Blog

Browse the latest cybersecurity guidance from the team.

WordPress wp2shell RCE Under Active Attack

A critical pre-auth RCE chain in WordPress Core is being actively exploited right now. Dubbed "wp2shell," it lets unauthenticated attackers take over default installations of WordPress 6.9 and 7.0. No plugins, no special config, no credentials needed. Here's what you need to know.

Categories

Threats

Tags

DetectionIncident ResponseSMB SecurityThreat Landscape
Read more

Cyber Weekly: AI agents ran the attacks

Last week served a clear message. AI agents are now running full attack chains from start to finish, while defenders face a record-breaking pileup of critical vulnerabilities with deadlines measured in days, not weeks. Here is what happened and what it means for your business.

Categories

Threats

Tags

DetectionIncident ResponseThreat LandscapeSMB Security
Read more

SonicWall SMA 1000 Zero-Days: CVSS 10.0, Patch Now

Two critical SonicWall SMA 1000 flaws are being actively exploited in the wild. A CVSS 10.0 unauthenticated SSRF combined with a code injection bug gives attackers full appliance compromise from zero access. And yes, they are stealing your MFA seeds.

Categories

Threats

Tags

DetectionSMB SecurityIncident ResponseThreat Landscape
Read more

Patchageddon: 570 flaws, 2 zero-days in the wild

Microsoft just dropped the largest security update in company history, with 570+ vulnerabilities, two zero-days already being exploited, and a third publicly disclosed with no patch in sight. Here's what you need to patch first and why your triage list just got a lot longer.

Categories

Threats

Tags

Least PrivilegeIncident ResponseThreat LandscapeMicrosoft 365
Read more
12Next

A practical model designed for momentum.

See how we scope engagements to reduce risk quickly while keeping delivery predictable.

See how we do it