Category: Security
Threat Spotlight: Unpacking a stealthy new phishing kit targeting Microsoft 365
In this edition of the Threat Spotlight we see that Phishing-as-a-Service (PhaaS) platforms dominate the email threat landscape. The most prominent are sophisticated, well-resourced platforms offering tools, infrastructure, and support in return for payment or a share of the profits....
Cybersecurity Threat Advisory: ChaosBot malware exploits Discord
A recently discovered Rust-based malware called ChaosBot is being used compromise computers via Discord channels. Review the details within this Cybersecurity Threat Advisory to learn more and see how to protect your system. What is the threat? ChaosBot is a...
Cybersecurity Threat Advisory: Oracle E-Business Suite vulnerability
Oracle has issued a warning about a new security flaw in its E-Business Suite (EBS), tracked as CVE-2025-61884, with a CVSS score of 7.5. This vulnerability is remotely exploitable without authentication via HTTP and targets Oracle Configurator, a module used...
Stop AI-driven attacks: Why MSPs can’t afford to sell email security without XDR
Email protection and extended detection and response (XDR) are rapidly becoming a foundational pairing for modern cybersecurity, empowering organizations to proactively counter sophisticated threats, maximize their security ROI and streamline operations in a complex digital landscape. As cybercriminals embrace advanced...
AI, identity, and action: What MSPs must prioritize this Cybersecurity Awareness Month
This October marks the 22nd annual Cybersecurity Awareness Month, a campaign co-led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance. This year’s theme, “Building a Cyber Strong America,” coincides with the sponsoring agency – CISA...
Cybersecurity Threat Advisory: MySonicWall Cloud Backup breach
SonicWall has confirmed a security breach affecting firewall configuration backups for all customers using the MySonicWall Cloud Backup service. Review the details within this Cybersecurity Threat Advisory to learn more and see how to protect your data. What is the...
Cybersecurity Awareness Month: How to make strong password security habits stick
Cybersecurity Awareness Month is here, and it’s a timely reminder to strengthen your password security and authentication habits. Whether you’re an IT professional, a managed service provider (MSP) or simply someone who values data privacy, this is a good opportunity...
Cybersecurity Threat Advisory: Critical vulnerability in Dell UnityVSA
Cybersecurity researchers at WatchTowr have disclosed a critical vulnerability in Dell UnityVSA (and related Unity platforms) tracked as CVE-2025-36604. The flaw allows an attacker with no authentication to issue arbitrary OS commands on vulnerable appliances by abusing the login redirection...
Cybersecurity Threat Advisory: RediShell allows RCE in Redis
Redis has disclosed CVE-2025-49844, a critical remote code execution vulnerability known as RediShell, with a CVSS score of 10.0. The flaw has existed for over 13 years and could allow attackers to run arbitrary commands on vulnerable systems. Thousands of...
Cybersecurity Threat Advisory: Critical Oracle EBS flaw
Oracle released an emergency update for its E-Business Suite to address the critical vulnerability CVE-2025-61882 ( with a CVSS of 9.8) because it was actively being exploited by threat actors, particularly the Cl0p ransomware group, in a recent wave of...
