Threat analysis, guidance and product news
Practical reads on cyber risk, compliance and threat intelligence from the FortaRisks team.
RSS feed- Third-Party Risk
Quebec and Ontario breaches in August: six incidents, five findings that should change your plan
CCQ, xPayrience, Senvest, Waterloo, MOSAID, CMHA: what the incidents reported in Quebec and Ontario since August 1 actually show. In half the cases the organization affected is not the one that was attacked, and almost nobody learned it from their vendor.
August 31, 2026 · 8 min read - Threat Intelligence
The cyber week, through a risk lens: when the attack targets your operations, not your data
Week of August 24, 2026. Boston Scientific unable to ship, a UK power facility down for four days, a Winnipeg hospital without its doors and ventilation, Cl0p emptying Windchill vaults. Then three facts that change how you manage: Citrix exploited eight weeks after the patch, AI-written exploits against Siemens PLCs, and Nova Scotia Power unable to explain why thirty years of data was never deleted.
August 28, 2026 · 8 min read - AI
AI security (1/8): map shadow AI before it becomes your next incident
A 5-day playbook to inventory every AI use in your organization: where to look, what to record, how to triage. Includes the minimal 6-column register.
August 27, 2026 · 4 min read - Third-Party Risk
Wesco: when extortion skips the ransomware, your continuity plan never fires
Distributor Wesco has confirmed an incident in its cloud CRM: 2.6 million records published, no encryption, no business disruption. A scenario where backups are useless, because the harm lands entirely on customers and suppliers.
August 13, 2026 · 6 min read - Threat Intelligence
Gunra ransomware: when your security appliance becomes the front door
CISA, the FBI and the NSA have warned about Gunra, a Conti-derived ransomware that walks in through internet-facing appliances patched long ago. Three governance lessons: perimeter inventory, patch latency, and the fact that a patch does not evict an attacker who is already inside.
August 12, 2026 · 4 min read - Guidance
Paying a ransom is now a legal risk: OFAC goes after the infrastructure
For the first time, the US Treasury has sanctioned a VPN provider for facilitating ransomware. The decision to pay or not pay a ransom is now a governance question to settle before the crisis, not during it.
July 31, 2026 · 4 min read - Compliance
The FSB is targeting your routers, and Bill C-8 makes you accountable
On July 13, 19 agencies from 13 countries, including the Canadian Centre for Cyber Security, attributed a campaign against poorly configured network devices to Russia's FSB. A month earlier, Bill C-8 received royal assent. Together, they change the game for Canadian critical infrastructure.
July 30, 2026 · 4 min read - Threat Intelligence
Abbott: one phone call was enough
ShinyHunters claims access to Abbott systems after a voice phishing campaign compromised an SSO account. Why vishing beats MFA as deployed, and what the incident says about identity governance and acquisition risk.
July 29, 2026 · 4 min read - Threat Intelligence
Record Patch Tuesday: 570 flaws, 3 zero-days, and 3 days to patch
July 2026 is the largest Patch Tuesday in Microsoft's history. Beyond the volume, it exposes two governance gaps: prioritizing by severity instead of exploitation, and measuring patches instead of the exposure window.
July 28, 2026 · 4 min read
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.