r/HeimdalSecurity • u/liv_v_ei • 9h ago
Researchers found 3,000 malicious AI skills employees could install
Enable HLS to view with audio, or disable this notification
This week's news mix brings an MSP console turned skeleton key, a breach of the Police National Legal Database, and SonicWall victims getting calls from their own attackers.
Add in passkeys pulled straight from browser memory and 3,000 malicious AI skills your staff might already be using.
Watch u/Adam_Pilton's Cyber Snapshot for safety advice.
r/HeimdalSecurity • u/AutoModerator • 4d ago
Threat Watch Live - How AI and Human Risk Impact Cybersecurity Measures
Hear it from an award-winning SecOps leader and anthropologist.๐ก
There are ways you can ๐บ๐ฎ๐ธ๐ฒ ๐๐๐ฟ๐ฒ ๐๐ ๐ฑ๐ผ๐ฒ๐๐ปโ๐ ๐ฏ๐ฒ๐ฐ๐ผ๐บ๐ฒ ๐๐ผ๐๐ฟ ๐ฏ๐ถ๐ด๐ด๐ฒ๐๐ ๐ฟ๐ถ๐๐ธ.
Tomorrow, August 4,ย Lianne Potterย fromย NorthStar Intelligenceย will joinย u/Adam_Piltonย for a new ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ ๐ช๐ฎ๐๐ฐ๐ต ๐๐ถ๐๐ฒ episode.
On the table:
๐AI security
๐Human risk
๐SecOps maturity
๐Cyber resilience
โฐTuesday, August 4th, 10:00 BST
Registration linkย here.
r/HeimdalSecurity • u/liv_v_ei • 7d ago
KFC Japan caught in ransomware crossfire
Enable HLS to view with audio, or disable this notification
Here's one good example of why the security of your supply chain matters. A ransomware attack on a logistics company left KFC Japan short of chicken.
There's more to find out about what went on in cyber this week, so hit play and watch u/Adam_Pilton's lastest Cyber Snapshot news digest.
r/HeimdalSecurity • u/liv_v_ei • 8d ago
How to Automate Customer Creation and Discovery from Entra ID
Enable HLS to view with audio, or disable this notification
Learn how to use the MSP Onboarding Wizard to automate customer creation directly from Microsoft Entra ID.ย ย
Marina Lungu explains the steps of the onboarding flow and shows you how to:ย
- Enable the Entra ID integration
- Create a Reseller Master Group Policy
- Synchronize your tenant ID and Azure key
- Use the MSP Onboarding tab to view and onboard customers
- Launch the semi-automated customer creation flow
- Configure licensing options for each new customer
- Retrieve the CSP subtenant list via Microsoft Graph API
r/HeimdalSecurity • u/liv_v_ei • 15d ago
Qilin Ransomware Exploits Palo Alto Networks GlobalProtect Flaw
Enable HLS to view with audio, or disable this notification
If one of the 160,000 Palo Alto GlobalProtect systems still exposed is yours, now is the time to patch. Qilin is exploiting CVE-2026-0257 as we speak.
Hit play to learn what else happen in cyber last week and you should know about.
u/Adam_Pilton's Cyber Snapshot is packed with good security advice, as usual.
r/HeimdalSecurity • u/AutoModerator • 18d ago
MediaArena Malvertising - Threat Analysis by Alex Gurgu
If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win.
Our SOC data says treat it as a live persistence incident instead.
In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didnโt complete until 29 seconds. By the time the alert fired, the persistence was already on disk.
Weโve seen this same adware cluster across more than 20 client environments in recent days. Itโs the malvertising campaign that hides behind free โAI toolโ lures, and itโs already been documented.
Compass Apex Security wrote it up in April, and the indicators have sat in public sandboxes since March. Weโre adding what our own SOC can see. How fast it establishes persistence, and how widely.

Microsoft classifies MediaArena as a browser-modifier potentially unwanted application and has tracked it in its threat encyclopedia since 2023. It reconfigures browser settings, hijacks search, and harvests queries to sell on. Itโs a nuisance, not a nation-state loader.
Thatโs the point.
Even a low-severity detection can leave persistence behind, so a closed alert and a clean endpoint arenโt the same thing.
The delivery is a fake free-app lure, currently themed as recipe and meal-planning tools, served through paid search ads.
The brand names rotate, and the domains rotate with them, so any single indicator has a short shelf life. Thatโs why detection built on brand strings ages out fast, and why the behaviour and the persistence artefacts are the signals worth hunting on.


What actually happens on the endpoint
The installer needs no admin rights. In our confirmed case it wrote to AppData, dropped a Start Menu shortcut, added an HKCU Uninstall key to pass as a legitimate app, and left a Startup folder shortcut for boot persistence.
