Category: Featured

MSPs
MSPs are redefining supply chain defense

MSPs are redefining supply chain defense

As a journalist covering the cybersecurity business landscape, I’ve closely followed the growing impact of supply chain attacks throughout 2025. These incidents continue to escalate in frequency and complexity, affecting organizations of all sizes across industries. This two-part series brings...

/ September 30, 2025
CRN
Lindsay Faria: One of CRN’s 100 People You Don’t Know But Should

Lindsay Faria: One of CRN’s 100 People You Don’t Know But Should

Last week, Lindsay Faria, who leads managed service provider (MSP) Marketing for Barracuda in the Americas, was recognized as one of CRN’s 100 People You Don’t Know But Should for 2025. This annual list shines a light on the committed...

/ September 29, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cisco ASA zero-day vulnerability

Cybersecurity Threat Advisory: Cisco ASA zero-day vulnerability

Threat actors are actively exploiting two critical zero-day vulnerabilities in Cisco Secure Firewall ASA and FTD software. CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362 (CVSS 6.5) allow attackers to chain exploits that bypass authentication and execute malicious code. In response, the U.S....

/ September 26, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RCE vulnerability in SolarWinds WHD

Cybersecurity Threat Advisory: RCE vulnerability in SolarWinds WHD

A critical remote code execution (RCE) vulnerability, CVE-2025-26399, has been identified in SolarWinds Web Help Desk (WHD) and remains exploitable despite previous fixes. The flaw allows unauthenticated attackers to execute arbitrary code on vulnerable servers, leading to a full system...

/ September 24, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Severe GoAnywhere MFT vulnerability

Cybersecurity Threat Advisory: Severe GoAnywhere MFT vulnerability

Fortra disclosed a critical vulnerability in GoAnywhere Managed File Transfer (MFT), tracked as CVE-2025-10035, with a CVSS score of 10.0. The flaw allows attackers to execute remote code without authentication. Review this Cybersecurity Threat Advisory to keep your systems safe....

/ September 24, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Fake password managers

Cybersecurity Threat Advisory: Fake password managers

LastPass has issued a warning about a widespread cyber campaign targeting macOS users. Malicious software is being disguised as legitimate applications and distributed through fake GitHub repositories. Read this Cybersecurity Threat Advisory to stay informed and protect your data. What...

/ September 23, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Microsoft Entra ID vulnerability

Cybersecurity Threat Advisory: Critical Microsoft Entra ID vulnerability

A critical token validation vulnerability, tracked as CVE-2025-55241 with a CVSS of 10, in Microsoft Entra ID has been discovered. This flaw could have allowed attackers to impersonate any user, including global admins, across any tenant. Continue reading this Cybersecurity...

/ September 23, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall firewall backup breach

Cybersecurity Threat Advisory: SonicWall firewall backup breach

SonicWall has reported a security breach involving unauthorized access to its MySonicWall cloud backup service. Attackers used brute-force techniques to obtain firewall preference and backup files containing full device configurations. Continue reading this Cybersecurity Threat Advisory to learn more about...

/ September 22, 2025
DarkBard
DarkBard: The “evil twin” of Google Bard

DarkBard: The “evil twin” of Google Bard

In the shadowy realm of cybercrime, DarkBard has emerged as a significant player, representing a crossover into non-OpenAI territory. As its name suggests, DarkBard is modeled as the dark counterpart to Google’s Bard artificial intelligence (AI). This tool surfaced in...

/ September 22, 2025 / 6 Comments
Tech Time Warp
Tech Time Warp: Meet ERMA, the machine that automated check processing

Tech Time Warp: Meet ERMA, the machine that automated check processing

When did you last write a check? In July 2024, Target became the latest retailer to stop accepting checks, citing “extremely low volumes” of customers paying by check. Use of checks — already declining before the COVID-19 pandemic — took...

/ September 19, 2025