Skip to content

Meet5 & NordLayer Case Study

Meet5’s Security Transformation: Securing a Hybrid Workforce with NordLayer

Executive Brief: Meet5, a rapidly growing social networking platform, successfully consolidated its fragmented network and VPN infrastructure by implementing NordLayer. The transition eliminated critical security gaps, empowered a distributed workforce, and reduced administrative security management to just one hour per week.

The Context: Scaling a Modern Social Platform

Founded in Germany in 2017, Meet5 is a social networking app designed to bring people together through small group activities. The platform has experienced explosive growth, expanding its user base to over 3.5 million across North America and Europe, while its internal team scaled from 30 to more than 75 employees.

Operating primarily out of a Frankfurt hub with a hybrid schedule, Meet5 also relies on a network of remote engineers scattered across Europe. As the team distributed, the need for a robust, business-grade VPN to safely access corporate resources became paramount.

The Challenge: Fragmented Defenses and Shared Credentials

Prior to integrating NordLayer, Meet5’s security architecture was heavily decentralized. Engineering pods relied on disparate private VPNs, managing their own infrastructure access in silos. This fragmented approach led to a highly insecure practice: sharing static login credentials via a password manager.

This environment suffered from severe visibility blind spots and inherent security vulnerabilities. Meet5 required a unified, enterprise-grade VPN that could provide centralized oversight, support multiple gateways, and utilize dedicated IP addresses to cleanly segment different user groups.

“Our previous infrastructure was fundamentally flawed from a security perspective. Because each team managed their own VPNs and simply shared logins via a password manager, we completely lacked the tracking and granular control necessary for a scaling company.”

— Viktor Mogurenko, Cybersecurity Engineer at Meet5


The NordLayer Solution

Tasked with finding a scalable solution, Viktor Mogurenko evaluated various platforms using insights from G2 and Gartner. NordLayer emerged as the ideal candidate, offering an optimal blend of budget-friendly pricing, enterprise-grade features, and seamless infrastructure compatibility. To ensure operational stability, Meet5 initiated a rigorous two-month pilot program with 20 users before greenlighting a company-wide deployment.

Core Operational Benefits

  • Benefit 1: Unified Access & Centralized Control: Meet5 replaced a messy web of multiple vendors with NordLayer. By mapping dedicated IPs to specific user groups, the company eliminated risky credential sharing. Viktor now commands total network visibility from a single dashboard, enforcing mandatory VPN usage for remote staff and ensuring developer environments remain entirely hidden from the public internet.
  • Benefit 2: Frictionless Onboarding: Deploying NordLayer across the entire organization took only a few hours. Today, onboarding is as simple as sending an automated email invite. The new hire clicks the link, installs the client, and connects. This efficiency has slashed Viktor’s administrative burden to approximately one hour per week.
  • Benefit 3: Advanced Perimeter Defenses: With engineers working across borders, Meet5 leverages NordLayer’s advanced access controls. Country restrictions automatically block login attempts from unauthorized geographic regions. Furthermore, Always-On VPN and Kill Switch protocols guarantee that no data is accidentally exposed if a local internet connection drops.

Measurable Impact & Results

After more than a year of utilizing NordLayer, Meet5 has drastically modernized its security posture. The transition provided several distinct operational advantages:

Operational AreaResult with NordLayer
Network Visibility100% centralized oversight of all network endpoints via a single admin console.
ScalabilityFrictionless addition of new users and groups as the startup continues to grow.
Regulatory ComplianceStreamlined adherence to strict European data privacy frameworks, including GDPR and NIS2.
Cost EfficiencyAffordable enterprise-level security that acts as a financial safeguard against catastrophic data breaches.

Expert Cybersecurity Advice for Growing Startups

Based on his experience securing Meet5, Viktor Mogurenko offers three actionable strategies for scaling businesses:

  1. Implement Architecture Early: Do not wait for enterprise scale to adopt enterprise tools. Rolling out security protocols is infinitely easier for a team of 5 than it is for a team of 75.
  2. Allocate Dedicated Budgets: Reserve at least 15% of your IT budget exclusively for cybersecurity. This financial buffer is critical for quickly adapting to new compliance regulations like NIS2.
  3. Embrace “Invisible” ROI: Understand that the best security is silent. If your protective tools are functioning correctly, you will never truly feel their impact—until an incident is successfully neutralized.

Ready to centralize your hybrid team’s security?

Stop wrestling with fragmented VPNs and shared credentials. Discover how NordLayer can streamline your network access and secure your workforce.

Explore NordLayer’s enterprise plans and book your personalized demo today.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Keepit Backup & Recovery for Autodesk Forma

Safeguarding Autodesk Forma: Keepit’s Dedicated Backup & Recovery Solution

The AEC Lifeline: For the Architecture, Engineering, and Construction (AEC) sector, Autodesk Forma (formerly Autodesk Construction Cloud) is indispensable. It houses the critical blueprints, cost data, RFIs, issues logs, and transmittals that keep projects on track. Even a momentary loss of data access translates directly to stalled construction sites. Keepit steps in as the industry’s first enterprise SaaS data protection platform to offer independent backup and recovery for Forma, ensuring your operations survive the unexpected.

