<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Heimdal Security Blog</title>
	<atom:link href="https://heimdalsecurity.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>A blog about all things internet security</description>
	<lastBuildDate>Thu, 03 Sep 2026 12:59:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>
	<item>
		<title>Shift Browser is signed adware that fingerprints your endpoint before it drops payload</title>
		<link>https://heimdalsecurity.com/blog/shift-browser-signed-adware-fingerprints-endpoint-before-payload/</link>
		
		<dc:creator><![CDATA[Alexandru Gurgu]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 12:25:11 +0000</pubDate>
				<category><![CDATA[Advanced malware researches]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Forensics and threat hunting]]></category>
		<category><![CDATA[Threat center]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88334</guid>

					<description><![CDATA[<p>Heimdal&#8217;s SOC flagged a surge in detections tied to a program called Shift Browser on 2 September 2026. Our team confirmed activity on more than 50 client environments in a single day. The installers we captured trace to a malvertising lure. Shift Browser also runs a documented paid creator and affiliate marketing operation, though we [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/shift-browser-signed-adware-fingerprints-endpoint-before-payload/">Shift Browser is signed adware that fingerprints your endpoint before it drops payload</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/shift-browser-signed-adware-fingerprints-endpoint-before-payload/shift-browser-is-signed-adware-that-fingerprints-your-endpoint-before-it-drops-payload/</image><subtitle></subtitle>	</item>
		<item>
		<title>6 ThreatLocker alternatives that should make your shortlist</title>
		<link>https://heimdalsecurity.com/blog/threatlocker-alternatives/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 12:56:02 +0000</pubDate>
				<category><![CDATA[Comparisons]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88315</guid>

					<description><![CDATA[<p>There are a few reasons that MSPs start looking for ThreatLocker alternatives. You might have had enough of the friction with end users. The high levels of admin required to set policies for your different customers. Or that, while powerful, it can only handle certain kinds of security risks.  If so, we wrote this guide [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/threatlocker-alternatives/">6 ThreatLocker alternatives that should make your shortlist</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/threatlocker-alternatives/threatlocker-alternatives/</image><subtitle></subtitle>	</item>
		<item>
		<title>50+ insider threat statistics for 2026</title>
		<link>https://heimdalsecurity.com/blog/insider-threat-statistics/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 15:00:30 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88301</guid>

					<description><![CDATA[<p>In 2026, insider threats are probably a bigger risk than you think. In fact, they could cost your organization $19.5 million a year. But it’s not really a problem with hackers, spies, or malicious employees. Instead, it’s about negligence, training, and IT privileges. Often, the most expensive mistake is a stolen credential doing exactly what [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/insider-threat-statistics/">50+ insider threat statistics for 2026</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/insider-threat-statistics/insider-threats-statistics-2/</image><subtitle>Negligence, AI blind spots, and containment measures against insider threats</subtitle>	</item>
		<item>
		<title>The Planting Seeds philosophy. Selling into schools takes years, not quarters</title>
		<link>https://heimdalsecurity.com/blog/msp-school-sales/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 06:44:59 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88292</guid>

					<description><![CDATA[<p>It&#8217;s tempting for MSPs to write off event sponsorship in education as a waste of money. You sponsor an event, hand out flyers, follow up with an email, and hear nothing back. Rick Cowell says you&#8217;re judging it on the wrong timescale. Rick spent 20 years as a school network manager, and he founded the [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/msp-school-sales/">The Planting Seeds philosophy. Selling into schools takes years, not quarters</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/msp-school-sales/msps-schools/</image><subtitle></subtitle>	</item>
		<item>
		<title>What the DfE&#8217;s cyber security update means for multi-academy trusts</title>
		<link>https://heimdalsecurity.com/blog/dfe-cyber-standard-education-heimdal/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 17:13:59 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88275</guid>

