- 3 min read
When the hotel Wi-Fi is the attack
Microsoft has tied a campaign to Russian intelligence that takes over Wi-Fi at hotels and conference centers, then serves fake software updates and fake Microsoft sign-in pages. Three rules for anyone who travels.
Read - 5 min read
Attackers didn't hack those water systems. They just found them.
The FBI and EPA warned water utilities in seven states this week. No zero-day, no malware — the equipment was simply reachable from the internet. Here's how to find out what of yours is.
Read - 3 min read
Windows 10 got another free year — your business computers didn't
Microsoft's free Windows 10 extension to 2027 covers personal PCs only. Business machines are excluded — and their paid coverage doubles in price this fall.
Read - 4 min read
Your website is a computer too — and its plugins are how attackers get in
A leaked hacker server revealed a target list of 1.4 million websites. Your company site is a computer nobody patches — the 15-minute fix.
Read - 3 min read
The fake CAPTCHA that talks you into infecting your own computer
A fake 'prove you're human' check tells you to paste a command — and you install the malware yourself. How ClickFix works, and the one rule that stops it.
Read - 3 min read
Ransomware Is Now a Small-Business Problem: 5 Numbers From Verizon's 2026 Breach Report
Verizon's 2026 breach report found ransomware in 88% of small-business breaches — and unpatched software is now the #1 way attackers get in. Here are the numbers and five moves that change your odds.
Read - 3 min read
Infostealers: the 30-second malware behind many of today's break-ins
Infostealer malware copies every password and login session off a computer in seconds, then sells them — often within 48 hours. Here's how it works and the five defenses that actually counter it.
Read - 3 min read
Why attackers love small businesses (it's not the size of the payout)
Small businesses often assume they're too small to be a target. In 2026, the opposite is true — and the reason has nothing to do with how much money you have.
Read - 3 min read
Your vendors can get you breached — third-party risk for small teams
The apps you connect, the IT provider you trust, the contractor with a shared password — any of them can become the door an attacker walks through into your systems.
Read - 4 min read
AI just made scams more convincing — here is what is new and how to defend
Attackers now use AI to write flawless phishing emails, clone voices on the phone, and build fake websites that look real. The defenses are mostly old-fashioned and they still work.
Read - 4 min read
Quishing: the QR code scam hiding in plain sight
QR codes are everywhere now, and we scan them without a second thought. Attackers turned that habit into an attack — sometimes with nothing more than a sticker. Here is how QR code scams work.
Read - 3 min read
What your LinkedIn tells an attacker before they ever contact you
Attackers do research, and most of what they need is public. Your website, your team's LinkedIn, and your social posts can quietly hand over the org chart, the tools you use, and the perfect cover story.
Read - 3 min read
Why even MFA isn't bulletproof: the session-theft trick explained
Multi-factor authentication blocks most attacks, but a newer technique gets around it by stealing your logged-in session instead of your password. Here is how it works and why MFA still matters.
Read
See your own risk
Reading about it is one thing. Seeing your own gaps is another.
Start a 7-day Pro trial and get a plain-English security report for your Microsoft 365 and Azure — no credit card.