Pantropic Newsletter #54

Posted May 19, 2026

by Sarah





 

Pantropic Newsletter #54 (March 2026)

 

 

 

CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability

 

Actively exploited SharePoint vulnerabilities are giving attackers direct access to critical business data and collaboration systems. Once compromised, these platforms can expose sensitive documents, internal communications, and user credentials that support day-to-day operations. SharePoint’s central role in many organizations makes it a high-impact entry point for lateral movement and data exfiltration. Organizations should confirm patches are applied, restrict unnecessary external access, and monitor for unusual activity across collaboration environments. Now is the time to review your patching timelines and access controls to reduce exposure to fast-moving exploitation campaigns.

(Source: Securityweek)

 

 

LEARN MORE INFO
 
Image from gstudioimagen1 on Freepik

 

 

 

On-device threats jump 16.2% to 3.8 million in 2025

 

A sharp rise in device-based threats is expanding the attack surface faster than many organizations can track or secure. With 38 million threats recorded in 2025, attackers are increasingly targeting endpoints, mobile devices, and connected systems that often lack consistent visibility and protection. These gaps allow threats to bypass traditional defenses and spread across environments unnoticed. Organizations should ensure all connected devices are accounted for, enforce consistent security policies, and strengthen endpoint monitoring capabilities. Reviewing device visibility and control now can help prevent overlooked systems from becoming entry points for attackers.

(Source: Singapore Business Review)

 

 

LEARN MORE INFO
 

Veeam warns admins to patch now as critical RCE flaws hit Backup & Replication

 

Unpatched vulnerabilities in backup systems are creating direct opportunities for attackers to compromise recovery infrastructure. Critical remote code execution flaws in Veeam Backup and Replication allow attackers to take control of systems designed to restore operations after an incident. In many self-managed environments, delays in patching create a persistent patch gap that attackers can exploit before fixes are applied. This leaves backup systems exposed at the exact moment they are needed most. Organizations should reassess patch timelines, access controls, and monitoring around backup infrastructure. Moving to a managed backup approach can help close this gap and ensure systems remain protected against evolving threats.

(Source: CSO Online)

 

 

LEARN MORE INFO
 

Sophos fixed critical vulnerabilities in its firewall product

 

Delayed patching in perimeter security systems can leave organizations exposed to active exploitation. Critical vulnerabilities in Sophos firewalls highlight the risks of relying on traditional patch cycles, where updates must be manually applied and systems may remain unprotected in the meantime. Firewalls are a primary line of defense, and any delay in remediation increases the likelihood of unauthorized access. In contrast, cloud-native platforms like CrowdStrike operate on an evergreen model with continuous updates that reduce dependency on manual patching. Organizations should evaluate whether their current security tools can respond fast enough to emerging threats. If you are interested to learn more about modern, continuously updated security approaches, reach out to us for a no-obligation discussion.

(Source: Security Affairs)

 

 

LEARN MORE INFO
 

To view our past newsletter editions, click here. 

 

 

 

 

 

 

 
Backup and Cybersecurity Solutions Offered by Pantropic

 

 

ATEGO® ENTERPRISE
This “white glove” managed service is the next generation secure offsite backup you need right now. We monitor your backups daily, help you troubleshoot any problems, and can assist you with restorations when you need it. Our Data Security Module can perform bi-directional anti-malware scans, content disarm and reconstruction (CDR), and protect your backups with biometric Deep MFA and multi-person workflow, crucial in stopping stolen credential attacks.
CROWDSTRIKE FALCON
A next-generation endpoint protection platform using AI and machine learning to effectively stop breaches, featuring true NGAV, powerful endpoint detection and response (EDR), threat intelligence management, and built-in automation. It delivers real-time visibility, rapid threat hunting, lightweight cloud-native performance, and seamless scalability to secure complex environments with speed and confidence.
Leading desktop and laptop backup solution providing automated and continuous data backup protection with unlimited capacity backup licensing and flexible deployment options. 
World’s largest security awareness training platform with simulated phishing attacks, educating and empowering employees to strengthen IT security against cybercriminals.
GET IN TOUCH

 

 
Copyright © 2026 Pantropic Online Pte Ltd. All rights reserved.