RESEARCH
Threat Thursday: June 4th, 2026

Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup. This week's stories have a clear pattern: attackers didn't find obscure entry points or novel techniques but instead went after the things you were already using and already trusting. As always, ...
Communicating Risk
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
Value That Converts: Why Your vCSO Pitch Keeps Getting Pushed to IT

You walked out of that meeting feeling like a closer. Your credentials were on point. You covered the whole stack: EDR, SIEM, MDR, quarterly risk assessments, tabletop exercises, NIST alignment. Your vCSO offering was solid. You even had a phased ...
Dark Web Monitoring & Threat Intelligence
Part 2: Congratulations, Your Password Manager Made the News (Again)

If you caught Part 1 last week, you know the shape of what TeamPCP has been running since December 2024: one supply chain campaign, still expanding, with credentials stolen over a year ago still being spent today. Part 2 is ...
Part 1: Congratulations, Your Password Manager Made the News (Again)

You've probably seen the headlines. Bitwarden compromised. Trivy compromised. Checkmarx tools compromised. A handful of other developer tools before that. Each one got its own news cycle, its own advisory, its own "here's what to do if you're affected" post. ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Human Layer Security
The Deepfake Was Convincing. So Was My Backpack.

Why Social Engineering Still Works, Why AI is Making it Sharper, and the One Habit that Stops it In early 2024, an employee at Arup, a global engineering firm, joined a video call with several colleagues, including someone who appeared ...
The Invisible Workforce

The Shadow AI Running Inside Your Clients' Environments and How MSPs Can Get Ahead of It It's Monday morning. A client's controller is on the phone. She spent Friday afternoon cleaning up the vendor list inside their accounting platform's new ...
Your AI Agent Visits Websites on Your Behalf. Attackers Are Leaving It Notes.

The last two years of AI adoption inside businesses have followed a pretty consistent pattern. A team tries a tool, it saves them time, word gets around, and suddenly half the company is using something IT didn't approve. Now those ...
More Articles
Paradise Ransomware Using Internet Query Files To Deliver Payload
The Paradise ransomware is like a bad penny; it just keeps turning up. The strain first appeared back in 2017, when it was spread far and wide via phishing emails. Then it ...
Malware Is Targeting Cookies On Android Devices To Gain Access
There's a new malware threat to be aware of, called "CookieThief," which is an apt name that describes what the malware does. Honestly though, the Hackers missed the mark here. "CookieMonster" would ...
Intel Graphics Get Update To Address Security Issues
If you have a personal computer that uses Intel technology, you're not going to want to miss the update released in March's Patch Tuesday. The latest update addresses a total of 27 ...
Google Chrome Guest Mode Is Great For Shared Computers
Google has recently rolled out a small but important change to its Chrome browser for Windows, Linux and macOS users. The most recent update adds a 'Default to Guest mode' to the ...
Certain RAM Modules Continue To Have Security Vulnerabilities
Remember the Rowhammer vulnerability that made headlines around the world last year? 2019 saw all sorts of unusual threats, so if you're struggling to recall the details of that one in particular, ...
Recent Data Breach Affects Some Walgreens Mobile App Users
Are you a Walgreens customer? Do you make use of the company's mobile app, available for both Android and iOS devices? If so, be advised that the company recently disclosed a serious ...
The Web Browser Wars Have A Clear Winner In 2020
It's notoriously difficult to get reliable statistics on web browser usage. While there are sites that purport to track such things such as StatCounter and NetMarketShare, the numbers coming from these sources ...
T-Mobile Is The Latest To Get Hit By Data Breach
Are you a T-Mobile customer? If so, be advised, the company recently published a Notice of Data Breach on their website to inform all clients that an email vendor they utilize was ...
Phone Call And Text Phishing Scams Are On The Rise
For the last couple of years, the primary means of communication when conducting phishing campaigns has been email. Phishing emails have been absolutely rampant. So much so that people are increasingly on ...
New Phishing Emails Trick Users With Convincing Security Credentials
Unit 42 is a research division of Palo Alto Networks. Their researchers have discovered a sneaky and surprisingly effective phishing campaign that appears to have been launched in January of this year ...
Facebook Is Fighting Back Against Spam Accounts
Unless you're plugged into the world of social media, you may not realize it. There's a war on, and until recently, it was a war that Facebook was losing. The war is ...
JCrew Retailer Customers May Have Had Information Accessed
Another week, another data breach. This time, the target being US clothing retailer J. Crew. The company announced that sometime in April of 2019, an unknown group of hackers utilized a credential ...


