SRv6Implementing Layer 2 VPNs over SRv6Implementing SRv6 Micro-SID (uSID) compressionUsing IS-IS Flex-Algo for SRv6 traffic engineeringUsing Flex-Algo affinity for constraint-based path selectionImplementing MPLS-to-SRv6 interworkingThe launch expands INE’s advanced networking and Service Provider training portfolio, giving network professionals more opportunities to build practical skills with Segment Routing, IPv6, and modern Service Provider technologies.Implementing Segment Routing v6 (SRv6) is available now for individual learners with INE Premium access and for organizations through INE Enterprise licenses.
About INEINE is the premier provider of online networking, cybersecurity, cloud, and IT infrastructure training and certifications. Through expert-led instruction, hands-on labs, and practical learning paths, INE helps individuals and organizations build the technical skills needed to succeed in today's rapidly evolving technology landscape. Serving Fortune 500 enterprises, government agencies, and IT professionals worldwide, INE is committed to developing real-world expertise that prepares learners for today's most demanding technical roles.
INE Launches eIAMA Certification to Help Organizations Build Practical Identity and Access Management Skills
New vendor-neutral certification prepares cybersecurity and IT professionals to implement, operate, and secure identity systems in modern enterprise environments.CARY, N.C., August 26, 2026 — As identity continues to become the foundation of modern cybersecurity, INE, a leading global provider of hands-on technical training and certifications, today announced the launch of the Certified Identity & Access Management Associate (eIAMA) certification. Designed for today's cybersecurity and IT professionals, eIAMA validates the practical skills required to implement, operate, troubleshoot, and secure identity and access management (IAM) controls across modern enterprise environments.Identity has evolved beyond user authentication to become a critical security control supporting Zero Trust architectures, cloud adoption, privileged access management, and regulatory compliance. As organizations modernize their identity infrastructure, the demand for professionals who can operationalize IAM technologies has grown significantly.The eIAMA certification was developed to help close that skills gap through a vendor-neutral, hands-on learning path that emphasizes real-world implementation rather than product-specific administration."Identity is no longer just an IT function—it's the control plane for modern cybersecurity," said Tracy Wallace, Director of Content Development at INE. "Organizations need professionals who can do more than explain IAM concepts. They need practitioners who can implement secure authentication, troubleshoot federation issues, manage identity lifecycles, and validate access controls in production environments. eIAMA was built to develop and validate those practical capabilities."Unlike training focused on a single platform or identity provider, eIAMA prepares candidates to work across the technologies, workflows, and security principles that underpin enterprise identity programs. The certification covers the full identity lifecycle, including:Identity architecture and lifecycle managementAuthentication, single sign-on (SSO), and federationAuthorization and access policy designPrivileged access and service identity securityIAM monitoring, incident response, and governanceAudit readiness and compliance reporting.The certification is designed for a broad range of technical professionals, including identity and access management administrators, security engineers, systems administrators, SOC analysts, cloud administrators, and infrastructure teams responsible for implementing and supporting secure access across hybrid environments. It also supports organizations looking to build shared IAM capability across technical teams as part of broader Zero Trust and cybersecurity workforce development initiatives.The eIAMA certification and learning path is available beginning today, August 26, 2026. To learn more about the Certified Identity & Access Management Associate (eIAMA), visit: https://ine.com/security/certifications/eiama-certification
About INEINE is the premier provider of online networking, cybersecurity, cloud, and IT infrastructure training and certifications. Through expert-led instruction, hands-on labs, and practical learning paths, INE helps individuals and organizations build the technical skills needed to succeed in today's rapidly evolving technology landscape. Serving Fortune 500 enterprises, government agencies, and IT professionals worldwide, INE is committed to developing real-world expertise that prepares learners for today's most demanding technical roles.
Globally Trusted Workforce Development and Industry Certifications
Have a question?
We’re here to help!
Whether you’d like more information on our training materials or are interested in a free demo, please contact us at any time.