Microsoft Just Shipped Its Biggest Patch Ever — and Two Holes Are Already Being Attacked

Filed under: Cybersecurity · Patching · July 2026

What happened

On July 14, 2026, Microsoft released its monthly “Patch Tuesday” update — the largest in the company’s history, fixing a record 570 security flaws. Two of them are already being used in real attacks: a privilege-escalation bug in Active Directory Federation Services (CVE-2026-56155) and one in SharePoint Server (CVE-2026-50661 — a BitLocker bypass — was publicly disclosed but not yet exploited). More important for most small offices, the same update quietly fixes several “critical” flaws in Excel, Word, and PowerPoint that could let a booby-trapped document run malicious code the moment it’s opened, plus critical Windows bugs in DHCP and graphics.

Why it matters to your business

Every Phoenix small business runs Windows and Office, so this update touches essentially every PC in your office. The scary-sounding zero-days are in server products (AD FS and SharePoint) that most small firms don’t run on their own hardware — but the very same July patch closes the Office and Windows holes on your everyday laptops and desktops. A single un-patched machine where someone opens an emailed spreadsheet can be all an attacker needs to get a foothold, then move to your files, QuickBooks, and email.

What to do this week

Install the July updates on every computer now: Start → Settings → Windows Update → Check for updates, then reboot when prompted (the fixes don’t fully apply until you restart). Update Office too — in any Office app go to File → Account → Update Options → Update Now. If any machine is still on Windows 10, know that it stopped getting free security updates in October 2025 — those PCs should be upgraded to Windows 11 or replaced, because they will not receive these fixes. Turn on automatic updates so you’re not doing this by hand each month (Settings → Windows Update → Advanced options). If you happen to run SharePoint Server or AD FS on-premises, patch those immediately or call us — those are the ones already under active attack.

The bigger picture

A record-breaking patch is a reminder that the number of flaws keeps climbing, and attackers move within days of each release to hit whoever hasn’t updated yet. Staying patched on a schedule is the cheapest, highest-return security work you’ll ever do — far cheaper than cleaning up after the one machine everyone forgot. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Confident every computer in your office actually installed this month’s updates? Book a free consult → https://micro1tech.com/contact/

That “IT Support” Call on Teams Might Be a Hacker Taking Over Your PC

Filed under: Cybersecurity · Social Engineering · July 2026

What happened

Security researchers at Palo Alto Networks’ Unit 42 uncovered an active campaign in which criminals pose as your own IT support over Microsoft Teams. It starts with a phishing email — often an “Employee Survey” with a PDF attached — followed minutes later by a Teams voice call from an outside account claiming to be a “System Administrator.” The caller talks the employee into installing a legitimate remote-control tool like AnyDesk or HopToDesk, then uses that access to plant malware called EtherRAT that hands the attacker full control of the computer. This is happening in the wild right now, and researchers found the crooks are already on their ninth version of the installer.

Why it matters to your business

For a Phoenix small business, Teams and Microsoft 365 are everyday tools, and a friendly “IT is calling to fix something” feels completely normal — especially when there’s no in-house IT desk to check against. One employee granting remote access gives a stranger the keys to that machine: saved passwords, email, QuickBooks, client files, and a foothold to spread across your network. Because AnyDesk and HopToDesk are legitimate, widely-used programs, your antivirus usually won’t flag the initial break-in. The endgame is data theft, wire-transfer fraud, or ransomware.

What to do this week

Set one firm rule with your team: real IT never cold-calls to install software or take remote control — if someone does, hang up and call back on a number you already trust. In Teams, limit who can reach your staff from outside: open the Teams admin center (admin.teams.microsoft.com) → Users → External access, and block or tightly restrict unknown external domains and unmanaged Teams accounts. Make sure remote-control apps like AnyDesk, HopToDesk, TeamViewer, and Windows Quick Assist are only installed and used by your actual IT provider, and remove any your team doesn’t recognize. Finally, treat unexpected “Employee Survey” emails with PDF attachments as suspicious and report them.

The bigger picture

Attackers have shifted from breaking in to being invited in — the fastest route onto your network is now a convincing phone call, not a software flaw. Teaching your team to pause and verify before granting access is the control that stops this cold. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Want help locking down Teams and remote-access tools before a fake “IT” call gets through? Book a free consult — https://micro1tech.com/contact/

Scammers Are Now Phoning Your Staff to Hijack Microsoft 365 — and Passkeys Won’t Save You

Filed under: Cybersecurity • Phishing • July 2026

What happened

Since April 2026, a criminal crew that researchers track as “Pink” has been calling employees at small and mid-sized companies, posing as Microsoft or internal IT and claiming a “security upgrade” is required. On the phone, they walk the victim through a fake Microsoft 365 login and passkey-enrollment page in real time, capture the password and the MFA approval, sign in to the real account, then quietly register their own passkey so they keep access even after the victim changes their password. There is no software bug here — the attackers simply abuse the legitimate passkey feature Microsoft turned on in May. Security firm Okta detailed the campaign on July 8, 2026.

