A New Trick Lets Malware Slip Past Windows Defender Even on Fully Updated PCs

Filed under: Cybersecurity — Patching — August 2026

What happened

A security researcher has published a proof-of-concept called “ShieldBreak” that bypasses a Windows Defender fix Microsoft shipped in July, letting an attacker who already has a foothold on a PC escalate to full SYSTEM-level control — even on a fully patched Windows 11 or Windows Server 2025 machine. It works by tampering with files during a Defender cloud scan. As of this week there’s no official Microsoft patch, and there’s no evidence it’s being used in real attacks yet — it’s a public proof-of-concept, not an active threat.

Why it matters to your business

This isn’t a way for attackers to break into your network from the outside — it requires malware or an attacker to already be running on the machine. But that’s exactly the scenario a bad phishing click or a sketchy download creates every day. Since Windows Defender is the default, built-in antivirus on nearly every Windows PC your business owns, a bypass like this means the last line of defense on an already-infected machine may not hold.

What to do this week

Keep Windows fully updated (Start > Settings > Windows Update) so you’re ready the moment Microsoft ships a fix, and make sure Defender’s Tamper Protection is on (Windows Security > Virus & threat protection > Manage settings > Tamper Protection). Since this bug needs a foothold first, focus on preventing that foothold: remove standing local-admin rights from everyday user accounts, and keep training staff to recognize phishing emails and unexpected download prompts. Watch Microsoft’s security update guide for a fix in the coming weeks and apply it promptly once released.

The bigger picture

This is the second bypass researchers have found for the same underlying Defender flaw in a month, echoing the pattern we saw with the “LegacyHive” Windows bug in July — public disclosure racing ahead of an official fix. Layered defenses matter precisely because no single tool, including your antivirus, can be assumed unbreakable. New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

Not sure which of your PCs still have unnecessary local-admin accounts? Book a free consult — https://micro1tech.com/contact/

That Free CCleaner Download Could Be Secretly Logging Everything Your Employees Type

Filed under: Cybersecurity — Malware & Browser Security — August 2026

What happened

Researchers found a fake website, ccleanerwind[.]top, built to look exactly like the real download page for CCleaner, the popular free PC-cleanup tool. Anyone who downloads and runs the “installer” instead gets a malicious Chrome extension called GhostDesk quietly installed, which logs every keystroke, takes screenshots of open browser tabs, steals saved passwords and login cookies, and swaps out any cryptocurrency address copied to the clipboard. The same fake-installer trick is being used to spread copies of 7-Zip and Adobe Acrobat, all reporting back to the same attacker-controlled server. This isn’t proof-of-concept research — it’s an active campaign already infecting real users.

Why it matters to your business

Free utilities like CCleaner and 7-Zip are exactly the kind of thing an employee downloads on their own without asking IT first, often after clicking a sponsored search result rather than the real vendor site. Once GhostDesk is running in someone’s browser, an attacker can capture their Microsoft 365 or Google Workspace login, banking session, or QuickBooks password the moment it’s typed — no phishing email required, and no obvious sign anything is wrong.

What to do this week

Remind staff to download software only from the official publisher’s site (ccleaner.com, 7-zip.org, adobe.com) and never from a search ad or a link in an email or chat. In Chrome, have everyone check chrome://extensions for anything unfamiliar — especially extensions not installed through the Chrome Web Store — and remove it. If your business allows it, restrict who can install new browser extensions or desktop software on work machines. Anyone who installed a “cleanup” tool recently should run a full scan with Windows Defender or your antivirus and change their Microsoft 365, email, and financial passwords as a precaution.

