Cyber Resilience

Coverage Demonstrator

Pick the services you offer. See the vulnerabilities, threats and incidents from the last 90 days that each one addresses, grouped by how it helps — prevent, detect, respond, recover.

Rollup window ending 2026-09-12 · 2899 stories · Last updated: 12 September 2026 13:16 UTC

What the last 90 days already address

355 distinct news items in the last 90 days are addressed by at least one service an MSP sells, spread across 20 services. A story counts once per service and may count under several, so the column sums far past 355 — the headline is a distinct count, not a total.

Show the per-service breakdown (20 services)
Service90d30dDistinctive forAddresses it by
Vulnerability Management2901409PreventDetect
Managed XDR2591392PreventDetectRespond
Firewall194117135PreventDetect
SASE/SSE18711348PreventDetect
WAF17210730PreventDetect
End-user elevation15192146Prevent
AI-enabled attack detection301218Detect
DLP2811Prevent
Compliance2615Prevent
Third-party2210Prevent
MFA133Prevent
SSO131Prevent
Gateway81Prevent
IEP (M365 email protection)81Prevent
Phishing simulation81Prevent
Training81Prevent
AI/ML system security72Prevent
Risk Management52Prevent
Help Desk validation21Prevent
M365 backup20Recover

No story in this window ties to Entra ID backup, Google Backup, Shadow AI discovery and control specifically. The page says so below and links nothing — an honest empty, not a gap.

Client view: only confirmed and corroborated reports are shown — never an unverified leak-site claim.

My service offerings

Check the services you provide to see the threats each one addresses. Saved on this device only; no account.

Identity
Applications
Email
Data
Network
Managed XDR
GRC

End-user elevation 151

Active threats this quarter that End-user elevation addresses:

Prevent

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Learn the help desk's reset procedure, then call back and use it
  • Take dozens of build servers, then wait
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over

Help Desk validation 2

Active threats this quarter that Help Desk validation addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • Learn the help desk's reset procedure, then call back and use it
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over

MFA 13

Active threats this quarter that MFA addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

SSO 13

Active threats this quarter that SSO addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Extort the victim a second time, from inside your own operation
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Learn the help desk's reset procedure, then call back and use it
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

AI/ML system security 7

Active threats this quarter that AI/ML system security addresses:

Vulnerability Management 290

Active threats this quarter that Vulnerability Management addresses:

Prevent

Detect

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • A state-linked group that sells the access instead of using it
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Take dozens of build servers, then wait
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • Phish the credential, then change where the money is sent

WAF 172

Active threats this quarter that WAF addresses:

Prevent

Detect

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Make the victim run the payload as proof they are human
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Chain four flaws in an end-of-life security appliance
  • Ransom hospitals to pay for the nuclear-programme espionage
  • The pipeline stopped because the company stopped it
  • The tool that certifies the appliance is clean can be told to say so
  • The QR code exists to get the victim off the managed device

Gateway 8

Active threats this quarter that Gateway addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Make the victim run the payload as proof they are human
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

IEP (M365 email protection) 8

Active threats this quarter that IEP (M365 email protection) addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Make the victim run the payload as proof they are human
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

Phishing simulation 8

Active threats this quarter that Phishing simulation addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • An exploit that applies on viewing, defeating every control built around user action
  • Make the victim run the payload as proof they are human
  • The account of someone who left, and the backup that kept their desk
  • Learn the help desk's reset procedure, then call back and use it
  • Extort by telling the victim's customers
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

Training 8

Active threats this quarter that Training addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • An exploit that applies on viewing, defeating every control built around user action
  • Make the victim run the payload as proof they are human
  • The account of someone who left, and the backup that kept their desk
  • Learn the help desk's reset procedure, then call back and use it
  • Extort by telling the victim's customers
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

DLP 28

Active threats this quarter that DLP addresses:

Prevent

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • The account of someone who left, and the backup that kept their desk
  • A state-linked group that sells the access instead of using it
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Extort by telling the victim's customers
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent

Entra ID backup

No story in this window ties to Entra ID backup specifically:

Identity backup restores directory objects after tampering or deletion. 50 extortion or ransomware claims this window, none naming an Entra ID or Azure AD estate.