The Reality of Shared Responsibility

Like the majority of enterprise SaaS providers, Autodesk operates on a shared responsibility model. They guarantee the infrastructure, but you own the data. Relying solely on native capabilities during a platform-wide incident simply won’t keep your projects afloat.
Autodesk’s Responsibility (The Platform) Your Responsibility (The Data)
Securing and operating the core platform Retaining data long-term, beyond active subscription periods
Managing infrastructure resilience and uptime Recovering from mass permission errors or botched integrations
Replicating data across their own storage facilities Maintaining independent, off-site backup copies
Providing basic “Deleted Items” recovery Meeting strict business continuity and disaster recovery (DR) mandates

Why Native Tools Aren’t Enough

Forma is the central nervous system for information you absolutely cannot afford to lose. Version histories map the evolution of drawings, while issue logs track defects straight through to resolution. If this reference material vanishes—due to accidental modification, upstream infrastructure events, or platform outages—work grinds to a halt. Beyond daily operations, this data serves as a vital compliance ledger. For highly regulated construction enterprises, these records are mandatory for audit readiness, regulatory compliance, and fulfilling contractual obligations. Missing data doesn’t just cause delays; it invites legal and financial consequences. While Autodesk Forma does offer a basic trash bin and version history during an active subscription, it lacks essential enterprise features: it cannot perform point-in-time restores, it doesn’t allow for custom retention policies, and it provides no long-term, off-platform archiving. If an incident occurs, you are entirely at the mercy of the provider’s recovery timeline.

The Keepit Advantage: True Independent Protection

Keepit eliminates these vulnerabilities by backing up your project data entirely outside of the SaaS provider’s ecosystem. Deploying Keepit for Autodesk Forma guarantees:
  • Uncompromised Independence: Your backup data resides on Keepit’s proprietary, vendor-neutral cloud. Because it is completely decoupled from Autodesk’s environment, your business continuity is mathematically guaranteed.
  • Set-and-Forget Automation: Enjoy two automated snapshots every single day by default, complete with fully customizable retention policies. Say goodbye to manual, error-prone data exports.
  • Comprehensive Data Coverage: Keepit secures the full spectrum of your workspace, including users, companies, projects, sheets (and their version histories), complex folder structures, file packages, transmittals, and issue logs complete with comments and attachments.
  • Precision Point-in-Time Recovery: Every snapshot acts as a complete, time-indexed replica of your environment, granting you full access to your data even during a severe platform outage.

Unified Defense Across Your SaaS Portfolio

Keepit doesn’t just stop at Autodesk; it provides a fortified last line of defense across your entire SaaS ecosystem. Currently supporting 17 major applications—ranging from project management hubs to source code repositories—Keepit simplifies the complex task of securing enterprise data. For construction firms orchestrating massive, multi-party projects within Autodesk Forma, Keepit effortlessly bridges the gap between Autodesk’s native features and your organization’s rigorous business continuity requirements.

Ready to secure your project data?

Explore the full capabilities of our independent backup solution.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Beyond RMM: Why MSPs Need True Layered Security

The RMM Illusion: Why Managed Service Providers Must Evolve Their Security Stack

The Bottom Line

  • A False Sense of Security: RMM platforms are designed for operational hygiene, not comprehensive threat detection.
  • The Attack Surface Has Shifted: Cybercriminals now bypass endpoints entirely, focusing on cloud infrastructure, identities, and email.
  • The Hunter Becomes the Hunted: Due to their massive level of privileged access, RMM tools are now prime targets for supply-chain attacks.
  • The Missing Link: True protection requires a layered approach, augmenting RMMs with EDR, ITDR, and cloud-native security protocols.

The Reality of RMM “Built-In” Security

For most Managed Service Providers (MSPs), Remote Monitoring and Management (RMM) platforms are the beating heart of daily operations. Over time, these platforms have absorbed basic security features: antivirus deployment, patch management, script automation, and baseline policy checks. While incredibly useful, this bundling creates a dangerous illusion that security is “handled.” The hard truth is that these features are rooted in IT operations, not cybersecurity. They excel at ensuring a device is updated and configured correctly. However, they are completely blind to a hijacked Microsoft 365 session, a sophisticated Business Email Compromise (BEC) campaign, or stolen credentials floating on the dark web. RMM security is a hygiene layer, not an active defense mechanism.

Three Reasons RMMs Fall Short Today

1. Blind Spots in the Modern Attack Chain

Today’s threat actors rarely bother breaking into a heavily patched endpoint when they can simply log in. According to Microsoft’s 2025 Digital Defense Report, identity-centric attacks spiked by 32%, with password-based attacks making up a staggering 97% of those incidents. Because RMMs are inherently device-centric, an attacker manipulating email forwarding rules or bypassing MFA in a cloud tenant remains completely invisible to the MSP.

2. Escalating Compliance and Insurance Mandates

The regulatory and insurance landscape has fundamentally shifted. Frameworks like SOC 2 and HIPAA, alongside cyber insurance underwriters, now demand concrete proof of proactive detection and response capabilities. Checking a box for “patch management” is no longer enough. Failure to implement advanced controls can be catastrophic; IBM’s 2025 Cost of a Data Breach Report highlights a $10.22 million average breach cost in the US—a death knell for most SMBs.