The bigger picture

Attackers increasingly skip email phishing altogether and just wait for someone to search for free software — a reminder that “I found it on Google” isn’t the same as “it’s safe.” Fake CCleaner installs GhostDesk Chrome spyware

Not sure what’s actually installed on your office computers? Book a free consult — https://micro1tech.com/contact/

Microsoft’s August Update Fixes 400 Security Holes — Hackers Are Already Using One to Take Over PCs

Filed under: Cybersecurity — Patching — August 2026

What happened

On August 11, 2026, Microsoft released its August “Patch Tuesday” update, fixing 400 security flaws — 42 of them rated “critical.” One bug is already being used in real attacks: a flaw in a core Windows networking driver (CVE-2026-68820) that lets an attacker who’s already gotten a foothold on a PC grab full administrative control. Researchers tie the active attacks to the same North Korea-linked hacking group behind the “LegacyHive” bug we flagged a few weeks ago — and this update also ships the official fix for LegacyHive itself (CVE-2026-62832), which previously had no patch at all.

Why it matters to your business

Every Windows PC in your office is touched by this update, whether it’s running Office, QuickBooks, or just email and a browser. The actively-exploited bug doesn’t get an attacker in the door by itself — it’s the move they make right after, turning one compromised login or one bad email click into full control of the machine. For a small business without dedicated IT staff watching for this, a single unpatched laptop can be the difference between a contained incident and a full network breach.

What to do this week

Update every Windows PC now: Start > Settings > Windows Update > Check for updates, then restart when prompted — the fix doesn’t take effect until you reboot. Update Office separately in any Office app via File > Account > Update Options > Update Now. If you have machines still running Windows 10, remember free security updates stopped in October 2025 — those PCs need to move to Windows 11 or be replaced, since this and future patches won’t reach them. Turn on automatic updates (Settings > Windows Update > Advanced options) so this isn’t a manual chore every month.

The bigger picture

Patch Tuesday keeps getting bigger, and attackers are consistently ready to exploit the highest-value bugs within days of disclosure. A predictable monthly patch routine is the cheapest insurance you’ll ever buy against becoming that first target. Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Confident every PC in your office actually installed this month’s updates? Book a free consult — https://micro1tech.com/contact/

Your IT Provider’s Remote-Management Tool May Have Been Hacked — Here’s What to Ask Them

Filed under: Cybersecurity — Patching & Vendor Risk — August 2026

What happened

N-able, maker of the N-central platform that thousands of IT service providers use to remotely monitor and fix client computers, disclosed that attackers broke into N-central servers using a login bypass that let them get administrator access without a password (CVE-2026-18556). N-able’s first patch didn’t fully close the hole — a second exploitation path (CVE-2026-18577) was found days later — so it rushed out an emergency fix, build 2026.3.1.7, on August 2. Once inside a server, attackers used its built-in remote-control feature to reach the computers that server manages, then planted a hidden backdoor designed to survive a reboot and outlast the patch.

Why it matters to your business

If your business relies on an outside IT company for support rather than an in-house team, there’s a good chance they use a remote monitoring and management tool like this one to patch and troubleshoot your machines without a truck roll. That’s exactly what makes this software such a valuable target: one compromised management server can hand attackers a foothold into every client network it touches, including yours, through no fault of your own. It’s the same style of attack that hit small businesses through their IT providers in the 2021 Kaseya ransomware incident.

What to do this week

Ask your IT provider directly: “Do you use N-able N-central, and if so, have you upgraded to build 2026.3.1.7 or later?” Being on 2026.2 is not enough — that version was still exposed to the second bug. Ask whether they’ve checked managed devices for a service named “Cloudflared” or a stray svchost.exe sitting in a Users\Documents folder, both signs of the backdoor attackers left behind, since patching the server alone doesn’t remove access already planted on endpoints. If you run N-central yourself in-house, upgrade immediately and review ui_access_control.log and the BASupSrvc logs for Take Control sessions you don’t recognize.