Entra ID backup

Worked cases this service addresses:

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • The pipeline stopped because the company stopped it

Google Backup

No story in this window ties to Google Backup specifically:

Backup is the recovery arm when data is encrypted or purged. 50 extortion or ransomware claims this window, none naming a Google Workspace estate.

Google Backup

Worked cases this service addresses:

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • The pipeline stopped because the company stopped it

M365 backup 2

Active threats this quarter that M365 backup addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • The pipeline stopped because the company stopped it

Shadow AI discovery and control

No story in this window ties to Shadow AI discovery and control specifically:

Shadow AI discovery finds company data going into unsanctioned assistants. 13 AI-security items ran this window, but none described staff use of an outside tool, which is what this service addresses.

AI-enabled attack detection 30

Active threats this quarter that AI-enabled attack detection addresses:

Detect

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • An exploit that applies on viewing, defeating every control built around user action
  • Make the victim run the payload as proof they are human
  • A state-linked group that sells the access instead of using it

Firewall 194

Active threats this quarter that Firewall addresses:

Prevent

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • Build the target list before the vulnerability is public
  • Ransom hospitals to pay for the nuclear-programme espionage
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over

SASE/SSE 187

Active threats this quarter that SASE/SSE addresses:

Prevent

Detect

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Make the victim run the payload as proof they are human
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Build the target list before the vulnerability is public
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • Extort by telling the victim's customers
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

Managed XDR 259

Active threats this quarter that Managed XDR addresses:

Prevent

Detect

Respond

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Make the victim run the payload as proof they are human
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Build the target list before the vulnerability is public
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • Take dozens of build servers, then wait
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

Cloud Detection & Response

Worked cases this service addresses:

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • Build the target list before the vulnerability is public
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • The pipeline stopped because the company stopped it
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over

Endpoint Detection & Response

Worked cases this service addresses:

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Make the victim run the payload as proof they are human
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • Take dozens of build servers, then wait
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

Identity Threat Detection & Response

Worked cases this service addresses:

  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • Register your own device as the second factor, and the lock is now yours
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Ransom hospitals to pay for the nuclear-programme espionage
  • Learn the help desk's reset procedure, then call back and use it
  • The pipeline stopped because the company stopped it
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over
  • Phish the credential, then change where the money is sent
  • The QR code exists to get the victim off the managed device

Network Detection & Response

Worked cases this service addresses:

  • Ransomware sold as a product, with security professionals recruited as the supply chain
  • Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Select victims by exposure alone, finish the same day, and change name to stay unattributed
  • Extort the victim a second time, from inside your own operation
  • Chain four flaws in an end-of-life security appliance
  • The account of someone who left, and the backup that kept their desk
  • The identities that cannot have a second factor
  • A state-linked group that sells the access instead of using it
  • Build the target list before the vulnerability is public
  • Ransom hospitals to pay for the nuclear-programme espionage
  • The pipeline stopped because the company stopped it
  • Phish from inside the marketing platform the recipient already trusts
  • The tool that certifies the appliance is clean can be told to say so
  • He says he is from IT, and if you will not let him in remotely he drives over

Compliance 26

Active threats this quarter that Compliance addresses:

Prevent

Risk Management 5

Active threats this quarter that Risk Management addresses:

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Learn the help desk's reset procedure, then call back and use it

Third-party 22

Active threats this quarter that Third-party addresses:

Prevent

Worked cases

Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.

  • An exploit that applies on viewing, defeating every control built around user action
  • Tell the device to mail you its own configuration, using the management protocol's write function
  • Compromise the carrier, and inherit everyone whose traffic crosses it
  • Exploited inside the mandated patching window, then exploited again on a second instance during the response
  • Build the target list before the vulnerability is public
  • Learn the help desk's reset procedure, then call back and use it