Tag: cybersecurity
How MSPs can bridge the security leadership gap
CISOs and SMBs are not a combination you often see. Not because SMBs don’t need security leadership. Regulatory pressure, cyber insurance requirements, and customer security questionnaires are making strategic security leadership a necessity. The challenge is cost. A skilled CISO...
The MSP playbook for agentic AI
For years, AI helped security teams detect threats faster while humans remained responsible for taking action. Agentic AI changes that model. Today’s tools can isolate endpoints, disable accounts, block traffic, and launch remediation workflows automatically. The speed benefits are clear,...
Cybersecurity Threat Advisory: Malicious Notepad++ plugins
CERT-UA has identified an ongoing campaign in which threat group UAC-0099 distributes trojanized Notepad++ bundles that install malware on Windows systems. The campaign primarily targets organizations in Ukraine and is linked to activity associated with APT44 (Sandworm). What is the...
Cybersecurity Threat Advisory: Credential-stealing RAT
Researchers have identified a new remote access trojan (RAT) called ChonkyChicken, which threat actors use to steal browser credentials, hijack active browser sessions, and move laterally across Windows networks. Barracuda advises organizations to focus on detection, monitoring, and security hardening,...
Deepfakes are now an MSP problem
Not long ago, creating a convincing deepfake required a team of specialists, weeks of production, and significant technical expertise. What a difference a few years make. That world is gone. According to the 2026 HYPR State of Passwordless Identity Authentication...
Cybersecurity Threat Advisory: SonicWall SMA1000 exploits
SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments. What is...
Why MFA fatigue attacks keep working
MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...
When MFA isn’t enough: The session hijacking problem
Good ol’ MFA. It’s the bane of existence for people who want to log in quickly. For cybersecurity professionals, however, MFA has long been a source of reassurance. But some of that confidence is beginning to fade. For years, organizations...
Cybersecurity Threat Advisory: SilverFox deploys ValleyRAT rootkit
SilverFox threat actors are actively running a ValleyRAT campaign to bypass security controls, escalate privileges, and maintain deep system access while avoiding detection. Organizations should treat this as a high-priority threat. Continue reading this Cybersecurity Threat Advisory to protect against...
Cybersecurity Threat Advisory: Adobe ColdFusion exploited
Adobe has confirmed that attackers are actively exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. Threat intelligence reports indicate exploitation began within hours of disclosure. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, allowing remote code execution on unpatched...
