Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]

A cybersecurity report identified 143 managed service providers (MSPs), IT service providers, and telecommunication companies as ransomware victims in 2025. Phishing was responsible for 52% of initial access incidents, while unpatched vulnerabilities accounted for 27%. In response, a six-point checklist has been proposed for MSPs to enhance ransomware protection and accelerate recovery.
The checklist emphasizes that comprehensive ransomware protection extends beyond mere backup solutions or endpoint detection without a defined recovery strategy. It integrates prevention, detection, response, and recovery, requiring MSPs to verify each control against specific tenant, workload, storage, and service tier configurations.
The first point is to reduce exposure. This involves establishing service level agreements (SLAs) for patching based on severity and enforcing multi-factor authentication (MFA) for management portals and remote access. It also requires separating backup and security administration to prevent a compromised technician account from altering protection or deleting recovery points. Acronis Cyber Protect Cloud, for example, offers vulnerability assessment, patch management, URL filtering, and role-based administration to support these measures.
Second, detection across the attack lifecycle is crucial. MSPs should conduct controlled behavioral tests to confirm that actionable incidents are generated before widespread encryption occurs. This includes verifying endpoint isolation and the client's required response actions for identity, email, and Microsoft 365. Acronis Active Protection and EDR provide endpoint behavioral analysis, while Acronis XDR extends visibility to email, identity, and Microsoft 365.
Third, a 24/7 response capability is essential. This requires confirming who monitors, investigates, contains, and contacts clients after hours, testing escalation paths, and documenting approval requirements for actions. Acronis MDR offers 24/7/365 monitoring and response, with full remediation actions available in its Advanced tier.
Fourth, preserving recovery points is critical, utilizing access-separated, immutable, and, where necessary, offline copies. MSPs should attempt deletion with compromised credentials to verify retention, alerts, and storage policy changes. Acronis Cyber Protect Cloud supports immutable backup storage designed to protect recovery points from malicious removal.
Fifth, clean recovery involves selecting a known-good point, scanning it, restoring it in isolation, rebuilding dependencies in order, and validating the application. MSPs should record achieved recovery point objective (RPO) and recovery time objective (RTO) rather than just backup job success. Acronis Cyber Protect Cloud can scan backups for malware-free recovery, and Acronis Disaster Recovery can coordinate failover and recovery workflows.
Finally, consistent operation across tenants is necessary. This means applying standard policies without compromising client requirements, testing role separation, cross-tenant visibility, reporting, API access, and RMM/PSA handoffs while preventing cross-tenant exposure. Acronis provides multi-tenant management, centralized reporting, and RMM/PSA integrations within its Cyber Protect Cloud platform.
The report also clarifies the roles of various security technologies. Endpoint Detection and Response (EDR) monitors endpoint activity for investigation, isolation, and remediation. Extended Detection and Response (XDR) integrates endpoint signals with other attack surfaces like email and identity to provide a unified incident view. Managed Detection and Response (MDR) adds human expertise for round-the-clock investigation and response. Immutable backup protects recovery points but does not detect data theft or eliminate breach notification obligations. These tools are most effective when used together.
A recovery runbook is recommended to reduce recovery time by streamlining each stage of the incident response process, especially handoffs between different teams. Key steps include declaring the incident, assigning a commander, isolating compromised systems, preserving evidence, closing entry points, and restoring from a validated clean recovery point. Automation can remove repeatable delays, but high-impact actions should still be approved by an incident commander.
While immutable backup can preserve recoverability, it does not address data exfiltration in double-extortion ransomware attacks. Therefore, a comprehensive protection service must look for data theft and identity abuse before encryption. This involves correlating telemetry from endpoints, identity systems, email, Microsoft 365, DNS, proxies, and egress points. During response, devices should be isolated, sessions and tokens revoked, credentials rotated, attacker destinations blocked, and evidence preserved.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed