Posts

An Extortion Group Has Been Breaking Into Companies Worldwide This Year Using a Tool Built Into Every Web Browser: View Source

AI THREAT    DEFENSE GAP    RESEARCH    SEPTEMBER 2026  ·  8 MIN READ Eighteen months ago, the best publicly tested AI systems could barely get started on a realistic simulated cyberattack. By early 2026, the best one tested was averaging nearly half of the attack sequence. The estimated cost of attempting the entire exercise: about $87 . That last number may matter more to a small business than almost anything else in the report. This is not a story about an AI system independently breaking into a company from beginning to end. The government researchers who ran the tests specifically said today's public models still could not reliably do that. It is a story about something more immediate: how quickly the cost, skill and time required to perform parts of an attack are falling. And that creates a problem for businesses whose defenses still move a...

Eight States Will Now Shield Your Business From Punitive Damages After a Breach — If You Can Prove You Were Ready First.

Image
Legal & Policy New Angle September 2026  ·  8 min read Eight States Will Now Shield Your Business From Punitive Damages After a Breach — If You Can Prove You Were Ready First. Nearly every post in this series has been about preventing a breach. This one is about what happens if, despite doing the work, you get breached anyway — and a growing number of states have quietly decided that businesses who prepared in advance deserve real legal protection when that happens. Texas became the latest state to pass this kind of law in 2025. Here's what it actually protects, what it doesn't, and why the framework your CyberScore is already built around happens to be exactly what qualifies. This is general information, not legal advice. Cybersecurity safe harbor laws vary by state, change over time, and apply differently depending on your specific circumstances. If you're considering how one of these laws might app...

October Is Cybersecurity Awareness Month. Its Advice Wasn't Written for a Twelve-Person Business — So Here's the Translation.

Image
Awareness Month SMB Translation September 2026  ·  8 min read For over twenty years, every October has brought the same national campaign: patch your systems, use a password manager, enable multi-factor authentication. None of it is wrong. All of it quietly assumes a dedicated IT department exists to carry it out. At a typical small business, that job falls to an owner, an office manager, or whoever already handles too much. This year's theme is about building toward the country's next quarter-century. Here's the version of that written for a business your size — one month, four weeks, and a direct link back to everything this series has already covered. Since 2004, the Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance have co-led a national campaign every October, urging individuals and organizations to take stock of their digital defenses. This year's theme, Securing the Ne...

153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story

Image
Breaking Vendor Risk September 2026  ·  7 min read 153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story. This week, a database of more than 170 million scanned identity documents — driver's licenses, ID cards, travel documents — surfaced for sale, reportedly traced to a single identity-verification company whose scanning equipment sits behind the counter at car rental desks, hotels, casinos, and age-restricted retailers across North America. The company hasn't confirmed the breach. The FBI has opened an investigation. But the part of this story that matters most for small businesses isn't who got breached — it's a gap in the rules that most businesses scanning a customer's ID have never thought to ask about. Late last week, researchers investigating a dark-web identity-theft marketplace found something unusually l...

Software Vendors Just Shipped Records Numbers of Security Patches. Your Patch List Didn't Get Longer by Accident.

Image
Trend Report Patch Management August 2026  ·  8 min read Something changed in how software vulnerabilities get found this year, and the numbers are startling: disclosed flaws are on pace to roughly double last year's already-record total, and the biggest names in software have each shattered their own patch-count records, sometimes by five times over. The cause isn't sloppier code. It's that the tools doing the looking got dramatically better — on both sides of the fight. Here's what's actually happening, and why the way you decide what to patch first matters more now than it ever has. If your IT provider has seemed busier than usual with updates this year, that's not your imagination, and it isn't a coincidence specific to your systems. Something structural shifted in how software vulnerabilities get discovered in 2026, and the scale of it is large enough that security researchers are describing it as...