					<description><![CDATA[<p>Before dawn on 10 July 2024, one ransomware attack took down ten schools inside the same multi-academy trust at once. Every control that eventually stopped it was something the Department for Education&#8217;s own cyber security standard already asked for, well before the attack. That&#8217;s a case DfE has published on its own Cyber Security Hub, [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/dfe-cyber-standard-education-heimdal/">What the DfE&#8217;s cyber security update means for multi-academy trusts</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/dfe-cyber-standard-education-heimdal/dfe-mat-featured-image-2c/</image><subtitle>MFA and patching just became all or nothing for every trust</subtitle>	</item>
		<item>
		<title>9 Proofpoint alternatives. Pros &#038; cons of the leading options</title>
		<link>https://heimdalsecurity.com/blog/proofpoint-alternatives/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 09:27:17 +0000</pubDate>
				<category><![CDATA[Comparisons]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88261</guid>

					<description><![CDATA[<p>Proofpoint catches malicious traffic and blocks data exfiltration well, with solid coverage for business email compromise, phishing, and malware. But it&#8217;s built for the enterprise, and it shows. G2 reviewers flagged a steep learning curve and steep pricing, and suggested Proofpoint’s support would need improving. The platform&#8217;s also in flux. Proofpoint closed a $1.8 billion [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/proofpoint-alternatives/">9 Proofpoint alternatives. Pros &#038; cons of the leading options</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/proofpoint-alternatives/proofpoint-alternatives/</image><subtitle></subtitle>	</item>
		<item>
		<title>The risk awareness radar. A superpower every MSP needs to train</title>
		<link>https://heimdalsecurity.com/blog/build-risk-awareness-radar/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Thu, 06 Aug 2026 15:28:45 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88015</guid>

					<description><![CDATA[<p>Most of the cyber incidents landing on our desks these days start with someone believing a lie. It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make people hand over exactly what the attacker needs. Last week I talked [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/build-risk-awareness-radar/">The risk awareness radar. A superpower every MSP needs to train</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/build-risk-awareness-radar/risk-awareness/</image><subtitle></subtitle>	</item>
		<item>
		<title>Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes</title>
		<link>https://heimdalsecurity.com/blog/mediaarena-adware-persistence-antivirus-quarantine/</link>
		
		<dc:creator><![CDATA[Madalina Popovici]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 12:49:55 +0000</pubDate>
				<category><![CDATA[All things Heimdal]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[press release]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87993</guid>

					<description><![CDATA[<p>London, UK, 30 July 2026 &#8211; New data from Heimdal&#8217;s telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine. The same pattern has been confirmed across more than 40 client environments. MediaArena is a browser-modifier adware family that Microsoft has tracked since 2023. It is low-severity, and that is [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/mediaarena-adware-persistence-antivirus-quarantine/">Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/mediaarena-adware-persistence-antivirus-quarantine/heimdal-data-reveals-mediaarena-adware-completes-persistence-before-antivirus-quarantine-finishes-blog/</image><subtitle>Heimdal&#8217;s Threat Intelligence team directly measured, using its own telemetry, the timeline of a real infection.</subtitle>	</item>
		<item>
		<title>How Heimdal grew from a bold idea into a global cybersecurity platform</title>
		<link>https://heimdalsecurity.com/blog/how-heimdal-grew-global-cybersecurity-platform/</link>
		
		<dc:creator><![CDATA[Morten Kjaersgaard]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 08:32:57 +0000</pubDate>
				<category><![CDATA[All things Heimdal]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87972</guid>

					<description><![CDATA[<p>Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a challenge. Could they create something that could identify vulnerabilities, intercept malicious activity and help protect machines before threats could take hold? That technology went on to compete at the Defcon CTF world [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/how-heimdal-grew-global-cybersecurity-platform/">How Heimdal grew from a bold idea into a global cybersecurity platform</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/how-heimdal-grew-global-cybersecurity-platform/heimdal-and-brigantia-ten-year-partnership-2/</image><subtitle></subtitle>	</item>
		<item>
		<title>MediaArena malvertising: why a quarantine isn&#8217;t the end of the incident</title>
		<link>https://heimdalsecurity.com/blog/media-arena-malvertising-report/</link>
		
