All our threat-report news
Cyber Risk Alert: Threat report published 2025-03-10T20
Threat report published 2025-03-10T20:29:07.925Z. Types: threat-report. FortiGuard Labs has analyzed malicious software packages detected from November 202…
Michael Guiao
9 min read
Desert Dexter: Why Social Engineering Belongs on Cyber Underwriting Forms
Desert Dexter shows low-tech social engineering can match zero-day claim severity. What MENA-exposed insurers must add to underwriting questionnaires.
Lazarus Group Resurfaces Against Windows Web Servers: Underwriting Risks
State-aligned Lazarus APT exploits unpatched Windows web servers with modular tooling and proxy nodes. Underwriters should reassess patch posture and EOL e…
New Phishing List Bypasses All Filters: What Insurers Must Know
A phishing campaign evaded major email filters, compromising 12,000+ mailboxes. For insurers, this signals increased loss frequency and severity,...
Power BI Phishing: How Trusted Platforms Fuel Credential Theft & Insurance Risks
How the Power BI phishing campaign exploits SharePoint trust to steal credentials, reshaping cyber insurance underwriting and claims frequency.
Power BI Phishing: How Trusted Platforms Fuel Cyber Insurance Claims
Phishing campaign uses SharePoint and Power BI to steal credentials across 1,800+ firms. How this drives up claims frequency and severity for cyber insurers.
Russian State Cyber Ops Are Reshaping Cyber Underwriting
APT28, APT29, and APT44 operate undetected for 277+ days, driving $20–100M losses that demand new underwriting models for state-sponsored risk.
SideWinder APT Targets Maritime & Nuclear: New Risks for Cyber Insurers
State-sponsored SideWinder campaign hits ports and nuclear facilities, converging business interruption and physical damage risks—creating coverage gray zones for insurers.
SimpleHelp Exploit: How RMM Vulnerabilities Trigger Cyber Insurance Claims
SimpleHelp RMM flaws enable Sliver C2 attacks and ransomware. For cyber insurers, this shows RMM as a single point of failure with cascading claims risk.
SmokeLoader Campaign: Open Directory Risks for Insurers
SmokeLoader's use of open directories in Ukraine highlights a universal risk: basic security gaps continue to drive cyber insurance claims frequency...
TRUMP Coin Phish Delivers ScreenConnect RAT: Underwriting View
Binance-impersonating campaign drops ConnectWise ScreenConnect as a RAT, a textbook ransomware precursor with $5.13M average claim cost.
Trusted Platform Phishing: Cyber Insurance Risks from SharePoint & Power BI Attacks
New phishing campaign exploits Microsoft SharePoint and Power BI to bypass security. For underwriters, this shifts risk modeling and requires coverage updates.
XCSSET Returns: macOS Xcode Supply Chain Risk Resurfaces for Insureds
Microsoft documents updated XCSSET malware infecting Xcode projects. Underwriting implications for macOS developer supply chain exposure.
blog.featured
AI Tooling RCE: The Sublimit Layer Underwriters Rarely Underwrite
9 min read
SolarWinds SAML Bypass: The IT Ticketing Supply-Chain Path
9 min read
AM Best and S&P Flag Cyber Pricing Risks: What Underwriters Should Do at Renewal
7 min read
One Salesforce Integration Breach Just Hit 200 Cyber Insureds
8 min read
Premium Report
2026 Cyber Risk Landscape Report
24 pages of threat analysis, claims data, and underwriting implications for European cyber insurance.
View Reports →