Tag: cybersecurity
Cybersecurity Threat Advisory: SonicWall SMA1000 exploits
SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments. What is...
Why MFA fatigue attacks keep working
MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...
When MFA isn’t enough: The session hijacking problem
Good ol’ MFA. It’s the bane of existence for people who want to log in quickly. For cybersecurity professionals, however, MFA has long been a source of reassurance. But some of that confidence is beginning to fade. For years, organizations...
Cybersecurity Threat Advisory: SilverFox deploys ValleyRAT rootkit
SilverFox threat actors are actively running a ValleyRAT campaign to bypass security controls, escalate privileges, and maintain deep system access while avoiding detection. Organizations should treat this as a high-priority threat. Continue reading this Cybersecurity Threat Advisory to protect against...
Cybersecurity Threat Advisory: Adobe ColdFusion exploited
Adobe has confirmed that attackers are actively exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. Threat intelligence reports indicate exploitation began within hours of disclosure. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, allowing remote code execution on unpatched...
Incident management issues rising in the age of AI
Managed service providers (MSPs) should take note: as the volume of code created using artificial intelligence (AI) coding tools continues to grow, so does the number of incidents that may require their attention. A survey of 406 IT decision-makers at...
Cybersecurity Threat Advisory: EvilTokens targets Microsoft 365
Recent research describes a phishing kit called EvilTokens. It is actively targeting organizations in the U.S. and Europe, especially those in finance and other high-value sectors. Barracuda recommends deploying browser-aware phishing analysis and strengthening Microsoft 365 OAuth and device-code controls....
How MSPs can fix burnout (hint: it’s not more people)
SOC burnout has become a festering issue in the MSP world. Symptoms include analysts cycling through client environments, drowning in alerts, and quietly heading for the door. But the experts working closest to the problem say the conversation has been...
Nation-state tactics are now in criminal hands
Government-backed hackers once reserved these techniques for targeted campaigns. Today, those techniques appear in everyday malware. For MSPs, the distinction between “targeted” and “opportunistic” attacks is disappearing. “The line between nation-state attacks and criminal attacks is disappearing faster than many...
Tech Time Warp: Nine years since the NotPetya nightmare
With damages estimated at $10 billion worldwide, the NotPetya malware attack of late June 2017 was a nightmare scenario by any standard. But several aspects of the malware — the work of Russian military intelligence officers — were particularly fiendish:...
