Anatomy of a Phishing-to-BEC Campaign Revealed by One Inbox Rule
A suspicious inbox rule exposed an account compromise before it became a larger incident.
Read Analysis →Company news, AIR releases, customer outcomes, and insights from the BitLyft SOC.
A suspicious inbox rule exposed an account compromise before it became a larger incident.
Read Analysis →Reinstalling an operating system can remove many forms of malware, but it does not necessarily eliminate threats embedded deeper in a device. Firmware-level attacks can compromise components below the operating system and potentially persist through traditional recovery procedures.
Read more →SIM swap fraud can allow attackers to hijack a victim's phone number and intercept authentication codes intended to protect sensitive accounts. When SMS is used as an MFA channel, control of the number can turn a trusted security measure into an attack path.
Read more →Cybersecurity teams are under pressure to detect threats faster, respond with more consistency, and protect more environments without endlessly expanding headcount. For managed service providers, that pressure is even greater. MSPs must support multiple clients, different tools, varied risk profiles, and nonstop alert volume.
Read more →Active Directory remains a high-value target because compromised identities can provide attackers with pathways to sensitive systems and privileged access. Kerberoasting is one technique defenders must recognize, but effective detection requires visibility into a much broader range of identity abuse.
Read more →Security operations teams are being asked to do more with less. Cloud environments keep expanding, endpoints are everywhere, identities are under constant attack, and security tools generate more alerts than most teams can realistically review.
Read more →Red teaming and penetration testing both help organizations uncover security weaknesses before attackers exploit them, but they answer different questions. Choosing the right assessment depends on whether the priority is finding vulnerabilities or testing the effectiveness of the broader security program.
Read more →Energy and utilities companies operate some of the most critical infrastructure in the country. Power providers, water systems, gas utilities, renewable energy operators, and grid-connected organizations all depend on secure, reliable technology to keep services running.
Read more →Cyber asset management provides organizations with a clearer understanding of the devices, applications, cloud resources, identities, and other technology assets operating across their environments. As infrastructure becomes increasingly distributed, security teams cannot effectively protect systems they do not know exist.
Read more →Higher education institutions face cybersecurity challenges unlike those in most other industries. Universities must protect sensitive student records, research data, financial systems, healthcare information, cloud applications, and sprawling campus networks, often with limited security staff and complex user environments.
Read more →Attack surface reduction helps organizations minimize the systems, services, identities, and access points attackers can exploit. Reducing unnecessary exposure makes complex environments easier to defend and limits opportunities for compromise.
Read more →Every security team's day starts the same way. Open the platform. Try to figure out what's happening right now and how you're doing overall. Try to spot the thing that needs attention before someone asks. BitLyft AIR® v1.30 is all about visibility. This release gives your team a faster, clearer read on what's happening across your environment. It rebuilds the AIR® Overview into a metrics-driven operational home, introduces Custom Dashboards so you can build the views that matter most to you, and makes multi-tenant notifications easier to triage by putting the tenant name front and center. A Redesigned Overview We rebuilt the Overview from the ground up into the operational home for your security program. Instead of a configurable grid of widgets, it now opens on a curated, metrics-first view of how your operation is performing over whatever time range you choose. Quick toggles switch between the last 24 hours, 7 days, 30 days, or a custom range in a single click. A live "last updated" indicator and on-demand refresh keep the picture current. Key metrics, at a glance: Total Cases: case volume across the selected period MTTD: mean time to detect MTTI: mean time to investigate (new) MTTR: mean time to respond Auto-Resolved Rate: the share of cases resolved automatically, so you can see how much work AIR® is taking off your team's plate (new) These headline metrics are now consolidated into a single, clean row, replacing the separate manual and automated tiles, so the numbers that matter are the first thing you see. Below the metrics, three views bring the detail into focus: Cases Breakdown: see how your cases are distributed, and switch the dimension on the fly between Conclusion, Status, Severity, and Integration to answer different questions from the same widget. Cases Created: a daily trend of new cases, stacked by conclusion, so spikes and patterns are easy to spot. Recent Cases: your newest cases with creation time, status, severity, and the investigation verdict, each linking straight through to full Case Management. The result is an Overview that answers "how are we doing right now?" the moment you land on it. No report-building required. Custom Dashboards With the Overview now curated