<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Heimdal Security Blog</title>
	<atom:link href="https://heimdalsecurity.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>A blog about all things internet security</description>
	<lastBuildDate>Wed, 22 Jul 2026 15:52:54 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>How to choose the best SOC platform in 2026 (and our top 4)</title>
		<link>https://heimdalsecurity.com/blog/best-soc-platforms/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 15:52:54 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87941</guid>

					<description><![CDATA[<p>Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. There are many cybersecurity tools that an SOC can use, and there are many vendors selling comparable products. The [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/best-soc-platforms/">How to choose the best SOC platform in 2026 (and our top 4)</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/best-soc-platforms/soc-featured-image-selection/</image><subtitle></subtitle>	</item>
		<item>
		<title>MediaArena malvertising: why a quarantine isn&#8217;t the end of the incident</title>
		<link>https://heimdalsecurity.com/blog/media-arena-malvertising-report/</link>
		
		<dc:creator><![CDATA[Alexandru Gurgu]]></dc:creator>
		<pubDate>Fri, 17 Jul 2026 08:41:38 +0000</pubDate>
				<category><![CDATA[Threat center]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87918</guid>

					<description><![CDATA[<p>If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn&#8217;t complete until 29 seconds. By the time the alert fired, [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/media-arena-malvertising-report/">MediaArena malvertising: why a quarantine isn&#8217;t the end of the incident</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/media-arena-malvertising-report/mediaarena-blog-cover/</image><subtitle>By Alexandru Gurgu, Threat Intelligence Security Analyst, Heimdal</subtitle>	</item>
		<item>
		<title>Top 6 Managed Detection and Response Providers</title>
		<link>https://heimdalsecurity.com/blog/top-managed-detection-response-providers/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 12:57:58 +0000</pubDate>
				<category><![CDATA[MXDR]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87867</guid>

					<description><![CDATA[<p>There are several major managed detection and response (MDR) companies to choose from. We&#8217;ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a security team stretched too thin and drowning in alerts from dozens of tools. Whatever [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/top-managed-detection-response-providers/">Top 6 Managed Detection and Response Providers</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/top-managed-detection-response-providers/mdr-featured-image/</image><subtitle></subtitle>	</item>
		<item>
		<title>Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors </title>
		<link>https://heimdalsecurity.com/blog/customers-raising-bar-msps/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 09:19:02 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87843</guid>

					<description><![CDATA[<p>Your client is no longer just buying your security advice. They’re auditing whether you live by it.  That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators.  Heather’s exactly the kind of customer MSPs should be paying attention to. She’s informed, commercially minded, and willing to challenge vendors to [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/customers-raising-bar-msps/">Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors </a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/customers-raising-bar-msps/heather-macdonald-interview-for-msps/</image><subtitle></subtitle>	</item>
		<item>
		<title>How to scale your patches without scaling your team (the patch wave)</title>
		<link>https://heimdalsecurity.com/blog/how-scale-patches-without-scaling-team/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 15:30:53 +0000</pubDate>
				<category><![CDATA[Patch management]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87827</guid>

					<description><![CDATA[<p>Most breaches don&#8217;t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the first time in the 19-year history of Verizon&#8217;s Data Breach Investigations Report, with 31% of breaches now [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/how-scale-patches-without-scaling-team/">How to scale your patches without scaling your team (the patch wave)</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/how-scale-patches-without-scaling-team/patch-wave-featured/</image><subtitle></subtitle>	</item>
		<item>
		<title>AI didn&#8217;t break patching. It showed us patching was already broken.</title>
		<link>https://heimdalsecurity.com/blog/ai-showed-patching-broken/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 11:14:49 +0000</pubDate>
				<category><![CDATA[Patch management]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87821</guid>

