Category: Security
The smart devices putting SMBs at risk
In 2026, an office is a web of connected devices. The office aquarium. The smart thermostat in the corner. The IP camera above the reception desk. The networked printer down the hall. Most people do not view these devices as...
Cybersecurity Threat Advisory: TrustSink attack targets Microsoft Entra ID
TrustSink is an attack technique that abuses Microsoft Entra ID’s federated trust model. It uses a rogue MFA provider to intercept user credentials during legitimate login attempts. The attack captures plaintext passwords in real time without the user’s knowledge. Attackers...
Cybersecurity Threat Advisory: Citrix NetScaler vulnerabilities
Attackers are actively exploiting two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Citrix confirmed the vulnerabilities, CVE-2026-88771 and CVE-2026-88772, on September 27. Both flaws enable remote code execution, and attackers have used them to deploy web shells and...
The MSP guide to managing supply chain risk
In 2026, supply chain attacks have become one of the most feared threats in cybersecurity, and for good reason. When attackers compromise a vendor with privileged access to multiple environments, they do not just breach one organization. They can potentially...
Cybersecurity Threat Advisory: Ransomware exploits Confluence servers
Feral Wolf has targeted Russian organizations through exposed Confluence servers, insecure 1C configurations, and compromised contractors, ultimately deploying ransomware. The campaign exploited the Atlassian Confluence vulnerability CVE-2023-22515. What is the threat? Feral Wolf is a financially motivated ransomware group that...
Cybersecurity Threat Advisory: WordPress Click2Shell flaw enables RCE
Researchers have disclosed a WordPress exploit chain known as Click2Shell, which was addressed in WordPress 7.1.1 as part of a security release containing 11 fixes. When combined with vulnerabilities in affected themes, the attack can lead to remote code execution...
How AI is reshaping the cybersecurity talent pipeline
Through conversations with managed service provider owners, I often hear optimism about AI’s ability to close the cybersecurity talent gap. In Part I of this series, we explored how MSPs can develop talent internally, create career paths, and use AI...
Why MSPs need a unified IAM platform to scale securely
With identity becoming the new security perimeter, many MSPs are looking for ways to simplify identity and access management (IAM) while delivering stronger protection to their customers. Consolidating essential identity security capabilities into a single platform can help reduce operational...
Cybersecurity Threat Advisory: KATARU IoT malware
KATARU is a newly identified IoT malware family that targets internet-facing Linux devices and recruits them into Mirai-style DDoS botnets. It commonly gains access through exposed Telnet services protected by weak or default credentials. What is the threat? KATARU is...
