Category: Security
How AI is reshaping the cybersecurity talent pipeline
Through conversations with managed service provider owners, I often hear optimism about AI’s ability to close the cybersecurity talent gap. In Part I of this series, we explored how MSPs can develop talent internally, create career paths, and use AI...
Why MSPs need a unified IAM platform to scale securely
With identity becoming the new security perimeter, many MSPs are looking for ways to simplify identity and access management (IAM) while delivering stronger protection to their customers. Consolidating essential identity security capabilities into a single platform can help reduce operational...
Cybersecurity Threat Advisory: KATARU IoT malware
KATARU is a newly identified IoT malware family that targets internet-facing Linux devices and recruits them into Mirai-style DDoS botnets. It commonly gains access through exposed Telnet services protected by weak or default credentials. What is the threat? KATARU is...
Cybersecurity Threat Advisory: Linux kernel RDS vulnerability
A critical Linux kernel vulnerability, CVE-2026-43502 (ZcopyReaper), affects the RDS zerocopy send path. The flaw allows unprivileged local attackers to escalate privileges and gain root access on affected systems. A public proof-of-concept (PoC) exploit is available, making immediate patching essential...
The cybersecurity skills gap isn’t a hiring problem
The cybersecurity talent shortage remains a major challenge in the United States. The number of professionals has not kept pace with demand, and while AI is helping close some gaps, organizations still need skilled people. Despite years of hiring efforts,...
Cybersecurity Threat Advisory: ScreenConnect file-transfer issue
ConnectWise has issued a security advisory for an undisclosed file-transfer issue affecting ScreenConnect cloud-hosted and on-premises deployments. The company recommends immediate temporary mitigations while it develops a permanent fix and awaits a CVE assignment. What is the threat? This issue...
Cybersecurity Threat Advisory: AI-Powered Server Attacks
Cybersecurity researchers have identified a threat actor that leverages artificial intelligence throughout the attack lifecycle to conduct search engine optimization (SEO) fraud, steal data, and maintain persistence in compromised environments. What is the threat? The threat actor, UAT-10147, uses a...
Cybersecurity Threat Advisory: ShieldCrash Grants SYSTEM Access
Security researcher Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldCrash, shortly after Microsoft’s September 2026 Patch Tuesday updates. According to the researcher, ShieldCrash bypasses the fix for the previously patched ShieldBreak Defender privilege escalation vulnerability. What...
How MSPs can bridge the security leadership gap
CISOs and SMBs are not a combination you often see. Not because SMBs don’t need security leadership. Regulatory pressure, cyber insurance requirements, and customer security questionnaires are making strategic security leadership a necessity. The challenge is cost. A skilled CISO...
Cybersecurity Threat Advisory: SynkLoader Teams phishing campaign
Security researchers have identified a phishing campaign that uses Microsoft Teams messages impersonating IT support staff to distribute a newly discovered malware known as SynkLoader. Read this Cybersecurity Threat Advisory to understand the risks associated with SynkLoader, identify potential exposure,...
