Connects to any signal across any vendor stack and powers adaptive AI Operatives that expose, detect, and neutralize cyberattacks.
Atlas Operations CenterSee what our SOC sees, review investigations, and see how we are protecting your business.
Technology IntegrationsAtlas connects to any signal across your current security tools. Whatever you're running, we're running with you.
Extend your team with immediate expertise, hands-on remediation, and the human accountability layer that boards, regulators, and cyber insurers require.
Threat Response UnitProactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Response and RemediationPairs machine-speed containment with human judgment, delivering full threat response that's policy-bounded, reversible, and explainable.
MDR that moves first, multi-signal attack surface coverage, and 24/7 Elite threat hunters working as one continuous security program across any vendor stack.
Get unlimited Incident Response with threat suppression guarantee- anytime, anywhere.
Atlas Preempt deploys AI Operatives to continuously validate attack paths exposing attacker targets of opportunity before they take advantage.
Protect insurance operations from cyber attacks.
ConstructionSecure project data and jobsite operations.
FinanceDefend financial services from cyber disruption.
LegalSafeguard client data and legal operations.
ManufacturingStop threats before they disrupt production.
Private EquityProtect portfolio companies from cyber risk.
HealthcareDefend patient data and clinical operations.
RetailProtect customer data and retail operations.
Food SupplySecure the food supply chain from cyber threats.
Government and EducationProtect public sector and education systems.
Automotive DealershipsSecure dealership operations and customer data.
Stop ransomware before it spreads.
Identity ResponseStop identity-based cyberattacks.
Zero Day AttacksDetect and respond to zero-day exploits.
Cybersecurity ComplianceMeet regulatory compliance mandates.
Third-Party RiskDefend third-party and supply chain risk.
Cloud MisconfigurationEnd misconfigurations and policy violations.
Cyber RiskAdopt a risk-based security approach.
Mid-Market SecurityMid-market security essentials to prioritize.
Sensitive Data SecurityProtect your most sensitive data.
Cyber InsuranceMeet insurability requirements with MDR.
Cyber Threat IntelligenceOperationalize cyber threat intelligence.
Security LeadershipBuild a proven security program.
On October 4th, 2026, Citrix disclosed the zero-day vulnerability CVE-2026-88779, impacting NetScaler ADC and NetScaler Gateway deployments. CVE-2026-88779 (CVSS: 8.7) is a memory overflow…
On October 1st, 2026, Fortinet disclosed a critical zero-day vulnerability impacting multiple versions of FortiMail. Fortinet has confirmed active exploitation prior to patch disclosure.The…
eSentire is a leader in Controlled Autonomy SecOps, protecting thousands of organizations across 35+ industries around the world. Founded in 2001, the company’s Controlled Autonomy SecOps operating model pairs agentic AI operatives with engineered human-judgment controls, delivering expert-depth security outcomes at machine speed without ceding accountability to opaque automation.
About Us Leadership Careers Event Calendar → Newsroom → Aston Villa Football Club →
We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Search our site
Multi-Signal MDR with 300+ technology integrations to support your existing investments.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
We offer three flexible MDR pricing packages that can be customized to your unique needs.
The latest security advisories, blogs, reports, industry publications and webinars published by TRU.
Compare eSentire to other Managed Detection and Response vendors to see how we stack up against the competition.
See why thousands of organizations globally have chosen eSentire for our MDR Solution.
On December 16th, 2025, Hewlett Packard Enterprise (HPE) disclosed a critical vulnerability in HPE OneView. CVE-2025-37164 (CVSS: 10) is an unauthenticated Remote Code Execution (RCE) vulnerability impacting versions of HPE OneView before 11.0. A detailed Proof-of-Concept (PoC) exploit code was released by Rapid7 following the disclosure. Successful exploitation may allow threat actors to execute arbitrary code, potentially resulting in full network compromise, data theft, or malware deployment.
Although there are no reports of active exploitation at the time of writing, public availability of PoC exploit code significantly increases the risk to organizations running affected versions of the application. As the vulnerability impacts all versions prior to 11.0, organizations are strongly advised to apply the required updates to mitigate the potential risk of exploitation.
HPE OneView is an IT infrastructure management software that provides centralized control over IT operations, including managing data center networks and servers through a unified dashboard interface. In its advisory, Rapid7 noted that "the real concern here is exposure and trust assumptions," highlighting the application's central role within the environment and the potential impact of exploiting a trusted component that is integral to network operations. Rapid7 released a Metasploit module demonstrating the exploitation of CVE-2025-37164.
The PoC exploit code indicates that the vulnerability exists within the ID Pools feature of HPE OneView. The API associated with this feature processes command execution requests without requiring authentication, allowing unauthenticated callers to supply and execute commands. Rapid7's finding indicates that, despite the HPE advisory stating that all HPE OneView versions prior to 11.0 are vulnerable, the ID Pools feature is not present across all editions. Rapid7 noted in its assessment that this observation requires clarification and confirmation from HPE and does not eliminate the need for patching as a mitigation measure.
Due to the high risk associated with CVE-2025-37164, organizations should remediate the vulnerability by upgrading to a secure version or applying the appropriate hotfix. Additionally, restrict access to management interfaces to prevent exposure to the Internet or untrusted networks, review access logs for suspicious activity, and rotate any potentially exposed credentials or secrets.
References:
[1] https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1
[2] https://nvd.nist.gov/vuln/detail/CVE-2025-37164
[3] https://attackerkb.com/topics/ixWdbDvjwX/cve-2025-37164/rapid7-analysis
[4] https://myenterpriselicense.hpe.com/cwp-ui/product-details/HPE_OV_CVE_37164_Z7550-98077/-/sw_free
[5] https://support.hpe.com/hpesc/public/swd/detail?swCollectionId=MTX-64daeb5ed0df44a0
[6] https://www.rapid7.com/blog/post/etr-cve-2025-37164-critical-unauthenticated-rce-affecting-hewlett-packard-enterprise-oneview/
[7] https://github.com/rapid7/metasploit-framework/pull/20792