Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Beyond the Inbox: How BEC Leads to SSO Abuse

For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim's mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money or sensitive information. Today, we're seeing something different at LevelBlue. Across multiple recent investigations, we've observed attackers treating a compromised mailbox as just the first step.

Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk

SpiderLabs’ technical review of the July attacks examines the affected technologies, observed activity, and broader threat landscape. The next question is practical: what can small utilities realistically do about it? At many small water and wastewater facilities, there is often no dedicated security team to understaff. A licensed operator may be responsible for sampling, maintenance, compliance, and after-hours callouts, perhaps with limited support from municipal IT.

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action

When people hear the word cybersecurity, they often picture analysts racing to stop an attack in real time. Those roles are absolutely critical, but a lot of effective security happens long before an alert ever appears. As Director of Operational Intelligence (OpsIntel) at LevelBlue, my job isn't to respond to every incident myself.