In April 2025, Fortinet warned that attackers who had exploited older FortiOS SSL-VPN vulnerabilities were maintaining read-only access to affected devices through a symbolic link, even […]
Every serious incident in early 2025, from ransomware outbreaks to the Bybit theft, reinforced a familiar truth: the organizations that fared best had decided how they […]
Cloud breaches rarely stem from a broken hyperscaler. Through the first half of 2025, the recurring story remained the same: exposed storage buckets, overly permissive identity […]
In March 2025, US authorities issued a joint advisory on the Medusa ransomware operation, detailing its tactics against organizations across multiple sectors. The advisory is a […]
Phishing in 2025 rarely looks like the clumsy, misspelled emails of a decade ago. Following large breaches such as the PowerSchool incident, attackers hold rich context: […]
On February 21, 2025, cryptocurrency exchange Bybit disclosed the theft of roughly 1.5 billion US dollars in Ethereum, the largest digital-asset heist on record. Investigators attributed […]
Zero Trust has been marketed so heavily that many small and mid-sized Canadian businesses assume it is a costly enterprise project reserved for organizations with large […]
Late January 2025 saw DeepSeek’s low-cost reasoning models dominate the technology news cycle and rattle markets. Beyond the economics, the moment raised a practical question for […]
January 2025 opened with another edge-device zero-day. Ivanti disclosed CVE-2025-0282, a critical stack-based buffer overflow in Connect Secure, Policy Secure, and related gateways, that was already […]