Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI-Generated Phishing Achieves a 54% Click Rate

For years, phishing has worked for one simple reason: it exploits the weakest link, the user. The defensive strategy has followed the same formula: better email filtering, more user awareness, and an extra layer of authentication. It wasn't perfect, but it was a workable balance.

QR Code Attacks Surge 146% in Two Months

One particularly concerning trend in the recent evolution of phishing is the rise of QR code-based attacks. It doesn't rely on new malware or sophisticated exploits. Instead, it takes advantage of something much simpler: the trust users place in QR codes every day. Over the last few months, QR codes have become one of the most popular tactics for steering users toward malicious sites on mobile devices or in browser environments, where the visibility of many security tools is very limited.

WatchGuard's Cyber Hygiene Report - The 443 Podcast - Episode 379

This week on the podcast we cover the key takeaways from the just-released Cyber Hygiene Report from WatchGuard. After that, we discuss a recent alert from CISA and other international security agencies on state-sponsored attacks against network equipment. We end with an interesting research post on exfiltrating data from Claude's memory.

The Real Cybersecurity Challenge is Operational Capacity

For years, the cybersecurity industry has assumed that the primary challenge was to see more, detect better, and deploy increasingly sophisticated tools. That paradigm no longer reflects the reality of today's cybersecurity operations. Organizations have never had so much visibility into their attack surface or so many capabilities to identify threats. However, the rapid evolution of AI is increasing the speed and complexity of attacks to a point where detection alone is no longer enough.

Why WatchGuard Is Investing Across the Frontier AI Ecosystem

Artificial intelligence is quickly becoming one of the most transformative technologies in cybersecurity. Unfortunately, it's not transforming the industry exclusively for defenders. Attackers are already experimenting with AI to accelerate reconnaissance, analyze software for vulnerabilities, develop fully-functional exploits, and automate nearly all parts of the attack lifecycle.

Beyond Security: How Complexity is Pushing Companies to the Brink

The cybersecurity conversation usually revolves around attacks. We talk about ransomware, phishing, and critical vulnerabilities—but there is a much less visible problem that is limiting many organizations' ability to respond: operational complexity. Today, a single company might rely on dozens of security tools, manage workloads spread across multiple cloud providers, handle hundreds or thousands of digital identities, and support employees connecting from absolutely anywhere.

The 30-Minute Cloud Risk Assessment Every MSP Should Be Offering

Every time a client gets breached through a cloud app, it's the MSP who gets the call. Compromised Microsoft 365 accounts, unauthorized AI tools, and misconfigured sharing settings. Attackers aren't breaking in anymore. They're logging in through gaps that your endpoint, firewall, and MDR tools were never designed to see.

Why Now Is the Time to Replace Your VPN

For years, the VPN has been the default answer to remote access. It solved a problem organizations faced when employees primarily worked from offices and only occasionally connected from home. That world no longer exists. Today, employees work from everywhere. Applications run across SaaS platforms, public cloud, private cloud, and on-premises environments. Security teams are expected to provide seamless access while protecting against increasingly sophisticated attacks.