BLOG

The Great Agentic Shift: Redefining Cybersecurity in 2026

In the opening weeks of 2026, the cybersecurity landscape has undergone a transformation more profound than the migration to the cloud or the mobile revolution. We have officially moved past the era of “Generative AI”—where Large Language Models (LLMs) served as glorified search engines and drafting assistants—and entered the Era of Agentic AI. Today, AI …

Read More

Public Cloud vs Hybrid Cloud: Best Strategy for Business

Why the Cloud vs. Hybrid Cloud Decision Has Never Mattered More The traditional framing of this debate public cloud for flexibility, on-premises for security was always a simplification. But in 2026, it is an insufficient one. Agentic AI systems require persistent access to sensitive data pipelines, customer records, financial transactions, and operational systems. When those …

Read More

The Coming Doldrums for PC Users: How Windows 11’s Strict Hardware Requirements Leave Millions Behind

When Microsoft unveiled Windows 11, it promised a faster, sleeker, and more secure operating system designed for the modern era. The new interface, improved multitasking features, and deep integration with cloud services painted a picture of the future of computing. But there’s a dark cloud looming over that future—one that could leave millions of PC …

Read More

Why Skipping a Reverse Proxy May Leave Your Network Vulnerable

When it comes to safeguarding a company’s network infrastructure, many businesses rely on complex security setups that help protect sensitive data and ensure smooth operation. One such tool is the reverse proxy, which acts as a protective shield between the external world and a company’s internal servers. But what if your organization chooses not to …

Read More

Cybersecurity Accreditation Bodies in Canada: Ensuring Robust Protection for Organizations

As cyber threats become more sophisticated and pervasive, Canadian organizations must take proactive steps to protect their data, operations, and reputation. One of the most reliable ways to ensure cybersecurity best practices are in place is through certifications from recognized accreditation bodies. These certifications confirm that a company adheres to strict security standards, instilling confidence …

Read More

Risks of Running Outdated SQL Servers

In the era of rapid technological and AI-driven advancement, businesses rely heavily on technology to drive operations and ensure efficiency. However, the use of outdated SQL servers poses a significant risk that cannot be ignored. This article explores the numerous risks and repercussions of running outdated SQL servers. From security vulnerabilities to performance issues, understanding …

Read More

US Cybersecurity Changes and Their Impact on Canada in 2025

Cybersecurity remains a paramount concern for nations around the world, that requires global collaboration to combat. Constant threats of cyberattacks and digital breaches are looming large. As the United States continues to make significant changes to its cybersecurity policies and practices, the impacts of these shifts will undoubtedly have far-reaching implications for its neighbours, including …

Read More

Risks of Poor Password Storage Practices

The importance of strong password protection cannot be overstated. However, many individuals and employees still resort to storing their passwords in easily accessible places such as notebooks, documents or spreadsheets – a practice that poses significant security risks. In this article, we will explore the dangers associated with storing passwords in physical or digital forms …

Read More

Combatting Phishing: The Role of Passkeys in Security

The threat of phishing attempts looms large over businesses and individuals with every suspicious unopened email. Phishing attacks, wherein cybercriminals trick unsuspecting users into disclosing sensitive information such as passwords or financial data, have become increasingly sophisticated and widespread. In order to combat this growing menace, companies are turning to innovative solutions such as passkeys …

Read More

The Impact of AI on Software, Application, and Website Code

The use of Artificial Intelligence (AI) to automate tasks has become increasingly prevalent in more and more industries. Areas that have been significantly impacted by this trend are software, application and website development, with AI being utilized to write code more efficiently and quickly than ever before.  Gartner estimates that by 2028, 75% of enterprise …

Read More

Security software cybersecurity professionals use for personal computers

Software to protect against intrusions on personal computers is more important than ever. As professionals in the field who are constantly battling against threats and cyberattacks, cybersecurity professionals understand the critical need for robust yet simple antivirus/anti-malware software to protect personal computers. With multitudes of online threats, choosing the right software can be a daunting …

Read More

The London Drugs Cyberattack 2024

London Drugs, a popular retailer in Western Canada, was the target of a devastating cyberattack that sent shockwaves through the retail world as many customers rely on their essential services. In an interview detailing this malicious breach, London Drug’s CEO stated that sensitive customer information was not compromised, but it’s obvious that critical vulnerabilities in …

Read More

Penetration Testing as a Service (PTaaS)

Today, organizations find themselves confronted with mounting threats to their sensitive data and networks within the continuously evolving cybersecurity landscape. Penetration testing has emerged as a crucial tool in identifying and addressing vulnerabilities before they can be exploited by malicious actors. One approach that is gaining traction is the concept of Penetration Testing as a …

Read More

SEC updates all cybersecurity rules

In today’s technology-driven world, cybersecurity concerns continue to grow exponentially. With hackers becoming increasingly sophisticated in their tactics, it is of utmost importance for organizations and individuals alike to stay updated on the latest regulatory requirements and guidelines established by governing bodies. In light of this pressing issue, the U.S. Securities and Exchange Commission (SEC), …

Read More

Chinese and Indian hackers take aim at Canadian digital assets

China and India have emerged as two powerhouse nations with well-established hacking groups. These clandestine organizations operate on a scale that rivals those of state-sponsored actors, infiltrating networks across the globe to harness valuable information for political gain or financial motives. This article delves into the intriguing world of Chinese and Indian hackers, shedding light …

Read More

Everything we know about the MGM Cyberattack

Cyberattacks involving ransomware are a growing threat to organizations worldwide in the digital age. One recent incident that has captured global attention is the MGM cyberattack. As one of the largest entertainment companies in the world, MGM’s security breach has raised concerns about data protection and cybersecurity measures across industries. In this article, we aim …

Read More

Cyber Defence Sensors

Cyber Defence Sensors: Enhancing Security in the Digital Sphere In an increasingly interconnected digital world, where cyber threats pose a significant risk to individuals, businesses and governments alike, the need for robust cyber defence measures has never been more pressing. Cyber defence sensors have emerged as powerful tools in identifying and mitigating these threats, allowing organizations …

Read More

Commercial Spyware Technology Examined

In today’s digital age, the benefits of modern technology are undeniable for businesses. However, with these advancements come risks, particularly concerning privacy and security. Commercial spyware is concerning because it can be used to illegally obtain sensitive information or spy on individuals without their consent. This poses a threat to privacy and security. In this …

Read More

Preventing internal cybersecurity threats

In the modern world, cyber-security threats are becoming more than a nuisance. They have become a real danger for organizations everywhere, with internal cybersecurity threats being among the biggest issues to worry about. With so many staff members and employees now connected to a network in some way or another as well as giving access …

Read More

Endpoint Detection and Response (EDR) Security

Endpoint security is the general term for protecting your organization’s computer endpoints. This includes computers, laptops, tablets, smartphones and other devices that individual users connect to the network. Endpoint security can include several different technologies used to secure your company’s computer endpoints. From password management and two-factor authentication to application whitelisting and virtualization controls…endpoint security …

Read More

Double Extortion Ransomware Attacks

It’s no secret that cybercriminals are constantly trying to improve their methods of targeting victims. As a result, they have also come up with more creative ways of extorting money from their victims. The most common variants of ransomware these days attack the users by asking for payment in exchange for unlocking files and restoring …

Read More

What is a distributed denial-of-service (DDoS) attack?

A distributed denial-of-service attack, or DDoS attack, is when hackers use multiple computers or bots to send requests to a website simultaneously. This overload causes legitimate users who try to access the site to have trouble and slow it down. If you’re a website owner and your visitors can’t get through on one page or …

Read More

Unified Communications as a Service (UCaaS) 

UCaaS is a cloud-based communication platform that gives businesses the ability to have unified communications with their employees. It’s essentially a virtual communication system, and it’s ideal for small businesses who need an easy-to-use solution to communicate with their employees but don’t have the resources or staff to maintain a traditional phone system. With UCaaS, …

Read More

Zero Trust: A Model for More Effective Security

Forrester Research analyst John Kindervag came up with the zero trust network model in 2010 while a principal analyst at the firm. It is now twelve years later that corporate leaders worldwide are increasingly embracing zero trust as the technologies that facilitate it reaches the mainstream. The pressure to protect enterprise systems and data increases, …

Read More

How to Prepare your Business for Cyber Attacks Resulting from Russia Ukraine Crisis

A new era of cyberwarfare For many years, Russia has been known to harbour malicious actors who undertake endless cyber Attacks on North American digital property.  From industrial plants, medical facilities and education institutions, nothing of off limits for these highly skilled, rogue operators.  Even after instructions from Russian government to handover any cybercriminals these …

Read More

Onedrive Security Features & Review

Onedrive Security Features & Review Does Onedrive come with reliable security? All Onedrive users are extended both two factor authentication and also the ability to access Personal Vault which will further safeguard data with a variety of settings for added protection.  Encryption is offered to all users but it’s not considered impenetrable as data transfer …

Read More

Activity Summary – Week Ending November 16, 2018

This week Fortinet released our latest Quarterly Threat Landscape Report. Every second of every day FortiGuard Labs is collecting data gathered from millions of devices and sensors around the world. The sheer volume of data we analyze gives us a distinct and unparalleled perspective of the global threat landscape. This data cumulates into our quarterly …

Read More

Activity Summary – Week Ending November 9, 2018

The TrickBot malware family has been around for many years, initially focused on stealing victim’s online banking credentials. However, FortiGuard Labs has analyzed some new samples where we have found TrickBot, utilizing a new module, has evolved to much more trickery.

