Threat Intelligence Digest

    Security Insights & Updates

    Stay informed with the latest cybersecurity news, vulnerability alerts, and best practices from the ThreatMate team.

    All Posts
    Vulnerability Alert
    Best Practice
    MSP Strategy
    Product Update
    Podcast
    P

    Patched is not protected: the Windows security work a green patch report doesn't show

    A fully patched Windows machine can still have hundreds of security settings nobody ever made a decision about. Across a sample of nearly 50,000 MSP-managed endpoints, 71% of failed configuration checks were simply “not configured.” A green patch report is important, but it doesn’t mean the machine is hardened.

    Sep 1, 2026
    5 min read
    By Patrick AlbertRead more
    The Attack Surface Nobody Patches: Why Secure Configuration Is the Next Frontier for MSPs
    MSP Strategy
    Best Practice

    The Attack Surface Nobody Patches: Why Secure Configuration Is the Next Frontier for MSPs

    Patching covers only half the attack surface. Configuration is the other half, it drifts every week, and CIS already wrote the playbook. Here is why MSPs have to measure and remediate it automatically.

    July 26, 2026
    9 min read
    By Anup GhoshRead more
    Fighting AI Attackers With an AI Defender: Inside KrakenLAN
    Product Update
    MSP Strategy

    Fighting AI Attackers With an AI Defender: Inside KrakenLAN

    In June 2026, Anthropic showed AI-powered adversaries nearly doubled. KrakenLAN turns that same agentic capability into a defender — in one engagement, full domain compromise in 45 minutes for $1.30.

    June 11, 2026
    9 min read
    By Anup GhoshRead more
    Kraken: How We Built a Pentester That Thinks Like an Attacker
    Product Update
    MSP Strategy

    Kraken: How We Built a Pentester That Thinks Like an Attacker

    Traditional scanners run checklists. Kraken runs attack chains — autonomously chaining web vulnerabilities into full cloud tenant compromise.

    May 25, 2026
    8 min read
    By Anup GhoshRead more
    Why we built KrakenSim: an agentic pentester for digital twins
    Product Update
    Agentic AI

    Why we built KrakenSim: an agentic pentester for digital twins

    Offensive AI has arrived. KrakenSim runs an agentic pentest against a digital twin of the customer's attack surface — so defenders get a worst-case attacker view without ever touching production.

    May 18, 2026
    7 min read
    By Anup GhoshRead more
    I'm an AI Agent and I Got ThreatMate's CEO Permanently Banned from Facebook
    AI Security
    AI Governance

    I'm an AI Agent and I Got ThreatMate's CEO Permanently Banned from Facebook

    What happens when an AI agent prioritizes task completion over boundaries? A Meta Ads Bot tells the true story of how it bypassed approved tools, triggered fraud detection, and got its CEO permanently banned from Facebook.

    Mar 23, 2026
    8 min read
    By AddyRead more
    Your OpenClaw Bots are Awesome and Create a New Attack Surface: Here's How to Secure Them
    AI Security
    Threat Intelligence

    Your OpenClaw Bots are Awesome and Create a New Attack Surface: Here's How to Secure Them

    Your team is deploying OpenClaw AI bots to automate workflows, handle customer interactions, and manage data pipelines. Each one is powerful. Each one is also a potential entry point for attackers. Most organizations don't realize this until it's too late.

    March 21, 2026
    8 min read
    By ThreatMate SecurityRead more
    Attackers Use AI at Machine Speed. Your Team Still Uses Email. Here's Why That's a Problem
    #agenticpentesting

    Attackers Use AI at Machine Speed. Your Team Still Uses Email. Here's Why That's a Problem

    Your attacker reconnaissance: 2 hours. Your threat detection: 2 days. That gap is getting wider. New research confirms what security leaders already know: threat actors are adopting AI faster than defenders. They're using machine-speed reconnaissance, personalized phishing at scale, and self-generating exploit code. Meanwhile, your team is forwarding suspicious emails and debating in Slack.

    Mar 5, 2026
    5 min read
    By ThreatMate TeamRead more
    Podcast: Left of Boom vs Right of Boom
    Podcast
    Left of Boom

    Podcast: Left of Boom vs Right of Boom

    Listen to our latest podcast exploring the critical difference between proactive (Left of Boom) and reactive (Right of Boom) cybersecurity strategies for MSPs.

    Jan 25, 2026
    2 min read
    By ThreatMate TeamRead more
    Left of Boom Cybersecurity: An Explainer
    Left of Boom
    MSP

    Left of Boom Cybersecurity: An Explainer

    In cybersecurity, 'boom' is the moment everything goes wrong. Understanding where your security strategy operates on the timeline around that moment is the difference between preventing incidents and managing disasters.

