Microsoft Just Shipped Its Biggest Patch Ever — and Two Holes Are Already Being Attacked

Filed under: Cybersecurity · Patching · July 2026

What happened

On July 14, 2026, Microsoft released its monthly “Patch Tuesday” update — the largest in the company’s history, fixing a record 570 security flaws. Two of them are already being used in real attacks: a privilege-escalation bug in Active Directory Federation Services (CVE-2026-56155) and one in SharePoint Server (CVE-2026-50661 — a BitLocker bypass — was publicly disclosed but not yet exploited). More important for most small offices, the same update quietly fixes several “critical” flaws in Excel, Word, and PowerPoint that could let a booby-trapped document run malicious code the moment it’s opened, plus critical Windows bugs in DHCP and graphics.

Why it matters to your business

Every Phoenix small business runs Windows and Office, so this update touches essentially every PC in your office. The scary-sounding zero-days are in server products (AD FS and SharePoint) that most small firms don’t run on their own hardware — but the very same July patch closes the Office and Windows holes on your everyday laptops and desktops. A single un-patched machine where someone opens an emailed spreadsheet can be all an attacker needs to get a foothold, then move to your files, QuickBooks, and email.

What to do this week

Install the July updates on every computer now: Start → Settings → Windows Update → Check for updates, then reboot when prompted (the fixes don’t fully apply until you restart). Update Office too — in any Office app go to File → Account → Update Options → Update Now. If any machine is still on Windows 10, know that it stopped getting free security updates in October 2025 — those PCs should be upgraded to Windows 11 or replaced, because they will not receive these fixes. Turn on automatic updates so you’re not doing this by hand each month (Settings → Windows Update → Advanced options). If you happen to run SharePoint Server or AD FS on-premises, patch those immediately or call us — those are the ones already under active attack.

The bigger picture

A record-breaking patch is a reminder that the number of flaws keeps climbing, and attackers move within days of each release to hit whoever hasn’t updated yet. Staying patched on a schedule is the cheapest, highest-return security work you’ll ever do — far cheaper than cleaning up after the one machine everyone forgot. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Confident every computer in your office actually installed this month’s updates? Book a free consult → https://micro1tech.com/contact/

That “IT Support” Call on Teams Might Be a Hacker Taking Over Your PC

Filed under: Cybersecurity · Social Engineering · July 2026

What happened

Security researchers at Palo Alto Networks’ Unit 42 uncovered an active campaign in which criminals pose as your own IT support over Microsoft Teams. It starts with a phishing email — often an “Employee Survey” with a PDF attached — followed minutes later by a Teams voice call from an outside account claiming to be a “System Administrator.” The caller talks the employee into installing a legitimate remote-control tool like AnyDesk or HopToDesk, then uses that access to plant malware called EtherRAT that hands the attacker full control of the computer. This is happening in the wild right now, and researchers found the crooks are already on their ninth version of the installer.

Why it matters to your business

For a Phoenix small business, Teams and Microsoft 365 are everyday tools, and a friendly “IT is calling to fix something” feels completely normal — especially when there’s no in-house IT desk to check against. One employee granting remote access gives a stranger the keys to that machine: saved passwords, email, QuickBooks, client files, and a foothold to spread across your network. Because AnyDesk and HopToDesk are legitimate, widely-used programs, your antivirus usually won’t flag the initial break-in. The endgame is data theft, wire-transfer fraud, or ransomware.

What to do this week

Set one firm rule with your team: real IT never cold-calls to install software or take remote control — if someone does, hang up and call back on a number you already trust. In Teams, limit who can reach your staff from outside: open the Teams admin center (admin.teams.microsoft.com) → Users → External access, and block or tightly restrict unknown external domains and unmanaged Teams accounts. Make sure remote-control apps like AnyDesk, HopToDesk, TeamViewer, and Windows Quick Assist are only installed and used by your actual IT provider, and remove any your team doesn’t recognize. Finally, treat unexpected “Employee Survey” emails with PDF attachments as suspicious and report them.

