Filed under: Cybersecurity — Malware & Browser Security — August 2026
What happened
Researchers found a fake website, ccleanerwind[.]top, built to look exactly like the real download page for CCleaner, the popular free PC-cleanup tool. Anyone who downloads and runs the “installer” instead gets a malicious Chrome extension called GhostDesk quietly installed, which logs every keystroke, takes screenshots of open browser tabs, steals saved passwords and login cookies, and swaps out any cryptocurrency address copied to the clipboard. The same fake-installer trick is being used to spread copies of 7-Zip and Adobe Acrobat, all reporting back to the same attacker-controlled server. This isn’t proof-of-concept research — it’s an active campaign already infecting real users.
Why it matters to your business
Free utilities like CCleaner and 7-Zip are exactly the kind of thing an employee downloads on their own without asking IT first, often after clicking a sponsored search result rather than the real vendor site. Once GhostDesk is running in someone’s browser, an attacker can capture their Microsoft 365 or Google Workspace login, banking session, or QuickBooks password the moment it’s typed — no phishing email required, and no obvious sign anything is wrong.
What to do this week
Remind staff to download software only from the official publisher’s site (ccleaner.com, 7-zip.org, adobe.com) and never from a search ad or a link in an email or chat. In Chrome, have everyone check chrome://extensions for anything unfamiliar — especially extensions not installed through the Chrome Web Store — and remove it. If your business allows it, restrict who can install new browser extensions or desktop software on work machines. Anyone who installed a “cleanup” tool recently should run a full scan with Windows Defender or your antivirus and change their Microsoft 365, email, and financial passwords as a precaution.
The bigger picture
Attackers increasingly skip email phishing altogether and just wait for someone to search for free software — a reminder that “I found it on Google” isn’t the same as “it’s safe.” — Fake CCleaner installs GhostDesk Chrome spyware
Not sure what’s actually installed on your office computers? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Phishing — August 2026
What happened
Security researchers presenting at Black Hat USA showed a new attack technique that hides malicious HTML and CSS inside an email so it breaks out of its normal boundaries and messes with the mail program’s own interface. In one demonstrated chain against Outlook, the trick pops up a fake Microsoft sign-in box that looks like it belongs to the app itself and captures whatever password the reader types. A similar trick against Gmail was used to quietly send data out to an attacker’s server. This is proof-of-concept research only — the researchers found no evidence it has been used in real attacks yet, but the underlying flaws in Outlook and Gmail were still unpatched as of the August 6, 2026 publication date.
Why it matters to your business
Almost every Phoenix small business runs on Outlook, Gmail, or both, and this attack needs nothing more than the victim opening an email — no attachment, no link click required to start. Because the fake login box appears to come from inside a program employees already trust, it’s harder to spot than a typical phishing email, and it specifically targets the Microsoft 365 and Google Workspace credentials that unlock everything else in your business.
What to do this week
Make sure Outlook (desktop and web) and Chrome/Edge are set to auto-update, since fixes from Microsoft and Google will roll out as patches rather than a single big announcement. Remind staff that Microsoft 365 and Google will never ask for a password inside a pop-up that appears while simply reading an email — if a sign-in prompt shows up unexpectedly while previewing a message, close it and log in directly at office.com or google.com instead. If you haven’t already, turn on multi-factor authentication for every Microsoft 365 and Google Workspace account; it won’t stop every version of this attack, but it blocks the plain password theft variant cold.
The bigger picture
This is a reminder that browser-based email interfaces are their own attack surface, not just the messages inside them — the same category of trick showed up in this year’s Ubiquiti and hotel Wi-Fi login-hijack stories. — New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Not sure if your team would spot a fake login prompt? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Browser Security — August 2026
What happened
Security researchers at Unit 42 disclosed three proof-of-concept attack methods, nicknamed “Pass-ta-key,” that let malware already running on a Windows PC steal passkeys saved in Google Password Manager, Chrome’s built-in passkey vault. The most serious version can pull the master key that protects every passkey synced to a Google account straight out of Chrome’s memory — and unlike a stolen password, that key can’t be changed or revoked once it’s taken. This is research only, not an active attack: all three methods require a device to already be infected with other malware first, and there is no evidence of real-world use yet.
Why it matters to your business
Passkeys have been promoted as the fix for phishing, and more small businesses — including ones we work with — have started turning them on for Microsoft 365, Google Workspace, and banking logins. This research doesn’t undo that; a passkey still can’t be phished away over email or a fake login page. But it’s a reminder that a passkey is only as safe as the computer it lives on, and right now there’s no patch for this specific weakness — just the reality that basic malware protection matters more than ever.
What to do this week
Keep using passkeys — they still block the phishing attacks that steal most passwords. Alongside them, make sure Microsoft Defender (or your endpoint antivirus) is active and up to date on every Windows PC, and that no one has quietly turned off real-time protection. In Chrome, go to Settings > Privacy and security > Security and confirm “Enhanced protection” is turned on. Review who has local administrator rights on company laptops — fewer admin accounts means fewer easy footholds for malware to gain the access this attack depends on. There’s no fix to install yet, so watch for a Chrome or Google Password Manager update addressing it.
The bigger picture
Passwordless login is real progress, but it shifts the target from your password to your device — meaning antivirus, patching, and limiting admin rights matter just as much in a passkey world as they did in a password one. — The First Line of Defense in Employee Data Misuse
Curious whether your team’s devices are locked down enough to trust with passwordless logins? Book a free consult — https://micro1tech.com/contact/