Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

From Isolated Attacks to Continuously Optimized Operations

Security teams have spent years improving their ability to detect and respond to cyber threats. More visibility, better tools, and richer telemetry have helped organizations identify suspicious activity across users, devices, applications, and infrastructure. But the nature of the challenge is changing. Modern attacks are rarely defined by a single event.

Your Clients Already Deployed AI. Nobody Sold Them the Security for It.

Every vendor this year says the same thing: AI is transforming cybersecurity. True, and not useful. Here is the useful version. AI is doing two things at once. It is compressing the time between a vulnerability being found and being exploited, which is the part everyone talks about. And it is quietly installing a brand new attack surface inside your clients' businesses, which is the part nobody is selling against yet.

Oops, OpenAI Hacked Australia's Health System - The 443 Podcast - Episode 389

This week on the podcast, we cover yet another rogue AI security incident that Australia's Prime Minister disclosed in front of the United Nations last week. Before that, we discuss an FBI alert on WaterPlum, a North Korean threat actor targeting IT professionals. Then, we cover the FBI themselves becoming a victim of cyberattack, this time by ShinyHunters.

HTTPS Content Inspection: Give Your Firebox a Better View

HTTPS protects communications between users and the services they access by encrypting data in transit. That makes it much harder for someone to intercept and read that information. But there is a trade-off: encryption can also prevent security controls from seeing what is inside the traffic they are supposed to protect. Your Firebox may know that a user is connecting to a website or service. Without HTTPS inspection, however, it may have limited visibility into what is actually being exchanged.

Provider to Advisor: The MSP Shift Toward Risk Leadership | WatchGuard Webinar

Most MSP client reviews cover what got installed. The endpoint agent was deployed, the firewall rules were tuned, and the tickets were closed inside the SLA. Meanwhile, boards, insurers, and auditors are asking for something more: a clear account of the business's current security and compliance risks. The partner who can provide that answer earns client trust and increases credibility.

One Image to Root Them All - The 443 Podcast - Episode 388

This week on the podcast, we break down how a heap overflow in an image-decoding library nobody thinks about became a pull request inside OpenAI's internal monorepo. Three researchers chained it with an OpenAI single sign-on flaw to hijack employee ChatGPT and Codex accounts in under 72 hours; and had an AI write the exploit for them. Before that, we cover the actively exploited maximum-severity authentication bypass in Cisco's Identity Services Engine. Then we close with RatHat, a new Android malware that enables Wireless Debugging, reads its own pairing code from the screen, and asks a commercial AI assistant where to tap.

Unlock MSP Growth: How AI Drives Operational Efficiency and New Revenue | WatchGuard Webinar

Artificial intelligence is no longer a future consideration for MSPs because it is already reshaping how leading providers run their businesses, protect their clients, and create new revenue streams. Separating real business value from hype requires a clear-eyed, practitioner-driven perspective.

Attackers Have Changed Their Playbook. Has Your Security Strategy Changed With Them?

Cybersecurity teams have spent years preparing for malware, ransomware, and high-volume attacks. Yet the latest WatchGuard Global Threat Report reveals a more nuanced and potentially more dangerous reality: attackers are becoming quieter, more evasive, and increasingly reliant on stolen credentials, legitimate tools, encrypted communications, and long-known vulnerabilities. For MSPs and IT leaders, the challenge isn't simply understanding these trends.