Why it matters to your business

Passkeys and multi-factor authentication are exactly what we tell every client to turn on — and this attack is built to defeat both by fooling a person on the phone instead of breaking any software. Once the crooks plant their own passkey, they own that mailbox and can silently read and download everything in SharePoint and OneDrive: your invoices, client records, tax documents, and banking details. For a Phoenix small business, one convincing call to a receptionist or bookkeeper can turn into wire fraud or a reportable data breach.

What to do this week

Tell every employee plainly: MicroOne (or your IT provider) will never phone you and walk you through adding a passkey or approving an MFA prompt — if you get that call, hang up and call us back on a number you already have. In the Entra admin center, review each user’s registered sign-in methods (Users > select the user > Authentication methods) and remove any passkey or authenticator you don’t recognize. Then tighten who can enroll: Entra ID > Security > Authentication methods > Passkey (FIDO2), and restrict registration to trusted devices. Finally, turn on a Conditional Access rule that blocks sign-ins from countries you don’t do business in.

The bigger picture

The lock on your accounts is only as strong as the person who can be talked into opening it, and attackers have simply moved from email to the phone. Coaching your team to recognize the pitch is now as important as any software setting. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Not sure who could add a passkey to your Microsoft 365 accounts right now? Book a free consult → https://micro1tech.com/contact/

Fake “Interpol Investigation” Emails Are Locking Up Small Businesses With Ransomware

Filed under: Cybersecurity · Ransomware · July 2026

What happened

Security researchers are tracking an active phishing campaign in which criminals pose as Interpol’s cybercrime unit. The emails claim your company is under investigation and link to a password-protected Proton Drive archive that supposedly holds “video evidence.” The file inside is really a program disguised as a video — opening it installs custom-built ransomware that encrypts your files and demands payment. Businesses across the U.S., Europe, Asia, and the Middle East have already been hit, spanning legal, medical, finance, media, and other everyday industries.

Why it matters to your business

This campaign is aimed squarely at small businesses without a dedicated IT or security team — exactly the kind of Phoenix companies most at risk. A “law enforcement is investigating you” email is engineered to make a busy owner or bookkeeper panic and click before thinking. There is no fixed ransom: the attackers size up your business only after they have locked your files, so even a small firm can face a painful demand — on top of downtime that stops billing, payroll, and QuickBooks cold.

What to do this week

Treat any unsolicited “law enforcement” email as a scam — real agencies don’t email you a Proton Drive link and a password. Turn on file extensions in Windows (File Explorer → View → Show → File name extensions) so a file named “evidence.mp4.exe” gives itself away. Never open password-protected archives from outside your company, and never run a file that asks you to “enable” or “unzip and open” it. Confirm your backups are running and kept offline or in a separate cloud account, and that MFA is on for email and Microsoft 365 or Google Workspace. Finally, give the people who handle email and invoices a quick heads-up that this exact scam is circulating.

The bigger picture

Ransomware crews keep leaning on fear and urgency because it works far better than any technical exploit, and once files are encrypted, paying rarely gets everything back cleanly. The only dependable “recovery” is not getting hit in the first place — layered email filtering, tested backups, and trained staff. Why the Only True Recovery from Ransomware Is Prevention

Would your backups actually survive a ransomware hit — or just look like they would? Book a free consult → https://micro1tech.com/contact/

A Fake Microsoft Login Can Hijack Your 365 Account in Seconds — No Password Needed

Filed under: Cybersecurity · Phishing · July 2026

What happened

Attackers have refined a trick called “ConsentFix,” an evolution of the “ClickFix” scam, that steals Microsoft 365 accounts without ever grabbing a password. The victim gets a real-looking Microsoft sign-in screen and is coached to drag a small “localhost” link into their browser, which quietly hands the attacker a live session token. Because the token is already an approved, signed-in session, it sails right past the account password and multi-factor authentication (MFA). Step-by-step instructions, working code, and video tutorials for this attack were posted to Russian cybercrime forums back in March, so it is no longer limited to skilled hackers.

Why it matters to your business

For most Phoenix small businesses, the Microsoft 365 mailbox is the crown jewels — it holds invoices, banking details, client files, and the password-reset links for everything else. Attackers scout targets on LinkedIn first, then send a tailored lure through trusted services like Dropbox or DocSend, so the message looks routine. One employee dragging one link can give a stranger full access to email, and MFA won’t save you because it was never challenged. From there it’s a short step to fake invoices, wire-transfer fraud, and messages sent to your clients in your own name.