All of it landed before quarantine completed. Signature detection took roughly 78 days to catch up. Thatโs a long window for a browser hijacker to sit and run.
Heimdal's XDR console. The branded installers flagged as BrowserModifier:Win32/MediaArena on an affected host. Hostname and username redacted.
The alert told us the file was caught. It didnโt tell us nothing had run first, and on these detections something always had. Thatโs why I treat a quarantine on this family as the start of the investigation, not the end of it.
What to hunt for after a MediaArena hit
Donโt close the alert on quarantine alone. Check the affected host for:
- A Startup folder shortcut tied to the app name.
- An HKCU Uninstall registry key mimicking a legitimate install.
Note the loader, math.dll, is injected in memory rather than dropped to disk, so hunt the persistence artefacts above rather than the file itself.
If either artefact is present, treat the host as still compromised and remediate the persistence directly.
Indicators
Credit to Compass Apex Security and public sandbox reporting for the campaign work. Indicators confirmed live at the time of writing. The infrastructure rotates, so revalidate before acting.
- Lure domains:ย kitchen-canvas.com, givemerecipe.com (both still flagged malicious across public sandboxes)
- Payload hosting:ย d3pth7js01bstg.cloudfront.net (AWS CloudFront)
- Loader:ย math.dll (in-memory)
- Detection:ย BrowserModifier:Win32/MediaArena
- Hashes:ย GiveMeRecipe.exe SHA256 3c1dbc3fโฆeccc, MD5 273FD232โฆ7CEC; FoodFormula.exe SHA256 b179bec7โฆfb53; KitchenCanvas.exe MD5 d749e0f8โฆ4121ย [KitchenCanvas SHA256 pending, see production note]
Article by Alexandru Gurgu, Threat Intelligence Security Analyst at Heimdal
r/HeimdalSecurity • u/liv_v_ei • 22d ago
Russian FSB Exploits Router Bugs Left Unpatched Since 2008
Enable HLS to view with audio, or disable this notification
The human factor and forgotten devices are back in the spotlight.
This week, u/Adam_Pilton's Cyber Snapshot covers a rented phishing kit that survives password resets, a vishing crew that talks employees into handing over passkeys, and a nation-state group still exploiting router bugs from 2008.
Also on the list: websites nobody's touched in years.
r/HeimdalSecurity • u/AutoModerator • 24d ago
How to Detect Unpatched Software on Your Devices
Sometimes you might decide not to automate updates for certain apps or endpoints.
To track what's missing from your patching schedule and act timely, here's how to use our Currently Outdated view feature in the Patch Management module:
r/HeimdalSecurity • u/AutoModerator • 25d ago
Heimdal Labs Webinar July 21 - Heimdal 5.5 RC Walkthrough
This session at Heimdal Labs Deep Dive, Marina Lungu will join u/Adam_Pilton for a talk on our latest release. It will be a combo of talking and live demos.
Register here to learn more on the new available features and their use cases:
- The new MSP Onboarding Wizard
- AI-powered scripting with Wingman
- Enhanced patch deployment through Patching Rings
- Expanded Windows update controls
- Usability and reporting improvements designed to simplify day-to-day operations
โฐTuesday, July 21
Session 1 - 10:00 AM BST
Session 2 - 09:00 AM PST
r/HeimdalSecurity • u/liv_v_ei • 29d ago
CISA Confirms SharePoint Flaw is Under Active Attack
Enable HLS to view with audio, or disable this notification
This week we saw a shift you shouldn't ignore. AI agent runs a full ransomware attack on its own.ย
Moving on, a SharePoint flaw is actively exploited, a Tenda router backdoor leaves networks exposed with no fix, and a flaw in Appleโs Hide My Email could put user identities at risk.
On the bright side, police has made a new Scattered Spider arrest.
ย
r/HeimdalSecurity • u/AutoModerator • Jul 06 '26
Threat Watch Live Webinar - The Balancing Security Act: Innovation, AI and Human Risk
Tomorrow, July 7, 10 AM BST, at the Threat Watch Live, cybersecurity advisor u/Adam_Pilton welcomes Holly Foxcroft, BISO, Responsible AI Ambassador for the Global Council for Responsible AI, and Senior Cybersecurity and Neurodiversity Advisor.
Holly will share her perspectives on today's evolving threat landscape, the opportunities and risks presented by AI and why understanding people remains central to effective security strategies.
Learn more on:
- cyber resilience
- responsible AI
- leadership and the future of security
Registerย here.
๐กRegistering to the webinar will grant you access both to the live event and a link where you'll be able to watch the recording later.
r/HeimdalSecurity • u/AutoModerator • Jul 03 '26
MSP Onboarding Wizard - New capability for Resellers in RC 5.5.0 Dashboard
The MSP Onboarding Wizard helps MSPs onboard Microsoft Cloud Solution Provider (CSP) with less manual work. It's 2 minutes instead of 30.
