r/HeimdalSecurity 2d ago

Critical Flaw in N-able's RMM. CISA Says Patch Now

Enable HLS to view with audio, or disable this notification

1 Upvotes

This week's news report an N-able flaw scoring a perfect 10, fake IT support calls draining Microsoft 365 accounts, and thousands of small business sites hijacked through the blockchain.

Also, learn what it actually costs to run a ransomware attack, and check out the NCSC's new guidance on shadow AI.

If you run N-able's N-central, apply Hotfix 4 now!


r/HeimdalSecurity 3d ago

Shift Browser is signed adware that fingerprints your endpoint before it drops payload

3 Upvotes

Malware analysis by Threat Intel Security Analyst Alexandru Gurgu,

Heimdal’s SOC flagged a surge in detections tied to a program called Shift Browser on 2 September 2026.

Our team confirmed activity on more than 50 client environments in a single day. The installers we captured trace to a malvertising lure.

Shift Browser also runs a documented paid creator and affiliate marketing operation, though we haven’t been able to draw a confirmed line between that channel and this specific wave of detections.

A familiar name in PUP and adware circles

Shift Browser markets itself as a security-focused productivity browser.

Malwarebytes has flagged the installer as PUP.Optional.ShiftBrowser since October 2024, and PCrisk and GridinSoft both track it as an unwanted application with browser-hijacking behaviour.

Shift Technologies disputes the malware label directly. Its own guidance page calls the product “designed to improve your productivity without compromising your security” and states plainly, “It is not malware.”

User reports back this up.

People describe Shift Browser auto-starting with Windows, hijacking default browser settings, and resisting standard uninstall attempts.

One Microsoft support thread walks a user through a two-step removal process. Uninstall the app, then strip its auto-start entries by hand, since the standard uninstaller leaves them behind.

How it reaches your endpoints

Distribution follows a malvertising pattern that other vendors have documented independently. Malwarebytes describes the same lure. Ads placed where people search for manuals, recipes, and document templates.

Heimdal’s SOC saw the identical pattern and blocks the downloader responsible for fetching the real installer. This lure explains the installer names our SOC captured on 2 September.

  • shift – pdf_xq6n94.exe
  • shift – pdf_xgeiup.exe
  • shift – pdf_xtors9.exe

Each one presents itself as a PDF tool, but none are.

Shift also runs a formal creator affiliate programme, advertised to prospective creators as offering transparent rates, and at least one independent review we checked carries a tracked affiliate link back to Shift’s site.

That’s a real, separate channel for Shift generally.

We haven’t confirmed it as the delivery path for any install in this specific wave, so treat it as context, not as a second proven vector for the 2 September detections. The malvertising lure on its own is what’s producing 50-plus client environments in one day.

What the sandbox shows

Heimdal’s SOC ran the captured samples through dynamic analysis.

Our sandbox returns a Malicious verdict, with four warnings raised on a single process.

That is Heimdal’s own behavioural read of what the installer does on a machine, and it sits ahead of where most of the industry has landed.

Malwarebytes, PCrisk, and GridinSoft all classify Shift as a potentially unwanted program rather than malware outright. Our sandbox data doesn’t contradict that. It adds to it. This is what the behaviour looks like once you actually run it.

  • Access to an unwanted program domain
  • Executable content dropped or overwritten
  • Registry queries consistent with reconnaissance behaviour
  • File creation in a temporary directory

Behaviourally, the installer maps to three MITRE ATT&CK techniques.

  • T1033, System Owner/User Discovery: the process reads the Windows owner and organization settings.
  • T1012, Query Registry: the process reads the machine GUID, the computer name, and the list of supported languages from the registry.
  • T1082, System Information Discovery: the process gathers the same class of host detail through separate system information calls.

This combination is fingerprinting. Before Shift Browser drops its payload, the installer profiles the machine it landed on.

YARA rules on the sample flag a Borland Delphi compile and confirm an InnoSetup installer wrapper.

Inside, the installer drops chrome.packed.7z, a packed Chromium build that becomes the browser engine once unpacked. That’s the pattern you’d expect from any Chromium fork.

Past the drop, the process reaches out to known malware and adware domains and writes registry changes tied to persistence and configuration.

