The cloud rarely fails; the settings do Most cloud incidents we investigate do not come from an exotic exploit. They come from a setting that was […]
By the end of 2025, a clear pattern held across the breaches we investigated: attackers increasingly did not break into networks, they logged into clouds. Stolen […]
Multi-factor authentication is now table stakes, and that is exactly the problem. Attackers have adapted. The 2025 wave of identity-driven intrusions, from help-desk social engineering to […]
Through the first half of 2025, a loose collective often tracked as Scattered Spider ran a highly effective campaign against retail, aviation, insurance, and hospitality organizations. […]
Ask incident responders where modern breaches begin and the answer is remarkably consistent: identity. Across the first half of 2025, from credential-driven SaaS breaches to ransomware […]
Zero Trust has been marketed so heavily that many small and mid-sized Canadian businesses assume it is a costly enterprise project reserved for organizations with large […]
In early November 2024, it emerged that a suspect linked to the wave of cloud data-theft and extortion campaigns tied to Snowflake customer accounts had been […]
By mid-July 2024, the scope of the attacks against Snowflake customer accounts had grown, with more organizations disclosing that data had been exported from cloud environments […]