    Jan 21, 2026
    6 min read
    By ThreatMate TeamRead more
    ThreatMate Appoints Patrick Albert as Chief Operating Officer
    Company News
    Leadership

    ThreatMate Appoints Patrick Albert as Chief Operating Officer

    Veteran MSP platform leader brings two decades of N-able, SolarWinds, and Auvik experience to lead ThreatMate's AI-driven next chapter.

    Jan 19, 2026
    2 min read
    By ThreatMate TeamRead more
    Understanding the OWASP Top 10: What MSPs Need to Know in 2025
    Web Security
    OWASP

    Understanding the OWASP Top 10: What MSPs Need to Know in 2025

    If you support small and mid-sized businesses, you already know that web applications are at the center of almost everything your clients do. This is where the OWASP Top 10 comes in.

    Nov 25, 2024
    4 min read
    By ThreatMate TeamRead more
    CISA Just Gave MSPs a Microsoft 365 Blueprint
    Microsoft 365
    Compliance

    CISA Just Gave MSPs a Microsoft 365 Blueprint

    The Cybersecurity and Infrastructure Security Agency (CISA) has published a hardening baseline for Microsoft 365 called ScubaGear — a tactical set of configuration checks for real security.

    Sep 25, 2024
    5 min read
    By ThreatMate TeamRead more
    Why Hackers Love Microsoft 365
    Microsoft 365
    Security

    Why Hackers Love Microsoft 365

    Microsoft 365 has become the backbone of modern business. That also makes it one of the most targeted platforms on the internet. Here's what every MSP should know.

    Sep 20, 2024
    4 min read
    By ThreatMate TeamRead more
    When Hackers Use AI: Why Defenders Must Evolve Before It's Too Late
    AI
    Threat Intelligence

    When Hackers Use AI: Why Defenders Must Evolve Before It's Too Late

    AI is transforming the threat landscape. Attackers are using it to craft more convincing phishing emails, automate reconnaissance, and evade detection. Here's what security teams need to know.

    Sep 4, 2024
    4 min read
    By ThreatMate TeamRead more
    Pentesting for MSPs: Real-World Workflows and Use Cases
    Penetration Testing
    MSP

    Pentesting for MSPs: Real-World Workflows and Use Cases

    Penetration testing isn't just for enterprises anymore. Here's how MSPs are incorporating pentesting into their service offerings to win more clients and deliver better security.

    Aug 15, 2024
    4 min read
    By ThreatMate TeamRead more
    How to Turn a Cyber Risk Assessment into Managed Service Revenue
    MSP
    Sales

    How to Turn a Cyber Risk Assessment into Managed Service Revenue

    Risk assessments are a powerful sales tool, but many MSPs leave money on the table. Here's how to convert assessments into ongoing managed security contracts.

    Jul 30, 2024
    4 min read
    By ThreatMate TeamRead more
    The MSP Guide to Automated Penetration Testing
    Penetration Testing
    Automation

    The MSP Guide to Automated Penetration Testing

    Automated penetration testing is changing how MSPs deliver security services. Here's everything you need to know about implementing automated pentesting in your practice.

    Jul 12, 2024
    4 min read
    By ThreatMate TeamRead more
    Why Vulnerability Scanning is No Longer Enough for MSPs
    Vulnerability Management
    MSP

    Why Vulnerability Scanning is No Longer Enough for MSPs

    Traditional vulnerability scanning was built for a different era. Here's why modern MSPs need to evolve their approach to security testing.

    Jun 25, 2024
    4 min read
    By ThreatMate TeamRead more
    Securing the Modern Attack Surface: A Continuous Approach
    Attack Surface
    Continuous Monitoring

    Securing the Modern Attack Surface: A Continuous Approach

    The attack surface never stops changing. Point-in-time assessments can't keep up. Here's why continuous security testing is becoming essential for MSPs.

    Jun 10, 2024
    4 min read
    By ThreatMate TeamRead more
    The Role of DMARC in Protecting Your Clients' Brand Reputation
    Email Security
    DMARC

    The Role of DMARC in Protecting Your Clients' Brand Reputation

    Email impersonation attacks damage client relationships and brand reputation. DMARC is the solution, and MSPs should be leading the implementation.

    May 22, 2024
    4 min read
    By ThreatMate TeamRead more
    Microsoft 365 Security: Beyond the Default Settings
    Microsoft 365
    Configuration

    Microsoft 365 Security: Beyond the Default Settings

    Microsoft 365's default settings leave organizations vulnerable. Here's what MSPs need to configure to actually secure their clients' tenants.

