Blog

Browse the latest cybersecurity guidance from the team.

Cyber Weekly: Attackers took the keys

This week's theme is the keys to the kingdom. Attackers went after the tools that open everything else: remote management platforms, virtualization layers, build servers, and out-of-band management chips. The result was a week of CVSS 9.8s with no workarounds, active exploitation before disclosure, and a record crypto heist pulled off in 41 minutes. Here is what happened and what it means for your business.

Categories

Threats

Tags

Vendor SecurityRansomwareSupply ChainSMB SecurityThreat Landscape
Read more

Cyber Weekly: Creds, signed drivers, and shutdowns

Three things happened this week that don't normally happen. A vendor told customers to physically shut down their servers. A ransomware strain used a Microsoft-signed driver to kill antivirus before encryption. And researchers confirmed that stolen FortiGate credentials are directly fueling ransomware deployments at industrial scale. That's not a normal Tuesday. Between July 1 and 13, we saw an AI agent run a complete ransomware attack without human help, 7 million driver's license records leak from one phished employee, and attackers calling businesses on Microsoft Teams pretending to be IT support. The credential-to-ransomware pipeline is no longer a theory. It's the operating model. Here's what happened and what you actually need to do about it.

Categories

Threats

Tags

Threat LandscapeSupply ChainRansomwareDetectionPhishingSMB Security
Read more

Cyber Weekly: FortiBleed, cPanel, and Ubiquiti hit SMBs

Last week was one of those weeks where the threats landed in layers. First the FortiGate story broke with numbers that made everyone stop. Then cPanel. Then Ubiquiti. By Thursday you couldn't ignore the pattern: attackers had figured out that the easiest way into a small business is through the infrastructure it relies on every day. Here's what happened, what it actually means, and the one thing you should check before you finish this post.

Categories

Threats

Tags

RansomwareSMB SecuritySupply ChainThreat LandscapeThird-Party RiskPhishing
Read more

Cyber Weekly: Supply chains under siege

If you run a small or medium business and you've been treating cybersecurity as a big company problem, this week should change your mind. We had a Fortinet credential leak exposing 74,000+ devices, a WordPress plugin supply chain attack backdooring paying customers, a critical Splunk bug being exploited in the wild, and a Salesforce OAuth breach that started with one vendor's old password. The common thread? None of these required sophisticated, nation-state-level attacks. They required a forgotten admin account, an auto-update you trusted, and an exposed VPN. Here's what happened, what it means, and what to do about it.

Categories

Threats

Tags

Threat LandscapeSMB SecurityRansomwareThird-Party RiskSupply Chain
Read more
1

A practical model designed for momentum.

See how we scope engagements to reduce risk quickly while keeping delivery predictable.

See how we do it