-
Introducing Threat Watch Live: Heimdal’s New Monthly Cybersecurity Intelligence Webinar
At Heimdal, we know there’s no shortage of noise when it comes to cybersecurity news. But what MSP leaders and technical teams really need isn’t more headlines. It’s clear, focused intelligence that helps you act fast and stay ahead. That’s why we’re excited to launch Threat Watch Live, our new monthly webinar series designed to…
-
Scattered Spider Attacks US Airlines – The MSP Cyber News Snapshot – July 3rd
From courtroom breaches to cockpit infiltration, here’s this week’s Cyber Snapshot. Five critical stories you need on your radar, with safety advice included. We’ve got insider revenge, MFA manipulation, rogue browser extensions, and state-sponsored email theft, all in one rapid-fire rundown. Whether you’re in IT, cybersecurity compliance, or just trying to keep your team one…
-
Heimdal Partners with Portland to Deliver Unified Cybersecurity for Benelux MSPs
Amsterdam, Netherlands – July 3, 2025 – Heimdal, a leading European provider of unified, AI-driven cybersecurity solutions, today announced a strategic distribution partnership with Portland, a top-tier IT channel specialist in the Benelux region. The collaboration gives Managed Service Providers (MSPs) across Belgium, the Netherlands, and Luxembourg streamlined access to Heimdal’s award-winning Extended Detection and…
-
97% of MSPs Still Use Excel. Here’s the Risk – With Kevin Lancaster
Too many vendors, too little time, and more logins than you can count. Sound familiar? Our guest today is Kevin Lancaster, an advisor, investor, and founder of Channel Program, a platform that gives MSPs and vendors the data they need to make smarter, faster decisions. Kevin’s been on every side of this industry, from building…
-
AI-fueled fake IDs and identity theft: What you need to know
Identity theft happens every 22 seconds in the U.S. and now, artificial intelligence is making it easier for scammers. What used to be rough Photoshop jobs has evolved into slick, AI-generated IDs that can trick high-end security systems. These fakes often rely on something people give away freely: their social media photos. As AI tools…
-
New DDoS Attack Record – The MSP Cyber News Snapshot – June 26th
Cybersecurity Advisor Adam Pilton is back with a fresh Cyber News Snapshot for MSPs & other professionals in the IT industry. Top cybersecurity news between 20th and 26th June talks about Qilin ransomware’s new tricks, a DHS advisory on Iran-supported threat actors, a healthcare facilities’ data breach impact, and a new record for DDoS attacks. Adam seasoned all that with actionable…
-
CVE-2025-54572 – Apache Ruby SAML Denial-of-Service Vulnerability
CVE ID : CVE-2025-54572 Published : July 30, 2025, 2:15 p.m. | 1 hour, 5 minutes ago Description : The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response…
-
CVE-2025-46811 – SUSE Manager WebSocket Root RCE
CVE ID : CVE-2025-46811 Published : July 30, 2025, 3:15 p.m. | 38 minutes ago Description : A Missing Authentication for Critical Function vulnerability in SUSE Manager allows anyone with access to the websocket at /rhn/websocket/minion/remote-commands to execute arbitrary commands as root. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 0.3.7-150600.3.6.2; Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before…
-
CVE-2025-54430 – Apache Dedupe GitHub Token Exfiltration
CVE ID : CVE-2025-54430 Published : July 30, 2025, 2:15 p.m. | 1 hour, 38 minutes ago Description : dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution quickly on structured data. Before commit 3f61e79, a critical severity vulnerability has been identified within the .github/workflows/benchmark-bot.yml workflow, where a issue_comment…
-
CVE-2025-8323 – Ventem e-School Arbitrary File Upload Remote Code Execution
CVE ID : CVE-2025-8323 Published : July 30, 2025, 4:16 a.m. | 11 hours, 37 minutes ago Description : The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. Severity: 8.8 | HIGH Visit the link for more…