Category: Security
Cyber insurance is getting pickier: What MSPs need to know
A mainstay of American life is that after a disaster, insurance adjusters show up. Whether the damage is caused by wind, flooding, or hail, consumers simply want coverage. Insurers, however, examine the details, exceptions, and requirements before approving a claim....
How MSPs can reduce risk with Privileged Access Management (PAM)
Identity is the new attack surface. Microsoft’s Digital Defense Report found that identity-based attacks surged 32 percent in the first half of 2025, with more than 97 percent involving password attacks. Why PAM is a must-have For MSPs, the risk is amplified because technicians often have privileged...
The hidden costs of backup sprawl
A lot of businesses end up with a piecemeal approach to backup. While that’s certainly better than having no backup at all, it often creates a patchwork environment that is far less reliable than it appears. As someone who regularly...
The MSP playbook for agentic AI
For years, AI helped security teams detect threats faster while humans remained responsible for taking action. Agentic AI changes that model. Today’s tools can isolate endpoints, disable accounts, block traffic, and launch remediation workflows automatically. The speed benefits are clear,...
Cybersecurity Threat Advisory: Malicious Notepad++ plugins
CERT-UA has identified an ongoing campaign in which threat group UAC-0099 distributes trojanized Notepad++ bundles that install malware on Windows systems. The campaign primarily targets organizations in Ukraine and is linked to activity associated with APT44 (Sandworm). What is the...
Cybersecurity Threat Advisory: Credential-stealing RAT
Researchers have identified a new remote access trojan (RAT) called ChonkyChicken, which threat actors use to steal browser credentials, hijack active browser sessions, and move laterally across Windows networks. Barracuda advises organizations to focus on detection, monitoring, and security hardening,...
Deepfakes are now an MSP problem
Not long ago, creating a convincing deepfake required a team of specialists, weeks of production, and significant technical expertise. What a difference a few years make. That world is gone. According to the 2026 HYPR State of Passwordless Identity Authentication...
Cybersecurity Threat Advisory: Qilin exploits GlobalProtect flaw
Threat actors are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain remote access and deploy Qilin ransomware. The attacks target internet-facing firewalls and Prisma Access deployments, allowing attackers to establish VPN sessions that appear...
Cybersecurity Threat Advisory: SonicWall SMA1000 exploits
SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments. What is...
