Category: Security

Threat Spotlight
Threat Spotlight: Unpacking a stealthy new phishing kit targeting Microsoft 365

Threat Spotlight: Unpacking a stealthy new phishing kit targeting Microsoft 365

In this edition of the Threat Spotlight we see that Phishing-as-a-Service (PhaaS) platforms dominate the email threat landscape. The most prominent are sophisticated, well-resourced platforms offering tools, infrastructure, and support in return for payment or a share of the profits....

/ October 20, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: ChaosBot malware exploits Discord

Cybersecurity Threat Advisory: ChaosBot malware exploits Discord

A recently discovered Rust-based malware called ChaosBot is being used compromise computers via Discord channels. Review the details within this Cybersecurity Threat Advisory to learn more and see how to protect your system. What is the threat? ChaosBot is a...

/ October 16, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Oracle E-Business Suite vulnerability

Cybersecurity Threat Advisory: Oracle E-Business Suite vulnerability

Oracle has issued a warning about a new security flaw in its E-Business Suite (EBS), tracked as CVE-2025-61884, with a CVSS score of 7.5. This vulnerability is remotely exploitable without authentication via HTTP and targets Oracle Configurator, a module used...

/ October 16, 2025
XDR
Stop AI-driven attacks: Why MSPs can’t afford to sell email security without XDR

Stop AI-driven attacks: Why MSPs can’t afford to sell email security without XDR

Email protection and extended detection and response (XDR) are rapidly becoming a foundational pairing for modern cybersecurity, empowering organizations to proactively counter sophisticated threats, maximize their security ROI and streamline operations in a complex digital landscape. As cybercriminals embrace advanced...

/ October 15, 2025
Cybersecurity Awareness Month
AI, identity, and action: What MSPs must prioritize this Cybersecurity Awareness Month

AI, identity, and action: What MSPs must prioritize this Cybersecurity Awareness Month

This October marks the 22nd annual Cybersecurity Awareness Month, a campaign co-led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance. This year’s theme, “Building a Cyber Strong America,” coincides with the sponsoring agency – CISA...

/ October 14, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: MySonicWall Cloud Backup breach

Cybersecurity Threat Advisory: MySonicWall Cloud Backup breach

SonicWall has confirmed a security breach affecting firewall configuration backups for all customers using the MySonicWall Cloud Backup service. Review the details within this Cybersecurity Threat Advisory to learn more and see how to protect your data. What is the...

/ October 14, 2025
Cybersecurity Awareness Month
Cybersecurity Awareness Month: How to make strong password security habits stick

Cybersecurity Awareness Month: How to make strong password security habits stick

Cybersecurity Awareness Month is here, and it’s a timely reminder to strengthen your password security and authentication habits. Whether you’re an IT professional, a managed service provider (MSP) or simply someone  who values data privacy, this is a good opportunity...

/ October 13, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical vulnerability in Dell UnityVSA

Cybersecurity Threat Advisory: Critical vulnerability in Dell UnityVSA

Cybersecurity researchers at WatchTowr have disclosed a critical vulnerability in Dell UnityVSA (and related Unity platforms) tracked as CVE-2025-36604. The flaw allows an attacker with no authentication to issue arbitrary OS commands on vulnerable appliances by abusing the login redirection...

/ October 9, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RediShell allows RCE in Redis

Cybersecurity Threat Advisory: RediShell allows RCE in Redis

Redis has disclosed CVE-2025-49844, a critical remote code execution vulnerability known as RediShell, with a CVSS score of 10.0. The flaw has existed for over 13 years and could allow attackers to run arbitrary commands on vulnerable systems. Thousands of...

/ October 8, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Oracle EBS flaw

Cybersecurity Threat Advisory: Critical Oracle EBS flaw

Oracle released an emergency update for its E-Business Suite to address the critical vulnerability CVE-2025-61882 ( with a CVSS of 9.8) because it was actively being exploited by threat actors, particularly the Cl0p ransomware group, in a recent wave of...

/ October 8, 2025