Filed under: Cybersecurity — Phishing & Scams — August 2026
What happened
Researchers at Malwarebytes found a network of fake Microsoft-branded websites running phony “security scans.” The sites tell visitors their antivirus software is incompatible with Windows and must be uninstalled immediately — a completely false claim. Once a victim removes their real protection, the site pushes them into a fake refund process that harvests their name, address, banking details, cryptocurrency accounts, and even remote-access tool credentials, sending everything straight to the scammers via a Telegram bot. Researchers found eleven of these lookalike domains running on a single host.
Why it matters to your business
This scam is built to hit exactly the moment an employee is trying to do the right thing — checking that their PC is secure. If someone on your team hits one of these sites and follows the instructions, you end up with an unprotected computer, a scammer with your banking information, and potentially a stranger with remote access to a company machine. That last part is the real danger for a small business: one compromised PC with remote-access software installed can be a foothold into your whole network.
What to do this week
Remind your team that Microsoft does not run pop-up “security scans” from a website and will never ask you to uninstall your antivirus. If a scan result urges uninstalling security software, closing the browser tab is the right move — not calling a number or filling out a form. If anyone on staff already removed their antivirus or installed a remote-access tool because of a prompt like this, disconnect that PC from the network, reinstall your standard endpoint protection, and run a full scan before reconnecting. If banking details were entered anywhere, call your bank directly using the number on your card, not anything from the scam page.
The bigger picture
Scams like this work because they borrow trust from a brand everyone already relies on — and they’re getting more automated, routing stolen data through commodity tools like Telegram bots instead of custom infrastructure. — Fake Microsoft security scans trick victims into uninstalling their antivirus
Would your team know to close the tab instead of calling the number? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity · Endpoint Protection · August 2026
What happened
A Microsoft Defender signature update pushed out on August 18, 2026 caused Quick, Full, and Offline virus scans to abort partway through on Windows PCs instead of completing. The scan would appear to start normally, then Windows Security would report that the “threat service has stopped” — and restarting it didn’t help, since the next scan failed the same way. Microsoft confirmed the bug and shipped a fix in signature version 1.457.236.0 (some machines needed 1.457.238.0). This wasn’t an attack; it was a bad update that broke a security tool.
Why it matters to your business
If your office runs Windows with Microsoft Defender as your antivirus — which most small businesses do, whether they realize it or not — your PCs may have gone a day or two with scans silently failing instead of completing. There’s no dramatic warning banner telling you malware got a free pass; the machine just looks like it’s running normally. For a Phoenix business handling customer payment info or client records, that’s a quiet gap in coverage at exactly the wrong time, since attackers actively watch for windows like this.
What to do this week
On each PC, open Windows Security > Virus & threat protection > Protection updates, and confirm the antivirus definition version reads 1.457.236.0 or higher. If it’s older, click “Check for updates” to pull the fix down now. Once updated, run a manual Quick scan and watch it actually finish instead of stalling or throwing an error. If you use an RMM tool or IT provider to manage your fleet, ask them to confirm the fixed signature version has been pushed to every device, not just checked on one.
The bigger picture
Even the antivirus built into every Windows PC can fail quietly, which is exactly why relying on it alone — with nobody checking that it’s actually working — is a risk in itself. — Microsoft fixes known issue causing Windows Defender crashes
Would you know if your antivirus quietly stopped working tomorrow? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Ransomware Scams — August 2026
What happened
Security researchers uncovered a scam where a ransomware affiliate poses as a data-recovery company called “Ransom Busters.” After attacks tied to gangs like DragonForce, Settra, and Anubis, victims are contacted before the breach is even public, with an offer to retrieve stolen files and destroy the criminals’ copies of the data for $20,000 to $60,000. Investigators found the same “recovery firm” used the exact same hacking tools and backdoor passwords as the original attackers — it isn’t a rescue service, it’s the same crew running a second scam on the same victims.
Why it matters to your business
If your Phoenix business ever gets hit by ransomware, the instinct is to grab any lifeline that promises to make the problem disappear. This scam is built to exploit exactly that panic, tacking a second extortion payment onto the first with no real guarantee anything gets deleted. Because the outreach arrives before news of the breach has spread, it can look unsettlingly credible — which is what makes it work.