3. The Need for Cross-Vector Correlation

RMMs lack the ability to connect the dots. A sophisticated attack might start with a phishing email, pivot to a compromised identity, and end with a malicious payload. Because RMMs only monitor the device, they force security teams to investigate isolated fragments of an attack. True defense requires multi-tenant visibility that correlates events across all environments before the infection spreads.

The RMM Vulnerability Paradox

Ironically, the tool MSPs use to protect clients has become a highly lucrative attack vector. Compromising a single client is a minor win; compromising an MSP’s RMM grants keys to the entire kingdom.
  • The 2026 Verizon DBIR noted a terrifying 240% year-over-year surge in threat actors weaponizing RMM tools, while traditional malware use dropped by 27%.
  • Supply Chain Math: Intruding upon one MSP tool can yield dozens, or hundreds, of downstream victims.
  • Cloaked in Legitimacy: RMM agents are whitelisted and trusted. When hackers hijack them, their malicious activities blend seamlessly into normal administrative traffic, effortlessly bypassing traditional security scans.

Understanding the Structural Flaws

The Security Gap The Root Cause The Real-World Risk
Basic Endpoint Detection Bundled AV relies on outdated signature models, lacking behavioral analysis for fileless attacks. Modern ransomware bypasses these checks without triggering a single alert.
Zero Identity Threat Detection RMMs watch hardware, not human behavior or SaaS logins. Account takeovers and token theft go unnoticed until the damage is done.
Lack of Email Security Email traffic exists outside the RMM’s architectural scope. Phishing and BEC attacks slide right into user inboxes unimpeded.
No Automated Incident Response RMMs can generate alerts but cannot investigate or correlate the attack chain. Alert fatigue sets in, and containment relies entirely on slow, manual intervention.

The Blueprint for Layered Defense

RMMs shouldn’t be discarded—they must be augmented. A robust, modern security posture layers dedicated defenses over the blind spots left by device management tools:
  • Endpoint Detection and Response (EDR): Moves beyond signatures to monitor process behavior and memory in real-time, instantly isolating infected machines.
  • Identity Threat Detection and Response (ITDR): The missing piece of the puzzle. ITDR analyzes login patterns and permission changes in cloud workspaces to catch credential abuse early.
  • API-Driven Email Security: Intercepts phishing and impersonation attempts inside the mail environment before the user ever sees them.
  • Cloud Data & Footprint Monitoring: Scans for misconfigured SaaS apps, exposed files, and leaked credentials circulating on the dark web.

The Guardz Advantage: Unified Security for MSPs

To solve the fragmented tooling problem, Guardz offers a unified, agentic security platform specifically engineered for MSPs. It doesn’t replace your RMM; it completes it.
  • Enterprise-Grade Power: Features natively integrated SentinelOne Singularity EDR, ITDR for M365/Google Workspace, and Check Point-powered email security.
  • Agentic AI Triage: Eliminates alert fatigue by using AI to correlate signals across endpoints, email, and cloud data, escalating only validated threats.
  • Single Pane of Glass: Manage your entire client base from one intuitive, multi-tenant dashboard.
  • 24/7 MDR & Incident Flow: Automatically maps the full attack chain, backed by a 24/7 team of SOC analysts ready to contain threats immediately.
  • Built-In Human Defense: Automated security awareness training and AI-generated phishing simulations keep end-users sharp and accountable.
By adopting a comprehensive layered strategy, MSPs can confidently secure their clients’ identities, inboxes, and cloud data, transforming their security offering from a basic hygiene checklist into an impenetrable fortress.

About Guardz
Guardz is on a mission to create a safer digital world by empowering Managed Service Providers (MSPs). Their goal is to proactively secure and insure Small and Medium Enterprises (SMEs) against ever-evolving threats while simultaneously creating new revenue streams, all on one unified platform.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

The 2026 Guide to Shadow AI Governance

Navigating Shadow AI Governance: 2026 Buyer’s Guide

Overview: As organizations evaluate shadow AI governance solutions in 2026, understanding the architectural differences between platforms is critical. This guide breaks down the leading options, highlighting how they operate and where each solution excels, so you can make an informed, data-driven decision.

The Market Leaders in 2026

The top contenders in the shadow AI governance space currently include dope.security, Zscaler, Netskope, Palo Alto, and Cisco Umbrella. While every platform is designed to uncover AI usage and enforce organizational policies, their fundamental divergence lies in where the data inspection actually takes place. For instance, dope.security processes data directly on the endpoint (a “fly direct” approach), whereas competitors rely on cloud-based inspection or DNS-level filtering.

The Three Pillars of True AI Governance

To be considered a complete shadow AI governance solution, a platform must successfully execute three core functions:

  • Comprehensive Discovery: It must detect every AI application in use across the environment and accurately differentiate between personal accounts and enterprise-licensed tenants.
  • Granular Access Control: It must possess the ability to permit enterprise logins while simultaneously blocking personal account access on a per-tool basis.
  • Data Protection (DLP): It must actively intercept sensitive information—such as PII, PCI, PHI, and intellectual property—within prompts and file uploads before that data ever reaches the AI model.

