Posts

Featured Post

The Install Looked Legitimate. The Certificate Checked Out. It Still Handed an Attacker Remote Control

Image
Active Campaign Vendor & Access Risk September 2026  ·  6 min read Microsoft's security researchers just walked through a campaign where the file really was signed. The install really did work exactly as advertised. And by the time anyone noticed, attackers had remote access to the machine anyway, through software meant to help, not harm. A contractor shows up wearing the right uniform, driving the right van, carrying a badge that scans as valid. You let them in. Why wouldn't you? Everything checked out. The badge was stolen. The uniform was too. The van was real, but not theirs. That's close to what Microsoft's Defender Experts team described in research published this year. A phishing campaign sent out fake meeting invitations and fake PDF attachments, the kind most people have learned to eye with at least some suspicion by now. But the payload inside wasn't a crude, obvio...

Attackers Are Already Exploiting These Vulnerabilities. Three Out of Four Still Aren't Fully Fixed

Image
New Research Patch Priority September 2026  ·  7 min read Imagine the police handed you a list of five doors burglars were actively using to break into houses in your neighborhood. You checked your house. One of those doors was yours. Six weeks later, it still wasn't completely locked. That sounds absurd. It's also close to what Verizon's newest breach research found is actually happening across thousands of businesses right now. Imagine the police gave you a list of five doors burglars were actively using to break into houses in your neighborhood. You checked your house. One of those doors was yours. Six weeks later, it still wasn't completely locked. That scenario sounds like a plot hole. Nobody would leave a known, actively-used entry point open for six weeks after being told about it directly. And yet Verizon's 2026 breach research, drawn from more than 13,000 organizations ...

12,000 Inboxes Were Compromised Without Stealing a Password. The Victims Logged In on the Real Login Page

Image
Takedown Good News, Real Lesson September 2026  ·  8 min read The website was real. The password wasn't stolen. Multi-factor authentication worked exactly as designed. And the attacker still got in. This week, Microsoft disclosed and dismantled an AI-powered phishing operation that used exactly this technique to compromise more than 12,000 inboxes at over 10,000 organizations worldwide, since February. Here's how a real login page became part of the attack, and the one rule that stops it. For years, the first thing anyone learns about phishing is to check the address bar. Is this the real site? Is the certificate valid? Does the domain match? That instinct is correct, and it stops an enormous share of ordinary phishing. It's also, on its own, no longer a complete defense — because the technique behind this week's news doesn't need a fake website at all. ✓ The login page was genuine — the real Micr...

30,000 Computers Were Infected Through Fake Job Interviews. Your Employee May Not Be the Real Target

Image
FBI-Led Advisory Human Risk September 2026  ·  7 min read Your employee gets a message from a recruiter. The job looks legitimate. The interview is virtual. Near the end, the recruiter sends over a coding exercise, or the video call conveniently glitches and they're asked to run a quick fix. They do. There was never a job. The interview was the attack. Five days ago, the FBI and international partners confirmed that variations of this scheme have infected at least 30,000 computers in more than 100 countries — and your employee's own information may not have been the point. Most of the social engineering covered in this series follows a familiar shape: an urgent email, a scary invoice, a suspicious link. Employees have been trained, reasonably well by now, to be wary of things that look like trouble. This one doesn't look like trouble. It looks like an opportunity. The recruiter was the attacker On Sept...

You Changed the Password. You Reset MFA. The Attacker May Still Be Logged In. NIST Just Explained Why

Image
Fresh Guidance Identity & Access September 2026  ·  8 min read You discover an employee's account has been compromised. You do exactly what you've been told to do — change the password, reset MFA, have them sign back in. Problem solved. Except the attacker may never have needed the password again. Somewhere in the background, your cloud service may already have handed them something more useful: a token that says, in effect, this person has already proven who they are. Let them in. Six days ago, the US government's standards agency finalized an entire technical guide around exactly that problem. Every response plan in this series eventually says some version of the same thing: if an account is compromised, change the password and reset multi-factor authentication. That advice is correct, and it remains the right first move. It's also, on its own, sometimes incomplete — and the reason why has just been laid out...

18 Months Ago, AI Could Barely Start a Simulated Cyberattack. Now It Can Get Nearly Halfway Through One for About $87

Image
Government Research AI Threat Trend September 2026  ·  7 min read For years, your best defense was that attacking your business took real skill and real time. UK government researchers just measured how fast that's changing, and put a price on it: about $87 for an AI system to work through nearly half of a realistic attack sequence that would take a trained human roughly fourteen hours. Small businesses are still largely defending at human speed. Attackers increasingly don't have to. For years, one of the quiet advantages defenders had was that attacking a business took work. Someone had to find the target, probe it, understand what was exposed, figure out what might work, try something, fail, adjust, try again, move deeper into the network, find credentials, and decide what to do next. Automation has always been part of cybercrime, but much of that difficult middle stretch still required a person with real expertise and...