Blog

Browse the latest cybersecurity guidance from the team.

SonicWall SMA 1000 Zero-Days: CVSS 10.0, Patch Now

Two critical SonicWall SMA 1000 flaws are being actively exploited in the wild. A CVSS 10.0 unauthenticated SSRF combined with a code injection bug gives attackers full appliance compromise from zero access. And yes, they are stealing your MFA seeds.

Categories

Threats

Tags

DetectionSMB SecurityIncident ResponseThreat Landscape
Read more

Cyber Weekly: Creds, signed drivers, and shutdowns

Three things happened this week that don't normally happen. A vendor told customers to physically shut down their servers. A ransomware strain used a Microsoft-signed driver to kill antivirus before encryption. And researchers confirmed that stolen FortiGate credentials are directly fueling ransomware deployments at industrial scale. That's not a normal Tuesday. Between July 1 and 13, we saw an AI agent run a complete ransomware attack without human help, 7 million driver's license records leak from one phished employee, and attackers calling businesses on Microsoft Teams pretending to be IT support. The credential-to-ransomware pipeline is no longer a theory. It's the operating model. Here's what happened and what you actually need to do about it.

Categories

Threats

Tags

Threat LandscapeSupply ChainRansomwareDetectionPhishingSMB Security
Read more

Small Business Security Posture: 3 Fundamentals Beat Budgets

Small businesses aren't collateral damage anymore - they're the main target. The good news: fixing your security posture doesn't take an enterprise budget. It takes three fundamentals done well.

Categories

Strategy

Tags

SMB SecurityRiskDetectionReadinessAccess Control
Read more
Prev12

A practical model designed for momentum.

See how we scope engagements to reduce risk quickly while keeping delivery predictable.

See how we do it