Architectural Comparison: How the Top Tools Stack Up

The underlying architecture of an AI governance tool dictates its speed, privacy, and effectiveness. Here is how the major players compare:

PlatformInspection PointAccount-Level Control (Personal vs. Enterprise)
dope.securityOn-Device (Endpoint) – Direct connection, zero backhauling.Yes (via Cloud Application Control)
Zscaler & NetskopeCloud – Traffic is backhauled to vendor data centers.Yes
Palo AltoNetwork Path – Relies largely on network-level inspection.Varies by configuration
Cisco UmbrellaDNS Layer – Sees domains, but blind to prompts/accounts.No (Cannot distinguish between accounts on the same domain)

Key Capabilities Deep-Dive

1. Enforcing Enterprise-Only ChatGPT Access

Organizations often want to block personal ChatGPT usage while allowing their paid corporate instances. dope.security, Zscaler, and Netskope can successfully differentiate between accounts to enforce this rule. Cisco Umbrella falls short here; because its DNS-based approach only registers the top-level domain (which both personal and enterprise ChatGPT share), it cannot distinguish between user accounts. dope.security handles this directly on the device, syncing enforcement policies across the entire fleet in under a minute.

2. Securing Prompts Without Cloud Detours

If data privacy is paramount, you must consider where your AI prompts are being inspected. Traditional Cloud SWGs (Secure Web Gateways) decrypt and analyze your traffic inside their own data centers. dope.security eliminates this detour. Using its Dopamine DLP engine, it classifies prompts and uploads directly on the local device via zero-retention APIs, blocking sensitive data transmission before it ever leaves the endpoint.

3. Beyond the Browser: Securing Desktop Apps and IDEs

Shadow AI isn’t just happening in web browsers. Users leverage native desktop clients (like ChatGPT or Claude Desktop), IDE coding assistants, and API scripts. Browser extensions and DNS tools are blind to much of this activity. Cloud SWGs can manage it, provided their agent successfully steers that specific traffic to their cloud. dope.security natively covers these applications by enforcing policies directly at the operating system’s networking layer, capturing and decrypting traffic for supported apps at the source.

The Verdict: Choosing the Right Platform

When selecting your shadow AI governance tool, ask yourself three critical questions:

  1. Do you want prompts inspected locally on the user’s device, or are you comfortable routing them through a vendor’s cloud?
  2. Is it a strict requirement to allow enterprise AI instances while blocking personal accounts?
  3. How rapidly do you need to deploy, considering the explosive rate at which shadow AI spreads?

Top Overall Recommendation: If your priorities are lightning-fast deployment, strict per-tool account control, and uncompromising data privacy through on-device inspection, dope.security emerges as the premier choice for 2026. By delivering AI discovery, Cloud Application Control, and Dopamine DLP from a single console—without the proxy detour—it offers the most streamlined and secure governance experience.

Experience On-Device AI Governance Firsthand

Take control of your environment today. Uncover every AI application, lock usage to approved enterprise accounts, and halt sensitive data leaks directly at the endpoint.

 

About Dope Security
A comprehensive security solution designed to protect individuals and organizations from various cyber threats and vulnerabilities. With a focus on proactive defense and advanced technologies, Dope Security offers a range of features and services to safeguard sensitive data, systems, and networks.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

SealSuite | ByteDance’s All-in-One IT Security Platform

 

Manage and Secure Workspace

SealSuite is a cutting-edge digital work IT infrastructure developed by ByteDance. It is an open digital work platform that offers three key features such as Identity Access Management, Endpoint Management, Network Management and Security.

Identity and Access Management

🔹 Identity management and federation

🔹 Static and dynamic role management

🔹 Multi-factor authentication (MFA)

🔹 Single sign-on (SSO)

Endpoint Management

🔹 Mobile device management (MDM) & software management

🔹 Data loss prevention (DLP) & firewall management

🔹 Patch management & baseline scanning

Network Management and Security

🔹 Software-defined wide area network (SD-WAN)

🔹 VPN management

🔹 Wi-Fi and wired network management

🔹 Network access control (ACL)

SaaS Protection

🔹 Secure application gateway

🔹 Application discovery

🔹 Application control & Web data loss prevention

Empowering Organizations Around the World

SealSuite All-in-One IT Security Platform

Speak to us to customize your own solution!

ESET Research discovers vulnerable UEFI shims undermining devices’ Secure Boot

  • ESET researchers discovered 11 old, Microsoft-signed, UEFI applications that allow bypassing UEFI Secure Boot on the majority of UEFI-based systems.
  • An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware.
  • Exploitation is not limited to systems with the affected software or Operation system (OS) installed, as attackers can bring their own copy of the vulnerable binaries to any UEFI system with the Microsoft third-party UEFI certificate enrolled.
  • All UEFI systems with Microsoft third-party UEFI signing enabled are affected (Windows 11 Secured-core PCs are expected to have this option disabled by default).
  • The vulnerable binaries were revoked by Microsoft.