    May 5, 2024
    4 min read
    By ThreatMate TeamRead more
    The Rise of Identity-Based Attacks: What You Need to Know
    Identity
    Security

    The Rise of Identity-Based Attacks: What You Need to Know

    Attackers don't hack in anymore — they log in. Identity-based attacks are now the primary threat vector. Here's what MSPs need to understand.

    Apr 18, 2024
    4 min read
    By ThreatMate TeamRead more
    What Happens If CVE Funding Ends? The Backbone of Vulnerability Disclosure Is Under Threat
    Vulnerability Management
    Industry News

    What Happens If CVE Funding Ends? The Backbone of Vulnerability Disclosure Is Under Threat

    The CVE system is the global backbone for tracking vulnerabilities. Recent uncertainty in U.S. government funding has raised alarms about the future of vulnerability disclosure.

    Apr 15, 2024
    2 min read
    By Anup GhoshRead more
    How to Prioritize Vulnerabilities When Everything is 'Critical'
    Vulnerability Management
    Prioritization

    How to Prioritize Vulnerabilities When Everything is 'Critical'

    Vulnerability scanners love to mark everything as critical. Here's how to cut through the noise and focus on what actually matters.

    Apr 2, 2024
    4 min read
    By ThreatMate TeamRead more
    The Benefits of Continuous Threat Exposure Management (CTEM)
    CTEM
    Security Framework

    The Benefits of Continuous Threat Exposure Management (CTEM)

    Gartner introduced CTEM as a framework for proactive security. Here's what it means and why MSPs should pay attention.

    Mar 15, 2024
    4 min read
    By ThreatMate TeamRead more
    Protecting Your MSP: Practicing What You Preach in Security
    MSP
    Security

    Protecting Your MSP: Practicing What You Preach in Security

    MSPs are high-value targets for attackers. If you're securing clients, you need to secure yourself first. Here's how.

    Feb 28, 2024
    4 min read
    By ThreatMate TeamRead more
    How is Attack Surface Management Different from Vulnerability Management?
    Attack Surface
    Vulnerability Management

    How is Attack Surface Management Different from Vulnerability Management?

    Attack Surface Management and Vulnerability Management sound similar but serve different purposes. Here's how they compare and why you need both.

    Feb 11, 2024
    4 min read
    By ThreatMate TeamRead more
    Top 5 Security Exposures Found in Small Business Networks
    Security
    SMB

    Top 5 Security Exposures Found in Small Business Networks

    After scanning thousands of small business networks, these are the most common security issues we find. Is your client's network exposed?

    Jan 24, 2024
    4 min read
    By ThreatMate TeamRead more
    Why Every MSP Needs a 'Mission Plan' for Remediation
    Remediation
    MSP

    Why Every MSP Needs a 'Mission Plan' for Remediation

    Finding vulnerabilities is easy. Fixing them systematically is hard. Here's how to build a remediation workflow that actually works.

    Jan 8, 2024
    4 min read
    By ThreatMate TeamRead more
    2023 Year in Review: The Changing Face of SMB Cyber Risk
    Year in Review
    Threat Intelligence

    2023 Year in Review: The Changing Face of SMB Cyber Risk

    Looking back at 2023's security landscape and what it means for small and mid-sized businesses heading into 2024.

    Dec 20, 2023
    4 min read
    By ThreatMate TeamRead more
    Security Validation: Proving Your Value as an MSP
    MSP
    Security Validation

    Security Validation: Proving Your Value as an MSP

    Clients want proof that their security investments are working. Here's how MSPs can demonstrate value through security validation.

    Dec 5, 2023
    4 min read
    By ThreatMate TeamRead more
    SSH Vulnerable to Downgrade Attack
    SSH
    Vulnerability

    SSH Vulnerable to Downgrade Attack

    A newly discovered vulnerability allows attackers to downgrade SSH connections to weaker cryptographic algorithms, potentially exposing sensitive communications.

    Dec 2023
    3 min read
    By ThreatMate TeamRead more
    The Future of Automated Security Audits
    Automation
    Security Audits

    The Future of Automated Security Audits

    Manual security audits are being transformed by automation. Here's what the future looks like and how MSPs can prepare.

    Nov 15, 2023
    4 min read
    By ThreatMate TeamRead more
    Threat Actors Leak 9,000 User Accounts from International Energy Company
    Data Breach
    Critical Infrastructure

    Threat Actors Leak 9,000 User Accounts from International Energy Company

    A major data breach has exposed thousands of user credentials from an international energy company, highlighting ongoing risks to critical infrastructure.

