Category: Security

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: APT28 targets Windows and Office via MSHTML zero‑day

Cybersecurity Threat Advisory: APT28 targets Windows and Office via MSHTML zero‑day

Multiple security researchers and Microsoft have confirmed that the threat actor APT28 (Fancy Bear / Forest Blizzard) actively exploited a zero‑day vulnerability in the Microsoft MSHTML framework (CVE‑2026‑21513) prior to its fix in the February 2026 Patch Tuesday release. Read...

/ March 4, 2026
MSPs must adapt to stay ahead of AI-driven phishing

MSPs must adapt to stay ahead of AI-driven phishing

Phishing has long been cybercriminals’ weapon of choice — and the numbers remain sobering. In 2024, the FBI recorded 193,407 phishing complaints in the U.S. alone, while Business Email Compromise schemes caused $2.77 billion in losses. And when a breach...

/ March 3, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: PromptSpy Android malware abusing Google Gemini AI

Cybersecurity Threat Advisory: PromptSpy Android malware abusing Google Gemini AI

Reported by SecurityWeek on February 20, 2026, PromptSpy is a newly identified Android malware family developed by threat actors. Its standout capability is using Google Gemini at runtime to analyze on‑screen content and help the malware remain installed and active...

/ March 2, 2026
That’s not our admin: The blind spots that open doors to attackers

That’s not our admin: The blind spots that open doors to attackers

Lessons from around 600,000 security alerts analyzed by Barracuda Managed XDR Takeaways In 2025, 90% of ransomware incidents exploited firewalls, and the fastest observed ransomware case took three hours from breach to encryption. The most widely detected CVE vulnerability dates...

/ March 2, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Zero-day Cisco Catalyst SD-WAN flaw

Cybersecurity Threat Advisory: Zero-day Cisco Catalyst SD-WAN flaw

A critical authentication‑bypass flaw in Cisco Catalyst SD‑WAN, tracked as CVE‑2026‑20127, is being actively exploited as a zero‑day. The vulnerability allows remote attackers to compromise controllers and introduce malicious rogue peers into targeted networks. Review the Cybersecurity Threat Advisory now...

/ February 27, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: VMware Aria Operations vulnerabilities

Cybersecurity Threat Advisory: VMware Aria Operations vulnerabilities

On February 24, 2026, Broadcom released a critical security advisory addressing three distinct vulnerabilities in VMware Aria Operations. These flaws—ranging from Command Injection to Privilege Escalation—can compromise the confidentiality, integrity, and administrative control of affected systems. Immediate patching is required...

/ February 26, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical SolarWinds Serv-U flaw

Cybersecurity Threat Advisory: Critical SolarWinds Serv-U flaw

CVE‑2025‑40538 is a critical broken access control vulnerability in SolarWinds Serv‑U, a self‑hosted managed file transfer (MFT) and FTP/SFTP/FTPS/HTTP(S) server used for secure file exchange. Review the Cybersecurity Threat Advisory now to protect your systems from this critical vulnerability. What...

/ February 25, 2026
Evolving supply chain attacks create a critical opportunity for MSPs

Evolving supply chain attacks create a critical opportunity for MSPs

Supply chain attacks continue to pose a serious threat across the cybersecurity ecosystem—and like most threats, they’re evolving quickly. A supply chain attack in 2026 looks very different from one in 2021. Recent data from Risk Management Platform IO reveals...

/ February 24, 2026
Mastering AI fluency: The new imperative for MSP cyber resilience

Mastering AI fluency: The new imperative for MSP cyber resilience

The cybersecurity landscape isn’t just shifting; it’s being fundamentally rewritten. Artificial intelligence (AI) – specifically generative and agentic AI – has lowered the entry barrier for cybercriminals, allowing them to launch attacks with unprecedented speed, scale, and sophistication. For MSPs,...

/ February 23, 2026