BRATISLAVA — July 14, 2026 — ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities. UEFI shim bootloaders are tiny bits of code designed to bridge the gap between motherboard UEFI firmware and an operating system. The vulnerable shims, at versions 0.9 and below, can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts the Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system. Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits even on systems with UEFI Secure Boot enabled. ESET reported findings to CERT/CC; the vulnerable UEFI applications were then revoked.

The discovered shims come from various tools or software packages, including PC-diagnostic software, Linux distributions, and other UEFI-based utilities. Importantly, exploitation is not limited to systems with the affected software or OS installed, as attackers can bring their own copy of the vulnerable shims to any UEFI system with the Microsoft third-party UEFI certificate enrolled.

“What makes these old shims dangerous is not a novel vulnerability; it’s that no new vulnerability is needed to bypass UEFI Secure Boot. An attacker needs no complicated exploitation primitives – only a copy of an old, still-trusted, but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature as UEFI Secure Boot,” says ESET researcher Martin Smolár, who discovered the vulnerable shims.

“To understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, in the report we examine a few specific issues in the reported shims – issues that are easily exploitable and that highlight the breadth of the attack surface they expose,” adds Smolár.

Over the years, the UEFI shim bootloader has naturally evolved, with new improvements and security features introduced in successive releases of the upstream UEFI shim repository. At the same time, many third-party vendors have taken available versions of the shim source code to build their own binaries, which they subsequently submitted to Microsoft for signing. This behavior is expected and aligns with the original design of shims. However, insufficient attention has been given to revoking outdated Microsoft-signed shims, many of which can, by design, be leveraged to bypass newer security mechanisms. 

These vulnerable shims can be blocked by applying the latest UEFI revocations from Microsoft. Windows systems should be updated automatically.  For Linux systems, updates should be available through the Linux Vendor Firmware Service. For more general recommendations regarding how to protect against (or at least detect) exploitation of unknown vulnerable signed UEFI bootloaders and deployment of UEFI bootkits, see ESET Research blogpost: Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344.

For a more details about the vulnerable UEFI shims, check out the ESET Research blogpost “Forgotten UEFI shims undermining Secure Boot” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Simplified UEFI boot flow on Linux systems

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Threat Report: AI boosts cyber attackers’ efficiency

  • ESET Research has released its H1 2026 Threat Report with statistics from December 2025 through May 2026.
  • ClickFix – a social engineering technique leveraging fake error messages – has expanded into AI-themed help pages, browser extensions, and cloud authentication scenarios.
  • QR code phishing – also known as quishing – has reached record levels in ESET telemetry.
  • ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of malicious instances. AI is also beginning to appear within malware.
  • Ransomware showed no signs of slowing down, with its continued use of EDR killers – tools designed to disable security software during attacks.
BRATISLAVA — July 8, 2026 — ESET Research has released its H1 2026 Threat Report, which summarizes threat landscape trends seen in ESET telemetry, as well as insights from ESET threat detection and research experts, from December 2025 through May 2026. The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations. Artificial intelligence (AI) is playing a growing role in this development. ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances. AI is also beginning to appear within malware itself: ESET researchers have identified PromptSpy, the first known Android malware to use generative AI in its execution flow. “Rather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface,“ says ESET Director of Threat Prevention Labs Jiří Kropáč. “On the other hand, PromptSpy illustrates the potential for increased flexibility in future threats – although guardrails against abuse included in LLMs are likely slowing down the adoption,” explains Kropáč. AI skills are small add-ons or sets of instructions that instruct an AI agent how to perform a specific task, including which services or tools to use and what data to access. The published report covers details about malicious AI skills using third-party hacking tools such as Mimikatz or Impacket and a suspicious self-modifying skills designed to create a persistence mechanism (JSON file) and a tool for self-modification (Python code). This can lead to unpredictable behavior of the agent or its abuse by an attacker. And finally, there are benign but problematic skills such as those marketed as security scanners, which create a false sense of security but implement only basic scanning techniques – like AV tools from the 1990s – or simply query the reputation of hashes, URLs, and IP addresses on VirusTotal. Meanwhile, ClickFix – a social engineering technique leveraging fake error messages – has expanded beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions, and cloud authentication scenarios. AI-fix shows how adversaries exploit trust in generative AI, embedding ClickFix compromise chains into AI-generated troubleshooting content to nonexistent issues on pages that abuse domains of AI powerhouses. ConsentFix highlights an evolution toward token theft, combining ClickFix-style interaction with OAuth authorization abuse to hijack cloud accounts without the need to steal credentials, often bypassing MFA and relying entirely on legitimate login workflows. ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation. Phishing campaigns are also evolving in response to user behavior. QR code phishing – also known as quishing – has reached record levels in ESET telemetry, with attackers embedding malicious links in QR codes to bypass inspection and shift user interaction to mobile devices while exploiting the implicit trust many people place in the barcodes with square patterns. Approximately 11% of all detected phishing emails in H1 2026 utilized QR codes, and QR code phishing threats were most prevalent in the US (19% of detections), Spain (17%), and Mexico (6%). Last but not least, ransomware activity showed no signs of slowing down, with the continued use of EDR killers – tools designed to disable security software during attacks. ESET Research has documented over 100 different EDR killers used in the wild, with new variants appearing regularly. The number of ransomware attacks continued to grow in H1 2026, but the number of victims willing to pay reached all-time lows. Three recent industry reports confirmed this downward trend, reporting a 14–28% share of paying victims. For more information, check out the ESET Threat Report H1 2026 on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Unique AI skills scanned by ESET systems per day, seven-day average