The bigger picture

Your security is only as strong as the tools your IT vendor relies on, and a vendor that patches fast and checks for leftover backdoors — not just the version number — is doing the job right. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Not sure what remote-management tools are touching your network, or who’s watching them? Book a free consult — https://micro1tech.com/contact/

Your FortiGate Firewall May Still Be Compromised Even After You Patched It

Filed under: Cybersecurity — Patching — July 2026

What happened

Fortinet’s FortiGate firewalls had a nasty bug last year: attackers who broke in could plant a symbolic link that let them keep reading files on the device even after the security hole was patched. Fortinet issued a fix for that persistence trick too — but researchers just found a way around it by adding an extra slash into the web request, and CISA confirmed on July 27, 2026 that criminals are actively using this bypass in the wild (CVE-2025-68686). It only works on a device that was already compromised at some point, but it means old infections can survive a patch that was supposed to clean things up.

Why it matters to your business

FortiGate is one of the most common firewall brands sitting at the edge of small business networks here in Phoenix, and it’s the same product line involved in a wave of stolen VPN credentials we flagged a few weeks ago. If your firewall was ever compromised — even briefly, even a while back — this bug means attackers could still have a quiet foothold today, patch or no patch. That foothold is exactly how ransomware crews get back in after a business thinks it’s cleaned up.

What to do this week

Update FortiOS to the latest patched build (7.6.2, 7.4.7, or the current release for your version — check under System > Firmware in the FortiGate admin console). Don’t stop at patching: if your device runs any FortiOS version between 6.4 and 7.6.1 and has internet-facing SSL-VPN, have your IT provider check system logs and running config for unfamiliar admin accounts, scheduled tasks, or config changes you don’t recognize. If you’re not sure whether your firewall has ever been compromised, that’s worth a professional look rather than a guess.

The bigger picture

This is the second Fortinet-related warning for SMBs in a month — a reminder that patching alone doesn’t undo a break-in that already happened. U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

Not sure if your firewall has been checked for hidden footholds? Book a free consult — https://micro1tech.com/contact/

A New Windows Bug Lets Any User Grab Admin Powers — And There’s No Official Fix Yet

Filed under: Cybersecurity — Patching — July 2026

What happened

A security researcher publicly released proof-of-concept code for a Windows flaw (nicknamed “LegacyHive”) that lets a regular, logged-in user load an administrator’s registry hive and use it to escalate their own privileges. It affects every currently supported version of Windows, including machines fully patched with this month’s Patch Tuesday update. Microsoft has not shipped an official fix — this was disclosed publicly rather than reported to Microsoft first, so there’s no patch timeline yet. As of now, this is proof-of-concept only; there’s no evidence it’s being used in real attacks.

Why it matters to your business

The released exploit code is deliberately limited and still requires a second valid local account on the machine, so a random attacker on the internet can’t use it directly today. The real exposure is shared or multi-user PCs — front-desk computers, warehouse terminals, or any machine where more than one employee logs in with their own standard account. On one of those, this could let a lower-level employee’s account be used to seize full control of the machine.

What to do this week

Since Microsoft hasn’t patched this yet, the independent patching service 0patch released a free interim micropatch on July 20 covering all supported Windows versions — worth applying on any shared or multi-user workstations in the meantime. Separately, review which machines have more than one local user account and remove any that aren’t actually needed. Keep an eye out for Microsoft’s fix, likely at next month’s Patch Tuesday (August 11, 2026), and apply it promptly once available.

The bigger picture

This is the ninth Windows flaw the same researcher has disclosed publicly, without warning Microsoft first, in the last three months — a pattern that’s putting real pressure on Microsoft’s patch pipeline and leaving admins to fend for themselves in the gap. Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Want us to check whether your shared workstations need the interim patch? Book a free consult — https://micro1tech.com/contact/

Still Running Your Own SharePoint Server? Attackers Are Breaking In Right Now

Filed under: Cybersecurity — Patching & Ransomware — July 2026

What happened

Microsoft’s July Patch Tuesday fixed a critical flaw in on-premises SharePoint Server (CVE-2026-50522), but within days a public proof-of-concept leaked and attackers started using it for real. The bug lets an authenticated site user run their own code on the server, and once in, attackers are stealing the server’s cryptographic “machine keys” so they can keep quiet, persistent access even after the server is patched.

