Tag: cybersecurity

How MSPs can bridge the security leadership gap

How MSPs can bridge the security leadership gap

CISOs and SMBs are not a combination you often see. Not because SMBs don’t need security leadership. Regulatory pressure, cyber insurance requirements, and customer security questionnaires are making strategic security leadership a necessity. The challenge is cost. A skilled CISO...

/ September 8, 2026
The MSP playbook for agentic AI

The MSP playbook for agentic AI

For years, AI helped security teams detect threats faster while humans remained responsible for taking action. Agentic AI changes that model. Today’s tools can isolate endpoints, disable accounts, block traffic, and launch remediation workflows automatically. The speed benefits are clear,...

/ August 4, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Malicious Notepad++ plugins

Cybersecurity Threat Advisory: Malicious Notepad++ plugins

CERT-UA has identified an ongoing campaign in which threat group UAC-0099 distributes trojanized Notepad++ bundles that install malware on Windows systems. The campaign primarily targets organizations in Ukraine and is linked to activity associated with APT44 (Sandworm). What is the...

/ July 31, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Credential-stealing RAT

Cybersecurity Threat Advisory: Credential-stealing RAT

Researchers have identified a new remote access trojan (RAT) called ChonkyChicken, which threat actors use to steal browser credentials, hijack active browser sessions, and move laterally across Windows networks. Barracuda advises organizations to focus on detection, monitoring, and security hardening,...

/ July 31, 2026
Deepfakes are now an MSP problem

Deepfakes are now an MSP problem

Not long ago, creating a convincing deepfake required a team of specialists, weeks of production, and significant technical expertise. What a difference a few years make. That world is gone. According to the 2026 HYPR State of Passwordless Identity Authentication...

/ July 28, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall SMA1000 exploits

Cybersecurity Threat Advisory: SonicWall SMA1000 exploits

SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments. What is...

/ July 24, 2026
Why MFA fatigue attacks keep working

Why MFA fatigue attacks keep working

MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...

/ July 21, 2026
When MFA isn’t enough: The session hijacking problem

When MFA isn’t enough: The session hijacking problem

Good ol’ MFA. It’s the bane of existence for people who want to log in quickly. For cybersecurity professionals, however, MFA has long been a source of reassurance. But some of that confidence is beginning to fade. For years, organizations...

/ July 14, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SilverFox deploys ValleyRAT rootkit

Cybersecurity Threat Advisory: SilverFox deploys ValleyRAT rootkit

SilverFox threat actors are actively running a ValleyRAT campaign to bypass security controls, escalate privileges, and maintain deep system access while avoiding detection. Organizations should treat this as a high-priority threat. Continue reading this Cybersecurity Threat Advisory to protect against...

/ July 10, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Adobe ColdFusion exploited

Cybersecurity Threat Advisory: Adobe ColdFusion exploited

Adobe has confirmed that attackers are actively exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. Threat intelligence reports indicate exploitation began within hours of disclosure. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, allowing remote code execution on unpatched...

/ July 9, 2026