morphhats-logomorphhats-logomorphhats-logomorphhats-logo
  • Home
  • About me
  • Services
  • My works
  • Contact
  • MorphHats InfoSecure
  • Blog
Blog
✕

Threats & Attacks

  • Home
  • Blog
  • Threats & Attacks
  • Filter by
  • Categories
  • Tags
  • Authors
  • Show all
  • All
  • AI & Security
  • Announcements
  • Cloud Security
  • DFIR
  • Digital Forensics & Incident Response
  • Governance & Compliance
  • Security Awareness
  • Threats & Attacks
  • Tools & Techniques
  • Vulnerabilities & Patching
  • Zero Trust
  • All
  • Access Control
  • Agentic AI
  • AI Adoption
  • AI Governance
  • AI Security
  • Artificial Intelligence
  • Attack Surface
  • Attack Techniques
  • Authentication
  • Automation
  • Automotive
  • Awareness
  • Backups
  • BEC
  • Bill C-26
  • Bill C-8
  • Blue Team
  • Business Continuity
  • Canada
  • CCCS
  • CISA Advisory
  • Cl0p
  • Clop
  • Cloud
  • Cloud Security
  • Compliance
  • Conditional Access
  • Configuration
  • Credential Stuffing
  • Credential Theft
  • Critical Infrastructure
  • Culture
  • Data Breach
  • Data Brokers
  • Data Loss
  • Data Privacy
  • Data Protection
  • DDoS
  • Defensible Architecture
  • Detection
  • Detection Engineering
  • DevSecOps
  • DFIR
  • Digital Forensics
  • Double Extortion
  • Edge Devices
  • Education
  • Encrypted Messaging
  • Endpoint
  • Espionage
  • Extortion
  • F5
  • Forensics
  • FortiOS
  • Fraud
  • Governance
  • Government
  • Hardening
  • Help Desk
  • IAM
  • Identity
  • Identity & Access Management
  • Identity Theft
  • Incident Reporting
  • Incident Response
  • Least Privilege
  • Linux
  • LLM
  • Logging
  • Machine Learning
  • Managed File Transfer
  • MFA
  • MICCMAC
  • Microsoft
  • Misconfiguration
  • Misconfigurations
  • MITRE ATTACK
  • MorphHats
  • Multi-Cloud
  • Nation-State
  • Network Security
  • North Korea
  • npm
  • OpenSSH
  • Passkeys
  • Patch Management
  • Patching
  • Persistence
  • Personal Security
  • Phishing
  • Phishing-Resistant
  • PIPEDA
  • Policy
  • Preparedness
  • Prioritization
  • Privacy
  • Prompt Injection
  • Purple Team
  • Ransomware
  • RCE
  • Recovery
  • Regulation
  • Resilience
  • Risk
  • Risk Management
  • Roadmap
  • SaaS
  • Salt Typhoon
  • Scattered Spider
  • Security Architecture
  • Security Automation
  • Security Awareness
  • Segmentation
  • Shadow AI
  • Shared Responsibility
  • SharePoint
  • SIEM
  • Sigma
  • Signing
  • SMB
  • Social Engineering
  • Supply Chain
  • Tabletop
  • Tabletop Exercises
  • Telecom
  • Third-Party Risk
  • Threat Actors
  • Threat Detection
  • Threat Hunting
  • Threat Intelligence
  • Threats
  • Training
  • Validation
  • Vendor Risk
  • Visibility
  • VPN
  • Vulnerability Management
  • Windows
  • Zero Trust
  • Zero-Day
  • All
  • oga
January 14, 2026
January 14, 2026
Categories
  • Threats & Attacks

Ransomware Readiness: Assume It Will Happen, Then Prepare

Readiness beats prevention alone Prevention still matters, but the organizations that recover well from ransomware are the ones that planned for the bad day before it […]
Do you like it?0
Read more
November 25, 2025
November 25, 2025
Categories
  • Threats & Attacks

Salt Typhoon and the Long Game Against Telecom Infrastructure

Throughout 2025, the fallout from Salt Typhoon, a China-linked espionage campaign against telecommunications providers, continued to shape how governments think about critical-infrastructure security. The campaign compromised […]
Do you like it?0
Read more
October 14, 2025
October 14, 2025
Categories
  • Threats & Attacks

Cl0p, Oracle E-Business Suite, and the Return of Mass Extortion

In October 2025, the Cl0p extortion group launched another mass data-theft campaign, this time exploiting a zero-day in Oracle E-Business Suite tracked as CVE-2025-61882. The pattern […]
Do you like it?0
Read more
July 15, 2025
July 15, 2025
Categories
  • Threats & Attacks

Scattered Spider and the Help Desk: When Social Engineering Beats Your Firewall

Through the first half of 2025, a loose collective often tracked as Scattered Spider ran a highly effective campaign against retail, aviation, insurance, and hospitality organizations. […]
Do you like it?0
Read more
March 14, 2025
March 14, 2025
Categories
  • Threats & Attacks

Medusa and the Ransomware Playbook of 2025

In March 2025, US authorities issued a joint advisory on the Medusa ransomware operation, detailing its tactics against organizations across multiple sectors. The advisory is a […]
Do you like it?0
Read more
February 24, 2025
February 24, 2025
Categories
  • Threats & Attacks

The Bybit Heist: Lessons from the Largest Crypto Theft Yet

On February 21, 2025, cryptocurrency exchange Bybit disclosed the theft of roughly 1.5 billion US dollars in Ethereum, the largest digital-asset heist on record. Investigators attributed […]
Do you like it?0
Read more
January 15, 2025
January 15, 2025
Categories
  • Threats & Attacks

The PowerSchool Breach: What Canadian School Boards Should Learn

In early January 2025, a breach at PowerSchool, a widely used student information system, exposed data belonging to students, families, and staff across North America. Several […]
Do you like it?0
Read more
December 13, 2024
December 13, 2024
Categories
  • Threats & Attacks

Clop Returns Through Managed File Transfer: The Cleo Exploitation Campaign

In December 2024, attackers began exploiting vulnerabilities in Cleo’s managed file transfer products, and the Clop extortion group claimed responsibility for the resulting data theft. It […]
Do you like it?0
Read more
June 24, 2024
June 24, 2024
Categories
  • Threats & Attacks

The CDK Global Ransomware Attack: When One Vendor Freezes an Entire Industry

In mid-June 2024, a ransomware attack against CDK Global, the dealer management platform used by thousands of car dealerships across North America, forced the company to […]
Do you like it?0
Read more
Contact us

+1 (548) 333-2276


oga@morphhats.com


The Blue Team Jedi, aka Morpheus.

Localization

MorphHats InfoSecure
251, Northfield Dr E
Waterloo N2K 0G9
Ontario, Canada

© 2026 MorphHats InfoSecure
    Blog

      Powered by
      ►
      Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
      None
      ►
      Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
      None
      ►
      Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
      None
      ►
      Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
      None
      ►
      Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
      None
      Powered by