06/10/2026
Most ransomware attacks don't start with ransomware.
They start with a successful login.
A compromised VPN account.
A legitimate username.
A valid password.
And in one case investigated by our SOC, only 7 minutes separated initial access from attempted lateral movement.
The attacker didn't need to break in.
They logged in.
Our latest article walks through how SIEM detections identified malicious SSL VPN authentications early enough to stop the intrusion before it became a much bigger problem.
The timeline is eye-opening.
Read the full investigation
https://hubs.ly/Q04kWvG50