What to do this week
Decide now, before any incident, that ransomware response goes through a pre-agreed plan — not through whoever emails you first. If you ever experience a breach: don’t negotiate directly, loop in law enforcement (FBI IC3), and call your IT provider or incident response contact before responding to anyone claiming they can “recover” or “delete” stolen data for a fee. Never trust a recovery offer that shows up before you’ve publicly confirmed an incident, and never engage through any contact channel tied to the attack itself.
The bigger picture
Ransomware crews are now running secondary extortion rackets against their own victims, which means the financial and psychological pressure after a breach isn’t a one-time event — it can keep coming from unexpected directions. — Rogue ransomware affiliate poses as recovery firm to steal payments
Want a response plan in place before you ever need one? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Microsoft 365 Login Security — August 2026
What happened
Security firm Huntress reports that password-spraying attacks — where hackers try stolen or guessed passwords across many accounts at once — jumped 155x in the first half of 2026. The worst case: a June campaign against Microsoft’s sign-in system generated over 81 million login attempts in two weeks and compromised 78 accounts. Attackers exploited an old sign-in method (ROPC) that sends a password straight through without ever triggering a multi-factor authentication (MFA) prompt.
Why it matters to your business
Most Phoenix small businesses run on Microsoft 365, and many assume MFA means they’re covered. Huntress found that among the businesses hit, a third had no MFA at all — and every business that did have MFA still got breached anyway, because their policies only covered certain apps or users, relied on “trusted locations,” or were left running in report-only mode instead of actually enforcing anything. Half-on MFA can be worse than no MFA if it gives you false confidence.
What to do this week
Have whoever manages your Microsoft 365 tenant open the Entra admin center (entra.microsoft.com) and check Protection > Conditional Access: confirm MFA policies apply to all users and all apps, not a subset, and that none are stuck in “Report-only” mode. Under Protection > Authentication methods, disable legacy authentication protocols including ROPC if your business doesn’t specifically need them. If you don’t have Conditional Access licensing, turn on Security Defaults, which blocks legacy auth by default. Also glance at recent sign-in logs for spikes in failed login attempts from unfamiliar locations.
The bigger picture
Attackers have shifted from breaking passwords to finding the gaps between where MFA is supposed to apply and where it actually does — a reminder that security settings need to be checked, not just switched on once and forgotten. — Password spraying attacks surge 155x as hackers exploit MFA gaps
Not sure if your MFA actually covers everyone? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Data Protection — August 2026
What happened
Security researchers at Varonis found a flaw, nicknamed “CoSnitch” (CVE-2026-24301), in Microsoft Copilot Personal — the AI assistant built into Windows and Edge. By chaining three separate bugs, a single click on a crafted link could get Copilot to quietly reach into accounts it’s connected to, like email or OneDrive, and send data out to an attacker, with no further clicks or approval needed. Microsoft finished the fix on August 18, 2026. Researchers found no evidence it was ever used in a real attack — this was caught and closed before it became a live threat.
Why it matters to your business
Copilot now ships built into Windows 11 and Edge, and many employees are signed in with the same Microsoft account they use for work email and files. If that account is connected to anything business-related, a bug like this means a single bad link could have leaked company data without anyone noticing anything was wrong.
What to do this week
The fix is already out, so the main job is making sure it actually reaches your machines. Check Settings > Windows Update to confirm updates are current, and in Office apps go to File > Account > Update Options > Update Now. Remind staff that links tied to AI assistants (‘ask Copilot about this,’ shared prompts, etc.) deserve the same suspicion as any other unexpected link. If it’s not something your team relies on for work, there’s no downside to leaving Copilot signed out of business accounts.
The bigger picture
This is the third Copilot flaw Varonis has uncovered this year, and Microsoft took nearly eight months to fully close it after being told. AI assistants are being added to everyday software faster than they’re being secured, so it’s worth treating them as another app that needs oversight — not a black box you just trust. — Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps (The Hacker News)
Not sure what AI tools your team has quietly connected to business accounts? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Patching — August 2026
What happened
Google shipped a Chrome update fixing 15 security bugs, including two rated critical (CVE-2026-76034, CVE-2026-76036). Both let a malicious or booby-trapped webpage run code outside the browser’s normal safety sandbox, meaning a bad site could reach beyond the browser and onto the computer itself. There’s no evidence yet that either is being used in real attacks, but critical browser bugs like these tend to get weaponized fast once details are public.