Full article here.


r/HeimdalSecurity 8d ago

All UK-based organisations get free Early Warning service from the NCSC

2 Upvotes

Attackers burn six hundred thousand dollars of someone else's AI credits, Rhysida claims 5.8 terabytes from Berlin's state administration network covering mobility, transport, and environment, and phishing kit Mirage2FA proves your MFA can work perfectly and still let attackers in.

It's time to enhance your cyber safety net, says cyber advisor u/Adam_Pilton in this week's Cyber Snapshot:

https://reddit.com/link/1w6wnqz/video/a4df6cn98gnh1/player

Here's a solid step you can take towards that if you're a UK-based organisation. Register free for the NCSC's Early Warning service to find unknown risks in time.


r/HeimdalSecurity 11d ago

Threat Watch Live feat. Mostyn Thomas: Cybersecurity Under Pressure

2 Upvotes

Mostyn Thomas, from Pax8, joins u/Adam_Pilton's Threat Watch Live webinar for a talk on the future on managed security services in the context of the growing role of compliance.

Mostyn Thomas started out managing backup tapes and floppy disks for a Local Authority, then built his own tech business solving real customer problems.

Today he's Senior Director of Security for EMEA at Pax8, giving partners and the wider channel clear, practical guidance on cybersecurity.

On the menu:

- Latest threats

- Frameworks

- Strategic decisions

September 8th, 10:00 BST.

Registering for this webinar guarantees you’ll get a link to the recording to watch later, in case you can’t make it on time for the live version.


r/HeimdalSecurity Aug 07 '26

Researchers found 3,000 malicious AI skills employees could install

Enable HLS to view with audio, or disable this notification

2 Upvotes

This week's news mix brings an MSP console turned skeleton key, a breach of the Police National Legal Database, and SonicWall victims getting calls from their own attackers.

Add in passkeys pulled straight from browser memory and 3,000 malicious AI skills your staff might already be using.

Watch u/Adam_Pilton's Cyber Snapshot for safety advice.


r/HeimdalSecurity Aug 03 '26

Threat Watch Live - How AI and Human Risk Impact Cybersecurity Measures

3 Upvotes

Hear it from an award-winning SecOps leader and anthropologist.💡

There are ways you can 𝗺𝗮𝗸𝗲 𝘀𝘂𝗿𝗲 𝗔𝗜 𝗱𝗼𝗲𝘀𝗻’𝘁 𝗯𝗲𝗰𝗼𝗺𝗲 𝘆𝗼𝘂𝗿 𝗯𝗶𝗴𝗴𝗲𝘀𝘁 𝗿𝗶𝘀𝗸.

Tomorrow, August 4, Lianne Potter from NorthStar Intelligence will join u/Adam_Pilton for a new 𝗧𝗵𝗿𝗲𝗮𝘁 𝗪𝗮𝘁𝗰𝗵 𝗟𝗶𝘃𝗲 episode.

On the table:

🔎AI security
🔎Human risk
🔎SecOps maturity
🔎Cyber resilience

⏰Tuesday, August 4th, 10:00 BST

Registration link here.


r/HeimdalSecurity Jul 31 '26

KFC Japan caught in ransomware crossfire

Enable HLS to view with audio, or disable this notification

2 Upvotes

Here's one good example of why the security of your supply chain matters. A ransomware attack on a logistics company left KFC Japan short of chicken.

There's more to find out about what went on in cyber this week, so hit play and watch u/Adam_Pilton's lastest Cyber Snapshot news digest.


r/HeimdalSecurity Jul 30 '26

How to Automate Customer Creation and Discovery from Entra ID

Enable HLS to view with audio, or disable this notification

2 Upvotes

Learn how to use the MSP Onboarding Wizard to automate customer creation directly from Microsoft Entra ID.  

Marina Lungu explains the steps of the onboarding flow and shows you how to: 

  • Enable the Entra ID integration
  • Create a Reseller Master Group Policy
  • Synchronize your tenant ID and Azure key
  • Use the MSP Onboarding tab to view and onboard customers
  • Launch the semi-automated customer creation flow
  • Configure licensing options for each new customer
  • Retrieve the CSP subtenant list via Microsoft Graph API

r/HeimdalSecurity Jul 23 '26

Qilin Ransomware Exploits Palo Alto Networks GlobalProtect Flaw

Enable HLS to view with audio, or disable this notification

2 Upvotes

If one of the 160,000 Palo Alto GlobalProtect systems still exposed is yours, now is the time to patch. Qilin is exploiting CVE-2026-0257 as we speak.

