By the end of 2025, a clear pattern held across the breaches we investigated: attackers increasingly did not break into networks, they logged into clouds. Stolen […]
Throughout 2025, the fallout from Salt Typhoon, a China-linked espionage campaign against telecommunications providers, continued to shape how governments think about critical-infrastructure security. The campaign compromised […]
A recurring myth among smaller Canadian organizations is that meaningful detection requires an expensive commercial platform and a large team. It does not. The 2025 intrusions […]
In October 2025, F5 disclosed that a sophisticated, likely nation-state actor had maintained long-term access to its internal systems and stolen portions of BIG-IP source code […]
In October 2025, the Cl0p extortion group launched another mass data-theft campaign, this time exploiting a zero-day in Oracle E-Business Suite tracked as CVE-2025-61882. The pattern […]
October is Cybersecurity Awareness Month, and in Canada it is a natural moment to look honestly at the weakest and strongest link in any defense: people. […]
In September 2025, a self-propagating worm dubbed Shai-Hulud swept through the npm ecosystem, compromising hundreds of packages by stealing developer and CI credentials and using them […]
Through the second half of 2025, agentic AI moved from demo to deployment. Organizations began wiring language models into tools that can send email, query databases, […]
Multi-factor authentication is now table stakes, and that is exactly the problem. Attackers have adapted. The 2025 wave of identity-driven intrusions, from help-desk social engineering to […]