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Penta Security’s WAF Market Triumph

2025-12-09  Real-time log encryption is now essential because logs contain sensitive data and serve as blueprints for sophisticated attackers like APTs and ransomware groups. Following incidents like the Salesforce third-party breach, organizations must treat logs as critical assets requiring protection from the moment they’re created. This proactive approach, exemplified by solutions like Penta Security’s D.AMO, neutralizes damage if storage is compromised and enhances threat detection by preventing attackers from analyzing unencrypted system architecture and account patterns.

Continue reading

Rethinking Edge Computing: The End of the “Mini-Data Center” Era

Rethinking Edge Computing: The End of the “Mini-Data Center” Era

Why true architectural innovation, not incremental shrinking, is the only way forward for distributed enterprises.

For decades, the tech sector’s default strategy for remote infrastructure was simply shrinking massive, centralized data center models—hypervisors, management stacks, and storage networks—into compact retail closets or factory floors. This strategy is fundamentally flawed. Instead of building local resilience, we merely transplanted data center vulnerabilities into environments that demand the highest stability, accelerating distributed enterprises toward a massive Total Cost of Ownership (TCO) cliff.

The Dawn of the Unified Edge

The traditional playbook for managing distributed enterprises is officially obsolete. To thrive in a landscape defined by artificial intelligence and real-time processing, companies must ditch incremental tweaks and adopt purpose-built, native edge execution fabrics.

At the SC//Platform™ 2026 Summit earlier this year, GigaOm Field CTO Whit Walters outlined this evolution during his keynote on the “2026 State of the Edge.” Drawing on extensive GigaOm Radar research, Walters introduced the concept of the “Unified Edge”—a paradigm where security, computing, and networking seamlessly merge into a single, autonomous ecosystem. He emphasized that the convergence of managed networking and compute is no longer a luxury, but an absolute market necessity.

Achieving genuine edge maturity requires conquering three critical operational pillars:

1. Eradicating the Virtualization Overhead

Legacy edge setups heavily rely on type-two hypervisors clumsily layered over host operating systems. This bloated abstraction layer devours 20% to 30% of local CPU and RAM just to keep itself running. While massive cloud facilities can swallow this overhead, at the edge, it is a catastrophic waste.

This “virtualization tax” forces memory through redundant translation stages, crippling performance and injecting lethal latency into real-time applications like industrial telemetry, voice AI, and computer vision. Transitioning to a bare-metal, type-one hypervisor outright abolishes this tax, liberating essential compute resources for edge AI inference and revenue-driving tasks. Removing this overhead is a non-negotiable prerequisite for AI readiness.

2. Passing the Disconnect Test

True edge resilience is measured by a single, binary metric: Can the platform self-heal and operate flawlessly when the WAN goes down?

Unfortunately, many so-called “edge” products are merely cloud-dependent terminals. The moment the internet drops, they lose consensus, panic, and shut down. Network outages at the edge are inevitable, not exceptional. If a remote location cannot maintain autonomous operations and failover without a cloud heartbeat, it is a business liability. When the WAN goes dark, your assembly lines, wellheads, and cash registers must continue running without interruption.

3. Merging Compute and Networking

Driven by the insatiable need for autonomous, agentic AI, modern enterprises are hitting a severe data plumbing bottleneck. You simply cannot backhaul dozens of 4K camera feeds to a centralized cloud; the latency limits, bandwidth costs, and strict data residency compliance will instantly destroy your ROI.

Data gravity demands that processing power lives exactly where the data is generated. By baking SD-WAN and managed network security directly into the type-one compute tier, organizations can abandon fragmented hardware stacks in favor of streamlined, autonomous realities.

Industry Recognition: Leading the Charge

Validating this architectural shift, GigaOm recently named Scale Computing a Leader and Outperformer in the 2026 GigaOm® Radar for Full-Stack Edge Deployments. This distinction underscores the power of Scale Computing’s expanded portfolio, which masterfully blends secure edge infrastructure with advanced networking and services capabilities to drastically reduce operational friction in distributed environments.

The Bottom Line

In 2026, the data center is no longer the center of gravity—the edge is the universe. Evading the TCO cliff means we must stop treating edge environments as miniaturized dumping grounds for legacy enterprise software. It is time to deploy native edge fabrics that guarantee true structural resilience, predictable cost transparency, and absolute local autonomy.

Ready to Transform Your Infrastructure?

Dive deeper into the future of edge architecture. Watch Whit Walters’ complete keynote and explore all the breakout sessions from the SC//Platform 2026 Summit.

