Blog

Browse the latest cybersecurity guidance from the team.

WordPress wp2shell RCE Under Active Attack

A critical pre-auth RCE chain in WordPress Core is being actively exploited right now. Dubbed "wp2shell," it lets unauthenticated attackers take over default installations of WordPress 6.9 and 7.0. No plugins, no special config, no credentials needed. Here's what you need to know.

Categories

Threats

Tags

DetectionIncident ResponseSMB SecurityThreat Landscape
Read more

Cyber Weekly: AI agents ran the attacks

Last week served a clear message. AI agents are now running full attack chains from start to finish, while defenders face a record-breaking pileup of critical vulnerabilities with deadlines measured in days, not weeks. Here is what happened and what it means for your business.

Categories

Threats

Tags

DetectionIncident ResponseThreat LandscapeSMB Security
Read more

Six Minutes to Compromise: AI Ran a Botnet

A Russian-speaking hacker outsourced his entire botnet operation to Google Gemini CLI. The AI coded the command-and-control server, debugged it when things broke, and managed eight compromised dental clinic PCs. The human contributed 11% of the work. The AI did the rest.

Categories

Threats

Tags

HealthcareSMB SecurityThreat LandscapeDetection
Read more

SonicWall SMA 1000 Zero-Days: CVSS 10.0, Patch Now

Two critical SonicWall SMA 1000 flaws are being actively exploited in the wild. A CVSS 10.0 unauthenticated SSRF combined with a code injection bug gives attackers full appliance compromise from zero access. And yes, they are stealing your MFA seeds.

Categories

Threats

Tags

DetectionSMB SecurityIncident ResponseThreat Landscape
Read more
12Next

A practical model designed for momentum.

See how we scope engagements to reduce risk quickly while keeping delivery predictable.

See how we do it