Why it matters to your business

This only applies if your business (or a vendor you use) hosts its own SharePoint server on-site rather than using SharePoint Online inside Microsoft 365 — but if that’s you, this is a serious problem. This is the second on-prem SharePoint crisis this year, and the stolen-key trick means a server that gets patched today could still have a hidden backdoor left over from before the patch. That’s exactly the kind of quiet foothold ransomware crews use to sit inside a network for weeks before pulling the trigger.

What to do this week

If you have an on-prem SharePoint Server (Subscription Edition, 2019, or 2016), confirm the July 2026 security update is installed — check Central Administration > Upgrade and Migration > Check Product and Patch Installation Status. Because attackers may have already stolen machine keys before you patched, don’t stop there: rotate the ASP.NET machine keys and recycle the IIS application pools afterward, and have someone check IIS logs for unfamiliar w3wp.exe child processes or unexpected DLLs. If any of this is unfamiliar, treat it as a “stop and call someone” moment rather than a DIY afternoon.

The bigger picture

On-prem SharePoint has now had two actively-exploited critical bugs in a single year, and each one requires this same scramble of patch-plus-key-rotation. For most small businesses, moving that workload to SharePoint Online removes this recurring fire drill entirely. Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Not sure if your file server setup is exposed to this? Book a free consult — https://micro1tech.com/contact/

Microsoft Just Shipped Its Biggest Patch Ever — and Two Holes Are Already Being Attacked

Filed under: Cybersecurity · Patching · July 2026

What happened

On July 14, 2026, Microsoft released its monthly “Patch Tuesday” update — the largest in the company’s history, fixing a record 570 security flaws. Two of them are already being used in real attacks: a privilege-escalation bug in Active Directory Federation Services (CVE-2026-56155) and one in SharePoint Server (CVE-2026-50661 — a BitLocker bypass — was publicly disclosed but not yet exploited). More important for most small offices, the same update quietly fixes several “critical” flaws in Excel, Word, and PowerPoint that could let a booby-trapped document run malicious code the moment it’s opened, plus critical Windows bugs in DHCP and graphics.

Why it matters to your business

Every Phoenix small business runs Windows and Office, so this update touches essentially every PC in your office. The scary-sounding zero-days are in server products (AD FS and SharePoint) that most small firms don’t run on their own hardware — but the very same July patch closes the Office and Windows holes on your everyday laptops and desktops. A single un-patched machine where someone opens an emailed spreadsheet can be all an attacker needs to get a foothold, then move to your files, QuickBooks, and email.

What to do this week

Install the July updates on every computer now: Start → Settings → Windows Update → Check for updates, then reboot when prompted (the fixes don’t fully apply until you restart). Update Office too — in any Office app go to File → Account → Update Options → Update Now. If any machine is still on Windows 10, know that it stopped getting free security updates in October 2025 — those PCs should be upgraded to Windows 11 or replaced, because they will not receive these fixes. Turn on automatic updates so you’re not doing this by hand each month (Settings → Windows Update → Advanced options). If you happen to run SharePoint Server or AD FS on-premises, patch those immediately or call us — those are the ones already under active attack.

The bigger picture

A record-breaking patch is a reminder that the number of flaws keeps climbing, and attackers move within days of each release to hit whoever hasn’t updated yet. Staying patched on a schedule is the cheapest, highest-return security work you’ll ever do — far cheaper than cleaning up after the one machine everyone forgot. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Confident every computer in your office actually installed this month’s updates? Book a free consult → https://micro1tech.com/contact/

That “IT Support” Call on Teams Might Be a Hacker Taking Over Your PC

Filed under: Cybersecurity · Social Engineering · July 2026

What happened

Security researchers at Palo Alto Networks’ Unit 42 uncovered an active campaign in which criminals pose as your own IT support over Microsoft Teams. It starts with a phishing email — often an “Employee Survey” with a PDF attached — followed minutes later by a Teams voice call from an outside account claiming to be a “System Administrator.” The caller talks the employee into installing a legitimate remote-control tool like AnyDesk or HopToDesk, then uses that access to plant malware called EtherRAT that hands the attacker full control of the computer. This is happening in the wild right now, and researchers found the crooks are already on their ninth version of the installer.