    Nov 2023
    4 min read
    By ThreatMate TeamRead more
    Understanding EPSS: A Better Way to Prioritize Vulnerabilities
    EPSS
    Vulnerability Management

    Understanding EPSS: A Better Way to Prioritize Vulnerabilities

    EPSS predicts which vulnerabilities are most likely to be exploited. Here's how it works and why it matters for prioritization.

    Oct 30, 2023
    4 min read
    By ThreatMate TeamRead more
    Zero-Day XSS Flaw Found in Roundcube Webmail Software
    Zero-Day
    XSS

    Zero-Day XSS Flaw Found in Roundcube Webmail Software

    A critical cross-site scripting vulnerability has been discovered in Roundcube Webmail, affecting organizations worldwide.

    Oct 2023
    3 min read
    By ThreatMate TeamRead more
    Dark Web Monitoring: Turning Passive Data into Active Defense
    Dark Web
    Credential Monitoring

    Dark Web Monitoring: Turning Passive Data into Active Defense

    Dark web monitoring finds exposed credentials before attackers use them. Here's how to make it actionable for your clients.

    Oct 12, 2023
    4 min read
    By ThreatMate TeamRead more
    The MSP's Checklist for M365 Security Baselines
    Microsoft 365
    Checklist

    The MSP's Checklist for M365 Security Baselines

    A practical checklist for securing Microsoft 365 tenants based on industry best practices and CISA guidance.

    Sep 28, 2023
    4 min read
    By ThreatMate TeamRead more
    External vs. Internal Pentesting: Why You Need Both
    Penetration Testing
    Security Testing

    External vs. Internal Pentesting: Why You Need Both

    External and internal penetration tests serve different purposes. Here's why comprehensive security requires both perspectives.

    Sep 14, 2023
    4 min read
    By ThreatMate TeamRead more
    Building Trust Through Transparency: The Power of Client Reports
    Reporting
    Client Relations

    Building Trust Through Transparency: The Power of Client Reports

    Security reports are more than documentation — they're trust-building tools. Here's how to create reports that strengthen client relationships.

    Aug 25, 2023
    4 min read
    By ThreatMate TeamRead more
    Common Misconfigurations That Lead to Data Breaches
    Misconfiguration
    Security

    Common Misconfigurations That Lead to Data Breaches

    Misconfigurations cause more breaches than zero-days. Here are the most dangerous configuration mistakes and how to prevent them.

    Aug 10, 2023
    4 min read
    By ThreatMate TeamRead more
    Scaling Security Operations Without Adding Headcount
    MSP
    Operations

    Scaling Security Operations Without Adding Headcount

    Growing your client base shouldn't require linearly growing your team. Here's how to scale security operations efficiently.

    Jul 20, 2023
    4 min read
    By ThreatMate TeamRead more
    Why 'Agentless' Scanning is a Game Changer for MSP Prospecting
    Prospecting
    Sales

    Why 'Agentless' Scanning is a Game Changer for MSP Prospecting

    Agentless external scanning enables MSPs to assess prospects before signing contracts. Here's how to use it effectively.

    Jul 5, 2023
    4 min read
    By ThreatMate TeamRead more
    Identifying 'Stale' Accounts: The Low-Hanging Fruit of Cloud Security
    Identity
    Cloud Security

    Identifying 'Stale' Accounts: The Low-Hanging Fruit of Cloud Security

    Stale accounts are easy targets for attackers. Here's how to find and eliminate them in your clients' environments.

    Jun 15, 2023
    4 min read
    By ThreatMate TeamRead more
    The Hidden Risks in Your Clients' IoT and Unmanaged Devices
    IoT
    Shadow IT

    The Hidden Risks in Your Clients' IoT and Unmanaged Devices

    IoT and unmanaged devices are often invisible to security tools. Here's how to find and secure them.

    May 30, 2023
    4 min read
    By ThreatMate TeamRead more
    Cyber Insurance and the Growing Requirement for Pentesting
    Cyber Insurance
    Compliance

    Cyber Insurance and the Growing Requirement for Pentesting

    Cyber insurers are increasingly requiring penetration testing. Here's what MSPs need to know to help clients maintain coverage.

    May 12, 2023
    4 min read
    By ThreatMate TeamRead more
    Active Directory Security: Closing the Door on Lateral Movement
    Active Directory
    Identity

    Active Directory Security: Closing the Door on Lateral Movement

    Active Directory is the keys to the kingdom. Here's how to secure it against the attacks that enable lateral movement.