					<description><![CDATA[<p>Claude Mythos, an AI model from Anthropic, has found 23,019 software vulnerabilities in the past month. Fewer than 1% of them have been patched. That gap is the story. Finding a vulnerability used to be the hard part, the thing that limited how fast software got fixed. AI just closed that gap to almost nothing. [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/ai-showed-patching-broken/">AI didn&#8217;t break patching. It showed us patching was already broken.</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/ai-showed-patching-broken/patch-wave-featured-1200x628/</image><subtitle></subtitle>	</item>
		<item>
		<title>Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes</title>
		<link>https://heimdalsecurity.com/blog/heimdal-msp-onboarding-wizard/</link>
		
		<dc:creator><![CDATA[Madalina Popovici]]></dc:creator>
		<pubDate>Wed, 01 Jul 2026 07:55:36 +0000</pubDate>
				<category><![CDATA[All things Heimdal]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[press release]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87805</guid>

					<description><![CDATA[<p>COPENHAGEN, Denmark, 1 July 2026 &#8211; Heimdal today announced the launch of MSP Onboarding Wizard, a new capability that helps managed service providers onboard Microsoft Cloud Solution Provider (CSP) customers inside the Heimdal platform faster and with less manual work. Built for MSPs managing multiple Microsoft tenants, MSP Onboarding Wizard reduces customer onboarding from around [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/heimdal-msp-onboarding-wizard/">Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/heimdal-msp-onboarding-wizard/heimdal-msp-onboarding-wizard-2/</image><subtitle>New feature reduces manual setup, speeds up customer activation, and helps MSPs scale Microsoft CSP estates with less operational work.</subtitle>	</item>
		<item>
		<title>How Dynamic Defense shuts an attacker out without shutting down the business</title>
		<link>https://heimdalsecurity.com/blog/how-dynamic-defense-shuts-attacker-out/</link>
		
		<dc:creator><![CDATA[Morten Kjaersgaard]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 15:49:14 +0000</pubDate>
				<category><![CDATA[Endpoint security]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87796</guid>

					<description><![CDATA[<p>AI has handed hackers a resource advantage. Winning it back means spending your own resources far more precisely, and that&#8217;s the strategy we call Dynamic Defense. The principle is simple. Contain the threat just enough, for just long enough, until the risk is removed. This piece shows how that works as a five-stage loop that [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/how-dynamic-defense-shuts-attacker-out/">How Dynamic Defense shuts an attacker out without shutting down the business</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/how-dynamic-defense-shuts-attacker-out/dynamic-defense-featured-image/</image><subtitle></subtitle>	</item>
		<item>
		<title>Static security has run out of road. The case for Dynamic Defense</title>
		<link>https://heimdalsecurity.com/blog/case-dynamic-defense/</link>
		
		<dc:creator><![CDATA[Morten Kjaersgaard]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 10:10:38 +0000</pubDate>
				<category><![CDATA[Endpoint security]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87789</guid>

					<description><![CDATA[<p>AI has flipped the economics of cybersecurity in the attacker&#8217;s favor. For most of the last decade, defenders held the cost advantage, buying down their risk with a stack of largely static controls. That advantage is gone, and winning it back is the central problem facing every security team in 2026. I think the answer [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/case-dynamic-defense/">Static security has run out of road. The case for Dynamic Defense</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/case-dynamic-defense/featured-image-3/</image><subtitle></subtitle>	</item>
		<item>
		<title>Breaking the MSP Echo Chamber: The Power of Community</title>
		<link>https://heimdalsecurity.com/blog/msp-community-breaking-echo-chamber/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 11:46:03 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87772</guid>

					<description><![CDATA[<p>MSPs spend too much time talking to other MSPs and not enough time talking to the people they&#8217;re supposed to serve.  That’s Paul Croker’s view of some of the channel’s biggest growth problems.   While most industry events bring technology professionals together, they rarely put them in the same room as the business leaders making [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/msp-community-breaking-echo-chamber/">Breaking the MSP Echo Chamber: The Power of Community</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/msp-community-breaking-echo-chamber/new-blog-cover-7-3/</image><subtitle>An Interview with Paul Croker</subtitle>	</item>
		<item>
		<title>How attackers built a RAT on a Windows machine using its own .NET compiler</title>
		<link>https://heimdalsecurity.com/blog/how-attackers-built-rat-windows-machine-net-compiler/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 14:37:39 +0000</pubDate>
				<category><![CDATA[Latest threats]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87765</guid>

