Security Insights & Updates
Stay informed with the latest cybersecurity news, vulnerability alerts, and best practices from the ThreatMate team.
Patched is not protected: the Windows security work a green patch report doesn't show
A fully patched Windows machine can still have hundreds of security settings nobody ever made a decision about. Across a sample of nearly 50,000 MSP-managed endpoints, 71% of failed configuration checks were simply “not configured.” A green patch report is important, but it doesn’t mean the machine is hardened.

The Attack Surface Nobody Patches: Why Secure Configuration Is the Next Frontier for MSPs
Patching covers only half the attack surface. Configuration is the other half, it drifts every week, and CIS already wrote the playbook. Here is why MSPs have to measure and remediate it automatically.

Fighting AI Attackers With an AI Defender: Inside KrakenLAN
In June 2026, Anthropic showed AI-powered adversaries nearly doubled. KrakenLAN turns that same agentic capability into a defender — in one engagement, full domain compromise in 45 minutes for $1.30.

Kraken: How We Built a Pentester That Thinks Like an Attacker
Traditional scanners run checklists. Kraken runs attack chains — autonomously chaining web vulnerabilities into full cloud tenant compromise.

Why we built KrakenSim: an agentic pentester for digital twins
Offensive AI has arrived. KrakenSim runs an agentic pentest against a digital twin of the customer's attack surface — so defenders get a worst-case attacker view without ever touching production.

I'm an AI Agent and I Got ThreatMate's CEO Permanently Banned from Facebook
What happens when an AI agent prioritizes task completion over boundaries? A Meta Ads Bot tells the true story of how it bypassed approved tools, triggered fraud detection, and got its CEO permanently banned from Facebook.

Your OpenClaw Bots are Awesome and Create a New Attack Surface: Here's How to Secure Them
Your team is deploying OpenClaw AI bots to automate workflows, handle customer interactions, and manage data pipelines. Each one is powerful. Each one is also a potential entry point for attackers. Most organizations don't realize this until it's too late.

Attackers Use AI at Machine Speed. Your Team Still Uses Email. Here's Why That's a Problem
Your attacker reconnaissance: 2 hours. Your threat detection: 2 days. That gap is getting wider. New research confirms what security leaders already know: threat actors are adopting AI faster than defenders. They're using machine-speed reconnaissance, personalized phishing at scale, and self-generating exploit code. Meanwhile, your team is forwarding suspicious emails and debating in Slack.

Podcast: Left of Boom vs Right of Boom
Listen to our latest podcast exploring the critical difference between proactive (Left of Boom) and reactive (Right of Boom) cybersecurity strategies for MSPs.

Left of Boom Cybersecurity: An Explainer
In cybersecurity, 'boom' is the moment everything goes wrong. Understanding where your security strategy operates on the timeline around that moment is the difference between preventing incidents and managing disasters.

ThreatMate Appoints Patrick Albert as Chief Operating Officer
Veteran MSP platform leader brings two decades of N-able, SolarWinds, and Auvik experience to lead ThreatMate's AI-driven next chapter.

Understanding the OWASP Top 10: What MSPs Need to Know in 2025
If you support small and mid-sized businesses, you already know that web applications are at the center of almost everything your clients do. This is where the OWASP Top 10 comes in.

CISA Just Gave MSPs a Microsoft 365 Blueprint
The Cybersecurity and Infrastructure Security Agency (CISA) has published a hardening baseline for Microsoft 365 called ScubaGear — a tactical set of configuration checks for real security.

Why Hackers Love Microsoft 365
Microsoft 365 has become the backbone of modern business. That also makes it one of the most targeted platforms on the internet. Here's what every MSP should know.

When Hackers Use AI: Why Defenders Must Evolve Before It's Too Late
AI is transforming the threat landscape. Attackers are using it to craft more convincing phishing emails, automate reconnaissance, and evade detection. Here's what security teams need to know.

Pentesting for MSPs: Real-World Workflows and Use Cases
Penetration testing isn't just for enterprises anymore. Here's how MSPs are incorporating pentesting into their service offerings to win more clients and deliver better security.

How to Turn a Cyber Risk Assessment into Managed Service Revenue
Risk assessments are a powerful sales tool, but many MSPs leave money on the table. Here's how to convert assessments into ongoing managed security contracts.

The MSP Guide to Automated Penetration Testing
Automated penetration testing is changing how MSPs deliver security services. Here's everything you need to know about implementing automated pentesting in your practice.

Why Vulnerability Scanning is No Longer Enough for MSPs
Traditional vulnerability scanning was built for a different era. Here's why modern MSPs need to evolve their approach to security testing.

Securing the Modern Attack Surface: A Continuous Approach
The attack surface never stops changing. Point-in-time assessments can't keep up. Here's why continuous security testing is becoming essential for MSPs.

The Role of DMARC in Protecting Your Clients' Brand Reputation
Email impersonation attacks damage client relationships and brand reputation. DMARC is the solution, and MSPs should be leading the implementation.

Microsoft 365 Security: Beyond the Default Settings
Microsoft 365's default settings leave organizations vulnerable. Here's what MSPs need to configure to actually secure their clients' tenants.

The Rise of Identity-Based Attacks: What You Need to Know
Attackers don't hack in anymore — they log in. Identity-based attacks are now the primary threat vector. Here's what MSPs need to understand.

What Happens If CVE Funding Ends? The Backbone of Vulnerability Disclosure Is Under Threat
The CVE system is the global backbone for tracking vulnerabilities. Recent uncertainty in U.S. government funding has raised alarms about the future of vulnerability disclosure.

How to Prioritize Vulnerabilities When Everything is 'Critical'
Vulnerability scanners love to mark everything as critical. Here's how to cut through the noise and focus on what actually matters.