The bigger picture

Attackers have shifted from breaking in to being invited in — the fastest route onto your network is now a convincing phone call, not a software flaw. Teaching your team to pause and verify before granting access is the control that stops this cold. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Want help locking down Teams and remote-access tools before a fake “IT” call gets through? Book a free consult — https://micro1tech.com/contact/

Scammers Are Now Phoning Your Staff to Hijack Microsoft 365 — and Passkeys Won’t Save You

Filed under: Cybersecurity • Phishing • July 2026

What happened

Since April 2026, a criminal crew that researchers track as “Pink” has been calling employees at small and mid-sized companies, posing as Microsoft or internal IT and claiming a “security upgrade” is required. On the phone, they walk the victim through a fake Microsoft 365 login and passkey-enrollment page in real time, capture the password and the MFA approval, sign in to the real account, then quietly register their own passkey so they keep access even after the victim changes their password. There is no software bug here — the attackers simply abuse the legitimate passkey feature Microsoft turned on in May. Security firm Okta detailed the campaign on July 8, 2026.

Why it matters to your business

Passkeys and multi-factor authentication are exactly what we tell every client to turn on — and this attack is built to defeat both by fooling a person on the phone instead of breaking any software. Once the crooks plant their own passkey, they own that mailbox and can silently read and download everything in SharePoint and OneDrive: your invoices, client records, tax documents, and banking details. For a Phoenix small business, one convincing call to a receptionist or bookkeeper can turn into wire fraud or a reportable data breach.

What to do this week

Tell every employee plainly: MicroOne (or your IT provider) will never phone you and walk you through adding a passkey or approving an MFA prompt — if you get that call, hang up and call us back on a number you already have. In the Entra admin center, review each user’s registered sign-in methods (Users > select the user > Authentication methods) and remove any passkey or authenticator you don’t recognize. Then tighten who can enroll: Entra ID > Security > Authentication methods > Passkey (FIDO2), and restrict registration to trusted devices. Finally, turn on a Conditional Access rule that blocks sign-ins from countries you don’t do business in.

The bigger picture

The lock on your accounts is only as strong as the person who can be talked into opening it, and attackers have simply moved from email to the phone. Coaching your team to recognize the pitch is now as important as any software setting. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Not sure who could add a passkey to your Microsoft 365 accounts right now? Book a free consult → https://micro1tech.com/contact/

Fake “Interpol Investigation” Emails Are Locking Up Small Businesses With Ransomware

Filed under: Cybersecurity · Ransomware · July 2026

What happened

Security researchers are tracking an active phishing campaign in which criminals pose as Interpol’s cybercrime unit. The emails claim your company is under investigation and link to a password-protected Proton Drive archive that supposedly holds “video evidence.” The file inside is really a program disguised as a video — opening it installs custom-built ransomware that encrypts your files and demands payment. Businesses across the U.S., Europe, Asia, and the Middle East have already been hit, spanning legal, medical, finance, media, and other everyday industries.

Why it matters to your business

This campaign is aimed squarely at small businesses without a dedicated IT or security team — exactly the kind of Phoenix companies most at risk. A “law enforcement is investigating you” email is engineered to make a busy owner or bookkeeper panic and click before thinking. There is no fixed ransom: the attackers size up your business only after they have locked your files, so even a small firm can face a painful demand — on top of downtime that stops billing, payroll, and QuickBooks cold.

What to do this week

Treat any unsolicited “law enforcement” email as a scam — real agencies don’t email you a Proton Drive link and a password. Turn on file extensions in Windows (File Explorer → View → Show → File name extensions) so a file named “evidence.mp4.exe” gives itself away. Never open password-protected archives from outside your company, and never run a file that asks you to “enable” or “unzip and open” it. Confirm your backups are running and kept offline or in a separate cloud account, and that MFA is on for email and Microsoft 365 or Google Workspace. Finally, give the people who handle email and invoices a quick heads-up that this exact scam is circulating.

The bigger picture

Ransomware crews keep leaning on fear and urgency because it works far better than any technical exploit, and once files are encrypted, paying rarely gets everything back cleanly. The only dependable “recovery” is not getting hit in the first place — layered email filtering, tested backups, and trained staff. Why the Only True Recovery from Ransomware Is Prevention

Would your backups actually survive a ransomware hit — or just look like they would? Book a free consult → https://micro1tech.com/contact/

A Fake Microsoft Login Can Hijack Your 365 Account in Seconds — No Password Needed

Filed under: Cybersecurity · Phishing · July 2026

What happened

Attackers have refined a trick called “ConsentFix,” an evolution of the “ClickFix” scam, that steals Microsoft 365 accounts without ever grabbing a password. The victim gets a real-looking Microsoft sign-in screen and is coached to drag a small “localhost” link into their browser, which quietly hands the attacker a live session token. Because the token is already an approved, signed-in session, it sails right past the account password and multi-factor authentication (MFA). Step-by-step instructions, working code, and video tutorials for this attack were posted to Russian cybercrime forums back in March, so it is no longer limited to skilled hackers.