		<dc:creator><![CDATA[Alexandru Gurgu]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 08:21:38 +0000</pubDate>
				<category><![CDATA[Threat center]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87918</guid>

					<description><![CDATA[<p>If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn&#8217;t complete until 29 seconds. By the time the alert fired, [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/media-arena-malvertising-report/">MediaArena malvertising: why a quarantine isn&#8217;t the end of the incident</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/media-arena-malvertising-report/mediaarena-blog-cover/</image><subtitle>By Alexandru Gurgu, Threat Intelligence Security Analyst, Heimdal</subtitle>	</item>
		<item>
		<title>Tools Change. Teach People How to Keep Up</title>
		<link>https://heimdalsecurity.com/blog/ai-strategy-insights-joe-head/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 14:51:27 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87960</guid>

					<description><![CDATA[<p>&#8220;Make everyone one percent better and it compounds across the team.&#8221; That&#8217;s the line Joe Head wrote about his own job and when I read it back to him, he didn&#8217;t hesitate. &#8220;That is 100% the objective,&#8221; he said. Joe runs AI adoption for an 80-person team as the only AI automation specialist in the [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/ai-strategy-insights-joe-head/">Tools Change. Teach People How to Keep Up</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/ai-strategy-insights-joe-head/ai-strategy-insights/</image><subtitle>Why MSP Leaders Should Refuse to Build Their AI Strategy Around Any Single Tool</subtitle>	</item>
		<item>
		<title>4 Best Managed EDR Solutions &#038; Service Suppliers (and how to choose)</title>
		<link>https://heimdalsecurity.com/blog/best-managed-edr-services/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 10:25:54 +0000</pubDate>
				<category><![CDATA[EDR]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87948</guid>

					<description><![CDATA[<p>There are several cybersecurity companies that offer managed EDR services in 2026. Here&#8217;s what actually separates them, and who each one suits. Most successful cyber attacks begin with a breached laptop, a smartphone or a server. Over the past 15 years, endpoint detection and response (EDR) has gone from niche to a mainstream security solution. [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/best-managed-edr-services/">4 Best Managed EDR Solutions &#038; Service Suppliers (and how to choose)</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/best-managed-edr-services/edr-featured-image-selection/</image><subtitle></subtitle>	</item>
		<item>
		<title>Top 4 Best SOC Platforms 2026 &#8211; Provider Comparison</title>
		<link>https://heimdalsecurity.com/blog/best-soc-platforms/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 15:52:54 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87941</guid>

					<description><![CDATA[<p>Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. There are many cybersecurity tools that an SOC can use, and there are many vendors selling comparable products. The [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/best-soc-platforms/">Top 4 Best SOC Platforms 2026 &#8211; Provider Comparison</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/best-soc-platforms/soc-featured-image-selection/</image><subtitle></subtitle>	</item>
		<item>
		<title>Top 6 Best Managed Detection and Response Providers 2026</title>
		<link>https://heimdalsecurity.com/blog/top-managed-detection-response-providers/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 12:57:58 +0000</pubDate>
				<category><![CDATA[MXDR]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87867</guid>

					<description><![CDATA[<p>There are several major managed detection and response (MDR) companies to choose from. We&#8217;ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a security team stretched too thin and drowning in alerts from dozens of tools. Whatever [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/top-managed-detection-response-providers/">Top 6 Best Managed Detection and Response Providers 2026</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/top-managed-detection-response-providers/mdr-featured-image/</image><subtitle></subtitle>	</item>
		<item>
		<title>Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors </title>
		<link>https://heimdalsecurity.com/blog/customers-raising-bar-msps/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 09:19:02 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87843</guid>

					<description><![CDATA[<p>Your client is no longer just buying your security advice. They’re auditing whether you live by it.  That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators.  Heather’s exactly the kind of customer MSPs should be paying attention to. She’s informed, commercially minded, and willing to challenge vendors to [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/customers-raising-bar-msps/">Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors </a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/customers-raising-bar-msps/heather-macdonald-interview-for-msps/</image><subtitle></subtitle>	</item>
	</channel>
</rss>