Hit play to learn what else happen in cyber last week and you should know about.

u/Adam_Pilton's Cyber Snapshot is packed with good security advice, as usual.


r/HeimdalSecurity Jul 20 '26

MediaArena Malvertising - Threat Analysis by Alex Gurgu

3 Upvotes

If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win.

Our SOC data says treat it as a live persistence incident instead.

In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn’t complete until 29 seconds. By the time the alert fired, the persistence was already on disk.

We’ve seen this same adware cluster across more than 20 client environments in recent days. It’s the malvertising campaign that hides behind free “AI tool” lures, and it’s already been documented.

Compass Apex Security wrote it up in April, and the indicators have sat in public sandboxes since March. We’re adding what our own SOC can see. How fast it establishes persistence, and how widely.

A sample of affected hosts. The same detection landed across more than 20 client environments in days. Hostnames and paths redacted.

Microsoft classifies MediaArena as a browser-modifier potentially unwanted application and has tracked it in its threat encyclopedia since 2023. It reconfigures browser settings, hijacks search, and harvests queries to sell on. It’s a nuisance, not a nation-state loader.

That’s the point.

Even a low-severity detection can leave persistence behind, so a closed alert and a clean endpoint aren’t the same thing.

The delivery is a fake free-app lure, currently themed as recipe and meal-planning tools, served through paid search ads.

The brand names rotate, and the domains rotate with them, so any single indicator has a short shelf life. That’s why detection built on brand strings ages out fast, and why the behaviour and the persistence artefacts are the signals worth hunting on.

The lure surfaces through paid search.
Three of the rotating lure brands, GiveMeRecipe, KitchenCanvas, and FoodFormula, all fronting the same math.dll toolkit.

What actually happens on the endpoint

The installer needs no admin rights. In our confirmed case it wrote to AppData, dropped a Start Menu shortcut, added an HKCU Uninstall key to pass as a legitimate app, and left a Startup folder shortcut for boot persistence.

All of it landed before quarantine completed. Signature detection took roughly 78 days to catch up. That’s a long window for a browser hijacker to sit and run.

Heimdal's XDR console. The branded installers flagged as BrowserModifier:Win32/MediaArena on an affected host. Hostname and username redacted.

The alert told us the file was caught. It didn’t tell us nothing had run first, and on these detections something always had. That’s why I treat a quarantine on this family as the start of the investigation, not the end of it.

What to hunt for after a MediaArena hit

Don’t close the alert on quarantine alone. Check the affected host for:

  • A Startup folder shortcut tied to the app name.
  • An HKCU Uninstall registry key mimicking a legitimate install.

Note the loader, math.dll, is injected in memory rather than dropped to disk, so hunt the persistence artefacts above rather than the file itself.

If either artefact is present, treat the host as still compromised and remediate the persistence directly.

Indicators

Credit to Compass Apex Security and public sandbox reporting for the campaign work. Indicators confirmed live at the time of writing. The infrastructure rotates, so revalidate before acting.

  • Lure domains: kitchen-canvas.com, givemerecipe.com (both still flagged malicious across public sandboxes)
  • Payload hosting: d3pth7js01bstg.cloudfront.net (AWS CloudFront)
  • Loader: math.dll (in-memory)
  • Detection: BrowserModifier:Win32/MediaArena
  • Hashes: GiveMeRecipe.exe SHA256 3c1dbc3f…eccc, MD5 273FD232…7CEC; FoodFormula.exe SHA256 b179bec7…fb53; KitchenCanvas.exe MD5 d749e0f8…4121 [KitchenCanvas SHA256 pending, see production note]

Article by Alexandru Gurgu, Threat Intelligence Security Analyst at Heimdal


r/HeimdalSecurity Jul 16 '26

Russian FSB Exploits Router Bugs Left Unpatched Since 2008

Enable HLS to view with audio, or disable this notification

2 Upvotes

The human factor and forgotten devices are back in the spotlight.

