Category: Security

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Malicious Notepad++ plugins

Cybersecurity Threat Advisory: Malicious Notepad++ plugins

CERT-UA has identified an ongoing campaign in which threat group UAC-0099 distributes trojanized Notepad++ bundles that install malware on Windows systems. The campaign primarily targets organizations in Ukraine and is linked to activity associated with APT44 (Sandworm). What is the...

/ July 31, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Credential-stealing RAT

Cybersecurity Threat Advisory: Credential-stealing RAT

Researchers have identified a new remote access trojan (RAT) called ChonkyChicken, which threat actors use to steal browser credentials, hijack active browser sessions, and move laterally across Windows networks. Barracuda advises organizations to focus on detection, monitoring, and security hardening,...

/ July 31, 2026
Deepfakes are now an MSP problem

Deepfakes are now an MSP problem

Not long ago, creating a convincing deepfake required a team of specialists, weeks of production, and significant technical expertise. What a difference a few years make. That world is gone. According to the 2026 HYPR State of Passwordless Identity Authentication...

/ July 28, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Qilin exploits GlobalProtect flaw

Cybersecurity Threat Advisory: Qilin exploits GlobalProtect flaw

Threat actors are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain remote access and deploy Qilin ransomware. The attacks target internet-facing firewalls and Prisma Access deployments, allowing attackers to establish VPN sessions that appear...

/ July 27, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall SMA1000 exploits

Cybersecurity Threat Advisory: SonicWall SMA1000 exploits

SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments. What is...

/ July 24, 2026
The hidden MSP opportunity in AI-built applications

The hidden MSP opportunity in AI-built applications

There’s a lot of chatter these days about a so-called “SaaSpocalypse” that could have significant consequences for IT services providers. As more organizations embrace artificial intelligence (AI), they are deploying more custom applications created with AI-powered coding tools. The rise...

/ July 23, 2026
Why MFA fatigue attacks keep working

Why MFA fatigue attacks keep working

MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...

/ July 21, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical ServiceNow vulnerability

Cybersecurity Threat Advisory: Critical ServiceNow vulnerability

ServiceNow has disclosed a critical vulnerability, tracked as CVE-2026-6875, with a CVSS score of 9.5, that could allow unauthenticated attackers to execute code in affected ServiceNow environments. The flaw is classified as a sandbox escape vulnerability and affects both hosted...

/ July 17, 2026
Barracuda acquires Evo Security, purpose-built identity and access management for MSPs

Barracuda acquires Evo Security, purpose-built identity and access management for MSPs

Cybersecurity has traditionally focused on protecting devices, networks, applications, and email. Today, however, identity has become one of the most critical attack surfaces. Instead of breaking through defenses, attackers are increasingly logging in with stolen credentials, using AI-powered techniques to make phishing...

/ July 13, 2026