โŒ

Normal view

Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes

30 July 2026 at 14:49

London, UK, 30 July 2026 โ€“ New data from Heimdalโ€™s telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine. The same pattern has been confirmed across more than 40 client environments. MediaArena is a browser-modifier adware family that Microsoft has tracked since 2023. It is low-severity, and that is [โ€ฆ]

The post Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes appeared first on Heimdal Security Blog.

How Heimdal grew from a bold idea into a global cybersecurity platform

30 July 2026 at 10:32

Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a challenge. Could they create something that could identify vulnerabilities, intercept malicious activity and help protect machines before threats could take hold? That technology went on to compete at the Defcon CTF world [โ€ฆ]

The post How Heimdal grew from a bold idea into a global cybersecurity platform appeared first on Heimdal Security Blog.

MediaArena malvertising: why a quarantine isnโ€™t the end of the incident

30 July 2026 at 10:21

If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didnโ€™t complete until 29 seconds. By the time the alert fired, [โ€ฆ]

The post MediaArena malvertising: why a quarantine isnโ€™t the end of the incident appeared first on Heimdal Security Blog.

Tools Change. Teach People How to Keep Up

28 July 2026 at 16:51

โ€œMake everyone one percent better and it compounds across the team.โ€ Thatโ€™s the line Joe Head wrote about his own job and when I read it back to him, he didnโ€™t hesitate. โ€œThat is 100% the objective,โ€ he said. Joe runs AI adoption for an 80-person team as the only AI automation specialist in the [โ€ฆ]

The post Tools Change. Teach People How to Keep Up appeared first on Heimdal Security Blog.

The 4 best managed EDR service suppliers (and how to choose)

23 July 2026 at 12:25

There are several cybersecurity companies that offer managed EDR services in 2026. Hereโ€™s what actually separates them, and who each one suits. Most successful cyber attacks begin with a breached laptop, a smartphone or a server. Over the past 15 years, endpoint detection and response (EDR) has gone from niche to a mainstream security solution. [โ€ฆ]

The post The 4 best managed EDR service suppliers (and how to choose) appeared first on Heimdal Security Blog.

Top 4 Best SOC Platforms 2026 โ€“ Provider Comparison

22 July 2026 at 17:52

Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. There are many cybersecurity tools that an SOC can use, and there are many vendors selling comparable products. The [โ€ฆ]

The post Top 4 Best SOC Platforms 2026 โ€“ Provider Comparison appeared first on Heimdal Security Blog.

Received โ€” 17 July 2026 โญ Heimdal Security Blog

Top 6 Managed Detection and Response Providers

10 July 2026 at 14:57

There are several major managed detection and response (MDR) companies to choose from. Weโ€™ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a security team stretched too thin and drowning in alerts from dozens of tools. Whatever [โ€ฆ]

The post Top 6 Managed Detection and Response Providers appeared first on Heimdal Security Blog.

Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendorsย 

8 July 2026 at 11:19

Your client is no longer just buying your security advice. Theyโ€™re auditing whether you live by it.ย  That was a clear message from my exclusive interview withย Heather MacDonald Alford,ย an MSP finance specialist and owner ofย Counting Creators.ย  Heatherโ€™sย exactly the kind of customer MSPs should be paying attentionย to. Sheโ€™sย informed, commercially minded, and willing to challenge vendors to [โ€ฆ]

The post Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendorsย  appeared first on Heimdal Security Blog.

How to scale your patches without scaling your team (the patch wave)

3 July 2026 at 17:30

Most breaches donโ€™t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the first time in the 19-year history of Verizonโ€™s Data Breach Investigations Report, with 31% of breaches now [โ€ฆ]

The post How to scale your patches without scaling your team (the patch wave) appeared first on Heimdal Security Blog.

AI didnโ€™t break patching. It showed us patching was already broken.

3 July 2026 at 13:14

Claude Mythos, an AI model from Anthropic, has found 23,019 software vulnerabilities in the past month. Fewer than 1% of them have been patched. That gap is the story. Finding a vulnerability used to be the hard part, the thing that limited how fast software got fixed. AI just closed that gap to almost nothing. [โ€ฆ]

The post AI didnโ€™t break patching. It showed us patching was already broken. appeared first on Heimdal Security Blog.

Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes

1 July 2026 at 09:55

COPENHAGEN, Denmark, 1 July 2026 โ€“ Heimdal today announced the launch of MSP Onboarding Wizard, a new capability that helps managed service providers onboard Microsoft Cloud Solution Provider (CSP) customers inside the Heimdal platform faster and with less manual work. Built for MSPs managing multiple Microsoft tenants, MSP Onboarding Wizard reduces customer onboarding from around [โ€ฆ]

The post Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes appeared first on Heimdal Security Blog.

How Dynamic Defense shuts an attacker out without shutting down the business

26 June 2026 at 17:49

AI has handed hackers a resource advantage. Winning it back means spending your own resources far more precisely, and thatโ€™s the strategy we call Dynamic Defense. The principle is simple. Contain the threat just enough, for just long enough, until the risk is removed. This piece shows how that works as a five-stage loop that [โ€ฆ]

The post How Dynamic Defense shuts an attacker out without shutting down the business appeared first on Heimdal Security Blog.

Static security has run out of road. The case for Dynamic Defense

26 June 2026 at 12:10

AI has flipped the economics of cybersecurity in the attackerโ€™s favor. For most of the last decade, defenders held the cost advantage, buying down their risk with a stack of largely static controls. That advantage is gone, and winning it back is the central problem facing every security team in 2026. I think the answer [โ€ฆ]

The post Static security has run out of road. The case for Dynamic Defense appeared first on Heimdal Security Blog.

Breaking the MSP Echo Chamber: The Power of Community

24 June 2026 at 13:46

MSPs spend too much time talking to other MSPs and not enough time talking to the people theyโ€™re supposed to serve.ย  Thatโ€™s Paul Crokerโ€™s view of some of the channelโ€™s biggest growth problems. ย  While most industry events bring technology professionals together, they rarely put them in the same room as the business leaders making [โ€ฆ]

The post Breaking the MSP Echo Chamber: The Power of Community appeared first on Heimdal Security Blog.

How attackers built a RAT on a Windows machine using its own .NET compiler

22 June 2026 at 16:37

In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, [โ€ฆ]

The post How attackers built a RAT on a Windows machine using its own .NET compiler appeared first on Heimdal Security Blog.

Attacker enables RDP, creates admin, erases evidence in ten seconds

22 June 2026 at 10:28

At 06:34am on 2 June 2026, an attacker logged on to a customerโ€™s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.ย  The intrusion reached 34 endpoints and was over in under ten seconds.ย  Heimdal Extended Threat Protection (XTP) and Ransomware [โ€ฆ]

The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.

Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It

15 June 2026 at 14:52

London, UK, 16 June 2026 โ€“ Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The reportโ€™s headline finding is a divide inside the same organizations: the closer a person sits to the day-to-day running of AI, the less [โ€ฆ]

The post Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It appeared first on Heimdal Security Blog.

Received โ€” 18 June 2026 โญ Heimdal Security Blog

Your Next Insider Threat May Be an AI Coworker

12 June 2026 at 17:09

Heimdal sysadmin Alex Panait spent weeks testing Claude Cowork inside the company. His verdict was blunt. It felt like onboarding a junior employee with no manager, no scoped access, and no clear accountability when something goes wrong. Except this one can delete your SharePoint. That is the uncomfortable reality behind autonomous AI desktop assistants. They [โ€ฆ]

The post Your Next Insider Threat May Be an AI Coworker appeared first on Heimdal Security Blog.

The OSI Model and Its Two Missing Layers

12 June 2026 at 14:29

Cybersecurity failures now happen beyond the OSI stack. Faulty governance, the human factor, and AI tools create new attack surfaces. After seven years working across cybersecurity, cloud infrastructure, and Zero Trust architecture, Jayal Yadav explains how we got here and what organizations still get wrong. โ€œThe original seven layers of the OSI model still matter. [โ€ฆ]

The post The OSI Model and Its Two Missing Layers appeared first on Heimdal Security Blog.

Received โ€” 8 June 2026 โญ Heimdal Security Blog

Heimdalยฎ Marks Six Years of Consecutive ISAE 3000 SOC 2 Type II Certification

8 June 2026 at 13:29

COPENHAGEN, Denmark, June 8, 2026 โ€“ Heimdal has achieved ISAE 3000 SOC 2 Type II certification for the sixth consecutive year, reflecting the companyโ€™s continued focus on operational security, accountability, and data protection. The 2026 audit covered the period from 1 April 2025 to 31 March 2026 and examined Heimdalโ€™s controls across access management, data [โ€ฆ]

The post Heimdalยฎ Marks Six Years of Consecutive ISAE 3000 SOC 2 Type II Certification appeared first on Heimdal Security Blog.

โŒ