DFIR

LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses

LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses 2026-05-05 at 17:00 By Explore the latest trends, techniques, and procedures (TTPs) our incident response (IR) experts are actively facing with the TTP Briefing Q1 2026, a report built on frontline threat intelligence from our global incident response investigations across LevelBlue. This article is an excerpt

LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses Read More »

Incident Response Retainers Are Now Foundational to Cyber Resilience

Incident Response Retainers Are Now Foundational to Cyber Resilience 2026-04-30 at 17:35 By LevelBlue has been named a Representative Service Provider in the Gartner® Market Guide for Cybersecurity Incident Response Retainer Services (CIRR), marking the fifth consecutive time the company has been included in the report. We believe this continued recognition reflects LevelBlue’s ongoing focus

Incident Response Retainers Are Now Foundational to Cyber Resilience Read More »

Solving Four Common Incident Response Mistakes That Delay Containment and Drive Up Costs

Solving Four Common Incident Response Mistakes That Delay Containment and Drive Up Costs 2026-04-24 at 19:10 By Devon Ackerman Organizations often lose precious hours and sometimes millions of dollars because they lack a well-defined and tested incident response plan. In many cases, response roles are loosely defined and disconnected from key stakeholders, including digital forensics

Solving Four Common Incident Response Mistakes That Delay Containment and Drive Up Costs Read More »

The Exploit Window Collapse: Claude Mythos and the Future of Incident Response

The Exploit Window Collapse: Claude Mythos and the Future of Incident Response 2026-04-11 at 02:20 By Devon Ackerman Every so often, something comes along that forces you to recalibrate how you think about cyber risk. Not incrementally, but fundamentally. Claude Mythos feels like one of those moments. This article is an excerpt from LevelBlue Blog

The Exploit Window Collapse: Claude Mythos and the Future of Incident Response Read More »

LevelBlue Resilience Retainer Named 2026 SC Media Awards Europe Finalist for Best Incident Response Solution

LevelBlue Resilience Retainer Named 2026 SC Media Awards Europe Finalist for Best Incident Response Solution 2026-04-07 at 20:32 By LevelBlue is proud to share that we’ve been shortlisted as a finalist for the2026 SC Media Awards Europe for our recently launchedResilience Retainer, recognized in the Best Incident Response Solution category. This article is an excerpt from

LevelBlue Resilience Retainer Named 2026 SC Media Awards Europe Finalist for Best Incident Response Solution Read More »

LevelBlue Takes Home Twin 2026 Global Info Sec Awards

LevelBlue Takes Home Twin 2026 Global Info Sec Awards 2026-03-23 at 16:13 By LevelBlue is proud to announce thatCyber Defense Magazine has named it the winner of its Global InfoSec Awards 2026 for TrailblazingManaged Security Service Provider (MSSP) and Market DisruptorThreat Detection, Incident Response, Hunting and Triage Platform. This article is an excerpt from LevelBlue Blog View

LevelBlue Takes Home Twin 2026 Global Info Sec Awards Read More »

Executive Tabletop Exercises: From Compliance Exercise to Revenue Protection Strategy

Executive Tabletop Exercises: From Compliance Exercise to Revenue Protection Strategy 2026-03-19 at 16:56 By Anthony Abell Executive tabletop exercises are commonly positioned as cyber incident rehearsals. They tend to focus on breach containment decisions, regulatory notification timelines, and communications planning. Those elements are necessary; however, they are not what ultimately defines the true risk to

Executive Tabletop Exercises: From Compliance Exercise to Revenue Protection Strategy Read More »

The Resilience Retainer: Incident Response Retainers, Reimagined

The Resilience Retainer: Incident Response Retainers, Reimagined 2026-03-03 at 19:46 By Too many organizations today still rely on “legacy” retainer models. These traditional contracts are often rigid, opaque, and reactive, and designed for a world that no longer exists. This article is an excerpt from LevelBlue Blog View Original Source

The Resilience Retainer: Incident Response Retainers, Reimagined Read More »

Identity & Beyond: 2026 Incident Response Predictions

Identity & Beyond: 2026 Incident Response Predictions 2026-01-14 at 17:43 By Jamie Mamroe In 2026, incident response (IR) will continue its shift away from traditional malware-centric investigations toward identity-driven intrusions, abuse of trusted cloud services, and low-signal, high-impact activity that blends seamlessly into normal business operations. Rather than relying on technical exploits, threat actors are

Identity & Beyond: 2026 Incident Response Predictions Read More »

SpiderLabs Ransomware Tracker Update October 2025: Qlin Doubles Down on Attacks

SpiderLabs Ransomware Tracker Update October 2025: Qlin Doubles Down on Attacks 2025-11-04 at 17:18 By The worldwide ransomware landscape saw a dramatic shift in attacks in October 2025, jumping 41% month over month, with the most prolific attacker, Qlin, more than doubling the number of attacks it launched, according to Trustwave, A LevelBlue Company, research.

