Category: Security

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Connectwise Automate vulnerability

Cybersecurity Threat Advisory: Critical Connectwise Automate vulnerability

ConnectWise has disclosed a high-impact vulnerability in its ConnectWise Automate platform that could allow attackers to bypass critical integrity validation during the agent’s plugin loading and self-update mechanisms, potentially enabling malicious code execution on affected on-premises deployments. Read this Cybersecurity...

/ May 29, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: ClickFix attacks

Cybersecurity Threat Advisory: ClickFix attacks

Attackers are exploiting a critical vulnerability, tracked as CVE-2026-26980, in the Ghost Content Management System (CMS) to compromise more than 700 legitimate websites. Read this Cybersecurity Threat Advisory to reduce risk for you and your clients. What is the threat?...

/ May 27, 2026
IoT security
IoT threats in 2026: The blind spot MSPs can’t afford to ignore

IoT threats in 2026: The blind spot MSPs can’t afford to ignore

Cybersecurity experts have warned about IoT threats for years. But as the IoT security landscape continues to expand and evolve, so do the risks—making this a topic worth revisiting. While solutions to secure IoT devices exist, MSPs must stay immersed...

/ May 26, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Exchange on-premise OWA vulnerability exploited

Cybersecurity Threat Advisory: Exchange on-premise OWA vulnerability exploited

A Microsoft Exchange Server Outlook Web Access (OWA) spoofing vulnerability, tracked as CVE‑2026‑42897, is actively being exploited in the wild. This issue affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition across all update levels. Continue reading...

/ May 22, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cisco Catalyst SD-WAN zero day vulnerability

Cybersecurity Threat Advisory: Cisco Catalyst SD-WAN zero day vulnerability

An authentication bypass zero-day vulnerability, tracked as CVE-2026-20182 with a maximum CVSS score of 10.0, has been identified in Cisco Catalyst SD-WAN Controller and Manager. The vulnerability allows unauthenticated attackers to gain the highest level of administrative access to affected...

/ May 20, 2026
patching
Patch management: The basics still matter

Patch management: The basics still matter

Patching is such a core part of MSP DNA that it’s easy to overlook. I’ve talked with many MSP owners who get pulled into the latest, most urgent cyberthreats—only to lose sight of the basics: patching. Patching is the cybersecurity...

/ May 19, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RedSun exploits Microsoft Defender real-time protection

Cybersecurity Threat Advisory: RedSun exploits Microsoft Defender real-time protection

A new proof of concept (PoC), RedSun, exploits Windows devices running Microsoft Defender real‑time protection on Windows 10, Windows 11, and Windows Server 2019+. It abuses Defender’s handling of cloud‑tagged files to achieve local privilege escalation to SYSTEM. Read this...

/ May 15, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: BitUnlocker attack

Cybersecurity Threat Advisory: BitUnlocker attack

A newly published proof of concept (PoC) tool called BitUnlocker demonstrates a dangerous downgrade attack that can bypass Microsoft’s BitLocker full‑disk encryption on Windows 11 devices. Continue reading this Cybersecurity Threat Advisory to minimize your risk. What is the threat? BitUnlocker...

/ May 15, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: GhostLock – A new denial-of-availability attack technique

Cybersecurity Threat Advisory: GhostLock – A new denial-of-availability attack technique

GhostLock is a newly disclosed attack technique that abuses the Windows CreateFileW API to lock enterprise files by requesting exclusive, deny‑share handles. Read this Cybersecurity Threat Advisory to learn how to limit your organization’s exposure to this attack. What is...

/ May 14, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RMM-based phishing attacks

Cybersecurity Threat Advisory: RMM-based phishing attacks

An ongoing phishing campaign has been observed targeting multiple vectors and leveraging legitimate Remote Monitoring and Management (RMM) tools to establish persistent remote access on compromised hosts. Read this Cybersecurity Threat Advisory to mitigate risk for you and your clients....

/ May 14, 2026