What to do this week

Lock down who can approve apps: in the Microsoft Entra admin center (entra.microsoft.com), go to Identity → Applications → Enterprise applications → Consent and permissions → User consent settings, and set it to “Do not allow user consent” (or allow only verified publishers with low-impact permissions). Turn on the admin consent workflow on that same screen so approval requests route to you instead. Then tell your team the plain rule: Microsoft never asks you to drag or paste a link into your browser bar to log in — if a sign-in prompt does, stop and report it. Finally, in the Entra sign-in logs, spot-check for logins from unexpected cities or countries over the past two weeks.

The bigger picture

MFA is essential, but it is no longer a finish line — today’s attacks skip the password fight entirely and go after the human and the session token. Training your team to recognize the lure is now just as important as the technical controls behind it. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Not sure whether your Microsoft 365 is set up to block this? Book a free consult — https://micro1tech.com/contact/

Hackers Stole VPN Passwords From Thousands of Fortinet Firewalls — and Ransomware Gangs Have Them

Filed under: Cybersecurity · Network Security · July 2026

What happened

Researchers investigating “FortiBleed” — a massive credential-theft operation against Fortinet FortiGate firewalls — have now tied it directly to the INC and Lynx ransomware gangs. The attackers planted a traffic-sniffing tool on compromised firewalls to intercept VPN usernames and passwords as employees logged in, harvesting credentials from more than 73,000 devices; the operation targeted over 430,000 firewalls worldwide. Roughly 11,000 devices are believed to still be compromised, and investigators found backdoor admin accounts named “adminin” left behind on affected systems. This is confirmed real-world activity, not a proof of concept.

Why it matters to your business

FortiGate firewalls are common in small offices, often installed by a vendor years ago and rarely touched since. If yours was compromised, the passwords your staff use to connect remotely are sitting in a criminal database — and the groups holding them are ransomware operators whose business is getting into networks and encrypting everything. A firewall that was “fixed” by only changing passwords can still be compromised: if the sniffer is still on the device, new passwords get stolen too.

What to do this week

If your office firewall is a Fortinet: update it to the latest FortiOS firmware for your model, then — in that order — reset every VPN and admin password, since credentials changed before patching may already be captured. Check System → Administrators for any account you don’t recognize (especially “adminin”) and remove it. Turn on multi-factor authentication for VPN logins, and make sure the management interface isn’t reachable from the internet. Not sure what brand your firewall is or who manages it? Find out today — that answer shouldn’t be a mystery.

The bigger picture

Stolen credentials are the raw material of ransomware: gangs don’t need to hack your network if they can simply log in. Once they’re inside, recovery gets expensive fast — prevention is the only plan that reliably works. Why the Only True Recovery from Ransomware Is Prevention

Who last checked what’s running on your office firewall — and when? Book a free consult → https://micro1tech.com/contact/

Still Running Your Own SharePoint Server? A Ransomware Gang Is Hunting for It

Filed under: Cybersecurity · Ransomware · July 2026

What happened

A flaw in Microsoft SharePoint Server (CVE-2026-45659) is being actively exploited, and CISA added it to its Known Exploited Vulnerabilities list on July 1 with a July 4 patch deadline for federal agencies — about as urgent as those deadlines get. The bug lets attackers run their own code on the server remotely, and at least one group exploiting it, Storm-2603, follows up by deploying Warlock ransomware. Important: this affects on-premises SharePoint Server only — SharePoint Online, the version included with Microsoft 365, is not affected.

Why it matters to your business

Plenty of small businesses had a SharePoint server installed years ago for file sharing and haven’t touched it since — which is exactly the profile this gang targets. An old server sitting in a closet, reachable from the internet, missing patches: that’s not a file server anymore, it’s a ransomware entry point. If you’re fully on Microsoft 365, you can relax on this one. If you’re not sure which you have, that uncertainty is itself the finding.

What to do this week

Ask one question: “Do we run SharePoint on our own server?” If yes, apply Microsoft’s latest SharePoint Server security update now — not at the next maintenance window — and check whether the server actually needs to be reachable from the internet at all. If the server is old enough that it no longer gets updates, it’s time to plan a migration to SharePoint Online, where Microsoft does the patching for you.