SpiderLabs Ransomware Tracker Update October 2025: Qlin Doubles Down on Attacks Read More »

SpiderLabs Ransomware Tracker Update September 2025: Qilin, Akira Top Ransomware Attackers

SpiderLabs Ransomware Tracker Update September 2025: Qilin, Akira Top Ransomware Attackers 2025-09-30 at 16:00 By The threat groups Qilin and Akira together conducted about one-quarter of the 402 ransomware attacks tracked by Trustwave SpiderLabs in September, with the manufacturing and technology sectors receiving the brunt of these efforts. This article is an excerpt from Trustwave

SpiderLabs Ransomware Tracker Update September 2025: Qilin, Akira Top Ransomware Attackers Read More »

Why DFIR: A Guide to Digital Forensics and Incident Response Services and Retainers

Why DFIR: A Guide to Digital Forensics and Incident Response Services and Retainers 2025-09-15 at 16:17 By Digital Forensics and Incident Response (DFIR) services are a critical part of a proactive plan to combat inevitable security incidents, helping organizations minimize damage and recover quickly. From preparation and identification to containment and recovery, a solid incident

Why DFIR: A Guide to Digital Forensics and Incident Response Services and Retainers Read More »

How Curtin University Partnered with Trustwave Managed Detection and Response

How Curtin University Partnered with Trustwave Managed Detection and Response 2025-09-12 at 21:36 By With cybersecurity threats targeting higher education growing in sophistication and frequency, Australia’s Curtin University recognized the need to strengthen its visibility into potential attacks, maximize the effectiveness of its internal resources, and build new layers of resilience across its digital environment.

How Curtin University Partnered with Trustwave Managed Detection and Response Read More »

Chinese-Sponsored Threat Actors Attacks Spur International Security Advisory

Chinese-Sponsored Threat Actors Attacks Spur International Security Advisory 2025-09-04 at 16:18 By When nearly two dozen of the world’s leading cybersecurity agencies issue a joint warning, it underscores the severity and the global reach of the threat at hand. This article is an excerpt from Trustwave Blog View Original Source

Chinese-Sponsored Threat Actors Attacks Spur International Security Advisory Read More »

Trustwave Named as a Representative Vendor in the 2025 Gartner® Market Guide for DFIR Retainer Services

Trustwave Named as a Representative Vendor in the 2025 Gartner® Market Guide for DFIR Retainer Services 2025-07-31 at 20:36 By Trustwave is proud to announce that Gartner has named us as a Representative Vendor in the 2025 Gartner® Market Guide for Digital Forensics and Incident Response (DFIR) Retainer Services. This article is an excerpt from

Trustwave Named as a Representative Vendor in the 2025 Gartner® Market Guide for DFIR Retainer Services Read More »

The Breach Beyond the Runway: Cybercriminals Targeted Qantas Through a Trusted Partner

The Breach Beyond the Runway: Cybercriminals Targeted Qantas Through a Trusted Partner 2025-07-04 at 15:34 By Nikita Kazymirskyi On July 3, 2025, Qantas confirmed in an update statement that a cyber incident had compromised data from one of its contact centers, following the detection of suspicious activity on June 30. The breach didn’t strike at the heart

The Breach Beyond the Runway: Cybercriminals Targeted Qantas Through a Trusted Partner Read More »

Dire Wolf Strikes: New Ransomware Group Targeting Global Sectors

Dire Wolf Strikes: New Ransomware Group Targeting Global Sectors 2025-06-25 at 01:04 By Nathaniel Morales Dire Wolf is a newly emerged ransomware group first observed in May 2025 and Trustwave SpiderLabs recently uncovered a Dire Wolf ransomware sample that revealed for the first time key details about how the ransomware operates. This article is an

Dire Wolf Strikes: New Ransomware Group Targeting Global Sectors Read More »

Deep Dive: A DFIR Case Study in Hospitality

Deep Dive: A DFIR Case Study in Hospitality 2025-05-22 at 16:03 By Phishing in Hospitality: Real-world case study reveals how QR codes and fake e-signatures target hotel employees. Inside a Hotel Cyberattack: Learn DFIR tactics used to analyze and respond to phishing attempts against hospitality targets. Protect your Hospitality Business: Actionable insights from a 2024 phishing case study

Deep Dive: A DFIR Case Study in Hospitality Read More »

It’s Time to Prepare as Scattered Spider Spreads Its Web to the US

It’s Time to Prepare as Scattered Spider Spreads Its Web to the US 2025-05-19 at 22:08 By DFIR: Enhance your cybersecurity resilience with Trustwave’s DFIR retainer services, offering rapid response, priority handling, and cost-efficient solutions to manage digital forensics and incident response effectively. Offensive Security: Protect retail operations against emerging threats like Scattered Spider with Trustwave’s Offensive

It’s Time to Prepare as Scattered Spider Spreads Its Web to the US Read More »

Scroll to Top