Threat Briefs

Security news that actually affects your business

Active threats, urgent patches, and scams aimed at small businesses — filtered down to what matters for a Phoenix SMB, with plain-English steps you can act on.

Your WordPress Website Could Be Hijacked Without a Password — Attackers Are Already Scanning for It

Filed under: Cybersecurity · Patching · July 2026 What happened On July 17, 2026, WordPress disclosed a critical flaw nicknamed “wp2shell” that lets an attacker take over a…

Read the brief

Microsoft Just Shipped Its Biggest Patch Ever — and Two Holes Are Already Being Attacked

Filed under: Cybersecurity · Patching · July 2026 What happened On July 14, 2026, Microsoft released its monthly “Patch Tuesday” update — the largest in the company’s history,…

Read the brief

That “IT Support” Call on Teams Might Be a Hacker Taking Over Your PC

Filed under: Cybersecurity · Social Engineering · July 2026 What happened Security researchers at Palo Alto Networks’ Unit 42 uncovered an active campaign in which criminals pose as…

Read the brief

Scammers Are Now Phoning Your Staff to Hijack Microsoft 365 — and Passkeys Won’t Save You

Filed under: Cybersecurity • Phishing • July 2026 What happened Since April 2026, a criminal crew that researchers track as “Pink” has been calling employees at small and…

Read the brief

Fake “Interpol Investigation” Emails Are Locking Up Small Businesses With Ransomware

Filed under: Cybersecurity · Ransomware · July 2026 What happened Security researchers are tracking an active phishing campaign in which criminals pose as Interpol’s cybercrime unit. The emails…

Read the brief

A Fake Microsoft Login Can Hijack Your 365 Account in Seconds — No Password Needed

Filed under: Cybersecurity · Phishing · July 2026 What happened Attackers have refined a trick called “ConsentFix,” an evolution of the “ClickFix” scam, that steals Microsoft 365 accounts…

Read the brief

Hackers Stole VPN Passwords From Thousands of Fortinet Firewalls — and Ransomware Gangs Have Them

Filed under: Cybersecurity · Network Security · July 2026 What happened Researchers investigating “FortiBleed” — a massive credential-theft operation against Fortinet FortiGate firewalls — have now tied it…

Read the brief

Still Running Your Own SharePoint Server? A Ransomware Gang Is Hunting for It

Filed under: Cybersecurity · Ransomware · July 2026 What happened A flaw in Microsoft SharePoint Server (CVE-2026-45659) is being actively exploited, and CISA added it to its Known…

Read the brief

If Your Office Network Runs on Ubiquiti UniFi Gear, Patch It Now

Filed under: Cybersecurity · Network Security · July 2026 What happened Hackers are actively exploiting three maximum-severity flaws in Ubiquiti’s UniFi OS — the software running popular small-business…

Read the brief

Criminals Tried 81 Million Stolen Passwords Against Microsoft 365 — and MFA Didn’t Always Stop Them

Filed under: Cybersecurity · Cloud Account Security · July 2026 What happened Between June 12 and 26, attackers hammered Microsoft 365 accounts with more than 81 million login…

Read the brief

119 ‘Helpful’ Browser Extensions Were Quietly Stealing Logins

Microsoft pulled 119 malicious browser extensions that harvested Google and WordPress logins from 2.6 million users. Why extension vetting matters — and what to check on company machines.

Read the brief

Update Chrome Now: Critical Flaws Let Attackers Escape the Browser

Google patched 18 Chrome vulnerabilities, including sandbox-escape bugs that turn a bad web page into a compromised machine. Update to 149.0.7827.196+ and restart the browser.

Read the brief

Attackers Are Turning Off Microsoft Defender — Check Your Version

CISA confirmed two actively-exploited flaws in Microsoft Defender. If it is your only endpoint protection, here is the version to check and why one layer is not a…

Read the brief

Not sure if a threat affects you?

Book a free 30-minute consultation — we'll tell you straight whether you're exposed.

Book a free consult →