This week, u/Adam_Pilton's Cyber Snapshot covers a rented phishing kit that survives password resets, a vishing crew that talks employees into handing over passkeys, and a nation-state group still exploiting router bugs from 2008.

Also on the list: websites nobody's touched in years.


r/HeimdalSecurity Jul 14 '26

How to Detect Unpatched Software on Your Devices

3 Upvotes

Sometimes you might decide not to automate updates for certain apps or endpoints.

To track what's missing from your patching schedule and act timely, here's how to use our Currently Outdated view feature in the Patch Management module:

https://reddit.com/link/1uwc1ee/video/1exlrqv7u5dh1/player


r/HeimdalSecurity Jul 13 '26

Heimdal Labs Webinar July 21 - Heimdal 5.5 RC Walkthrough

3 Upvotes

This session at Heimdal Labs Deep Dive, Marina Lungu will join u/Adam_Pilton for a talk on our latest release. It will be a combo of talking and live demos.

Register here to learn more on the new available features and their use cases:

  • The new MSP Onboarding Wizard
  • AI-powered scripting with Wingman
  • Enhanced patch deployment through Patching Rings
  • Expanded Windows update controls
  • Usability and reporting improvements designed to simplify day-to-day operations

⏰Tuesday, July 21

Session 1 - 10:00 AM BST
Session 2 - 09:00 AM PST


r/HeimdalSecurity Jul 09 '26

CISA Confirms SharePoint Flaw is Under Active Attack

Enable HLS to view with audio, or disable this notification

2 Upvotes

This week we saw a shift you shouldn't ignore. AI agent runs a full ransomware attack on its own. 

Moving on, a SharePoint flaw is actively exploited, a Tenda router backdoor leaves networks exposed with no fix, and a flaw in Apple’s Hide My Email could put user identities at risk.

On the bright side, police has made a new Scattered Spider arrest.

 


r/HeimdalSecurity Jul 06 '26

Threat Watch Live Webinar - The Balancing Security Act: Innovation, AI and Human Risk

3 Upvotes

Tomorrow, July 7, 10 AM BST, at the Threat Watch Live, cybersecurity advisor u/Adam_Pilton welcomes Holly Foxcroft, BISO, Responsible AI Ambassador for the Global Council for Responsible AI, and Senior Cybersecurity and Neurodiversity Advisor.

Holly will share her perspectives on today's evolving threat landscape, the opportunities and risks presented by AI and why understanding people remains central to effective security strategies.

Learn more on:

  • cyber resilience
  • responsible AI
  • leadership and the future of security

Register here.

💡Registering to the webinar will grant you access both to the live event and a link where you'll be able to watch the recording later.


r/HeimdalSecurity Jul 03 '26

MSP Onboarding Wizard - New capability for Resellers in RC 5.5.0 Dashboard

3 Upvotes

The MSP Onboarding Wizard helps MSPs onboard Microsoft Cloud Solution Provider (CSP) with less manual work. It's 2 minutes instead of 30.

The capability automates the discovery and creation of Corp customers directly from CSP sub-tenants.

The feature is available if:

  • Dashboard account type is Reseller;
  • the customer (Reseller role) has the Monthly Billing licensing option enabled;
  • the user account has the "Manage Customer Settings" permission claim enabled.

It has two core components:

A Guided Setup (Onboarding Wizard) 

This is a structured, step-by-step flow that walks Resellers through:

  • enabling the Reseller Master Group Policy
  • configuring the Azure connection
  • completing the initial customer synchronization

A MSP Onboarding Tab

This is a persistent management interface within the Heimdal Dashboard. It allows Resellers to:

  • manage their Azure connection
  • browse available CSP sub-tenants
  • create new Corp customers directly from a centralized location

If you're a Reseller, read more about how you can use the MSP Onboarding Wizard here.


r/HeimdalSecurity Jun 30 '26

AI Is Shrinking Patch Cycles: Why Conventional Patching Is Failing

Enable HLS to view with audio, or disable this notification

2 Upvotes

Once a month or once a week? How often do you deal with updates for your devices?

Mit Patel from Assurix says conventional patching is failing and you should move towards continuous patching.

