In this episode of MSP Unscripted, Nawaz Ali sits down with Eddie Wlazlowski to discuss the evolution of Microsoft 365 Cyber Resilience. They explore why managing Microsoft 365 is no longer enough, what’s driving the shift toward cyber resilience, the gaps many organizations still have in protecting Microsoft 365, and how MSPs can evolve their offerings to deliver greater value. The conversation concludes with practical advice for MSPs looking to build differentiated, resilient Microsoft 365 services.
Growing engineering organizations all hit the same wall. More teams shipping software means more repositories, more permission requests, more onboarding cycles, and eventually one platform admin fielding every change. The platform that was supposed to accelerate delivery has now become the bottleneck. JFrog Projects is built to break that pattern.
Attackers dumped everything they harvested from LiteLLM builds during a 40-minute window in March. Here is what is inside and what it says about where secrets live.
BSidesLV 2026 presenters showed how attackers are increasingly exploiting valid trust relationships instead of breaking through the front door, and what we need to do about it.
Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.
Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital. “ are not only sending malicious links or dropping malware,” the report says. “They are abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority.
You cannot protect what you do not know exists. That statement has been true throughout the history of cybersecurity, but it has become even more important as organizations adopt new technologies and employees gain access to powerful AI tools. While many organizations focus on defending against external threats, they often overlook a growing problem much closer to home: devices, applications, and services operating within their environment that nobody knows about.
Most companies designed their resource permissions with a human user in mind. A senior engineer may be able to deploy to production, query a sensitive database, or revoke another user's access. Those privileges come with risk, but that risk has traditionally been bounded by two assumptions: the engineer will use human judgment, and the engineer can only act at human speed.