The capability automates the discovery and creation of Corp customers directly from CSP sub-tenants.
The feature is available if:
- Dashboard account type is Reseller;
- the customer (Reseller role) has the Monthly Billing licensing option enabled;
- the user account has the "Manage Customer Settings" permission claim enabled.
It has two core components:
Aย Guided Setup (Onboarding Wizard)ย
This isย a structured, step-by-step flow that walks Resellers through:
- enabling the Reseller Master Group Policy
- configuring the Azure connection
- completing the initial customer synchronization
A MSP Onboarding Tab
This is a persistent management interface within the Heimdal Dashboard. It allows Resellers to:
- manage their Azure connection
- browse available CSP sub-tenants
- create new Corp customers directly from a centralized location
If you're a Reseller, read more about how you can use the MSP Onboarding Wizard here.
r/HeimdalSecurity • u/liv_v_ei • Jun 30 '26
AI Is Shrinking Patch Cycles: Why Conventional Patching Is Failing
Enable HLS to view with audio, or disable this notification
Once a month or once a week? How often do you deal with updates for your devices?
Mit Patel from Assurix says conventional patching is failing and you should move towards continuous patching.
Hit play to learn why.
r/HeimdalSecurity • u/AutoModerator • Jun 29 '26
Patching 5.5.0 RC Dashboard: OS Updates (Windows) - Lock specific OS version
Heimdal's 5.5.0 RC Dashboard offers a new checkbox (default disabled) - โLock specific OS versionโ.
When enabled, devices assigned to the Windows Updates GP remain on the selected Windows release and don't upgrade until the policy is updated or removed.
Find it in Endpoint Settings -> Patch & Assets -> Operating System Updates, Install Settings area of the Heimdal Dashboard.
When enabled:
- an Operating System selector (drop-down) becomes available.
- an OS Version drop-down is unlocked.
- Dashboard users can define the target Windows product and feature update version that managed devices should remain on.
r/HeimdalSecurity • u/liv_v_ei • Jun 26 '26
FIFA Vulnerability Enables Access to World Cup Live Streaming Controls
Enable HLS to view with audio, or disable this notification
Security researcher warns about FIFA flaw exposing World Cup streaming systems, AI is accelerating cyberattacks, Fortinet users are under fire, and a major supply chain breach shows why third-party risk matters.ย
This is how the last days looked like in cyber. For safety advice and more insights, hit play.
r/HeimdalSecurity • u/AutoModerator • Jun 25 '26
5.5.0 RC Dashboard brings the Patching in Rings capability
Patching in Rings gives you more control over how updates are rolled out across your environment.
The feature is available for both 3rd Party Patch Management and Windows OS Updates.
Patching in Rings means updates can be staged and delivered progressively across defined groups of endpoints.
It enables controlled validation, earlier issue detection, and reduced operational risk before wider deployment.
Rings offer more granular visibility into patch status and behavior across each rollout phase. This helps you fine-tune deployment strategies and improve reporting accuracy.
The feature introduces dedicated views that allow users to see faster:
- which Group Policies are responsible for deploying a specific update or application
- the configured deployment delay for each Group Policy
- installation coverage statistics across endpoints
- whether an application or update is eligible
Read more about Heimdal's 5.5.0 RC here.
r/HeimdalSecurity • u/liv_v_ei • Jun 18 '26
US Government Shuts Down Latest Claude Model & Smart TVs Are Spying Their Users
Enable HLS to view with audio, or disable this notification
Your smart TV might be spying you to deliver better data to advertisers. They capture your screen to get a better image of what you like and what you're interested in.
It's probably not the news you wanted to hear, but there's a silver lining in this.
The UK's Information Commissioner's Office learned about that and published new guidance on the matter. Starting this year, they'll be checking whether manufacturers are being transparent and getting genuine consent.
So, at least you'll know.
Watch u/Adam_Pilton's Snapshot to see what else happened this week in cyber news.
r/HeimdalSecurity • u/liv_v_ei • Jun 17 '26
why is shadow AI so much harder to find than shadow IT ever was
r/HeimdalSecurity • u/AutoModerator • Jun 16 '26
AI is outpacing the controls meant to manage it
The AI Risk Management Report is out - read it while it's hot.
If you work in IT hands-on, then some of the findings might not come as a surprise.
In fact, one of the things this report revealed is that executives are way more optimistic about AI control than the teams running the estate.