About Scale Computing
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Broadcom’s VMware: A CTO’s Decision Framework for 2026

 

Broadcom’s VMware: A CTO’s Decision Framework for 2026

For the past eighteen months, my conversations with infrastructure architects have all started the same way: “We need to talk about our VMware renewal.” The follow-up sentence varies. Sometimes it’s a number — 4x, 6x, in one memorable case 11x. Sometimes it’s a deadline. Increasingly it’s both.

None of those conversations have been about whether to leave VMware. They’ve been about where to go, how fast, and what the consequences look like if the project slips past the renewal date. The strategic question was settled by Broadcom in 2024. What’s left is execution.

This piece is for the people running that execution. It’s not a vendor pitch — Storware happens to play in this space, but the framework below applies regardless of which backup or migration tools you end up with. I’ve tried to write the document I wished existed when our customers first started asking us these questions.

What actually changed, in plain language

Most coverage of the Broadcom changes reaches for adjectives — “seismic,” “disruptive,” “unprecedented.” The reality is more boring and more permanent. Four specific things happened:

  1. Perpetual licensing ended in early 2024. Every customer is on subscription, on one, three, or five-year terms.
  2. The product catalogue collapsed from over 160 SKUs to four primary bundles — VCF, VVF, vSphere Standard, vSphere Enterprise Plus. Standalone vSAN, NSX, and Aria are no longer sold as individual products.
  3. From April 10, 2025, the minimum licence purchase moved from 16 cores to 72 cores per product line. For shops running small or edge servers, you are now buying capacity that doesn’t physically exist.
  4. Late renewals carry a 20% penalty. Miss your anniversary date and the first-year subscription price is applied with that uplift, retroactively.

Aggregate price impact varies. The published numbers range from 150% to over 1,000%, with the worst hit landing on mid-market shops that previously ran vSphere Essentials Plus — discontinued, replaced by bundles that include features they never asked for. AT&T’s reported renewal proposal of 1,050% is the headline number, but it’s not the median.

The median, in my experience, is roughly 3x to 6x. That’s enough to fund a serious migration project. It is not enough to fund a five-year wait-and-see.

The strategic question was settled by Broadcom in 2024. What’s left is execution.

The mistake I see CTOs making most often

The most common error in these conversations isn’t choosing the wrong target platform. It’s choosing the target platform first.

Vendors love this framing, because it lets them lead with their product. “Migrate to Nutanix.” “Migrate to OpenStack.” “Migrate to Proxmox.” Each of those is a coherent destination for the right workload — but “the right workload” is the part that gets skipped.

Four questions need to be answered before the target platform conversation has any meaning. None of them are about the target platform.

Question 1: What is the workload profile?

A general-purpose Linux web tier, a stateful Oracle database with multi-pathed FC storage, a legacy Windows monolith from 2014 that nobody wants to touch, and an HPC cluster with GPU passthrough all want different target platforms. A migration plan that treats them as interchangeable VMs will succeed at the easy ones and fail at the hard ones — usually in production, usually loudly.

The discipline here is to bucket every VM into one of three categories before any vendor demo happens:

  • Lift-and-shift candidates. Most general-purpose Linux and Windows workloads. The migration is mechanical — disk format conversion, driver injection, network re-mapping. These are the bulk of the estate.
  • Refactor candidates. Applications close enough to end-of-life or container-suitable that the migration is a good moment to change architecture. This is a smaller bucket than people initially think.
  • Special-handling cases. Hardware passthrough, vGPU, NSX-specific networking, vSAN-only storage features, latency-sensitive transactional workloads. These need individual treatment. Sometimes they don’t migrate at all — they wait for a hardware refresh or get re-architected.

In most estates I’ve seen, the ratio is roughly 70/15/15. The 70% drives your platform decision. The other 30% drives your special-handling budget.

Question 2: What does your operations team already know?

The cheapest target platform on paper is rarely the cheapest after you factor in re-skilling, hiring, and the productivity cost of a steep learning curve. This is the cost that vendor pitches don’t include, because vendors don’t pay it. Rough rule of thumb from my own observations:

Target platformTime to operational productivity for a VMware adminNotes
Microsoft Hyper-VWeeksClosest operational model to vSphere; Windows-heavy shops adapt fastest
Nutanix AHVWeeks to a few monthsDesigned as a turnkey VMware-equivalent experience
Proxmox VEA few monthsDifferent mental model from vSphere but well-documented; mature WebUI
KVM (standalone, OL KVM, RHEL)MonthsCloser to bare-metal Linux operations; suits Linux-heavy shops
OpenStackA year-plus without external helpWorth it for scale; typically needs a Red Hat / Canonical / Mirantis / Platform9 partner
OpenShift VirtualizationDepends entirely on existing Kubernetes maturityTrivial if your team runs OpenShift already; very hard if not

If your team is small and your VMware estate isn’t, the platform with the lowest licence cost is almost certainly not the platform with the lowest total cost of ownership over three years.

Question 3: Where is your data legally allowed to live?

This is the question that’s most often skipped by US-headquartered vendors, because it doesn’t usually have a clean answer for them.