					<description><![CDATA[<p>In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/how-attackers-built-rat-windows-machine-net-compiler/">How attackers built a RAT on a Windows machine using its own .NET compiler</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/how-attackers-built-rat-windows-machine-net-compiler/heimdal-compiler-rat-featured-1/</image><subtitle></subtitle>	</item>
		<item>
		<title>Attacker enables RDP, creates admin, erases evidence in ten seconds</title>
		<link>https://heimdalsecurity.com/blog/attacker-enables-rdp-admin-erases-evidence-seconds/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 08:28:46 +0000</pubDate>
				<category><![CDATA[Latest threats]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87754</guid>

					<description><![CDATA[<p>At 06:34am on 2 June 2026, an attacker logged on to a customer&#8217;s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.  The intrusion reached 34 endpoints and was over in under ten seconds.  Heimdal Extended Threat Protection (XTP) and Ransomware [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/attacker-enables-rdp-admin-erases-evidence-seconds/">Attacker enables RDP, creates admin, erases evidence in ten seconds</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/attacker-enables-rdp-admin-erases-evidence-seconds/10-second-to-full-persistance-featured-image-2/</image><subtitle></subtitle>	</item>
		<item>
		<title>The State of AI Risk Management in 2026</title>
		<link>https://heimdalsecurity.com/blog/state-ai-risk-management/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 07:00:15 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87617</guid>

					<description><![CDATA[<p>Key findings US executives are more than four times as confident as their own practitioners that AI risk is under control, 29% to 7%. The UK gap runs the same direction, 18% to 11%. The board&#8217;s view and the team&#8217;s view aren&#8217;t the same view. ChatGPT sits in 7 in 10 IT estates and Microsoft [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/state-ai-risk-management/">The State of AI Risk Management in 2026</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/state-ai-risk-management/ai-risk-management-report/</image><subtitle>1,000 IT professionals say AI is outpacing the controls meant to manage it.</subtitle>	</item>
		<item>
		<title>Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It</title>
		<link>https://heimdalsecurity.com/blog/heimdal-ai-risk-management-survey-executive-confidence-gap/</link>
		
		<dc:creator><![CDATA[Madalina Popovici]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 12:52:53 +0000</pubDate>
				<category><![CDATA[All things Heimdal]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[press release]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87745</guid>

					<description><![CDATA[<p>London, UK, 16 June 2026 &#8211; Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report&#8217;s headline finding is a divide inside the same organizations: the closer a person sits to the day-to-day running of AI, the less [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/heimdal-ai-risk-management-survey-executive-confidence-gap/">Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/heimdal-ai-risk-management-survey-executive-confidence-gap/the-state-of-ai-risk-management-press-release-visual/</image><subtitle>New Heimdal research shows AI adoption is moving faster than security controls, exposing a confidence gap between executives and IT teams.</subtitle>	</item>
		<item>
		<title>Your Next Insider Threat May Be an AI Coworker</title>
		<link>https://heimdalsecurity.com/blog/insider-threat-ai-coworker/</link>
		
		<dc:creator><![CDATA[Madalina Popovici]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 15:09:41 +0000</pubDate>
				<category><![CDATA[Cybersecurity interviews]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87723</guid>

					<description><![CDATA[<p>Heimdal sysadmin Alex Panait spent weeks testing Claude Cowork inside the company. His verdict was blunt. It felt like onboarding a junior employee with no manager, no scoped access, and no clear accountability when something goes wrong. Except this one can delete your SharePoint. That is the uncomfortable reality behind autonomous AI desktop assistants. They [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/insider-threat-ai-coworker/">Your Next Insider Threat May Be an AI Coworker</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/insider-threat-ai-coworker/your-next-insider-threat-may-be-an-ai-coworker-2/</image><subtitle></subtitle>	</item>
	</channel>
</rss>
