morphhats-logomorphhats-logomorphhats-logomorphhats-logo
  • Home
  • About me
  • Services
  • My works
  • Contact
  • MorphHats InfoSecure
  • Blog
Blog
✕

Blog

  • Home
  • Blog
  • Filter by
  • Categories
  • Tags
  • Authors
  • Show all
  • All
  • AI & Security
  • Announcements
  • Cloud Security
  • DFIR
  • Digital Forensics & Incident Response
  • Governance & Compliance
  • Security Awareness
  • Threats & Attacks
  • Tools & Techniques
  • Vulnerabilities & Patching
  • Zero Trust
  • All
  • Access Control
  • Agentic AI
  • AI Adoption
  • AI Governance
  • AI Security
  • Artificial Intelligence
  • Attack Surface
  • Attack Techniques
  • Authentication
  • Automation
  • Automotive
  • Awareness
  • Backups
  • BEC
  • Bill C-26
  • Bill C-8
  • Blue Team
  • Business Continuity
  • Canada
  • CCCS
  • CISA Advisory
  • Cl0p
  • Clop
  • Cloud
  • Cloud Security
  • Compliance
  • Conditional Access
  • Configuration
  • Credential Stuffing
  • Credential Theft
  • Critical Infrastructure
  • Culture
  • Data Breach
  • Data Brokers
  • Data Loss
  • Data Privacy
  • Data Protection
  • DDoS
  • Defensible Architecture
  • Detection
  • Detection Engineering
  • DevSecOps
  • DFIR
  • Digital Forensics
  • Double Extortion
  • Edge Devices
  • Education
  • Encrypted Messaging
  • Endpoint
  • Espionage
  • Extortion
  • F5
  • Forensics
  • FortiOS
  • Fraud
  • Governance
  • Government
  • Hardening
  • Help Desk
  • IAM
  • Identity
  • Identity & Access Management
  • Identity Theft
  • Incident Reporting
  • Incident Response
  • Least Privilege
  • Linux
  • LLM
  • Logging
  • Machine Learning
  • Managed File Transfer
  • MFA
  • MICCMAC
  • Microsoft
  • Misconfiguration
  • Misconfigurations
  • MITRE ATTACK
  • MorphHats
  • Multi-Cloud
  • Nation-State
  • Network Security
  • North Korea
  • npm
  • OpenSSH
  • Passkeys
  • Patch Management
  • Patching
  • Persistence
  • Personal Security
  • Phishing
  • Phishing-Resistant
  • PIPEDA
  • Policy
  • Preparedness
  • Prioritization
  • Privacy
  • Prompt Injection
  • Purple Team
  • Ransomware
  • RCE
  • Recovery
  • Regulation
  • Resilience
  • Risk
  • Risk Management
  • Roadmap
  • SaaS
  • Salt Typhoon
  • Scattered Spider
  • Security Architecture
  • Security Automation
  • Security Awareness
  • Segmentation
  • Shadow AI
  • Shared Responsibility
  • SharePoint
  • SIEM
  • Sigma
  • Signing
  • SMB
  • Social Engineering
  • Supply Chain
  • Tabletop
  • Tabletop Exercises
  • Telecom
  • Third-Party Risk
  • Threat Actors
  • Threat Detection
  • Threat Hunting
  • Threat Intelligence
  • Threats
  • Training
  • Validation
  • Vendor Risk
  • Visibility
  • VPN
  • Vulnerability Management
  • Windows
  • Zero Trust
  • Zero-Day
  • All
  • oga
April 15, 2025
April 15, 2025
Categories
  • Vulnerabilities & Patching

Patched but Not Safe: Fortinet Symlink Persistence and the Cost of Old Vulnerabilities

In April 2025, Fortinet warned that attackers who had exploited older FortiOS SSL-VPN vulnerabilities were maintaining read-only access to affected devices through a symbolic link, even […]
Do you like it?0
Read more
March 31, 2025
March 31, 2025
Categories
  • Governance & Compliance

Before the Alarm: Building an Incident Response Plan That Works

Every serious incident in early 2025, from ransomware outbreaks to the Bybit theft, reinforced a familiar truth: the organizations that fared best had decided how they […]
Do you like it?0
Read more
March 26, 2025
March 26, 2025
Categories
  • Cloud Security

Misconfiguration, Not Malware: The Real Cloud Risk

Cloud breaches rarely stem from a broken hyperscaler. Through the first half of 2025, the recurring story remained the same: exposed storage buckets, overly permissive identity […]
Do you like it?0
Read more
March 14, 2025
March 14, 2025
Categories
  • Threats & Attacks

Medusa and the Ransomware Playbook of 2025

In March 2025, US authorities issued a joint advisory on the Medusa ransomware operation, detailing its tactics against organizations across multiple sectors. The advisory is a […]
Do you like it?0
Read more
February 26, 2025
February 26, 2025
Categories
  • Security Awareness

When the Phish Knows Your Name: Defending Against Targeted Lures

Phishing in 2025 rarely looks like the clumsy, misspelled emails of a decade ago. Following large breaches such as the PowerSchool incident, attackers hold rich context: […]
Do you like it?0
Read more
February 24, 2025
February 24, 2025
Categories
  • Threats & Attacks

The Bybit Heist: Lessons from the Largest Crypto Theft Yet

On February 21, 2025, cryptocurrency exchange Bybit disclosed the theft of roughly 1.5 billion US dollars in Ethereum, the largest digital-asset heist on record. Investigators attributed […]
Do you like it?0
Read more
February 12, 2025
February 12, 2025
Categories
  • Zero Trust

Zero Trust for the Rest of Us: A Starting Point for SMBs

Zero Trust has been marketed so heavily that many small and mid-sized Canadian businesses assume it is a costly enterprise project reserved for organizations with large […]
Do you like it?0
Read more
January 29, 2025
January 29, 2025
Categories
  • AI & Security

DeepSeek and the Rush to Adopt: AI Data Governance for SMBs

Late January 2025 saw DeepSeek’s low-cost reasoning models dominate the technology news cycle and rattle markets. Beyond the economics, the moment raised a practical question for […]
Do you like it?0
Read more
January 22, 2025
January 22, 2025
Categories
  • Vulnerabilities & Patching

CVE-2025-0282: Ivanti Connect Secure and the Edge-Device Problem

January 2025 opened with another edge-device zero-day. Ivanti disclosed CVE-2025-0282, a critical stack-based buffer overflow in Connect Secure, Policy Secure, and related gateways, that was already […]
Do you like it?0
Read more
Prev page
12345678
Next page
Contact us

+1 (548) 333-2276


oga@morphhats.com


The Blue Team Jedi, aka Morpheus.

Localization

MorphHats InfoSecure
251, Northfield Dr E
Waterloo N2K 0G9
Ontario, Canada

© 2026 MorphHats InfoSecure
    Blog

      Powered by
      ►
      Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
      None
      ►
      Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
      None
      ►
      Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
      None
      ►
      Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
      None
      ►
      Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
      None
      Powered by