For European organisations, three threads matter. GDPR is the floor — personal data needs to be processed under EU jurisdiction or under an equivalent regime. NIS2, in force across EU member states from October 2024, raises the bar on incident reporting and supply-chain security and applies to a much broader set of organisations than its predecessor. DORA, applicable from January 2025, imposes specific operational resilience requirements on financial services entities and gives competent authorities direct oversight of critical ICT third-party providers — including data protection vendors.

Layered on top of all three is the CLOUD Act, which gives US authorities legal grounds to compel US-based vendors to produce data held anywhere in the world. This creates a documented conflict with GDPR Article 48 that EU regulators have been increasingly explicit about.

In practical terms: if your VMware exit is also a moment to reassess your US-vendor dependencies more broadly, the data protection vendor running alongside the new platform is part of that decision. If sovereignty doesn’t matter to your organisation, ignore this section. If it does, this is not a soft factor — it’s a constraint.

If your team is small and your VMware estate isn’t, the platform with the lowest licence cost is almost certainly not the platform with the lowest total cost of ownership over three years.

Question 4: When does your renewal hit?

The 20% late-renewal penalty changes the project-planning math. Your migration timeline is not dictated by your project plan. It is dictated by your renewal anniversary.

Three positions exist. You renew (with a price uplift). You migrate before the renewal (which means the project is on a hard deadline). Or you renew and migrate during the next subscription window (which is the path most large enterprises end up choosing, because the alternative is unrealistic given inventory complexity).

Whatever position you take, decide it deliberately. The worst outcome is missing the renewal date by accident and paying the penalty on top of a subscription you didn’t want.


Three migration approaches, and which one suits which estate

Once the four questions above are answered, the technical conversation becomes tractable. Three architectural patterns dominate VMware-to-anywhere migration. The trade-offs are real.

  • Cold migration is the simplest and most universal: power down the VM, export the disk image, convert the format if needed, import to the target. Tools like virt-v2v and qemu-img handle the work. The downtime per workload is hours, not minutes. Suitable for the long tail of low-criticality workloads, not for anything customer-facing.
  • Warm migration uses VMware’s Changed Block Tracking to do most of the data transfer while the source is running, then a short cutover for the delta. Most standalone commercial migration tools sit here — Coriolis, Hystax, vendor-specific toolkits. The downside is that you’re buying and operating a separate product for the duration of the migration window, then either discontinuing it or maintaining it as another stack component.
  • Backup-as-migration is the architectural approach my own company takes, which I’ll declare openly before describing it. The same data protection engine that already backs up the VMware environment can restore those backups onto a different hypervisor type. The backup is the migration source. The catalogue is unchanged. The product you needed for backup is the product you also use for migration — there’s no second SKU.

This third approach has three structural advantages that get under-discussed. First, your protection coverage is uninterrupted before, during, and after the move — there’s no gap during the project window. Second, the rollback path is intrinsic to the architecture: if a migrated workload misbehaves on the target, the original backup is still there in the catalogue and restores back to VMware mechanically identically. Third, the operational model after migration is the same one you had before — same WebUI, same policies, same RBAC, same team. The platform you’re protecting changes; the protection layer doesn’t.

The catch — and this is real — is that backup-as-migration only works if your data protection vendor actually supports both source and target as first-class platforms with feature parity. Most don’t. That’s a vendor selection question, not an architectural one.

Two mistakes worth naming explicitly

The two failure patterns I see most often:

Mistake one: treating the migration project as separate from the protection strategy. Teams choose a target platform, then choose a migration tool, then later realise their existing backup vendor doesn’t support the new platform, and end up with two replacement projects running in parallel. The second project is invariably worse-scoped than the first because budget and attention were already spent.

Mistake two: optimising the architecture for the migration window rather than the steady state. The migration is a phase. The steady state is years. A platform combination that’s slightly easier to migrate to but materially harder to operate after the project is the wrong choice. Make the steady-state decision first; let it constrain the migration approach, not the other way around.

What I’d actually do if I were sitting in that chair

Treat the four questions above as the work product of week one. Inventory bucketed into three categories. Honest assessment of operational maturity. Sovereignty constraints documented. Renewal date on the wall.

Then run a scoped proof of concept on the most representative workload in the lift-and-shift bucket — not the easiest, not the hardest, the most representative. Measure how long it actually takes, what manual intervention was required, what broke. That number, multiplied by the estate size with a realistic batching assumption, is your project duration. It’s almost always longer than the initial vendor estimate.

Decide your protection strategy and your migration strategy as one decision, not two. If they have to be different tools, accept that and budget for it. If they can be the same tool, that’s a structural simplification worth optimising for.

And then start. The hardest part of these projects isn’t technical. It’s overcoming the inertia of an environment that worked well enough for fifteen years.


If you’d like to discuss any of the above against your own environment, Storware tech team is reachable through storware.eu/book-meeting/

About Storware
Storware is a backup software producer with over 10 years of experience in the backup world. Storware Backup and Recovery is an enterprise-grade, agent-less solution that caters to various data environments. It supports virtual machines, containers, storage providers, Microsoft 365, and applications running on-premises or in the cloud. Thanks to its small footprint, seamless integration into your existing IT infrastructure, storage, or enterprise backup providers is effortless.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.