Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

From Phishing to Persistence: Lessons from the CrySome RAT Infection Chain

Originally published on Cybersecurity Insiders. Phishing remains one of the most reliable entry points for attackers, serving as the initial intrusion vector in 58% of incidents analyzed in LevelBlue’s Q1 2026 TTP Briefing. But today’s campaigns are becoming increasingly targeted and technically sophisticated, evolving from simply convincing a user to click to establishing long-term access to enterprise environments.

How the SOC Analyst Agent cuts investigation time from four hours to fourteen minutes

MFA fatigue campaigns work on a simple bet: eventually, someone taps “approve” just to make the notifications stop. It paid off. The attacker was in. The first move was quiet — deactivate SMS authentication, a small settings change easy to miss on a busy queue, and exactly the kind of thing that buys room to work without tripping an alarm. Then came the real work: AWS credentials pulled from one system, SSH keys from another, and a slow and methodical pull of internal source code.

Tines achieves TX-RAMP Level 2 certification

Government teams are under growing pressure to modernize and improve efficiency while continuing to meet rigorous requirements for security, governance, and accountability. Meeting both demands requires technology that can support innovation without sacrificing control. That’s why we’re proud to share that Tines has achieved TX-RAMP Level 2 certification for both Tines Stories and Tines 3B.

Securing AI Beyond the Filter Layer | A10 Networks

Securing AI Beyond the Filter Layer | A10 Networks In this second session of our AI security series, Jamison Utter and Arjoyita Roy from A10 Networks dive into the limitations of traditional guardrails and explore what it takes to secure agentic AI. Learn why basic prompt filters fall short, how external guardrails fit into your security posture, and how to govern autonomous AI agents across the entire reasoning loop effectively.

Acronis Ranked #1 in Cloud Email Security in the G2 Fall 2026 Grid Report

Email remains the primary entry point for cyberattacks, making effective email security more critical than ever. That’s why we’re especially proud that customers ranked Acronis Cyber Protect Cloud in the G2 Fall 2026 Cloud Email Security Grid Report. Because G2 rankings are based on verified customer reviews, this recognition reflects the experience of the organizations and service providers that rely on Acronis to protect their users, data and business communications every day.

Introducing Acronis Cyber Compliance: Continuous compliance built for MSPs

There is no shortage of guidance available to MSPs on how they should secure customer environments. Security frameworks, industry standards, regulatory requirements and insurance obligations all provide recommendations on the controls organizations should have in place. Yet despite this abundance of guidance, cyber incidents remain common and continue to increase. At the same time, requirements are becoming more complex.

Securing Public Sector Software in 2026: Security Debt Demands Action

Public sector software, from defense platforms to K-12 student information systems, is accumulating a dangerous backlog of unresolved vulnerabilities. That’s the headline finding from Veracode’s 2026 State of Software Security report, and the data behind it is unambiguous: the pace of vulnerability discovery has structurally outrun the capacity to fix them.

Privileged Account and Session Management (PASM) Explained

Privileged accounts have elevated access that can be used to rewrite system configurations, alter sensitive databases, create new admin users, and exfiltrate confidential customer data. This makes them attractive targets for attackers and risky when poorly managed. Basic passwords and network firewalls aren’t enough to protect them. You need to monitor them continuously. This is where Privileged Account and Session Management (PASM) becomes essential.

How Conditional Access Protects Microsoft 365 Apps From Unmanaged Devices

Your sales representative logged into Outlook from a coffee shop laptop that isn't enrolled, isn't encrypted, and hasn't seen a security patch in eight months. Should Microsoft 365 let that sign-in through just because the password was correct? That single question is why conditional access exists. Passwords tell you who someone claims to be. They say nothing about whether the device behind that login is safe to trust with your company's email, SharePoint files, or Teams chats.