for you, the build-your-own flexibility gets a dedicated home. New in v1.30, Custom Dashboards let you assemble your own views of AIR® data. Create standalone widgets from live queries, pull from a library of existing widgets, and arrange them into dashboards tailored to your team. A SOC operations board. An executive summary. A tenant-specific view. Global filters let you scope an entire dashboard at once, so every widget reflects the same slice of your environment. It's the flexibility to make AIR® show you exactly what you need to see. Tenant Names in Notifications Email notification subjects and in-app notification titles now include the tenant name. For MSPs and teams managing multiple tenants, that means you can tell which environment a notification is about at a glance, right from your inbox or the notification panel, before you even open it. Less context-switching. Faster triage. One of those small changes your analysts will feel every single day. Built for the Way Your Team Actually Works Together, the three additions in v1.30 give your team: A curated Overview that shows how you're performing without any setup Custom Dashboards for the views your team actually needs Multi-tenant notifications that tell you which tenant they're about, up front More clarity. Less setup. And for MSPs, a noticeably cleaner workflow across every tenant you manage. Learn More To see the redesigned Overview, Custom Dashboards, and multi-tenant notifications in your environment, book a 15-minute walkthrough. Book a Demo
Read more →Secrets sprawl occurs when passwords, API keys, tokens, certificates, and other credentials become scattered across source code, repositories, CI/CD pipelines, and cloud environments. Left unmanaged, these hidden secrets can become easy targets for attackers.
Read more →Cybersecurity teams are surrounded by more information than ever before. Endpoints, cloud applications, identity platforms, email systems, and network technologies continuously generate security events. While this visibility is essential, it creates another challenge: security professionals must determine which signals represent genuine threats and respond before attackers can cause significant damage.
Read more →Browser security protection has become increasingly important as web browsers serve as a primary gateway to cloud applications, email, collaboration platforms, financial systems, and other critical business resources. Employees spend much of their workday inside browsers, giving cybercriminals opportunities to target users through phishing pages, malicious websites, compromised extensions, and credential theft.
Read more →The biggest problem facing modern security teams is not necessarily a lack of security technology. Many organizations already have endpoint protection, identity security, cloud monitoring, email security, SIEM, and other defensive tools generating information around the clock. The harder problem is turning all of those signals into decisions quickly enough to stop an attack.
Read more →Digital risk protection helps organizations identify and respond to external cyber threats that can damage brand reputation, compromise customers, or expose sensitive business information. As companies expand their presence across websites, social platforms, cloud services, mobile applications, and other digital channels, attackers gain more opportunities to impersonate trusted brands and target their audiences.
Read more →Cyber asset management provides organizations with a clearer understanding of the devices, applications, cloud resources, identities, and other technology assets operating across their environments. As infrastructure becomes increasingly distributed, security teams cannot effectively protect systems they do not know exist.
Read more →Manufacturing cybersecurity has changed dramatically as production environments have become more connected. Equipment that once operated independently is now linked to business applications, cloud platforms, remote access tools, industrial networks, and digital supply chains. These connections help manufacturers increase productivity and gain better operational visibility, but they also create more opportunities for cyber threats to reach critical systems.
Read more →Higher education security teams are being asked to protect environments that were never designed to operate like traditional enterprises. Universities support thousands of identities, unmanaged student devices, cloud applications, research systems, remote faculty access, SaaS platforms, and campus infrastructure—all while keeping those environments open enough to support learning and collaboration.
Read more →Healthcare organizations have embraced digital transformation to improve patient care, streamline clinical operations, and support better collaboration across hospitals, clinics, and specialty care providers. Electronic Health Records (EHRs), connected medical devices, telehealth platforms, cloud applications, and remote work have become essential to modern healthcare delivery. While these technologies improve efficiency, they also create new opportunities for cybercriminals to target one of the world's most critical industries.
Read more →Higher education has always been built on openness. Universities encourage collaboration between students, faculty, researchers, and industry partners while providing access to digital resources from virtually anywhere. This open environment fuels innovation, but it also creates one of the most challenging cybersecurity landscapes of any industry.
