From LulzSec to the incident response room, Cody Kretsinger knows what it costs to earn trust in this industry. Here's why Angelo Martino's case lands differently for him, and what leaders should do before the call comes in.
A ransomware negotiator at a trusted incident response firm spent 2023 feeding his clients' insurance limits and negotiating positions to BlackCat. Five organizations paid for it. One fishing boat got seized. Part 1 of 2.
A NIST mathematician just proved perfect AI guardrails can never exist. Here's why the internet got the takeaway wrong, and what your AI security program should really look like.
For the first time in 19 years, vulnerability exploitation has overtaken stolen credentials as the top breach vector. Here's what the Verizon DBIR is really saying and what to do about it.
OpenClaw's skill marketplace filled up with malware and nobody in security was surprised. Here's what it tells us about AI agent platforms, software supply chains, and the mistake the industry keeps making.
Patching isn't enough when the credentials were already stolen. Here's how to assess your exposure, rotate credentials completely, and ask your vendors the questions that matter.
Bitwarden, Trivy, Checkmarx, LiteLLM. These aren't separate incidents. They're one attack, still running, with stolen credentials still being spent today.
Opportunistic attacks at scale can impact any MSP client with exposed systems or weak controls. Without proper patching, MFA, and segmentation, vulnerabilities can be exploited en masse, leading to widespread breaches and serious liability.
Threat actors don't need to target your clients directly, if access is exposed, it will be found, sold, and used. MSPs that ignore initial access risks leave clients vulnerable to opportunistic attacks and costly breaches.