Threat analysis, guidance and product news
Practical reads on cyber risk, compliance and threat intelligence from the FortaRisks team.
RSS feed- Guidance
Paying a ransom is now a legal risk: OFAC goes after the infrastructure
For the first time, the US Treasury has sanctioned a VPN provider for facilitating ransomware. The decision to pay or not pay a ransom is now a governance question to settle before the crisis, not during it.
July 31, 2026 · 4 min read - Compliance
The FSB is targeting your routers, and Bill C-8 makes you accountable
On July 13, 19 agencies from 13 countries, including the Canadian Centre for Cyber Security, attributed a campaign against poorly configured network devices to Russia's FSB. A month earlier, Bill C-8 received royal assent. Together, they change the game for Canadian critical infrastructure.
July 30, 2026 · 4 min read - Threat Intelligence
Abbott: one phone call was enough
ShinyHunters claims access to Abbott systems after a voice phishing campaign compromised an SSO account. Why vishing beats MFA as deployed, and what the incident says about identity governance and acquisition risk.
July 29, 2026 · 4 min read - Threat Intelligence
Record Patch Tuesday: 570 flaws, 3 zero-days, and 3 days to patch
July 2026 is the largest Patch Tuesday in Microsoft's history. Beyond the volume, it exposes two governance gaps: prioritizing by severity instead of exploitation, and measuring patches instead of the exposure window.
July 28, 2026 · 4 min read - Third-Party Risk
Accenture breached: when your consultant becomes your attack surface
A threat actor claims 35GB of source code, SSH keys and Azure tokens stolen from Accenture. What the incident reveals about concentration risk in large service providers, and what a client should do right now.
July 27, 2026 · 4 min read - Compliance
Canada accelerates: C-8, CPCSC, C-36, the end of voluntary cybersecurity
In a few months, Canada passed Bill C-8, made the CPCSC mandatory for defence contracts and introduced Bill C-36 on privacy. What this regulatory acceleration means for executives, and how to prepare without multiplying projects.
July 24, 2026 · 4 min read - Guidance
The Canadian leader in integrated 360 risk management, built here
Why FortaRisks is the Canadian leader in integrated 360 risk management: unified coverage, data sovereignty and regulatory fit, built and hosted in Canada.
July 21, 2026 · 5 min read - Guidance
Agentic ransomware is here: what JadePuffer means and how to defend
JadePuffer is the first ransomware campaign run end to end by an AI agent. What happened, why it changes the risk equation, and the controls that actually cut your exposure.
July 14, 2026 · 7 min read - Third-Party Risk
How to get an SBOM from your third-party software vendors
A practical guide to getting an SBOM from your third-party software vendors: what to request, contract wording, red flags, and what to do once it arrives.
July 7, 2026 · 6 min read
See your real risk in a 30-minute demo.
A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.