Why it matters to your business

For most Phoenix small businesses, the Microsoft 365 mailbox is the crown jewels — it holds invoices, banking details, client files, and the password-reset links for everything else. Attackers scout targets on LinkedIn first, then send a tailored lure through trusted services like Dropbox or DocSend, so the message looks routine. One employee dragging one link can give a stranger full access to email, and MFA won’t save you because it was never challenged. From there it’s a short step to fake invoices, wire-transfer fraud, and messages sent to your clients in your own name.

What to do this week

Lock down who can approve apps: in the Microsoft Entra admin center (entra.microsoft.com), go to Identity → Applications → Enterprise applications → Consent and permissions → User consent settings, and set it to “Do not allow user consent” (or allow only verified publishers with low-impact permissions). Turn on the admin consent workflow on that same screen so approval requests route to you instead. Then tell your team the plain rule: Microsoft never asks you to drag or paste a link into your browser bar to log in — if a sign-in prompt does, stop and report it. Finally, in the Entra sign-in logs, spot-check for logins from unexpected cities or countries over the past two weeks.

The bigger picture

MFA is essential, but it is no longer a finish line — today’s attacks skip the password fight entirely and go after the human and the session token. Training your team to recognize the lure is now just as important as the technical controls behind it. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Not sure whether your Microsoft 365 is set up to block this? Book a free consult — https://micro1tech.com/contact/

Hackers Stole VPN Passwords From Thousands of Fortinet Firewalls — and Ransomware Gangs Have Them

Filed under: Cybersecurity · Network Security · July 2026

What happened

Researchers investigating “FortiBleed” — a massive credential-theft operation against Fortinet FortiGate firewalls — have now tied it directly to the INC and Lynx ransomware gangs. The attackers planted a traffic-sniffing tool on compromised firewalls to intercept VPN usernames and passwords as employees logged in, harvesting credentials from more than 73,000 devices; the operation targeted over 430,000 firewalls worldwide. Roughly 11,000 devices are believed to still be compromised, and investigators found backdoor admin accounts named “adminin” left behind on affected systems. This is confirmed real-world activity, not a proof of concept.

Why it matters to your business

FortiGate firewalls are common in small offices, often installed by a vendor years ago and rarely touched since. If yours was compromised, the passwords your staff use to connect remotely are sitting in a criminal database — and the groups holding them are ransomware operators whose business is getting into networks and encrypting everything. A firewall that was “fixed” by only changing passwords can still be compromised: if the sniffer is still on the device, new passwords get stolen too.

What to do this week

If your office firewall is a Fortinet: update it to the latest FortiOS firmware for your model, then — in that order — reset every VPN and admin password, since credentials changed before patching may already be captured. Check System → Administrators for any account you don’t recognize (especially “adminin”) and remove it. Turn on multi-factor authentication for VPN logins, and make sure the management interface isn’t reachable from the internet. Not sure what brand your firewall is or who manages it? Find out today — that answer shouldn’t be a mystery.

The bigger picture

Stolen credentials are the raw material of ransomware: gangs don’t need to hack your network if they can simply log in. Once they’re inside, recovery gets expensive fast — prevention is the only plan that reliably works. Why the Only True Recovery from Ransomware Is Prevention

Who last checked what’s running on your office firewall — and when? Book a free consult → https://micro1tech.com/contact/

Still Running Your Own SharePoint Server? A Ransomware Gang Is Hunting for It

Filed under: Cybersecurity · Ransomware · July 2026

What happened

A flaw in Microsoft SharePoint Server (CVE-2026-45659) is being actively exploited, and CISA added it to its Known Exploited Vulnerabilities list on July 1 with a July 4 patch deadline for federal agencies — about as urgent as those deadlines get. The bug lets attackers run their own code on the server remotely, and at least one group exploiting it, Storm-2603, follows up by deploying Warlock ransomware. Important: this affects on-premises SharePoint Server only — SharePoint Online, the version included with Microsoft 365, is not affected.

Why it matters to your business

Plenty of small businesses had a SharePoint server installed years ago for file sharing and haven’t touched it since — which is exactly the profile this gang targets. An old server sitting in a closet, reachable from the internet, missing patches: that’s not a file server anymore, it’s a ransomware entry point. If you’re fully on Microsoft 365, you can relax on this one. If you’re not sure which you have, that uncertainty is itself the finding.

