Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Beyond the Inbox: How BEC Leads to SSO Abuse

For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim's mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money or sensitive information. Today, we're seeing something different at LevelBlue. Across multiple recent investigations, we've observed attackers treating a compromised mailbox as just the first step.

Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk

SpiderLabs’ technical review of the July attacks examines the affected technologies, observed activity, and broader threat landscape. The next question is practical: what can small utilities realistically do about it? At many small water and wastewater facilities, there is often no dedicated security team to understaff. A licensed operator may be responsible for sampling, maintenance, compliance, and after-hours callouts, perhaps with limited support from municipal IT.

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action

When people hear the word cybersecurity, they often picture analysts racing to stop an attack in real time. Those roles are absolutely critical, but a lot of effective security happens long before an alert ever appears. As Director of Operational Intelligence (OpsIntel) at LevelBlue, my job isn't to respond to every incident myself.

Stronger Teams Build Stronger Cyber Resilience

LevelBlue has been named a U.S. News & World Report 2026–2027 Best Company to Work For, earning recognition across three categories: Best Companies to Work For Overall, Best Companies to Work For in Information Technology, and Best Companies to Work For in the Midwest. We are proud of this recognition because it reflects something central to who we are: our people.

Day in the Life of DFIR Leader: Bringing Order to Cyber Chaos

Most cyber investigations don’t begin at the beginning. Rather, they begin at the end, after systems are locked, data is exposed, and operations have already been disrupted. The outcome is visible, but the cause is not. From there, everything becomes a process of working backward on an incomplete picture. That’s the unique puzzle that keeps Devon Ackerman, Global Services Leader of Digital Forensics and Incident Response (DFIR) firmly planted in the world of chaos every day.

The Case for the Channel in an AI-Driven Security Market

Originally published by ChannelPro. There is an ongoing debate in the cybersecurity industry about whether vendors should go directly to customers or instead become a part of a wider partnership network. The standard argument is that consolidation of platforms and AI-driven cost-of-service delivery makes the traditional model of a channel ecosystem redundant. However, this is largely incorrect, at least when it comes to the SMB and mid-market segments where most UK businesses sit.

The Cybersecurity Homework You Can't Skip

Summer might mean slightly fewer meetings, lighter inboxes, and the illusion of breathing room (in a perfect world), but we all know that attackers don’t take vacations, so neither should the fundamentals that keep your organization secure. If anything, now is the perfect time to tackle the “homework” that often gets pushed aside during busier quarters. Recent incident patterns continue to reinforce a straightforward reality: breaches are rarely the result of a single control failure.

Your Phone Number Is More Valuable to Criminals Than You Think

When people think about cybersecurity, they usually think about protecting passwords, laptops, or email accounts. Phone numbers don't make the list very often. Maybe they should. A phone number by itself isn't especially dangerous. Someone can't hack your phone simply because they know your number. But it is often the starting point for a much larger attack.