MSPs are maturing endpoint security with patching, vulnerability remediation, and antivirus protection. But one high-impact risk still slips through in many client environments: unmanaged peripheral devices. A single unauthorized USB drive can copy sensitive client data in minutes and introduce malware into otherwise protected systems. This is why we've launched Device Control in MSP Central—an MSP-ready solution capable of governing every device that touches your client endpoints.
Every payment flow your organization runs, from card authorization to ACH transfers to embedded lending to open banking consent, is now an API call. That’s good for velocity. It’s also why payment APIs sit at the top of the attack surface for financial services and enterprise SaaS platforms handling money movement.
Not every threat matters equally to every organization. A newly discovered APT or ransomware group targeting European automotive manufacturers is definitely worth paying attention to, especially if you’re in that sector. But if you’re a financial services firm in California, it’s probably not an immediate priority. You might look into it, track its activity, and assess whether it could become relevant.
CTEM sounds straightforward as a five-stage loop, but most programs stall quietly somewhere inside it. This post breaks down the five places CTEM projects actually break — bad scoping, unreconciled discovery tools, severity mistaken for risk, skipped validation, and unowned remediation — and argues that these aren’t five separate problems, but symptoms of running CTEM as disconnected efforts instead of one continuous workflow.
Protecting patient information has always been central to HIPAA. Today, however, healthcare organizations must secure that information across a much larger and more complicated technology environment. Electronic health records, cloud platforms, remote access, mobile devices, connected medical equipment, third-party vendors, and legacy systems can all create potential paths to electronic protected health information (ePHI).
Gogs is an open-source Git hosting platform like GitHub or GitLab. The application allows users to manage their own repositories and organizations. Under the hood, it relies heavily on the git CLI.
Employees are increasingly using AI tools, working across unsecured networks, and bypassing established security practices creating new risks that traditional security controls alone can’t address. Join WatchGuard’s Marc Laliberte, Director of Security Operations, on August 20 for an exclusive webinar exploring the findings from the 2026 Cybersecurity Hygiene Report.
Public benchmarks in AI provide important signals and allow for regression testing, directional validation of model updates, and public discussion of capabilities and limitations. But the more attention a benchmark receives, the stronger the incentive to optimize for it. Once a score becomes the goal, teams start benchmaxxing: optimizing for the benchmark rather than the capability it is meant to measure. This is a familiar problem in the AI space.
Security teams often evaluate ChatGPT by examining its outputs. The greater risk, however, lies in the information employees submit before the model generates a single response. As generative AI becomes a big part of daily business operations, prompts increasingly contain confidential customer data, proprietary source code, legal documents, and strategic plans.