• When SMS Attacks Fall Outside Your Security Stack

    When SMS Attacks Fall Outside Your Security Stack

    Organizations invest significant resources in protecting their systems, networks, and corporate accounts. Most of this investment focuses on familiar channels such as email, corporate endpoints, and network access. At the same time, one attack vector continues to operate with little to no organizational oversight: SMS messages. Smishing attacks do not attempt to break security systems…

  • The Rise of Multi-Channel Phishing: Email, SMS, and Collaboration Tools

    The Rise of Multi-Channel Phishing: Email, SMS, and Collaboration Tools

    In the past, most phishing attacks focused solely on email. Today, attackers are increasingly using multi-channel strategies, targeting users via SMS, messaging apps like WhatsApp, and collaboration tools within the organization, such as Teams. These attacks present a new challenge for managers and organizations: messages appear legitimate and arrive through channels employees use regularly, making…

  • Ransomware Prevention: Beyond Backup

    Ransomware Prevention: Beyond Backup

    Most ransomware attacks do not begin with sophisticated exploits, zero-day vulnerabilities, or highly advanced malware.They start with a single action that appears completely legitimate – a click, an approval, or a login to a familiar account. In many cases, it is phishing.An email that looks internal. A Teams message that seems to come from a…

  • The Cost of Ignoring Minor Security Alerts

    The Cost of Ignoring Minor Security Alerts

    Organizations often receive dozens or even hundreds of security alerts daily. Many of these are labeled “low risk” or “informational,” and it can be tempting for teams to ignore them in favor of higher-priority incidents. But minor alerts are not always harmless. In some cases, what seems small at first can escalate into significant operational,…

  • Supply Chain Ransomware: How Third-Party Attacks Impact Major Companies

    Supply Chain Ransomware: How Third-Party Attacks Impact Major Companies

    In recent years, ransomware attacks have become a familiar threat, but in recent months a particularly dangerous pattern has become clearer: attacks aimed at one organization that end up impacting dozens or even hundreds of other companies through an external supplier. Instead of attempting to directly breach large, well-protected companies, attackers are increasingly targeting software…

  • SOC Evolution: From Alert Handling to Risk Control

    SOC Evolution: From Alert Handling to Risk Control

    For years, Security Operations Centers were built around one core mission: detect alerts, investigate them, and respond as quickly as possible. Speed mattered more than context, and volume often dictated priorities. Today, that model is no longer enough. Modern SOC teams operate in an environment where attacks are continuous, automated, and increasingly tailored. An alert…

  • Two Phishing Attacks That Show How Even Tech Giants Remain Vulnerable

    Two Phishing Attacks That Show How Even Tech Giants Remain Vulnerable

    August 2025 delivered a sharp reminder that even organizations with advanced security infrastructures are not immune to phishing and social engineering. Two separate attacks, one involving Salesforce and the other targeting Cisco, led to data exposure and once again underscored that the human factor remains a primary target for attackers. On August 6, a large…

  • HMRC Phishing Incident Leads to £47M Tax Fraud

    HMRC Phishing Incident Leads to £47M Tax Fraud

    A few days after a large scale phishing related incident affected the United Kingdom online tax services, it is already clear that this was not just another technical security issue. It is a concrete example of how phishing can lead to major financial and operational damage, even without a classic system breach. On June 4,…

  • Why Most Security Tools Miss What Employees Do on Their Phones

    Why Most Security Tools Miss What Employees Do on Their Phones

    For many organizations, security strategy is still built around laptops, corporate networks, and cloud systems. That is where most controls are deployed, most budgets are spent, and most dashboards are focused. But daily work has quietly shifted. Employees now approve requests, open links, read messages, and share files from their phones. SMS, WhatsApp, Teams, Slack,…