Threat Briefs

Security news that actually affects your business

Active threats, urgent patches, and scams aimed at small businesses — filtered down to what matters for a Phoenix SMB, with plain-English steps you can act on.

That ‘Free Microsoft Security Scan’ Popup Wants You to Uninstall Your Real Antivirus

Filed under: Cybersecurity — Phishing & Scams — August 2026 What happened Researchers at Malwarebytes found a network of fake Microsoft-branded websites running phony “security scans.” The sites…

Read the brief

A Broken Windows Update Quietly Stopped Antivirus Scans From Finishing on PCs Worldwide

Filed under: Cybersecurity · Endpoint Protection · August 2026 What happened A Microsoft Defender signature update pushed out on August 18, 2026 caused Quick, Full, and Offline virus…

Read the brief

Got a ‘We Can Recover Your Ransomware Data’ Email Before You Even Knew You Were Hacked? It’s the Attacker Again

Filed under: Cybersecurity — Ransomware Scams — August 2026 What happened Security researchers uncovered a scam where a ransomware affiliate poses as a data-recovery company called “Ransom Busters.”…

Read the brief

Password-Guessing Attacks on Microsoft 365 Are Up 155x — and Half-Configured MFA Isn’t Stopping Them

Filed under: Cybersecurity — Microsoft 365 Login Security — August 2026 What happened Security firm Huntress reports that password-spraying attacks — where hackers try stolen or guessed passwords…

Read the brief

A Single Click on a Link Could Have Let Microsoft Copilot Quietly Leak Your Data

Filed under: Cybersecurity — Data Protection — August 2026 What happened Security researchers at Varonis found a flaw, nicknamed “CoSnitch” (CVE-2026-24301), in Microsoft Copilot Personal — the AI…

Read the brief

Chrome and Edge Have Two Critical Security Holes — Update Your Browser Today

Filed under: Cybersecurity — Patching — August 2026 What happened Google shipped a Chrome update fixing 15 security bugs, including two rated critical (CVE-2026-76034, CVE-2026-76036). Both let a…

Read the brief

A New Trick Lets Malware Steal Every Saved Password From Chrome and Edge — Even With Extra Protection Turned On

Filed under: Cybersecurity — Browser Security — August 2026 What happened Security researchers publicly released a technique that lets malware already running on a Windows PC quietly switch…

Read the brief

Is Your Office Router on a Botnet’s Hit List? A New Attack Is Hijacking Old NETGEAR, TP-Link, D-Link, and Zyxel Devices

Filed under: Cybersecurity — Network Security — August 2026 What happened Researchers uncovered a new botnet called “Evooo1Bot” that’s been hijacking internet-facing routers and firewalls since at least…

Read the brief

RingCentral Confirms 1.6 Million Accounts Were Breached — What to Do If Your Business Uses It

Filed under: Cybersecurity — Data Protection — August 2026 What happened RingCentral, the phone and messaging platform used by more than 600,000 businesses, has confirmed that an extortion…

Read the brief

A New Trick Lets Malware Slip Past Windows Defender Even on Fully Updated PCs

Filed under: Cybersecurity — Patching — August 2026 What happened A security researcher has published a proof-of-concept called “ShieldBreak” that bypasses a Windows Defender fix Microsoft shipped in…

Read the brief

Another SharePoint Bug Is Being Exploited Within Hours of the Fix Going Public

Filed under: Cybersecurity — Patching — August 2026 What happened Microsoft quietly patched a critical SharePoint flaw (CVE-2026-55040) back in July, but this week security researchers at Rapid7…

Read the brief

That Free CCleaner Download Could Be Secretly Logging Everything Your Employees Type

Filed under: Cybersecurity — Malware & Browser Security — August 2026 What happened Researchers found a fake website, ccleanerwind[.]top, built to look exactly like the real download page…

Read the brief

Microsoft’s August Update Fixes 400 Security Holes — Hackers Are Already Using One to Take Over PCs

Filed under: Cybersecurity — Patching — August 2026 What happened On August 11, 2026, Microsoft released its August “Patch Tuesday” update, fixing 400 security flaws — 42 of…

Read the brief

Researchers Found a Way to Fake a Microsoft Login Screen Inside an Email — Here’s What to Watch For

Filed under: Cybersecurity — Phishing — August 2026 What happened Security researchers presenting at Black Hat USA showed a new attack technique that hides malicious HTML and CSS…

Read the brief

That RingCentral Voicemail Email? It Might Be Phishing for Your Microsoft 365 Login

Filed under: Cybersecurity — Phishing — August 2026 What happened Researchers caught a commercial phishing kit called “Greatness” — sold for $289 a month on Telegram — running…

Read the brief

Switched to Passkeys for “Better Security”? Malware Can Now Steal Those Too

Filed under: Cybersecurity — Browser Security — August 2026 What happened Security researchers at Unit 42 disclosed three proof-of-concept attack methods, nicknamed “Pass-ta-key,” that let malware already running…

Read the brief

Your IT Provider’s Remote-Management Tool May Have Been Hacked — Here’s What to Ask Them

Filed under: Cybersecurity — Patching & Vendor Risk — August 2026 What happened N-able, maker of the N-central platform that thousands of IT service providers use to remotely…

Read the brief

That “Payment Received” Email From QuickBooks? Check It Twice Before You Click

Filed under: Cybersecurity — Phishing — July 2026 What happened Security researchers at MailGuard caught a new phishing campaign impersonating Intuit QuickBooks, spotted July 29, 2026. The email…

Read the brief

Traveling for Business? Hacked Hotel Wi-Fi Is Stealing Microsoft 365 Logins — and Skipping Right Past MFA

Filed under: Cybersecurity — Phishing — July 2026 What happened Researchers at ReliaQuest found attackers breaking into the Wi-Fi gateway devices at hotels and conference centers — across…

Read the brief

Your FortiGate Firewall May Still Be Compromised Even After You Patched It

Filed under: Cybersecurity — Patching — July 2026 What happened Fortinet’s FortiGate firewalls had a nasty bug last year: attackers who broke in could plant a symbolic link…

Read the brief

A New Windows Bug Lets Any User Grab Admin Powers — And There’s No Official Fix Yet

Filed under: Cybersecurity — Patching — July 2026 What happened A security researcher publicly released proof-of-concept code for a Windows flaw (nicknamed “LegacyHive”) that lets a regular, logged-in…

Read the brief

Still Running Your Own SharePoint Server? Attackers Are Breaking In Right Now

Filed under: Cybersecurity — Patching & Ransomware — July 2026 What happened Microsoft’s July Patch Tuesday fixed a critical flaw in on-premises SharePoint Server (CVE-2026-50522), but within days…

Read the brief

Your WordPress Website Could Be Hijacked Without a Password — Attackers Are Already Scanning for It

Filed under: Cybersecurity · Patching · July 2026 What happened On July 17, 2026, WordPress disclosed a critical flaw nicknamed “wp2shell” that lets an attacker take over a…

Read the brief

Microsoft Just Shipped Its Biggest Patch Ever — and Two Holes Are Already Being Attacked

Filed under: Cybersecurity · Patching · July 2026 What happened On July 14, 2026, Microsoft released its monthly “Patch Tuesday” update — the largest in the company’s history,…

Read the brief

Not sure if a threat affects you?

Book a free 30-minute consultation — we'll tell you straight whether you're exposed.

Book a free consult →