The bigger picture

Ransomware gangs don’t break in through your newest system — they scan for the oldest thing you forgot you owned. Once files are encrypted, options shrink fast; the only reliable recovery is never letting them in. Why the Only True Recovery from Ransomware Is Prevention

Do you know every server your business still runs — and who’s patching them? Book a free consult → https://micro1tech.com/contact/

If Your Office Network Runs on Ubiquiti UniFi Gear, Patch It Now

Filed under: Cybersecurity · Network Security · July 2026

What happened Hackers are actively exploiting three maximum-severity flaws in Ubiquiti’s UniFi OS — the software running popular small-business network gear like the Dream Machine, Cloud Gateways, and Cloud Keys (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910). All three scored a perfect 10 out of 10: an attacker who can reach the device doesn’t need a password to take it over completely. CISA added them to its Known Exploited Vulnerabilities list on June 23 and gave federal agencies just three days to patch — its most urgent deadline.

Why it matters to your business UniFi is everywhere in small offices — it’s affordable, capable gear, and plenty of Phoenix businesses run their whole network on it. The catch: the box that controls your Wi-Fi and internet is exactly what you don’t want an attacker owning. From there they can watch traffic, redirect it, and reach every computer behind it — and network equipment rarely gets updated after installation, because nobody’s reminded to.

What to do this week Log into your UniFi console and check the firmware version under Settings → System (or Updates). Dream Machines, Cloud Gateways, Cloud Keys, and similar hardware need UniFi OS 5.1.12 or later; a standalone UniFi OS Server install needs version 5.0.8 or later. While you’re in there, turn on automatic firmware updates and make sure the management interface isn’t exposed to the open internet. Not sure what brand your network runs on? That’s worth finding out today.

The bigger picture Firewalls and routers only protect you while they’re current — a network device with a known, actively exploited hole is an open door, not a defense. Someone needs to own the job of keeping them patched. → [Proactive vs. Reactive IT Management]

Do you know who last updated your office router — or when? Book a free consult → https://micro1tech.com/contact/

Criminals Tried 81 Million Stolen Passwords Against Microsoft 365 — and MFA Didn’t Always Stop Them

Filed under: Cybersecurity · Cloud Account Security · July 2026

What happened Between June 12 and 26, attackers hammered Microsoft 365 accounts with more than 81 million login attempts, using username-and-password combinations leaked in old data breaches. Security firm Huntress confirmed 78 accounts compromised across 64 organizations — most of them small and mid-sized businesses. The twist: the attackers logged in through an automated back route (a legacy sign-in method called ROPC) that never shows an MFA prompt. Many victims had MFA turned on — it just wasn’t configured to cover this path.

Why it matters to your business If anyone at your company has ever reused a password that later showed up in a breach, that password may still open your Microsoft 365 door. “We have MFA” isn’t the same as “MFA covers everything” — common gaps include policies that apply only to admins, only to certain apps, only from “untrusted” locations, or that were left in report-only test mode. Once inside a mailbox, attackers read invoices, redirect payments, and phish your customers in your name.

What to do this week In the Microsoft Entra admin center (entra.microsoft.com → Protection → Conditional Access), confirm your MFA policy applies to all users and all cloud apps — not a subset — and that it’s set to “On,” not “Report-only.” Block legacy authentication with the built-in Conditional Access template. Then review Sign-in logs for waves of failed logins over the past three weeks, and reset any password that’s been reused across sites.

The bigger picture Old passwords never really die — they get sold, and eventually someone tries them on your front door. Strong account hygiene and correctly enforced MFA are the difference between a failed attempt and a hijacked mailbox. → [The First Line of Defense in Employee Data Misuse]

When did someone last actually check your MFA settings — not just confirm they exist? Book a free consult → https://micro1tech.com/contact/

119 ‘Helpful’ Browser Extensions Were Quietly Stealing Logins

What happened: Microsoft pulled 119 extensions from the Edge store tied to a single malware campaign nicknamed “StegoAd” — installed by roughly 2.6 million people. They posed as ordinary tools (ad blockers, VPNs, translators, video downloaders) and worked normally for a while, then “woke up” and started stealing: Google sign-in credentials and two-factor codes, session cookies for account hijacking, and — notably — WordPress admin logins. The same techniques work on any Chromium browser, not just Edge.

Why it matters to your business

Every extension your staff installs is a small program that can watch everything they do online — including logging into your business systems, email, and website. This campaign specifically harvested website admin credentials, which is exactly how a small business ends up with its own site defaced or used to attack its customers. And it hid by only activating on about 1 in 10 installs, so “it seems fine” means nothing.

What to do this week

Audit browser extensions on company machines and remove anything nobody can justify. Set a simple rule: no new extensions without approval, and judge by the developer’s reputation, not the star rating (fakes buy good reviews). If staff use Google or WordPress logins, rotating passwords and confirming two-factor is on is cheap insurance.

The bigger picture

This is the quiet version of the same threat we write about constantly: attackers don’t break the door down, they get an employee to hold it open. The defense isn’t a product — it’s knowing which everyday actions carry risk and having a policy for them: Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back.