- Comparitech Stack Report
- Posts
- Ransomware Is Now Trying to Blind Security Teams Before Attacking
Ransomware Is Now Trying to Blind Security Teams Before Attacking
Streamline identity threat detection and response
ADAudit Plus helps protect your identity infrastructure with capabilities like change auditing, logon tracking, privileged user monitoring, file auditing, attack surface analysis, user behavior analytics, response automation, backup and recovery, and compliance reporting across Active Directory, Entra ID, file systems, and more.
🔎 Cyber Watch 🔎
Ransomware Is Now Trying to Blind Security Teams Before Attacking
Researchers uncovered new activity from the Gentlemen ransomware operation, which appears to be investing heavily in custom “EDR killer” tooling designed to disable endpoint detection and response systems before encryption begins. Instead of relying only on malware execution, attackers are attempting to remove the systems meant to stop them first.
The development highlights a broader pattern in ransomware operations: more time spent on defense evasion and pre-attack preparation. Organizations that rely heavily on a single detection layer may face growing pressure to strengthen visibility across identities, networks, and endpoints.
Key takeaways
Ransomware groups are expanding beyond encryption into active security disruption.
Endpoint protection alone may not stop modern attacks.
Security teams should monitor for unusual service stoppages and tampering attempts.
Layered detection and response models continue to gain importance.
🎙️ Tech Briefing On‑Air 🎙️
Why Great Security Leaders Need More Than Technical Expertise
In Episode 192 of Cybersecurity Where You Are, CIS leaders Sean Atkinson and Tony Sager speak with Marcus Sachs, Senior Vice President and Chief Engineer at CIS, about a challenge that becomes more visible as careers progress: technical expertise alone does not create effective leadership.
One of the strongest themes from the discussion is the role of communication. Sachs explains that analogies and simple explanations can help technical teams connect with non-technical audiences and improve decision-making. The conversation also explores leadership maturity, particularly the ability to coordinate across teams, communicate upward with discipline, and understand when detail adds value versus when it creates noise.
Takeaways
Clear communication increases the impact of technical expertise.
Leadership maturity often shows through cross-functional coordination.
Knowing what to communicate is as important as technical accuracy.
Hybrid work environments require more intentional mentoring and knowledge transfer.
Strong security leaders continue learning beyond technology into business operations.
🤝 Partner Intel 🤝
ManageEngine ADAudit Plus
Identity remains one of the most targeted parts of enterprise infrastructure, and visibility gaps continue to slow detection and investigations. ADAudit Plus is designed to provide auditing, monitoring, reporting, and alerting across Active Directory, Windows environments, file servers, and hybrid identity environments.
Key Features
Tracks identity and configuration changes in real time.
Supports compliance reporting and audit readiness.
Adds visibility into privileged access and user activity.
Helps security teams shorten investigation time.
🤖 AI Runtime 🤖
AI Is Changing How Security Buyers Make Decisions, And MSSPs Have an Opening
AI is reshaping more than cyber threats and defenses. It is also changing how organizations evaluate and purchase security technology. New research highlighted by MSSP Alert shows that buyers are moving faster, reviewing vendors more often, and placing greater emphasis on measurable outcomes, integration, and AI readiness.
The report suggests that security leaders are becoming less loyal to existing providers and more willing to reassess their stacks. A large share of organizations plan to increase cybersecurity investment, while many are also considering changing providers to improve threat response and strengthen protection around AI systems. For managed security service providers (MSSPs), this creates a near-term opportunity to compete on clarity, operational simplicity, and business value rather than feature lists alone.
📊 By the Numbers 📊

Source: KPMG
🗳️ Your Monday Take 🗳️
Cast your vote on our weekly poll.
Which cybersecurity signal would concern you the most if it appeared tomorrow morning? |
📩 We’ll share the results in the Friday issue.
|
Until Wednesday’s edition - Let’s keep that zero-day count at zero!