Why it matters to your business
Every employee’s browser is open all day, every day, and it’s the single most common way malware and scams reach a work PC. Microsoft Edge runs on the same underlying engine as Chrome, so it needs this same fix. One employee clicking the wrong link or landing on a compromised ad could be enough to hand an attacker a foothold on your network.
What to do this week
Chrome and Edge update themselves automatically, but don’t assume — check. In Chrome, go to chrome://settings/help and confirm you’re on version 150.0.7871.181 or later. In Edge, go to edge://settings/help and install any pending update. Either way, fully close and reopen the browser (not just the window) — updates don’t take effect until it restarts. If you manage several PCs, ask your IT provider to confirm the update pushed to every machine, not just your own.
The bigger picture
Browsers are the software your team uses the most and the software attackers target the most — this kind of critical patch comes around every few weeks, not just a few times a year. Staying current is the single cheapest thing a small business can do to close off this attack path. — Update Chrome now: Two critical vulnerabilities fixed (Malwarebytes)
Not sure your team’s browsers are actually up to date across the board? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Browser Security — August 2026
What happened
Security researchers publicly released a technique that lets malware already running on a Windows PC quietly switch on Chrome or Edge’s built-in debugging tools, then use them to grab every saved password, cookie, and logged-in session in the browser — without ever touching the encrypted password file. It works even though Google added a feature called “App-Bound Encryption” specifically to stop this kind of theft. There’s no CVE and no patch coming, because it’s not a software bug — it’s a way of misusing a legitimate browser feature. It only works if an attacker already has some form of malware running on the machine, so this is a research disclosure, not an active mass attack, though Google says it has already seen a rise in attackers using this style of trick.
Why it matters to your business
Plenty of Phoenix-area small businesses have staff who stay logged into email, banking, QuickBooks Online, or Microsoft 365 in Chrome or Edge all day, and let the browser save passwords for convenience. If one employee opens a malicious attachment or installs a fake tool, this technique means an attacker doesn’t just get that one file — they can walk out with every saved login and every active session, including ones that already passed an MFA prompt. That turns a single infected laptop into a master key for your accounting, email, and customer systems.
What to do this week
Confirm every PC is running Chrome 136 or later, or a current version of Edge — both now block the debugging switches this trick relies on unless the browser is launched in an unusual way, closing the easiest path in. Make sure you have real endpoint protection (EDR), not just basic antivirus, since stopping the initial malware infection is what actually prevents this. Ask your IT provider whether Chrome’s newer “Device Bound Session Credentials” feature (Chrome 146+) is turned on — it ties a login session to the specific PC so a stolen cookie is useless anywhere else. And discourage staff from saving banking or admin passwords in the browser itself; a dedicated password manager app is safer.
The bigger picture
This isn’t a single flaw that gets patched and disappears — it’s a reminder that no browser feature fully replaces keeping malware off the PC in the first place. — Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Not sure your team’s endpoint protection would catch something like this? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Network Security — August 2026
What happened
Researchers uncovered a new botnet called “Evooo1Bot” that’s been hijacking internet-facing routers and firewalls since at least July by exploiting 18 known vulnerabilities — some dating back to 2007 — in devices from NETGEAR, TP-Link, D-Link, Zyxel, Tenda, and Alcatel. Once in, it turns the device into a traffic relay for other attacks, brute-forces SSH logins, sniffs credentials, and can be aimed at other targets in denial-of-service attacks. This is confirmed active exploitation, not a proof of concept, and infections have been tracked across North America, Europe, and Asia.
Why it matters to your business
Every one of these brands shows up in small-business networks around Phoenix — often installed years ago and never touched again. None of these are new, unpatched zero-days; they’re old, well-known bugs in devices that missed firmware updates or were simply never replaced. A hijacked router doesn’t just slow down your internet — it gives an attacker a foothold inside your network and a launchpad they can use to attack other companies from your office’s IP address.
What to do this week
Log into the admin panel of every router, firewall, and network camera in your office (check the label on the device for the default address, often 192.168.0.1 or 192.168.1.1) and check the firmware version against the vendor’s current release — most of these brands publish updates on their support sites. Turn off remote/WAN administration access unless you specifically need it; that’s the main way these devices get exploited. If a device is past its vendor’s support window and no longer gets firmware updates at all, budget to replace it — an unpatchable router is a permanent open door.
The bigger picture
Attackers don’t need a fresh zero-day when so many small businesses are still running network hardware that hasn’t been updated in years — old, cheap-to-fix bugs are doing the work just fine. — The Myth of Old Tech: How Outdated Equipment Is Costing You More
Not sure how old the firmware is on your office router or firewall? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Data Protection — August 2026
What happened
RingCentral, the phone and messaging platform used by more than 600,000 businesses, has confirmed that an extortion group called ShinyHunters broke in through a social-engineering attack in July and stole account data. This week that breach was confirmed to affect 1.6 million accounts, with names, email addresses, phone numbers, and physical addresses exposed. RingCentral refused to pay, and the group leaked a large batch of the stolen files publicly. Core calling and messaging service was not disrupted.
Why it matters to your business
If your business uses RingCentral for phones or voicemail, your account details may be in this leak — and we already flagged a phishing kit last week that impersonates RingCentral voicemail notifications to steal Microsoft 365 logins. That campaign just got more convincing: scammers now have real names, numbers, and addresses to make follow-up phishing calls or emails feel legitimate. Anyone whose contact info was exposed is a more attractive target for impersonation scams built around this breach.
What to do this week
Check whether your business email shows up at haveibeenpwned.com, change your RingCentral account password, and turn on multi-factor authentication under the RingCentral admin portal (Settings > Security > Multi-Factor Authentication) if it isn’t already required. Tell staff that any unexpected “RingCentral security alert” email, text, or phone call this month deserves extra scrutiny — verify through the official app or website rather than clicking a link or calling a number provided in the message. Watch for spear-phishing that references your real name, phone number, or address to seem trustworthy.
The bigger picture
A breach at a vendor you trust doesn’t stay contained to that vendor — stolen contact details become raw material for the next phishing campaign aimed at you and your customers. — RingCentral data breach exposed info of 1.6 million accounts
Want help checking if your team’s accounts show up in a breach like this? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Patching — August 2026
What happened
A security researcher has published a proof-of-concept called “ShieldBreak” that bypasses a Windows Defender fix Microsoft shipped in July, letting an attacker who already has a foothold on a PC escalate to full SYSTEM-level control — even on a fully patched Windows 11 or Windows Server 2025 machine. It works by tampering with files during a Defender cloud scan. As of this week there’s no official Microsoft patch, and there’s no evidence it’s being used in real attacks yet — it’s a public proof-of-concept, not an active threat.
Why it matters to your business
This isn’t a way for attackers to break into your network from the outside — it requires malware or an attacker to already be running on the machine. But that’s exactly the scenario a bad phishing click or a sketchy download creates every day. Since Windows Defender is the default, built-in antivirus on nearly every Windows PC your business owns, a bypass like this means the last line of defense on an already-infected machine may not hold.
What to do this week
Keep Windows fully updated (Start > Settings > Windows Update) so you’re ready the moment Microsoft ships a fix, and make sure Defender’s Tamper Protection is on (Windows Security > Virus & threat protection > Manage settings > Tamper Protection). Since this bug needs a foothold first, focus on preventing that foothold: remove standing local-admin rights from everyday user accounts, and keep training staff to recognize phishing emails and unexpected download prompts. Watch Microsoft’s security update guide for a fix in the coming weeks and apply it promptly once released.
The bigger picture
This is the second bypass researchers have found for the same underlying Defender flaw in a month, echoing the pattern we saw with the “LegacyHive” Windows bug in July — public disclosure racing ahead of an official fix. Layered defenses matter precisely because no single tool, including your antivirus, can be assumed unbreakable. — New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges
Not sure which of your PCs still have unnecessary local-admin accounts? Book a free consult — https://micro1tech.com/contact/