Why it matters to your business

For a Phoenix small business, Teams and Microsoft 365 are everyday tools, and a friendly “IT is calling to fix something” feels completely normal — especially when there’s no in-house IT desk to check against. One employee granting remote access gives a stranger the keys to that machine: saved passwords, email, QuickBooks, client files, and a foothold to spread across your network. Because AnyDesk and HopToDesk are legitimate, widely-used programs, your antivirus usually won’t flag the initial break-in. The endgame is data theft, wire-transfer fraud, or ransomware.

What to do this week

Set one firm rule with your team: real IT never cold-calls to install software or take remote control — if someone does, hang up and call back on a number you already trust. In Teams, limit who can reach your staff from outside: open the Teams admin center (admin.teams.microsoft.com) → Users → External access, and block or tightly restrict unknown external domains and unmanaged Teams accounts. Make sure remote-control apps like AnyDesk, HopToDesk, TeamViewer, and Windows Quick Assist are only installed and used by your actual IT provider, and remove any your team doesn’t recognize. Finally, treat unexpected “Employee Survey” emails with PDF attachments as suspicious and report them.

The bigger picture

Attackers have shifted from breaking in to being invited in — the fastest route onto your network is now a convincing phone call, not a software flaw. Teaching your team to pause and verify before granting access is the control that stops this cold. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Want help locking down Teams and remote-access tools before a fake “IT” call gets through? Book a free consult — https://micro1tech.com/contact/

Fake “Interpol Investigation” Emails Are Locking Up Small Businesses With Ransomware

Filed under: Cybersecurity · Ransomware · July 2026

What happened

Security researchers are tracking an active phishing campaign in which criminals pose as Interpol’s cybercrime unit. The emails claim your company is under investigation and link to a password-protected Proton Drive archive that supposedly holds “video evidence.” The file inside is really a program disguised as a video — opening it installs custom-built ransomware that encrypts your files and demands payment. Businesses across the U.S., Europe, Asia, and the Middle East have already been hit, spanning legal, medical, finance, media, and other everyday industries.

Why it matters to your business

This campaign is aimed squarely at small businesses without a dedicated IT or security team — exactly the kind of Phoenix companies most at risk. A “law enforcement is investigating you” email is engineered to make a busy owner or bookkeeper panic and click before thinking. There is no fixed ransom: the attackers size up your business only after they have locked your files, so even a small firm can face a painful demand — on top of downtime that stops billing, payroll, and QuickBooks cold.

What to do this week

Treat any unsolicited “law enforcement” email as a scam — real agencies don’t email you a Proton Drive link and a password. Turn on file extensions in Windows (File Explorer → View → Show → File name extensions) so a file named “evidence.mp4.exe” gives itself away. Never open password-protected archives from outside your company, and never run a file that asks you to “enable” or “unzip and open” it. Confirm your backups are running and kept offline or in a separate cloud account, and that MFA is on for email and Microsoft 365 or Google Workspace. Finally, give the people who handle email and invoices a quick heads-up that this exact scam is circulating.

The bigger picture

Ransomware crews keep leaning on fear and urgency because it works far better than any technical exploit, and once files are encrypted, paying rarely gets everything back cleanly. The only dependable “recovery” is not getting hit in the first place — layered email filtering, tested backups, and trained staff. Why the Only True Recovery from Ransomware Is Prevention

Would your backups actually survive a ransomware hit — or just look like they would? Book a free consult → https://micro1tech.com/contact/