Read More

Activity Summary – Week Ending November 2, 2018

Cybercrime-as-a Service has created an entry point for novice distributed denial-of-service (DDoS) attackers by offering simple options to anonymously attack nearly any website and forcing it offline. Due to the public release of source code for some popular bots, building a botnet to provide these sort of services is easier than ever. Minor modifications to …

Read More

Activity Summary – Week Ending October 26, 2018

Attackers have always been seeking new avenues for exploitation; short of discovering zero days themselves. Many attackers have relied on known vulnerabilities either disclosed responsibly or irresponsibly to a vendor. Also, even if there is a patch available, such as the industry standard Patch Tuesday cycle by Microsoft/Adobe, attackers have taken said patches from vendors …

Read More

Activity Summary – Week Ending October 5, 2018

FortiGuard Labs recently encountered malicious traffic traveling to a C2 server located in China. The connection was established by a domain using a name that closely resembled one of Japan’s most famous express post delivery services. Our analysis showed that the website making this connection is fake, there is no SSL certificate, and the page …

Read More

Activity Summary – Week Ending September 28, 2018

VPNFilter, a multi-stage modular framework that has infected hundreds of thousands of network devices around the world, has been discovered to have even greater capabilities than originally profiled. Announcing their findings through the Cyber Threat Alliance, Cisco’s Talos provided early awareness and early sharing of IOCs with the CTA members. Seven additional third-stage modules that …

Read More

Activity Summary – Week Ending September 21, 2018

Once again the Cyber Threat Alliance (CTA) members have collaborated on research. This week the CTA members released a collaborative report on illicit cryptomining (aka cryptojacking). Fortinet is a founding member of the CTA and believe that working together with other cybersecurity organizations, we can improve cybersecurity across our global digital ecosystem. Below is a …

Read More

Activity Summary – Week Ending September 14, 2018

Get patching! For September Patch Tuesday Microsoft released updates addressing 61 vulnerabilities! Severity breakdown is: 17 rated critical, 43 rated important, and only one is rated as moderate. There were several Adobe updates as well.

Read More

Activity Summary – Week Ending September 7, 2018

A new banking Trojan has been identified targeting major Brazilian banking customers, as well as public sector organizations. This malware, code-named CamuBot, uses interesting new tactics with social engineering and malware techniques to bypass security controls, including strong authentication.

Read More

Activity Summary – Week Ending August 31, 2018

FortiGuard Labs researchers have been monitoring an invasion of GandCrab malware updates of late. You can read our full blog to get all the chronology details. Below is a synopsis of what we discovered and has transpired lately.

Read More

Activity Summary – Week Ending August 24, 2018

For years there have been tools developed for malware research with a primary focus on the Windows platform, whereas tools for alternative operating systems, such as Linux and macOS, were few and far between. This made sense given the enormous adoption rate and market share that Windows operating systems had over the past several decades. …

Read More

Update on Buffer Overflow Vulnerability

Hikvision has become aware of a vulnerability involving its video surveillance products that could potentially present a cybersecurity risk. In the interest of protecting our customers from any potential cybersecurity threats, Hikvision has proactively corrected the vulnerability in the latest version of its firmware. We advise all users of the affected cameras to download the …

Read More

Activity Summary – Week Ending August 10, 2018

Fortinet has a culture of innovation. It isn’t more evident than at the BlackHat conference held this week in Las Vegas, where FortiGuard Labs researcher Kai Lu presented his application behavior monitoring tool called FortiAppMonitor for macOS.

Read More

Activity Summary – Week Ending August 3, 2018

Once again, Fortinet’s membership in the Cyber Threat Alliance (CTA) continues to pay dividends. Sophos, also a CTA member, published their comprehensive research into the SamSam ransomware this week. As part of their CTA membership, Sophos shared all the indicators of compromise (IOCs) with other members before they published their findings. This allows CTA members …

Read More