Posts

Showing posts from October, 2026

The Email Was Never Opened. Nobody Clicked Anything. The Mail Server Was Still Compromised.

Image
Active Exploitation Zero-Click October 2026  ·  6 min read The employee didn't click a link. There wasn't one. They didn't open an attachment, enter a password, or even read the message. The email simply arrived. Under one specific, vulnerable configuration, that alone was enough. You train every employee not to open a suspicious envelope. What happens when the mailroom itself can be triggered by the envelope just arriving, before anyone carries it upstairs? Nearly every piece of cybersecurity advice a small business hears starts the same way: don't click the link, don't open the attachment, don't enter your password on a fake page. It's good advice. It's also advice that assumes a human has to do something wrong first. Microsoft's security research team published findings on September 30, 2026 describing a vulnerability where that assumption simply doesn't apply....

They Didn't Steal the Password. They Didn't Bypass MFA. The Employee Clicked "Allow."

Image
FBI Advisory Identity & Access October 2026  ·  6 min read The employee logged in to the real account. The password was correct. Multi-factor authentication worked exactly as designed. No malware touched the machine. And the attacker still walked away with access to the inbox. The mistake came one screen later. You check the visitor's ID at the front desk. It's real. You verify it twice. It's still real. Then you hand them a key to a specific filing cabinet, because they asked politely and the request looked routine. The ID check was never the problem. The key was. That's the shape of a technique the FBI issued a public warning about in September 2026: OAuth consent phishing. It doesn't need a stolen password. It doesn't need to defeat multi-factor authentication. It asks the user to do something that looks, and often is, completely ordinary: approve an app's requ...