Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

World Password Day: The Hidden Cost of Compromised Credentials

Every year, World Password Day highlights the importance of strong credentials and password managers. But the real issue today isn't whether your password is complex enough—it's whether it's already been stolen and is for sale on the dark web. Millions of credentials are circulating in underground marketplaces like e-commerce platforms, complete with verified vendors, customer support, and full database access.

AI and Compliance with Adam Winston

This week on the podcast, we bring in Adam Winston, former CSO of ActZero and current Field CTO for Managed Services at WatchGuard to discuss automating the SOC with AI. We cover the history of AI in SecOps, the good and bad applications of AI and Machine Learning, what the future looks like, and how compliance might impact our ability to get there.

WatchGuard Signs The Climate Pledge, Commits to Net Zero by 2040

As a cybersecurity company, we spend every day thinking about how to protect the world from threats. As a global organization, WatchGuard has the power ‒ and the responsibility ‒ to step up and help fight the threat of unchecked climate change. That’s why we have signed The Climate Pledge and are deepening our commitment to environmental sustainability.

The CVE Near-Death Experience - The 443 Podcast - Episode 327

This week on the podcast, we discuss how the CVE program was granted an 11th hour temporary reprieve after the program's steward, MITRE, originally announced their contract had not been renewed. After that, we cover the recent cyberattack against 4chan that took it offline and resulted in leaked moderator information and source code. We end with a quick discussion on a post-exploitation technique being used in the wild against Fortinet FortiGate devices.

How to Grow a Strong Cybersecurity Culture

Let’s be honest — when most people hear “cybersecurity training,” their eyes glaze over faster than a workstation running Windows 98. But here’s the kicker: 74% of data breaches still involve a human element, whether through social engineering, errors, or misuse, according to Verizon’s 2023 DBIR. That’s not just a stat — it’s a blinking neon sign pointing to the importance of cybersecurity culture.

Key Takeaways from the Latest ISR: More Malware, and Harder to Detect

Malware hasn’t just increased—it’s become harder to detect. Evasive techniques are reshaping the threat landscape and pushing traditional security models to their limits. Today’s advanced malware campaigns are consistently slipping past multiple layers of defense—from email and network to endpoints—challenging even the most robust infrastructures.

Revoking Security Clearances as Punishment - The 443 Podcast - Episode 326

This week on the podcast, we discuss a recent White House executive order that revoked the security clearances of former CISA chief Christopher Krebs as well as all other employees at SentinelOne and the implications that brings to our industry. Before that, we give a quick update on the Oracle Cloud breach from a few weeks back that Oracle has finally confirmed. We end with our thoughts on a few Microsoft Windows AI features that just launched in early preview and how they might impact data privacy and security.

5 Cybersecurity Seeds to Plant for a Secure Tomorrow

Building strong cybersecurity doesn’t require fancy tools or a Hollywood-style war room. Often, it just takes the basics ‒ done really well. Think of it like gardening: healthy habits, applied consistently, create deep roots that protect your business when storms roll in. Here are five essential practices that every organization ‒ from small MSPs to midsize enterprises ‒ should plant today to ensure a secure tomorrow.

Get More from Defender with WatchGuard Core MDR for Microsoft

Small and midsize businesses (SMBs) are increasingly becoming prime targets for cybercriminals, accounting for 46% of all cyber breaches impacting companies with fewer than 1,000 employees. With an alarming 30,000 small business websites compromised daily and the average user receiving 1.5 malicious emails, the reality is clear: it's not a matter of if your business will face a cyber threat, but when.

Lucid, the Phishing-as-a-Service Platform - The 443 Podcast - Episode 325

This week on the podcast, we discuss a recent threat intelligence report on the Chinese Phishing-as-a-Service platform Lucid. Before that, we cover the alleged Oracle Cloud breach before reviewing the Singapore Shared Responsibility Framework, designed to combat financial scams.

Github Actions Supply Chain Attacks - Episode 324 - The 443 Podcast

This week on, Corey and Marc discuss a recent cascading supply chain attack involving multiple Github actions workflows that nearly succeeded in compromising a popular Coinbase application. Before that, they discuss a novel way to download malware onto an endpoint by abusing a web browser's caching feature. Additionally, they cover an FBI alert on file converter malware scams.

AI in XDR: A Step Towards More Advanced Cybersecurity

In recent years, cybersecurity has undergone a radical transformation. Traditional solutions, once sufficient to protect organizations' digital assets, have become obsolete against increasingly complex cyber threats. Malicious actors now leverage advanced technologies to launch sophisticated attacks at unprecedented scales and speeds. According to the UK's National Cyber Security Centre, AI is accelerating the spread of ransomware and lowering the entry barrier for less experienced cybercriminals.

30% of MSPs forecast growth of over 20% by 2025

As cyber threats intensify, demand for managed services continues to grow at a rapid pace. According to Canalys, by 2025, 28% of managed service providers are expected to achieve over 20% growth. To maintain this positive trend, MSPs must evolve towards an MSP 3.0 model, as AI integration and automation are essential tools in addressing cyber risks and regulatory challenges.