Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Github Actions Supply Chain Attacks

This week, we discuss a recent cascading supply chain attack involving multiple Github actions workflows that nearly succeeded in compromising a popular Coinbase application. Before that, we discuss a novel way to download malware onto an endpoint by abusing a web browser's caching feature. Additionally, we cover an FBI alert on file converter malware scams.

Backup: Why it's important to stay up to date with your data

Today, data is one of organizations' most valuable and vulnerable assets. Effective backups are essential for operational continuity and cybersecurity. With 80% of businesses exposed to ransomware attacks, this World Backup Day emphasizes the need to regularly back up critical systems to minimize downtime and ensure quick recovery from incidents. However, many organizations still face challenges with backup and restoration processes.

Five Reasons to Transition Away from On-Premises Identity Systems

Traditional on-premises identity management solutions are no longer adequate to support small and midsize organizations. Moreover, modern Cloud alternatives have significantly eased the complexity and inefficiencies of premises-based identity management.

Future-Proofing Data Centers: Essential Cybersecurity Strategies

Data centers are the backbone of our digital economy, housing critical applications, customer data, and Cloud services. As we observe International Data Center Day, it's imperative to address the escalating cybersecurity challenges these facilities face. The rise of sophisticated cyber threats, including AI-driven attacks and supply chain vulnerabilities, necessitates a proactive and robust security posture.

TrustRadius Trusted Seller | WatchGuard

We’re raising a glass to trust! We’re proud to be named to @TrustRadius’s Trusted Seller Program, recognizing our commitment to transparency, customer satisfaction, and delivering real value. Just like a perfectly poured pint, trust takes time to build and we’re grateful to our customers and partners for making this possible!

WatchGuard Wins CRN 5-Star for 9th Year, Dominating MSP Security

At WatchGuard, we proudly announce that our WatchGuardONE partner program has received the prestigious 5-star rating from CRN, a brand of The Channel Company, in the 2025 CRN Partner Program Guide. This marks the ninth consecutive year WatchGuard has earned this recognition, solidifying the commitment to providing the industry’s most powerful, profitable, and MSP-friendly security solutions.

Polymorphic Extensions - The 443 Podcast - Episode 323

This week on the podcast, we discuss a research post by SquareX that invents a new way to impersonate any extension installed on a victim's web browser. Before that, we cover the latest supply chain attack attempts from Lazarus, as well as a malvertising campaign that managed to infect 1 million endpoints. The 443 Security Simplified is a weekly podcast that gets inside the minds of leading white-hat hackers and security researchers, covering the latest cybersecurity headlines and trends.

Is It Possible to Include Patch Management in Your Service Package?

It is no longer surprising that cybercriminals are constantly searching for vulnerabilities to exploit. This is why patch management has become increasingly important in recent years. In fact, Verizon's 2024 Data Breach Investigations Report revealed a significant 180% increase compared to the previous year. This highlights the urgency of having a solid patch management process in place.

Silk Typhoon is Targeting MSPs - The 443 Podcast - Episode 322

This week on the podcast, we discuss a recent update from Microsoft's Threat Intelligence Center describing the latest tactics from Silk Typhoon, a Chinese nation state threat actor focusing in espionage. Before that, we cover the recent 0day vulnerabilities in VMware ESXi, Workstation and Fusion. We also analyze a report by S-RM on an Akira ransomware attack that leveraged IoT devices to hide from EDR tools.

Eliminate Security Complexity on Pi Day | WatchGuard Technologies

Cyber threats don’t stop, just like Pi (π). That doesn’t mean your security should be stuck in an endless loop of updates, patching, and stress. WatchGuard delivers real security - tailored to you, eliminating complexity, and keeping you ahead of threats. This Pi Day (3.14), let’s celebrate security that works.

5 ways to align your cybersecurity with World Economic Forum (WEF) guidance

2025 could be the most challenging year yet for the digital environment. As emerging factors such as the duality of AI, the rise in cybercrime, or the shortage of cybersecurity talent impact business, we ask the question, what should companies expect going forward?

Meet FireCloud Internet Access: The Future of Secure Remote Connectivity

With hybrid and remote work now the norm, organizations face an urgent challenge – how to provide employees with seamless, secure access to critical applications without the performance and security drawbacks of traditional VPNs. At WatchGuard, we recognize that businesses need a modern, scalable security solution that meets the demands of a distributed workforce.

How do misconfigurations affect your customers' security?

Incorrect configurations in digital systems represent a growing security threat, as even minor errors can help set up cyberattacks. These vulnerabilities arise when system, application, or network settings fail to follow security best practices, such as outdated default settings or failures in Cloud services, databases, or firewalls. These can expose your customers to serious risks, such as unauthorized access or theft of sensitive information.

Webinar: Secure Your Remote Workforce with a Secure Access Service Strategy

In today’s rapidly evolving digital landscape, traditional security models fail to protect remote workers and cloud-based applications. Shifting to a secure access service edge (SSE) strategy is an effective and affordable solution that will protect remote workers. SSE solutions deliver firewall-as-a-service (FWaaS) and secure web gateway (SWG) capabilities, ensuring safe, high-performance connectivity to Cloud applications.

ByBit Says Bye to $1.4 billion - The 443 Podcast - Episode 321

This week on the podcast, we cover the largest cryptocurrency heist ever (for now). Before that, we cover Apple's decision to disable Advanced Data Protection (ADP) for its UK customers. We end the episode with a review of Wiz's State of Code Security report for 2025. The 443 Security Simplified is a weekly podcast that gets inside the minds of leading white-hat hackers and security researchers, covering the latest cybersecurity headlines and trends.