Category: Security

The hidden MSP opportunity in AI-built applications

The hidden MSP opportunity in AI-built applications

There’s a lot of chatter these days about a so-called “SaaSpocalypse” that could have significant consequences for IT services providers. As more organizations embrace artificial intelligence (AI), they are deploying more custom applications created with AI-powered coding tools. The rise...

/ July 23, 2026
Why MFA fatigue attacks keep working

Why MFA fatigue attacks keep working

MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...

/ July 21, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical ServiceNow vulnerability

Cybersecurity Threat Advisory: Critical ServiceNow vulnerability

ServiceNow has disclosed a critical vulnerability, tracked as CVE-2026-6875, with a CVSS score of 9.5, that could allow unauthenticated attackers to execute code in affected ServiceNow environments. The flaw is classified as a sandbox escape vulnerability and affects both hosted...

/ July 17, 2026
Barracuda acquires Evo Security, purpose-built identity and access management for MSPs

Barracuda acquires Evo Security, purpose-built identity and access management for MSPs

Cybersecurity has traditionally focused on protecting devices, networks, applications, and email. Today, however, identity has become one of the most critical attack surfaces. Instead of breaking through defenses, attackers are increasingly logging in with stolen credentials, using AI-powered techniques to make phishing...

/ July 13, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SilverFox deploys ValleyRAT rootkit

Cybersecurity Threat Advisory: SilverFox deploys ValleyRAT rootkit

SilverFox threat actors are actively running a ValleyRAT campaign to bypass security controls, escalate privileges, and maintain deep system access while avoiding detection. Organizations should treat this as a high-priority threat. Continue reading this Cybersecurity Threat Advisory to protect against...

/ July 10, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Adobe ColdFusion exploited

Cybersecurity Threat Advisory: Adobe ColdFusion exploited

Adobe has confirmed that attackers are actively exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. Threat intelligence reports indicate exploitation began within hours of disclosure. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, allowing remote code execution on unpatched...

/ July 9, 2026
Incident management issues rising in the age of AI

Incident management issues rising in the age of AI

Managed service providers (MSPs) should take note: as the volume of code created using artificial intelligence (AI) coding tools continues to grow, so does the number of incidents that may require their attention. A survey of 406 IT decision-makers at...

/ July 9, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: EvilTokens targets Microsoft 365

Cybersecurity Threat Advisory: EvilTokens targets Microsoft 365

Recent research describes a phishing kit called EvilTokens. It is actively targeting organizations in the U.S. and Europe, especially those in finance and other high-value sectors. Barracuda recommends deploying browser-aware phishing analysis and strengthening Microsoft 365 OAuth and device-code controls....

/ July 8, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: LSHIY password spray campaign

Cybersecurity Threat Advisory: LSHIY password spray campaign

This Cybersecurity Threat Advisory covers a large-scale password and token spray campaign targeting Microsoft Azure CLI authentication flows. Researchers linked the campaign to activity originating from the IPv6 range 2a0a:d683::/32. The range is associated with LSHIY LLC / AS32167. Researchers...

/ July 8, 2026