Category: Security

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ivanti EPMM vulnerability

Cybersecurity Threat Advisory: Ivanti EPMM vulnerability

Ivanti has released updates for Endpoint Manager Mobile (EPMM) that address one medium and one high-severity vulnerability. When chained together, these vulnerabilities can enable unauthenticated remote code execution (RCE). Review the details in this Cybersecurity Threat Advisory for information on...

/ May 21, 2025
The SOC case files
The SOC case files: Ransomware gang reemerges to face a wall of XDR defenses

The SOC case files: Ransomware gang reemerges to face a wall of XDR defenses

Dive into this edition of ‘The SOC case files’ to see how the Barracuda’s Managed XDR team recently contained a suspected ransomware attack after the attackers gained access to a company’s network before it installed Managed XDR, compromising several Windows...

/ May 21, 2025
Cyber insurance
Cyber insurance: A must for MSPs

Cyber insurance: A must for MSPs

If you don’t carry cyber insurance yet, you may want to reconsider. Statistics show that if you are an MSP owner, you probably already have it, with 91.7 percent of managed service providers (MSPs) carry cyber insurance specifically for their operations,...

/ May 20, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SAP critical vulnerabilities

Cybersecurity Threat Advisory: SAP critical vulnerabilities

SAP has released patches to address a second vulnerability, CVE-2025-42999, affecting its SAP NetWeaver tool. The vulnerability involves a privilege escalation issue that, when chained with SAP’s CVE-2025-31324 vulnerability (unauthenticated file upload flaw in SAP NetWeaver Visual Composer), can enable...

/ May 16, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical zero-day vulnerability in Fortinet

Cybersecurity Threat Advisory: Critical zero-day vulnerability in Fortinet

A critical zero-day vulnerability affecting several Fortinet products, most notably FortiVoice enterprise phone systems, has recently been patched. Attackers are actively exploiting CVE-2025-32756 in the wild. Read the details of this Cybersecurity Threat Advisory to learn how to keep your...

/ May 15, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: ClickFix attack spreading malware

Cybersecurity Threat Advisory: ClickFix attack spreading malware

The official website of iClicker, a platform used for student engagement and classroom polling, was recently compromised in a ClickFix-style social engineering attack. Continue reading this Cybersecurity Threat Advisory to learn how to keep your systems safe. What is the...

/ May 15, 2025
Federal IT reviews signal fresh MSP opportunities ahead

Federal IT reviews signal fresh MSP opportunities ahead

Federal IT contractors have been facing major changes recently as part of the government’s broader effort to reduce overall spending. Leading systems integrators such as Accenture and Booz Allen are reportedly being asked to identify billions of dollars in savings...

/ May 15, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical ASUS vulnerabilities

Cybersecurity Threat Advisory: Critical ASUS vulnerabilities

Researchers have discovered two vulnerabilities within the ASUS DriverHub driver management tool that can allow malicious sites to execute commands on targeted devices. They have found no evidence that threat actors have exploited these vulnerabilities in real-world scenarios. Review the...

/ May 14, 2025
CIRP
An MSP’s guide to building cybersecurity incident response plan

An MSP’s guide to building cybersecurity incident response plan

Last week, we spoke with industry experts about why every organization needs a solid cybersecurity incident response plan (CIRP). This week, we’re taking it a step further—breaking down the essential steps Managed Service Providers (MSPs) should follow to build a...

/ May 13, 2025