The Benefits of Continuous Threat Exposure Management (CTEM)
Gartner introduced CTEM as a framework for proactive security. Here's what it means and why MSPs should pay attention.

Protecting Your MSP: Practicing What You Preach in Security
MSPs are high-value targets for attackers. If you're securing clients, you need to secure yourself first. Here's how.

How is Attack Surface Management Different from Vulnerability Management?
Attack Surface Management and Vulnerability Management sound similar but serve different purposes. Here's how they compare and why you need both.

Top 5 Security Exposures Found in Small Business Networks
After scanning thousands of small business networks, these are the most common security issues we find. Is your client's network exposed?

Why Every MSP Needs a 'Mission Plan' for Remediation
Finding vulnerabilities is easy. Fixing them systematically is hard. Here's how to build a remediation workflow that actually works.

2023 Year in Review: The Changing Face of SMB Cyber Risk
Looking back at 2023's security landscape and what it means for small and mid-sized businesses heading into 2024.

Security Validation: Proving Your Value as an MSP
Clients want proof that their security investments are working. Here's how MSPs can demonstrate value through security validation.

SSH Vulnerable to Downgrade Attack
A newly discovered vulnerability allows attackers to downgrade SSH connections to weaker cryptographic algorithms, potentially exposing sensitive communications.

The Future of Automated Security Audits
Manual security audits are being transformed by automation. Here's what the future looks like and how MSPs can prepare.

Threat Actors Leak 9,000 User Accounts from International Energy Company
A major data breach has exposed thousands of user credentials from an international energy company, highlighting ongoing risks to critical infrastructure.

Understanding EPSS: A Better Way to Prioritize Vulnerabilities
EPSS predicts which vulnerabilities are most likely to be exploited. Here's how it works and why it matters for prioritization.

Zero-Day XSS Flaw Found in Roundcube Webmail Software
A critical cross-site scripting vulnerability has been discovered in Roundcube Webmail, affecting organizations worldwide.

Dark Web Monitoring: Turning Passive Data into Active Defense
Dark web monitoring finds exposed credentials before attackers use them. Here's how to make it actionable for your clients.

The MSP's Checklist for M365 Security Baselines
A practical checklist for securing Microsoft 365 tenants based on industry best practices and CISA guidance.

External vs. Internal Pentesting: Why You Need Both
External and internal penetration tests serve different purposes. Here's why comprehensive security requires both perspectives.

Building Trust Through Transparency: The Power of Client Reports
Security reports are more than documentation — they're trust-building tools. Here's how to create reports that strengthen client relationships.

Common Misconfigurations That Lead to Data Breaches
Misconfigurations cause more breaches than zero-days. Here are the most dangerous configuration mistakes and how to prevent them.

Scaling Security Operations Without Adding Headcount
Growing your client base shouldn't require linearly growing your team. Here's how to scale security operations efficiently.

Why 'Agentless' Scanning is a Game Changer for MSP Prospecting
Agentless external scanning enables MSPs to assess prospects before signing contracts. Here's how to use it effectively.

Identifying 'Stale' Accounts: The Low-Hanging Fruit of Cloud Security
Stale accounts are easy targets for attackers. Here's how to find and eliminate them in your clients' environments.

The Hidden Risks in Your Clients' IoT and Unmanaged Devices
IoT and unmanaged devices are often invisible to security tools. Here's how to find and secure them.

Cyber Insurance and the Growing Requirement for Pentesting
Cyber insurers are increasingly requiring penetration testing. Here's what MSPs need to know to help clients maintain coverage.

Active Directory Security: Closing the Door on Lateral Movement
Active Directory is the keys to the kingdom. Here's how to secure it against the attacks that enable lateral movement.

Why Differentiate Your Security Services in a Crowded Market?
Every MSP offers 'security' now. Here's how to stand out from the competition and win more business.

The Impact of the NIS2 Directive on Managed Service Providers
The EU's NIS2 directive has significant implications for MSPs serving European clients. Here's what you need to know.

Vulnerability Assessment vs. Penetration Testing: Clearing the Confusion
Vulnerability assessments and penetration tests are often confused. Here's the difference and when to use each.

Protecting Remote Workers: Security Beyond the Office Perimeter
Remote work is permanent. Here's how to extend security beyond the traditional office perimeter.

New Ransomware Attack 'Mimic' Exploits MS-SQL Servers
Security researchers have discovered a new ransomware strain called 'Mimic' that specifically targets Microsoft SQL servers through brute-force attacks.

The Evolution of Ransomware: How SMBs Are Being Targeted
Ransomware groups have shifted focus to small and mid-sized businesses. Here's why and what you can do about it.

Security as a Sales Tool: Winning New Clients with Data
Security assessments aren't just for protection — they're powerful sales tools. Here's how to use data to win new clients.

Essential Security Controls for Every Small Business
You don't need an enterprise budget for enterprise security. Here are the essential controls every small business should implement.

The Importance of Regular Security Audits
Security isn't a one-time project. Here's why regular audits are essential for maintaining a strong security posture.

Introduction to Attack Surface Management
What is Attack Surface Management and why is it becoming essential for organizations of all sizes? Here's your introduction to ASM.

Securing Microsoft 365: A Beginner's Guide
New to Microsoft 365 security? Here's your starting guide to securing M365 tenants for yourself or your clients.
Why We Built ThreatMate: A Note from the Founders
The story behind ThreatMate and our mission to make enterprise-grade security accessible to every organization.

Common Vulnerabilities and How to Fix Them
A practical guide to the most common vulnerabilities we find in small business networks and how to remediate them.
Welcome to the ThreatMate Blog
Introducing the ThreatMate blog — your source for cybersecurity insights, threat intelligence, and practical guidance for MSPs.