Billy Hoffman

Billy Hoffman

Field CTO
Billy Hoffman is Field CTO at IONIX, where he works with CISOs and security teams on attack surface discovery, exposure management, and threat intelligence operationalization. He has spent more than two decades in offensive and applied security research, beginning at SPI Dynamics where he led web application security research before the firm was acquired by HP. He subsequently managed HP's Web Security Research Group, then founded Zoompf, a web performance and security startup acquired by Rigor, where he served as CTO. He is co-author of Ajax Security (Addison-Wesley), one of the earliest definitive guides to Web 2.0 application security, and has presented research at Black Hat, RSA Conference, and Shmoocon. He writes on attack surface management, supply chain risk, threat intelligence, and vulnerability research.

Posted by Billy Hoffman

  • Exposed, Misconfigured, Forgotten, External Cyber Risk

    Exposed, Misconfigured and Forgotten: The Triple Threat of External Risk (and how to fix with Cloudflare and IONIX) 

  • A doctor holds a tablet displaying a digital DNA strand, illustrating proactive cybersecurity in a reactive world. The text 'Prophylactic Cybersecurity: How to be Proactive in a Reactive World' is overlaid, along with the speaker's name and title: Billy Hoffman, Ionix Field CTO.

    Prophylactic Cybersecurity for Healthcare

  • Diagram showing a broken chain link representing a digital supply chain attack on Polyfill.io, with an exclamation point highlighting the vulnerability.

    Review of the Polyfill Supply Chain Attack – Lessons & Mitigation

  • Alert: A red triangle with an exclamation mark, indicating a security alert for CVE-2024-3400 PAN-OS command injection vulnerability in GlobalProtect Gateway.

    CVE-2024-3400 – PAN-OS OS Command Injection Vulnerability in GlobalProtect Gateway

  • Operationalizing Threat Intelligence with Attack Surface Management

    Operationalizing Threat Intelligence with Attack Surface Management