Posts

Researchers Compromised One Junior Employee's Inbox. The AI Assistant Did the Rest

Image
New Research Email Fraud August 2026  ·  8 min read In a controlled exercise, a security research team set out to get from an ordinary staff account to the chief executive's mailbox without being caught — using nothing but the AI assistant already built into the email system. The assistant hid the security alerts, mapped the organisation, learned the executive's writing style, found a pending wire transfer, and drafted the message that redirected it. Every step was a legitimate feature working exactly as designed. Over the past two years, almost every business email system has quietly acquired an AI assistant. It summarises long threads, drafts replies, searches your history in plain English, and sets up rules for you. For most small businesses it appeared as part of a subscription they already paid for — switched on by default, useful immediately, and never once discussed in a security review. A security research ...

Your Business Internet Connection Might Be Someone Else's Alibi. The FBI Just Explained How.

Image
FBI Advisory Network Hygiene August 2026  ·  7 min read Most cyberattacks try to take something from you. This one is different: it doesn't steal your data, it borrows your identity on the internet. The FBI has warned that criminals are routing their traffic through home and small business internet connections — using ordinary devices as cover so their activity looks like it's coming from an ordinary business. Yours. Here's how a device gets quietly conscripted, what it costs you, and the short list of fixes. Every attack this series has covered has one thing in common: someone wanted something you had. Your credentials, your files, your customers' data, your money. The threat in this post breaks that pattern, and that's exactly why most businesses never see it coming. In a public service announcement, the FBI warned about what are called residential proxies. Strip out the jargon and the idea is simple....

Every Major Breach We've Covered This Year Bypassed MFA Without Stealing a Single Password. Here's What They All Had in Common.

Image
Synthesis Identity Security July 2026  ·  8 min read A forgotten credential that opened the door to two hundred companies. A phishing service that captured Microsoft 365 access without ever seeing a password. An autonomous attacker that harvested credentials and moved on within seconds. Three completely different stories with one shared mechanic — and once you see it, the thing your business should be protecting changes. The password was never the prize. The token is. Think about checking into a hotel. At the desk, they verify who you are — ID, card, the whole routine. It's careful, and it happens once. Then you're handed a key card, and from that moment on nobody asks for your ID again. The card is your identity. Anyone holding it gets into that room, and the door has no opinion about whether they're the person who checked in. That is almost exactly how logging into a modern business system works. You prove who you ar...

A Ransomware Attack Just Ran Itself From Start to Finish. When It Hit an Error, It Fixed Itself in 31 Seconds.

Image
Landmark Case AI Ransomware July 2026  ·  8 min read Researchers have documented what they believe is the first ransomware operation carried out end to end by an autonomous AI agent — no human typing commands, no human adapting the attack, no human deciding what to do next. It broke in, looked around, stole credentials, moved deeper, encrypted a production database and wrote its own ransom note. When one of its steps failed, it diagnosed the problem and fixed itself in half a minute. Here's what actually happened, and why it changes the math for small businesses specifically. Ransomware has always had a person somewhere in it. Someone chose the target. Someone typed the commands. Someone watched the intrusion and adapted when it hit a wall. Even the most automated attacks were scripts — written in advance by a human, running a fixed sequence, and breaking when reality didn't match the plan. In late June 2026, tha...