-

Supply Chain Ransomware: How Third-Party Attacks Impact Major Companies
In recent years, ransomware attacks have become a familiar threat, but in recent months a particularly dangerous pattern has become clearer: attacks aimed at one organization that end up impacting dozens or even hundreds of other companies through an external supplier. Instead of attempting to directly breach large, well-protected companies, attackers are increasingly targeting software…
-

SOC Evolution: From Alert Handling to Risk Control
For years, Security Operations Centers were built around one core mission: detect alerts, investigate them, and respond as quickly as possible. Speed mattered more than context, and volume often dictated priorities. Today, that model is no longer enough. Modern SOC teams operate in an environment where attacks are continuous, automated, and increasingly tailored. An alert…
-

Two Phishing Attacks That Show How Even Tech Giants Remain Vulnerable
August 2025 delivered a sharp reminder that even organizations with advanced security infrastructures are not immune to phishing and social engineering. Two separate attacks, one involving Salesforce and the other targeting Cisco, led to data exposure and once again underscored that the human factor remains a primary target for attackers. On August 6, a large…
-

HMRC Phishing Incident Leads to £47M Tax Fraud
A few days after a large scale phishing related incident affected the United Kingdom online tax services, it is already clear that this was not just another technical security issue. It is a concrete example of how phishing can lead to major financial and operational damage, even without a classic system breach. On June 4,…
-

Why Most Security Tools Miss What Employees Do on Their Phones
For many organizations, security strategy is still built around laptops, corporate networks, and cloud systems. That is where most controls are deployed, most budgets are spent, and most dashboards are focused. But daily work has quietly shifted. Employees now approve requests, open links, read messages, and share files from their phones. SMS, WhatsApp, Teams, Slack,…
-

Millions of Passwords Leaked – and the Real Risk Is Only Beginning
In June 2025, it was revealed that approximately 6.5 million LinkedIn user passwords were shared on dark web forums. This was not a breach of a single system, but a clear example of how information stolen in one place quickly becomes a tool for much broader attacks. When passwords are leaked, they do not remain…
-

Attention! User Awareness Alone Cannot Stop Phishing
Organizations invest significant resources in employee training, phishing simulations, and security awareness programs. This is important, but it is no longer sufficient. Modern phishing does not rely only on human mistakes. It exploits workload pressure, automation, legitimate enterprise tools, and techniques that appear credible even to experienced employees. Reality shows that even in organizations with…
-

BEC is Not an Email Attack. It is an Identity Attack
In most organizations, Business Email Compromise is still viewed as just another type of phishing attack aimed at sending a convincing email. In practice, this is only a superficial view. BEC is first and foremost an attack on digital identity. The attacker uses email only as an entry point. The real objective is to obtain…
-

Telecom and Cybersecurity: A Strategic Partnership
In a world where phishing attacks, fraud, and impersonation increasingly originate from mobile devices and communication networks, telecom companies have become the first line of defense for both users and organizations. But a first line of defense is not enough. Telecom providers have deep visibility into network traffic, usage patterns, and attack entry points. Cybersecurity…