What to do this week

Ask one question: “Do we run SharePoint on our own server?” If yes, apply Microsoft’s latest SharePoint Server security update now — not at the next maintenance window — and check whether the server actually needs to be reachable from the internet at all. If the server is old enough that it no longer gets updates, it’s time to plan a migration to SharePoint Online, where Microsoft does the patching for you.

The bigger picture

Ransomware gangs don’t break in through your newest system — they scan for the oldest thing you forgot you owned. Once files are encrypted, options shrink fast; the only reliable recovery is never letting them in. Why the Only True Recovery from Ransomware Is Prevention

Do you know every server your business still runs — and who’s patching them? Book a free consult → https://micro1tech.com/contact/

The 5 cybersecurity mistakes Phoenix small businesses make — and how to fix them

Category: Cybersecurity

Most small businesses that get breached weren’t targeted by a genius. They were targeted by a script that scanned thousands of companies looking for one of a handful of common gaps — and found it. The FBI’s 2024 Internet Crime Report put total reported cybercrime losses at $16.6 billion, a 33% jump over the prior year, and ransomware remained the most pervasive threat to critical infrastructure. Small businesses aren’t spared because they’re small. They’re chosen because they’re softer.

After years of cleaning up after these incidents, we see the same five gaps over and over. None of them are exotic. All of them are fixable in an afternoon or two.

Mistake 1: No multi-factor authentication on email and remote access

If we could fix one thing across every business in Phoenix, it would be this. A stolen or guessed password is worthless to an attacker who also needs a code from your phone. Yet we still walk into offices where Microsoft 365, the VPN, and the remote-desktop gateway all accept a password alone.

The fix: Turn on MFA everywhere it’s offered, starting with email, remote access, and any admin account. In Microsoft 365, that means enforcing it through Conditional Access (or Security Defaults at minimum) and blocking legacy authentication protocols that quietly bypass MFA entirely. Use an authenticator app or hardware key rather than SMS where you can.

Mistake 2: Treating the firewall and antivirus as “set and forget”

A firewall you bought in 2019 with a lapsed subscription is a doorstop with a login page. The same goes for the free antivirus that came with the machine. Threats change monthly; a security product that isn’t updating and isn’t being watched is providing comfort, not protection.

The fix: Confirm your firewall’s security subscription is active and its firmware is current. Replace consumer-grade antivirus with a managed endpoint detection and response (EDR) tool that actually alerts someone when something is wrong. The alert is the point — software that catches a problem at 2 a.m. and tells no one hasn’t done much.

Mistake 3: Everyone’s a local administrator

It’s convenient to give staff full admin rights so they can install what they need. It’s also how a single click on a malicious attachment turns into an infection that spreads across the whole network instead of staying trapped in one user’s account. Most ransomware needs administrative privileges to do real damage.

The fix: Give day-to-day accounts standard-user rights. Keep admin credentials separate and use them only when installing or changing software. This one change dramatically limits how far an attacker or a bad download can travel.

Mistake 4: Assuming the backup works because it exists

This deserves its own article (and has one), but it belongs on this list. A backup you have never restored from is a hypothesis, not a safety net. We have watched businesses discover — mid-crisis — that their backup had been silently failing for months, or that it was sitting on a drive the ransomware also encrypted.

The fix: Keep at least one backup copy offline or immutable, so it can’t be reached and encrypted. Then test a restore on a schedule. If you can’t produce a working file from last night’s backup in a few minutes, you don’t yet have a backup you can trust.

Mistake 5: No plan for the human in the chair

Nearly every serious incident starts the same way — a person receives a convincing message and does what it asks. No firewall stops an employee from wiring money to a fake vendor or typing their password into a lookalike login page. The people are the perimeter now.

The fix: Run short, regular security awareness training — not an annual lecture, but ongoing, plain-language examples of what current scams look like. Pair it with a simple rule for anything involving money or credentials: verify out of band. A phone call to a known number beats a reply to a suspicious email every time.

The common thread

None of these fixes require a big budget or a security team. They require someone to own them and keep them current. That’s the actual gap in most small businesses — not a lack of tools, but a lack of anyone whose job it is to make sure the tools are turned on, updated, and watched.

If you’re not sure which of these five apply to you, that uncertainty is worth resolving before an attacker resolves it for you.

Want a straight answer on where you stand? Book a free 30-minute consult and we’ll walk through these five with your actual setup — no sales pitch, just where the gaps are