Read more →Cyber exposure management has become an important part of modern security strategy as organizations struggle to keep track of growing attack surfaces, cloud environments, identities, vulnerabilities, and third-party connections. Traditional vulnerability management often focuses on individual weaknesses, but exposure management takes a broader view of how those weaknesses combine to create real business risk.
Read more →Cybersecurity teams are under constant pressure to detect threats faster while managing an ever-growing volume of alerts. As organizations expand their cloud environments, embrace hybrid work, and deploy connected devices, traditional Security Operations Centers (SOCs) are struggling to keep pace. Security analysts spend valuable time investigating routine alerts, leaving less capacity for complex threats that require expert attention.
Read more →Most security leaders can tell you what they're paying for managed detection and response services. Far fewer can tell you, with confidence, whether those services are actually making their organization safer.
Read more →AI model security has become an increasingly important cybersecurity priority as organizations integrate artificial intelligence into applications, workflows, customer experiences, and business operations. While AI systems can improve efficiency and decision-making, they also introduce security risks that differ from those affecting traditional software.
Read more →Healthcare organizations are rapidly adopting digital technologies such as electronic health records (EHRs), cloud applications, connected medical devices, telehealth platforms, and AI-driven tools to improve patient care. While these innovations enhance efficiency, they also expand the attack surface for cybercriminals.
Read more →Session hijacking prevention is an important component of modern cybersecurity because attackers do not always need to steal a user's password to gain unauthorized access. By obtaining or manipulating an active session token, a threat actor may be able to impersonate an authenticated user and access applications, accounts, or sensitive information.
Read more →Cloud identity governance has become a critical component of modern cybersecurity as organizations continue migrating applications, workloads, and data to cloud environments. With identities serving as the primary security perimeter, organizations must ensure that users, devices, and applications receive only the access they need while continuously validating every access request.
Read more →AR VR cybersecurity has become an important consideration as augmented reality (AR) and virtual reality (VR) technologies gain wider adoption across healthcare, manufacturing, education, retail, entertainment, and enterprise collaboration. These immersive platforms collect and process significant amounts of user, device, and environmental data, creating new cybersecurity and privacy challenges.
Read more →Attack path analysis has become an essential cybersecurity practice for organizations seeking to understand how attackers could move through their environments to reach critical systems and sensitive data. Rather than evaluating individual vulnerabilities in isolation, attack path analysis examines how multiple weaknesses, misconfigurations, identities, and permissions can be combined to achieve a successful compromise.
Read more →Security teams today are drowning in alerts, stretched thin on headcount, and racing against attackers who move faster every year. Traditional Managed Detection and Response (MDR) models, built around human analysts triaging every alert one by one, are starting to buckle under this pressure. That is where Agentic MDR Services come in—a new approach that puts autonomous AI agents at the center of detection, investigation, and response while working alongside human experts instead of replacing them.
Read more →Cybersecurity regulations compliance has become a significant business responsibility as organizations collect more sensitive information and operate across increasingly complex digital environments. Regulatory requirements can affect how businesses protect data, manage cybersecurity risks, respond to incidents, and demonstrate that appropriate security controls are in place.
Read more →Security operations are changing faster than ever before. Organizations are generating more security data, expanding their cloud environments, supporting hybrid workforces, and adopting new technologies that continuously increase the complexity of cyber risk. While security tools have become more advanced, many security teams still struggle with the same challenge—making sense of thousands of alerts quickly enough to stop real attacks.
Read more →AI fraud detection systems are changing how organizations identify and respond to financial fraud. Traditional fraud controls often rely on predefined rules that flag transactions based on known patterns. While these controls remain valuable, sophisticated fraud can evolve quickly and may not match established indicators.
Read more →The last few BitLyft AIR® releases added a lot of new capability. Custom Policies gave teams the ability to build their own detection logic. Ask Noah brought plain-English search and case investigation to every analyst. Case Investigations started reviewing every new case the moment it's created. Each of these features gets more powerful the more of your environment AIR® can see.
Read more →SaaS security controls have become increasingly important as organizations rely on cloud-based applications for communication, collaboration, data storage, finance, and other critical business functions. While software-as-a-service platforms provide flexibility and scalability, they also expand the number of identities, integrations, and data repositories that security teams must protect.
