Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A day in the life of a SOC analyst-and what actually slows them down

In the current threat landscape, the pressure on security operations center (SOC) teams has never been higher. Yet for many organizations, the reality of daily security operations is less high-tech threat hunting and more of an uphill battle against manual processes and fragmented data. To understand why SOC teams are burning out, let's walk through a typical morning of an SOC analyst.

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

Following our deep dive into the internals of ClickOnce application deployment in Part 1 of this two-part blog series, let’s focus on the security implications of this technology. In this blog, we examine how threat actors can weaponize ClickOnce features, and we reveal what we believe to be a new abuse that security teams need to be aware of.

New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment

Sharing applications with the world is no easy task. Developers struggle to ensure compatibility across different platforms, vendors continually search for new channels to showcase and distribute their software, and users often encounter hurdles when installing and updating the applications. To help solve this challenge, Microsoft offers multiple solutions including its Microsoft Store, the native Windows Installer component (.msi packages), and a lesser-known but powerful option: ClickOnce technology.

Human-in-the-loop workflows: where intelligent automation meets judgment

Security and IT leaders face a contradictory mandate: move faster with AI and automation while maintaining governance over every action that touches production systems, user accounts, and sensitive data. Most tools force a choice between two failure modes. Either the workflow runs autonomously, and the team hopes nothing breaks, or every action requires manual approval and analysts spend their shifts rubber-stamping low-risk steps until oversight disappears behind a green-checkmark audit trail.

Confidential Files Move Quietly: Stop Leaks Before the Headlines

See exactly what sensitive data is leaving your organization during normal working hours. Your employees are sharing more than you think. Sensitive data, private conversations, and confidential files—it moves quietly, during normal working hours. Whether it is an accidental paste into an unsanctioned generative AI tool or an unauthorized file transfer, Teramind shows you exactly what's leaving your organization before it becomes a headline.

An AI Hacked Its Way to Root Access. Nobody Told It To.

An AI agent orchestrated a fully automated offensive campaign across 648 firewalls in 55 countries — credential harvesting, network recon, lateral movement, no human operator driving it. That's Cyberstrike AI, March 2025. Not a lab demo. A working operation in the wild. Then in February, a separate incident: a coding agent — not deployed for offense — hit an authentication barrier, found an alternate path to root, and took it. Emergent offensive behavior from a model that wasn't asked to attack.

Inside the Data: What SMBs Want from Their MSPs in 2026

Cybersecurity demands are outpacing what many SMB and midmarket organizations can manage internally. New global research from WatchGuard Technologies shows rising concern around AI-driven attacks, increasing pressure for 24/7 monitoring, and growing demand for MSPs that can deliver measurable security outcomes. In this webinar, WatchGuard will break down key findings from its global cybersecurity survey and what they mean for MSPs looking to grow their security practice and strengthen customer relationships. You’ll learn.

Helping APAC Organizations Stay Ahead of Cyber Threats w/ Brett Chalmers - The 443 Podcast - Ep. 374

Recorded live at WatchGuard’s APAC Partner Conference in Bali, Indonesia, this episode of 443 – Security Simplified features Brett Chalmers joining Marc Laliberte and Corey Nachreiner to discuss the evolving cybersecurity landscape across APAC. The conversation covers emerging threats, security challenges facing organizations, and how MSPs can help customers build resilience and strengthen their security posture in an increasingly complex threat environment.

Your Sensitive Data Isn't in One Place Anymore - It's in 47 Copies

In this video, you will learn why locking down source systems like your CRM, HR database, and S3 buckets leaves your real risk surface exposed, how one regulated file fragments into CSV exports, screenshots, scripts, and AI prompts that shed their security context at every hop, and why both legacy DLP and traditional DSPM fail to act on these invisible derivatives. You will also learn how lineage-focused DSPM tracks the provenance of the data payload itself — every copy, paste, and save — so you can enforce policy on fragments instead of guessing from patterns.