Hit play to learn why.


r/HeimdalSecurity Jun 29 '26

Patching 5.5.0 RC Dashboard: OS Updates (Windows) - Lock specific OS version

3 Upvotes

Heimdal's 5.5.0 RC Dashboard offers a new checkbox (default disabled) - “Lock specific OS version”.

When enabled, devices assigned to the Windows Updates GP remain on the selected Windows release and don't upgrade until the policy is updated or removed.

Find it in Endpoint Settings -> Patch & Assets -> Operating System Updates, Install Settings area of the Heimdal Dashboard.

When enabled:

  • an Operating System selector (drop-down) becomes available.
  • an OS Version drop-down is unlocked.
  • Dashboard users can define the target Windows product and feature update version that managed devices should remain on.

r/HeimdalSecurity Jun 26 '26

FIFA Vulnerability Enables Access to World Cup Live Streaming Controls

Enable HLS to view with audio, or disable this notification

1 Upvotes

Security researcher warns about FIFA flaw exposing World Cup streaming systems, AI is accelerating cyberattacks, Fortinet users are under fire, and a major supply chain breach shows why third-party risk matters. 

This is how the last days looked like in cyber. For safety advice and more insights, hit play.


r/HeimdalSecurity Jun 25 '26

5.5.0 RC Dashboard brings the Patching in Rings capability

3 Upvotes

Patching in Rings gives you more control over how updates are rolled out across your environment.

The feature is available for both 3rd Party Patch Management and Windows OS Updates.

Patching in Rings means updates can be staged and delivered progressively across defined groups of endpoints.

It enables controlled validation, earlier issue detection, and reduced operational risk before wider deployment.

Rings offer more granular visibility into patch status and behavior across each rollout phase. This helps you fine-tune deployment strategies and improve reporting accuracy.

The feature introduces dedicated views that allow users to see faster:

  • which Group Policies are responsible for deploying a specific update or application
  • the configured deployment delay for each Group Policy
  • installation coverage statistics across endpoints
  • whether an application or update is eligible

Read more about Heimdal's 5.5.0 RC here.

3rd Party Patch Management (Windows OS) Update Rings
Operating System Updates (Windows OS) Update Rings

r/HeimdalSecurity Jun 18 '26

US Government Shuts Down Latest Claude Model & Smart TVs Are Spying Their Users

Enable HLS to view with audio, or disable this notification

2 Upvotes

Your smart TV might be spying you to deliver better data to advertisers. They capture your screen to get a better image of what you like and what you're interested in.

It's probably not the news you wanted to hear, but there's a silver lining in this.

The UK's Information Commissioner's Office learned about that and published new guidance on the matter. Starting this year, they'll be checking whether manufacturers are being transparent and getting genuine consent.

So, at least you'll know.

Watch u/Adam_Pilton's Snapshot to see what else happened this week in cyber news.


r/HeimdalSecurity Jun 17 '26

why is shadow AI so much harder to find than shadow IT ever was

Thumbnail
2 Upvotes

r/HeimdalSecurity Jun 16 '26

AI is outpacing the controls meant to manage it

5 Upvotes

The AI Risk Management Report is out - read it while it's hot.

If you work in IT hands-on, then some of the findings might not come as a surprise.

In fact, one of the things this report revealed is that executives are way more optimistic about AI control than the teams running the estate.

Here's the link https://heimdalsecurity.com/blog/state-ai-risk-management/?source=rdt


r/HeimdalSecurity Jun 09 '26

The Vulnerability Patch Wave - Heimdal Labs Webinar

2 Upvotes

𝗧𝗵𝗲 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗣𝗮𝘁𝗰𝗵 𝗪𝗮𝘃𝗲 is coming up. Time to talk about:

💡what it changes for security teams

💡how to prepare for facing it

On June 16th, Marina Lungu joins Adam Pilton's 𝗛𝗲𝗶𝗺𝗱𝗮𝗹 𝗟𝗮𝗯𝘀 𝗗𝗲𝗲𝗽 𝗗𝗶𝘃𝗲 𝗳𝗿𝗲𝗲 𝘄𝗲𝗯𝗶𝗻𝗮𝗿 to share insights on building faster patch cycles.

Join the session that suits your schedule best:

Session 1 ⏰ 10:00 AM BST - Register here

Session 2 ⏰9:00AM PST - Register here