Webinar: Inside the SOC EP #002
The Cloud Attacks the Annual Threat Report Saw Coming
April 7th @ 10AM MT

Every month, Blackpoint SOC analysts pull back the curtain on the attacks they’re actively investigating. Live campaigns, real compromises, no slides full of theory.

The 2026 Annual Threat Report documented a year defined by one idea: attackers no longer need to break in if they can log in. This month’s session brings that finding to life with three active investigations your team needs to know about. 

Join us as our SOC walks through this month’s topics: 

-> A new malware strain, caught in the wild Our analysts are tracking Roadk1ll, a newly identified variant with behaviors that don’t match what traditional tools are built to flag. We’ll show you what it looks like in the telemetry and why it matters for your clients right now. 

-> Inside a major MSP compromise and the client fallout One compromised MSP became the entry point for attacks across its entire client base. We’ll walk through the chain of access, how trusted relationships were weaponized, and what the response looked like from the SOC’s perspective. This one connects directly to findings in the Annual Threat Report. 

-> Cloud identity under attack: why MFA isn’t the finish line Adversary-in-the-Middle (AiTM) attacks don’t break MFA. They wait for it to succeed, then steal what comes next. Our SOC saw this play out repeatedly across cloud account disables in 2025 and will show you exactly how this plays out in a Microsoft 365 environment and what you’d need to catch it. 

What You’ll Walk Away With 

  • A first look at an emerging malware strain before it’s widely documented 
  • A real-world example of MSP-to-client compromise and how fast it moves 
  • A clearer understanding of why cloud identity attacks keep succeeding and what actually stops them 

Want the full picture? 

Everything we cover in this series connects back to a larger story. Blackpoint’s 2026 Annual Threat Report documents the attack patterns, vulnerability trends, and SOC findings that shaped last year and what they mean for 2026. We’ll give you insight into how to access the full report live on the webinar.

 

Attend the briefing

Meet Your Speakers

Jason-Barnhizer
Jason Barnhizer

Director of Threat Operations

Blackpoint Cyber

Connect with Jason on LinkedIn
Jason-Rathbun-
Jason Rathbun

Technical Director of Threat Operations

Blackpoint Cyber

Connect with Jason on LinkedIn
Nevan Beal
Nevan Beal

Principal MDR Analyst

Blackpoint Cyber

Connect with Nevan on LinkedIn
Sam Decker
Sam Decker

Threat Intelligence Engineer

Blackpoint Cyber

Connect with Sam on LinkedIn