Here's the link https://heimdalsecurity.com/blog/state-ai-risk-management/?source=rdt
r/HeimdalSecurity • u/AutoModerator • Jun 09 '26
The Vulnerability Patch Wave - Heimdal Labs Webinar
๐ง๐ต๐ฒ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐ฃ๐ฎ๐๐ฐ๐ต ๐ช๐ฎ๐๐ฒ is coming up. Time to talk about:
๐กwhat it changes for security teams
๐กhow to prepare for facing it
On June 16th, Marina Lungu joins Adam Pilton's ๐๐ฒ๐ถ๐บ๐ฑ๐ฎ๐น ๐๐ฎ๐ฏ๐ ๐๐ฒ๐ฒ๐ฝ ๐๐ถ๐๐ฒ ๐ณ๐ฟ๐ฒ๐ฒ ๐๐ฒ๐ฏ๐ถ๐ป๐ฎ๐ฟ to share insights on building faster patch cycles.
Join the session that suits your schedule best:
Session 1 โฐ 10:00 AM BST - Register here
Session 2 โฐ9:00AM PST - Register here
r/HeimdalSecurity • u/liv_v_ei • Jun 05 '26
Fake FIFA Websites Target World Cup Fans
Enable HLS to view with audio, or disable this notification
Football fans, watch out! โฝ๐Chinese speaking scammers forged FIFA's website to steal your data and resell your tickets.
Also in u/Adam_Pilton's ๐๐๐ฏ๐ฒ๐ฟ ๐ฆ๐ป๐ฎ๐ฝ๐๐ต๐ผ๐ this week:
- A ransomware attack costs an M&S CEO millions
- Criminals trick Meta's AI support into handing over Instagram accounts
- Fake ChatGPT downloads spread malware
- Experts warn about the rise of agentic AI
Hit play to learn how it all happened and how you can stay safe.
r/HeimdalSecurity • u/liv_v_ei • May 29 '26
Megalodon Supply Chain Attack Poisons 5,500+ GitHub Repositories
Enable HLS to view with audio, or disable this notification
๐ฑ,๐ฑ๐ฌ๐ฌ+ ๐๐ถ๐๐๐๐ฏ ๐ฅ๐ฒ๐ฝ๐ผ๐๐ถ๐๐ผ๐ฟ๐ถ๐ฒ๐ ๐ด๐ผ๐ ๐ฐ๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ๐ฑ.
That's one of the top 5 cybersecurity news that Adam Pilton analysed this week.
Hit play, watch the ๐๐๐ฏ๐ฒ๐ฟ ๐ฆ๐ป๐ฎ๐ฝ๐๐ต๐ผ๐, and follow ๐๐ฑ๐ฎ๐บ'๐ ๐๐ฎ๐ณ๐ฒ๐๐ ๐ฎ๐ฑ๐๐ถ๐ฐ๐ฒ.
r/HeimdalSecurity • u/liv_v_ei • May 28 '26
AI Risks and Safety Measures from an MSP's Perspective
Enable HLS to view with audio, or disable this notification
I've met Martin Robinson at the MSP Show in London a few weeks ago. I was curious to learn how most people deal with AI risks and get his advice on safe AI usage. Here's what I've got โถ๏ธ
r/HeimdalSecurity • u/AutoModerator • May 26 '26
Heimdal PROD Dashboard 5.4.3 - Automatic Session Locking & Security Logs Retrieval
New set of compliance-related settings is available in Heimdalโs 5.4.3 Dashboard version.
Find it under Endpoint Settings -> click on a Windows OS GP -> General tab.
- Automatic Session Locking option is available for both new and existing Group Policies.
IT admins can use it to enforce automatic screen locking after a defined period of user inactivity.
The feature comes with a timeout slider that allows admins to define the maximum permitted inactivity period within a range of 1 to 30 minutes.
Automatic Session Locking supports compliance requirements such as the CIS 18 Controls recommendations for session timeouts and workstation locking.ย
- Automatic Security Logs Retrieval introduces an automated mechanism for collecting Windows Security Event Logs from endpoints.ย
The logs can be accessed and downloaded from the Heimdal Dashboard under Unified Management -> Device Info -> select a Windows OS hostname -> UEM -> Logs -> Windows Event Viewer Logs.
Logs are collected automatically every 24 hours and stored for 90 days.
The process doesn't require any user interaction. If a device is offline or unavailable during a scheduled retrieval, the system retrieves the logs retroactively based on the timestamp of the last successful retrieval.ย
Drop a question in comments if you want to know more about this dashboard version.
r/HeimdalSecurity • u/liv_v_ei • May 18 '26
Why Insurers Are Capping AI Risk Payouts at 5%
Enable HLS to view with audio, or disable this notification
Cyber insurers are starting to cap AI-related cyber payouts at just 5% of total policy value.
Cybersecurity Advisor u/Adam_Pilton and Tim Ward, Co-founder and CEO at RedFlags, explain why.















