June 26, 2024

June 26, 2024

Are your clients prepared for the 210% surge in Business Email Compromise attacks???

An HR manager narrowly avoids a costly scam - an email requesting to update direct deposit details. This scenario is all too common, with over 42,000 BEC attacks reported in 2023 alone. Businesses lost $2.9 billion to scams last year.?

Explore how debunking common email security myths can strengthen your client’s defenses against business email compromise and phishing attacks. Discover essential strategies to protect them from costly security breaches and empower your cybersecurity efforts. Read more to gain valuable insights and enhance your approach to email security.?

Beyond Phishing: 3 More Ways Adversaries Complicate Initial Intrusion?

Adversaries can break into your environment in more ways than a generic phishing email, hoping for a lucky click. This month, the Adversary Pursuit Group (APG) examined different ways adversaries broke into top organizations that aren’t “just” another phishing email, exploiting:?

  • Social engineering?at Ascension Health on May 8;?

  • Product vulnerabilities?at Checkpoint exploited on May 28; and?

  • Enemy network infrastructure designed to confuse defenders, per Mandiant research on May 22.

Learn More About Advanced Intrusion Techniques Beyond Phishing


Active SOC Saves of the Month?

May 24, 2024: Threat actors initially compromised a Consumer Cyclicals partner’s user account by abusing remote desktop protocol (RDP) , then infecting other devices within the environment and creating a malicious scheduled task “pypa-embed” for persistence.?

Read the Complete Full RDP Incident Analysis


June 4, 2024: A threat actor silently installed the RMM tool AnyDesk on an Energy partner’s machine, coinciding with a brute force attack against multiple M365 accounts at the same organization.?

Read the Complete Full AnyDesk Incident Analysis


June 9, 2024: A threat actor within an Industrial partner’s user account that, among other activities – including abuse of TeamViewer and other allowlisted applications as part of a “living off the land” (LotL) attack strategy – attempted to delete over 1,110 activity logs in the infected host.?

Read the Complete TeamViewer and LotL Incident Analysis


June 17, 2024: Two separate partners – Healthcare and Consumer Non-Cyclicals – suffered NetSupport RAT attacks on the same day , with the latter’s infection including a malicious JavaScript file disguised as an allowlisted update. ? ?

Read the Complete NetSupport Rat Incident Analysis


Key themes of Q2’s hottest event – Pax8 Beyond?

Missed out on attending Pax8 Beyond 2024, one of this year’s pivotal events for MSPs? No worries – we've compiled a comprehensive summary just for you. Dive into our blog to uncover the crucial insights and key takeaways that fellow MSPs are currently discussing:??

  1. Security remains a top priority for the MSP community?
  2. MSPs are eager to mature their business acumen?
  3. Simplifying billing models is a universal goal?
  4. Bold Predictions for the future of MSP?

Learn more about the event

Meet the Blackpoint Team in July!?

要查看或添加评论,请登录

社区洞察

其他会员也浏览了