Category: Security
Cybersecurity Threat Advisory: Microsoft Teams TURN relay exploit
Threat actors are using a custom backdoor to route their command-and-control (C2) traffic through Microsoft Teams’ TURN relay infrastructure. This technique blends malicious traffic with legitimate Teams communications. As a result, attackers can bypass traditional network defenses, maintain covert access...
The hidden data risks of MSP acquisitions
MSP consolidation is accelerating, yet most clients treat an acquisition as a routine business update—a new logo on invoices or a new account manager. In reality, far more is changing behind the scenes than branded T-shirts and welcome kits. In...
Cybersecurity Threat Advisory: Check Point VPN authentication bypass vulnerability exploited
CISA has issued an emergency directive requiring U.S. federal agencies to secure Check Point Remote Access VPN, Mobile Access, and Spark firewall deployments following active exploitation of a critical zero-day vulnerability (CVE-2026-50751). Continue reading this Cybersecurity Threat Advisory to learn...
Password managers: Your greatest defense or biggest weakness?
Passwords remain a cybersecurity mainstay, surviving despite years of predictions about their demise. Even with constant warnings from security professionals, users still rely on weak choices—like a dog’s name or home address. So, what is an MSP to do? For...
The AI-cybersecurity connection MSPs can’t afford to ignore
One thing is becoming clear for managed service providers (MSPs): future growth will be driven by artificial intelligence (AI) and cybersecurity. More importantly, AI is accelerating demand for cybersecurity services. A recent survey conducted by the Global Technology Industry Association...
The rise of the part-time hacker
Hackers have always run the gamut—from the college kid in his parents’ basement to the nation-state in a sophisticated bunker. There has always been a gap between what an individual hacker could accomplish and what a well-funded nation-state could achieve....
Cybersecurity Threat Advisory: Critical Connectwise Automate vulnerability
ConnectWise has disclosed a high-impact vulnerability in its ConnectWise Automate platform that could allow attackers to bypass critical integrity validation during the agent’s plugin loading and self-update mechanisms, potentially enabling malicious code execution on affected on-premises deployments. Read this Cybersecurity...
Cybersecurity Threat Advisory: ClickFix attacks
This Cybersecurity Threat Advisory has been revised based on a proactive threat hunt by Barracuda Managed XDR, which identified additional indicators of compromise (IOCs) and informed enhanced defensive guidance for customers. Threat actors are actively exploiting a critical Ghost CMS...
IoT threats in 2026: The blind spot MSPs can’t afford to ignore
Cybersecurity experts have warned about IoT threats for years. But as the IoT security landscape continues to expand and evolve, so do the risks—making this a topic worth revisiting. While solutions to secure IoT devices exist, MSPs must stay immersed...