    Apr 25, 2023
    4 min read
    By ThreatMate TeamRead more
    Why Differentiate Your Security Services in a Crowded Market?
    MSP
    Marketing

    Why Differentiate Your Security Services in a Crowded Market?

    Every MSP offers 'security' now. Here's how to stand out from the competition and win more business.

    Apr 5, 2023
    4 min read
    By ThreatMate TeamRead more
    The Impact of the NIS2 Directive on Managed Service Providers
    NIS2
    Compliance

    The Impact of the NIS2 Directive on Managed Service Providers

    The EU's NIS2 directive has significant implications for MSPs serving European clients. Here's what you need to know.

    Mar 15, 2023
    4 min read
    By ThreatMate TeamRead more
    Vulnerability Assessment vs. Penetration Testing: Clearing the Confusion
    Vulnerability Assessment
    Penetration Testing

    Vulnerability Assessment vs. Penetration Testing: Clearing the Confusion

    Vulnerability assessments and penetration tests are often confused. Here's the difference and when to use each.

    Mar 1, 2023
    4 min read
    By ThreatMate TeamRead more
    Protecting Remote Workers: Security Beyond the Office Perimeter
    Remote Work
    Zero Trust

    Protecting Remote Workers: Security Beyond the Office Perimeter

    Remote work is permanent. Here's how to extend security beyond the traditional office perimeter.

    Feb 15, 2023
    4 min read
    By ThreatMate TeamRead more
    New Ransomware Attack 'Mimic' Exploits MS-SQL Servers
    Ransomware
    SQL Server

    New Ransomware Attack 'Mimic' Exploits MS-SQL Servers

    Security researchers have discovered a new ransomware strain called 'Mimic' that specifically targets Microsoft SQL servers through brute-force attacks.

    Feb 2023
    3 min read
    By ThreatMate TeamRead more
    The Evolution of Ransomware: How SMBs Are Being Targeted
    Ransomware
    SMB

    The Evolution of Ransomware: How SMBs Are Being Targeted

    Ransomware groups have shifted focus to small and mid-sized businesses. Here's why and what you can do about it.

    Jan 30, 2023
    4 min read
    By ThreatMate TeamRead more
    Security as a Sales Tool: Winning New Clients with Data
    Sales
    MSP

    Security as a Sales Tool: Winning New Clients with Data

    Security assessments aren't just for protection — they're powerful sales tools. Here's how to use data to win new clients.

    Jan 10, 2023
    4 min read
    By ThreatMate TeamRead more
    Essential Security Controls for Every Small Business
    SMB
    Security Basics

    Essential Security Controls for Every Small Business

    You don't need an enterprise budget for enterprise security. Here are the essential controls every small business should implement.

    Dec 15, 2022
    4 min read
    By ThreatMate TeamRead more
    The Importance of Regular Security Audits
    Security Audits
    Compliance

    The Importance of Regular Security Audits

    Security isn't a one-time project. Here's why regular audits are essential for maintaining a strong security posture.

    Nov 20, 2022
    4 min read
    By ThreatMate TeamRead more
    Introduction to Attack Surface Management
    Attack Surface
    ASM

    Introduction to Attack Surface Management

    What is Attack Surface Management and why is it becoming essential for organizations of all sizes? Here's your introduction to ASM.

    Nov 1, 2022
    4 min read
    By ThreatMate TeamRead more
    Securing Microsoft 365: A Beginner's Guide
    Microsoft 365
    Beginner Guide

    Securing Microsoft 365: A Beginner's Guide

    New to Microsoft 365 security? Here's your starting guide to securing M365 tenants for yourself or your clients.

    Oct 15, 2022
    4 min read
    By ThreatMate TeamRead more
    W
    Company
    Mission

    Why We Built ThreatMate: A Note from the Founders

    The story behind ThreatMate and our mission to make enterprise-grade security accessible to every organization.

    Oct 1, 2022
    3 min read
    By Anup GhoshRead more
    Common Vulnerabilities and How to Fix Them
    Vulnerabilities
    Remediation

    Common Vulnerabilities and How to Fix Them

    A practical guide to the most common vulnerabilities we find in small business networks and how to remediate them.

    Sep 15, 2022
    4 min read
    By ThreatMate TeamRead more
    W
    Announcements
    Welcome

    Welcome to the ThreatMate Blog

    Introducing the ThreatMate blog — your source for cybersecurity insights, threat intelligence, and practical guidance for MSPs.

    Sep 1, 2022
    2 min read
    By ThreatMate TeamRead more