Read more →Security teams are under more pressure than ever. Alert queues keep growing, skilled analysts are hard to find, and attackers are moving faster than manual processes can keep up with. Traditional security operations centers, which depend on analysts working through alerts one at a time, are struggling to keep pace. Autonomous Security Operations offer a different path forward—one where AI agents handle the bulk of detection and investigation, and human experts focus on the decisions that actually need their judgment.
Read more →Higher education institutions are built on collaboration, innovation, and open access to information. Students connect from residence halls, faculty work remotely, researchers share data globally, and administrative staff rely on cloud-based applications to keep campus operations running smoothly. While this connected environment supports learning and discovery, it also creates one of the most complex cybersecurity landscapes of any industry.
Read more →Virtual machines are a fundamental component of modern cloud infrastructure, giving organizations the flexibility to deploy applications, scale computing resources, and support distributed operations without maintaining every workload on physical hardware. However, that flexibility also introduces security responsibilities that organizations must address throughout the virtual machine lifecycle.
Read more →Last week, BitLyft's SOC identified and contained a multi-account phishing campaign that escalated into classic business email compromise (BEC) evasion behavior. The pattern was consistent, the timing was tight, and one detection signal made all the difference. Here is what we saw and what it means for your own defenses.
Read more →Cybersecurity regulations are playing a larger role in how businesses manage data, technology, vendors, and risk. Organizations across industries are facing growing expectations to protect sensitive information, document security practices, respond to incidents, and demonstrate that reasonable safeguards are in place.
Read more →Ransomware remains one of the most disruptive cybersecurity threats facing modern organizations. An attack can encrypt critical files, interrupt business operations, and create significant financial and operational consequences. While prevention and detection remain essential parts of a strong security program, organizations must also prepare for the possibility that ransomware successfully reaches important systems.
Read more →Financial institutions have long been among the most targeted organizations for cyberattacks. Banks, credit unions, investment firms, insurance providers, and fintech companies manage vast amounts of sensitive financial and personal data, making them attractive targets for ransomware groups, credential theft campaigns, business email compromise, and insider threats.
Read more →Managed Service Providers (MSPs) are under increasing pressure to deliver cybersecurity services that can keep pace with today's evolving threat landscape. Clients expect continuous monitoring, rapid incident response, and proactive threat detection, yet many MSPs face the challenge of meeting these expectations with limited security resources. As organizations continue adopting cloud services, remote work, and connected technologies, the volume of security data has grown beyond what manual security operations can efficiently manage.
Read more →Insider trading cybersecurity focuses on protecting confidential financial information that could be exploited for illegal trading or competitive advantage. Organizations in financial services, publicly traded companies, legal firms, and advisory organizations routinely handle market-sensitive information that must remain confidential until officially disclosed.
Read more →Manufacturing has entered a new era of digital transformation. Smart factories, Industrial Internet of Things (IIoT) devices, cloud-connected production systems, robotics, and remote maintenance have created more efficient operations—but they have also expanded the attack surface for cybercriminals.
Read more →Cybersecurity has become one of the fastest-growing services offered by Managed Service Providers (MSPs), but client expectations have evolved just as quickly. Businesses no longer want security providers that simply generate alerts—they expect rapid investigations, continuous monitoring, actionable recommendations, and measurable improvements to their overall security posture. At the same time, regulatory requirements continue to expand, requiring organizations to demonstrate stronger visibility into their environments and maintain detailed evidence of security activities.
Read more →Security automation response has become a critical capability for organizations facing increasingly sophisticated cyber threats and growing volumes of security alerts. Manual investigation and response processes often struggle to keep pace with today's attack landscape, allowing threats to remain active for longer periods.
Read more →On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements, the assessment phase that would have required many defense contractors to pass a third-party certification before winning or keeping contracts. That phase was scheduled to take effect on November 10, 2026. For a lot of companies in the Defense Industrial Base, the news probably felt like a reprieve.
Read more →Dark web monitoring security has become an important component of proactive cybersecurity as organizations work to identify threats before they lead to security incidents. Cybercriminals frequently use dark web marketplaces and forums to sell stolen credentials, distribute malware, exchange attack techniques, and advertise compromised data.
Read more →For media inquiries, interview requests, company boilerplate, and approved brand assets.
See how autonomous response and expert-led MDR can strengthen your operation.
Request a Demo →