Reading view

The risk awareness radar. A superpower every MSP needs to train

Most of the cyber incidents landing on our desks these days start with someone believing a lie. It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make people hand over exactly what the attacker needs. Last week I talked […]

The post The risk awareness radar. A superpower every MSP needs to train appeared first on Heimdal Security Blog.

  •  

Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes

London, UK, 30 July 2026 – New data from Heimdal’s telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine. The same pattern has been confirmed across more than 40 client environments. MediaArena is a browser-modifier adware family that Microsoft has tracked since 2023. It is low-severity, and that is […]

The post Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes appeared first on Heimdal Security Blog.

  •  

How Heimdal grew from a bold idea into a global cybersecurity platform

Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a challenge. Could they create something that could identify vulnerabilities, intercept malicious activity and help protect machines before threats could take hold? That technology went on to compete at the Defcon CTF world […]

The post How Heimdal grew from a bold idea into a global cybersecurity platform appeared first on Heimdal Security Blog.

  •  

MediaArena malvertising: why a quarantine isn’t the end of the incident

If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn’t complete until 29 seconds. By the time the alert fired, […]

The post MediaArena malvertising: why a quarantine isn’t the end of the incident appeared first on Heimdal Security Blog.

  •  

Tools Change. Teach People How to Keep Up

“Make everyone one percent better and it compounds across the team.” That’s the line Joe Head wrote about his own job and when I read it back to him, he didn’t hesitate. “That is 100% the objective,” he said. Joe runs AI adoption for an 80-person team as the only AI automation specialist in the […]

The post Tools Change. Teach People How to Keep Up appeared first on Heimdal Security Blog.

  •  

The 4 best managed EDR service suppliers (and how to choose)

There are several cybersecurity companies that offer managed EDR services in 2026. Here’s what actually separates them, and who each one suits. Most successful cyber attacks begin with a breached laptop, a smartphone or a server. Over the past 15 years, endpoint detection and response (EDR) has gone from niche to a mainstream security solution. […]

The post The 4 best managed EDR service suppliers (and how to choose) appeared first on Heimdal Security Blog.

  •  

Top 4 Best SOC Platforms 2026 – Provider Comparison

Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. There are many cybersecurity tools that an SOC can use, and there are many vendors selling comparable products. The […]

The post Top 4 Best SOC Platforms 2026 – Provider Comparison appeared first on Heimdal Security Blog.

  •  

Top 6 Managed Detection and Response Providers

There are several major managed detection and response (MDR) companies to choose from. We’ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a security team stretched too thin and drowning in alerts from dozens of tools. Whatever […]

The post Top 6 Managed Detection and Response Providers appeared first on Heimdal Security Blog.

  •  

Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors 

Your client is no longer just buying your security advice. They’re auditing whether you live by it.  That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators.  Heather’s exactly the kind of customer MSPs should be paying attention to. She’s informed, commercially minded, and willing to challenge vendors to […]

The post Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors  appeared first on Heimdal Security Blog.

  •  

How to scale your patches without scaling your team (the patch wave)

Most breaches don’t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the first time in the 19-year history of Verizon’s Data Breach Investigations Report, with 31% of breaches now […]

The post How to scale your patches without scaling your team (the patch wave) appeared first on Heimdal Security Blog.

  •  

AI didn’t break patching. It showed us patching was already broken.

Claude Mythos, an AI model from Anthropic, has found 23,019 software vulnerabilities in the past month. Fewer than 1% of them have been patched. That gap is the story. Finding a vulnerability used to be the hard part, the thing that limited how fast software got fixed. AI just closed that gap to almost nothing. […]

The post AI didn’t break patching. It showed us patching was already broken. appeared first on Heimdal Security Blog.

  •  

Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes

COPENHAGEN, Denmark, 1 July 2026 – Heimdal today announced the launch of MSP Onboarding Wizard, a new capability that helps managed service providers onboard Microsoft Cloud Solution Provider (CSP) customers inside the Heimdal platform faster and with less manual work. Built for MSPs managing multiple Microsoft tenants, MSP Onboarding Wizard reduces customer onboarding from around […]

The post Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes appeared first on Heimdal Security Blog.

  •  

How Dynamic Defense shuts an attacker out without shutting down the business

AI has handed hackers a resource advantage. Winning it back means spending your own resources far more precisely, and that’s the strategy we call Dynamic Defense. The principle is simple. Contain the threat just enough, for just long enough, until the risk is removed. This piece shows how that works as a five-stage loop that […]

The post How Dynamic Defense shuts an attacker out without shutting down the business appeared first on Heimdal Security Blog.

  •  

Static security has run out of road. The case for Dynamic Defense

AI has flipped the economics of cybersecurity in the attacker’s favor. For most of the last decade, defenders held the cost advantage, buying down their risk with a stack of largely static controls. That advantage is gone, and winning it back is the central problem facing every security team in 2026. I think the answer […]

The post Static security has run out of road. The case for Dynamic Defense appeared first on Heimdal Security Blog.

  •  

Breaking the MSP Echo Chamber: The Power of Community

MSPs spend too much time talking to other MSPs and not enough time talking to the people they’re supposed to serve.  That’s Paul Croker’s view of some of the channel’s biggest growth problems.   While most industry events bring technology professionals together, they rarely put them in the same room as the business leaders making […]

The post Breaking the MSP Echo Chamber: The Power of Community appeared first on Heimdal Security Blog.

  •  

How attackers built a RAT on a Windows machine using its own .NET compiler

In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, […]

The post How attackers built a RAT on a Windows machine using its own .NET compiler appeared first on Heimdal Security Blog.

  •  

Attacker enables RDP, creates admin, erases evidence in ten seconds

At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.  The intrusion reached 34 endpoints and was over in under ten seconds.  Heimdal Extended Threat Protection (XTP) and Ransomware […]

The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.

  •  

Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It

London, UK, 16 June 2026 – Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report’s headline finding is a divide inside the same organizations: the closer a person sits to the day-to-day running of AI, the less […]

The post Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It appeared first on Heimdal Security Blog.

  •  

Your Next Insider Threat May Be an AI Coworker

Heimdal sysadmin Alex Panait spent weeks testing Claude Cowork inside the company. His verdict was blunt. It felt like onboarding a junior employee with no manager, no scoped access, and no clear accountability when something goes wrong. Except this one can delete your SharePoint. That is the uncomfortable reality behind autonomous AI desktop assistants. They […]

The post Your Next Insider Threat May Be an AI Coworker appeared first on Heimdal Security Blog.

  •  

The OSI Model and Its Two Missing Layers

Cybersecurity failures now happen beyond the OSI stack. Faulty governance, the human factor, and AI tools create new attack surfaces. After seven years working across cybersecurity, cloud infrastructure, and Zero Trust architecture, Jayal Yadav explains how we got here and what organizations still get wrong. “The original seven layers of the OSI model still matter. […]

The post The OSI Model and Its Two Missing Layers appeared first on Heimdal Security Blog.

  •  
❌