Tag: ransomware

The MSP guide to managing supply chain risk

The MSP guide to managing supply chain risk

In 2026, supply chain attacks have become one of the most feared threats in cybersecurity, and for good reason. When attackers compromise a vendor with privileged access to multiple environments, they do not just breach one organization. They can potentially...

/ September 29, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ransomware exploits Confluence servers

Cybersecurity Threat Advisory: Ransomware exploits Confluence servers

Feral Wolf has targeted Russian organizations through exposed Confluence servers, insecure 1C configurations, and compromised contractors, ultimately deploying ransomware. The campaign exploited the Atlassian Confluence vulnerability CVE-2023-22515. What is the threat? Feral Wolf is a financially motivated ransomware group that...

/ September 28, 2026
The 3-2-1 backup rule isn’t enough anymore

The 3-2-1 backup rule isn’t enough anymore

For decades, the 3-2-1 backup rule has been the mainstay of data protection: keep three copies of your data, on two different types of media, with one copy stored offsite. It was a sound framework for a world where the...

/ August 18, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Qilin exploits GlobalProtect flaw

Cybersecurity Threat Advisory: Qilin exploits GlobalProtect flaw

Threat actors are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain remote access and deploy Qilin ransomware. The attacks target internet-facing firewalls and Prisma Access deployments, allowing attackers to establish VPN sessions that appear...

/ July 27, 2026
Nation-state tactics are now in criminal hands

Nation-state tactics are now in criminal hands

Government-backed hackers once reserved these techniques for targeted campaigns. Today, those techniques appear in everyday malware. For MSPs, the distinction between “targeted” and “opportunistic” attacks is disappearing. “The line between nation-state attacks and criminal attacks is disappearing faster than many...

/ June 30, 2026
Tech Time Warp
Tech Time Warp: Ransomware continues to make computer users WannaCry

Tech Time Warp: Ransomware continues to make computer users WannaCry

This month’s Canvas ransomware attack—in addition to making finals week more stressful for thousands of college students and their professors—was a stark reminder about the continued threat of ransomware. Consider it a bit of a Tech Time Warp. It’s enough...

/ May 15, 2026
Start the year strong: 10 essential questions every IT team should address

Start the year strong: 10 essential questions every IT team should address

It’s a new year (and also a day ending in Y), which means it’s an excellent time for you to review your security posture. Use your renewed energy to seriously analyze your vulnerabilities, detection methods and organizational procedures. Answer these...

/ February 2, 2026
ransomware
Email breach delays can multiply ransomware risk eight-fold

Email breach delays can multiply ransomware risk eight-fold

Email breaches affect almost all organizations. The new Email Security Breach Report 2025 reveals the worrying fact that 78 percent of organizations experienced an email breach in the last year. Only half of them detected the breach within an hour....

/ November 3, 2025
ransomeware
Why ransomware attackers keep coming back for more

Why ransomware attackers keep coming back for more

Ransomware is an escalating threat, powered by its ability to evolve and adapt to a changing security landscape. Organizations around the world continue to fall victim to ransomware, often repeatedly, and the impact of these attacks can be devastating. We...

/ August 11, 2025 / 7 Comments
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall SSL VPN targeted by Akira ransomware – updated

Cybersecurity Threat Advisory: SonicWall SSL VPN targeted by Akira ransomware – updated

Update: This post was updated on August 7, 2025, to reflect corrected information regarding this threat.  An Akira ransomware campaign is specifically targeting SonicWall SSL VPN devices. Attackers are actively exploiting these vulnerabilities to gain unauthorized access to corporate networks....

/ August 7, 2025